Unexpected Shutdowns & intermittent link failure

Discussion in 'Malware Help (A Specialist Will Reply)' started by ChicagoWinters, Jun 27, 2010.

  1. ChicagoWinters

    ChicagoWinters Private E-2

    Two major symptoms on an HP laptop 4g RAM, 64-bit, Windows 7:

    Unexpected shutdowns. While using IE8, Windows will just shutdown and reboot.
    Also some links will not work and others will. Doesn't matter what website I'm using. Currently, I can't get anything on MajorGeeks to work and had to move to desktop to post a thread.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It would probably be a good idea to consider malware. You might want to talk a look at running the following, and when finished, if there is malware found, start a thread in the malware forum with the requested logs attached:

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. ChicagoWinters

    ChicagoWinters Private E-2

    Thank you. I am half way through that process. I thought you might recommend that. I won't be able to comment/respond again until Saturday or Sunday (July 3rd/4th). I currently am not in possession of the laptop. I didn't get finished last night with the "READ ME/RUN ME" section and I left this morning for North Carolina.

    Thank you for your guidance.
    ChicagoWinters.
     
  4. ChicagoWinters

    ChicagoWinters Private E-2

    First time I've attached stuff so please forgive me if I mess up.

    Finally got laptop back to run programs. Couldn't install Superspyware program. Had to use the portable version. Had a Trojan Vundo with 321 files infected. Yet when I went to Preferences to retrieve the removal information, there wasn't anything listed under Scanner Logs. Was that because I used the portabler version?

    Malware program: Got error message. MBAM_ERROR_Updating (120070,0,WinHttpSendRequest). I assume that's because I didn't have internet capabilities when running that one and it couldn't update. I have that log as I continued with the steps.

    Last, I have attached the log for MGTools. I've left defogger and AVG, etc. turned off as per instruction--which says to do that until you guys say different. Symptoms are still occurring. It was 25 mins. Reliability Monitor also shows trouble with the NVIDIA video driver.

    What would you have me do next?
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are still unable to get on the web, then you may need to post in the networking forum. There is only a few things that can be cleaned up. It would not be what is causing you to be unable to connect.

    Use add/remove programs to uninstall:
    Ask Toolbar

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    You also need to clean out your temp folders.

    Otherwise, your logs are clean.
     
  6. ChicagoWinters

    ChicagoWinters Private E-2

    Before I do your new instructions, I think I need to clarify a comment i made. First, it takes me a day or two to respond to your posts because I help out senior adults. I am retired but I am a part-time caregiver to end-of-life patients and I help other senior adults with their computers. This is the case currently with this laptop. It doesn't belong to me.

    When I stated "...I didn't have internet capabilities...", it was because Antispyware program was still running and it was time for the midnight shift so I kept it on and took the laptop with me to a patient's home where there is no internet connection which I needed in order to check for updates for the next part of the "Read Me First" instructions.

    I did not mean I couldn't get on the internet. I can connect fine, but after a dozen or so mouse clicks there's no response from the mouse. After that happens, that's when the laptop shuts down and reboots by itself.

    Owner of laptop says its been working much better since I ran "Read Me First" programs. Doesn't shut down as often.

    Another thing I was told: There are two operating systems on this laptop. Windows 7 is on C. Vista is on F: It's set to boot with C: only.

    Does any of this information change anything, or shall I continue with your instructions of July 4th?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok, then that explains some things. You can go ahead and finish the instructions from July 4th, but they are only minor issues. As to the shutting down issue, I would suggest you post in the software forum for that problem. Being a laptop, there is always the chance that the unit is overheating. Make sure all vents are clean and that it is exhausting hot air.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     
  8. ChicagoWinters

    ChicagoWinters Private E-2

    Okay. I've the laptop on for 2 hours working on the July 4th instructions and the post following that and there have been no unexpected shutdowns. However, I couldn't get your links to work so that symptom is still occuring. Links work for a while then quit. Another problem I'm now having is i can't get the firewalls and AVG stuff to re-enable. When I click to 'start service' (from Task Manager) it tells me Access is Denied. And of course when you open AVG9, the components aren't even there to re-enable. What have I done? Have I missed turning something back on?
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    All links? Or just links here on MG's? Do you have Ad-blocker installed on FF? Does it happen with IE?

    Have you tried uninstalling them both and then reinstalling them?
     
  10. ChicagoWinters

    ChicagoWinters Private E-2

    Sorry for not responding sooner. Troubled Laptop is out of town on a mission trip in Tennessee. Okay...AVG9 problems....I thought about reinstalling but didn't want to do anything major unless you guys suggested first.

    Next, hyperlinks stopping. It does it on all websites not just MG's. However, I don't know if hyperlinks quit working in Firefox. I will ask him to try using Firefox for a few days.

    Next, as far as I know there is no ad-blocker turned on.

    Also, laptop still rebooting itself, once or twice a day. The way it's being used currently, he turns it on mid-morning playing music to get the attention of the children in the area. After it's been on a while the laptop will make a buzzing sound for about 3-4 seconds then it reboots. He said yesterday after the buzzing it completely shut off, he couldn't get it to turn back on. He took the battery out, let it sit for 10 minutes then put it back in and the laptop was fine the rest of the day. He has the laptop elevated and he can feel the warm air from the fan. Could the fan not be working properly?

    Last, didnt you tell me to post this problem in software? That's where I started. How do I go back there. Do I open a new post? If so, how do I stop this one?

    Also, just an FYI, this is a laptop that I use on a consistent basis. I create very fancy Powerpoint slideshows with intense music cues and animations, moving mosaics/collages, etc. and other things that will ONLY work correctly with the 4G RAM. Slideshow timing cues don't stay perfect if the laptop is loaded with silly programs so the laptop is usually kept pretty "lean and mean" so to not interfere with my powerpt stuff.

    THanks you ever so much for all your help. Laptop will be home on Sunday. I'll reinstall the AVG9 and have answers for that and the FF usage at that time. --ChicagoWinters
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, having a weird sound just before it shuts down is a problem.. It very well may be that it is overheating caused by either the fan not working properly or just too much dust inside. Overheating can cause symptoms similar to malware issues. I would make sure it had a good blowing out once you have it back. Do let me know how things go when you have it again.
     
  12. ChicagoWinters

    ChicagoWinters Private E-2

    fyi...Just letting you know I have laptop now and using it 8-10 hours a day to get consistent symptoms. So far, Firefox is working fine with no link problem but laptop still shutting down. Will get back to you with more info in a couple of days. Thank you.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I suggest that you post in the software forum. If it is shutting down and restarting, then you need to stop that so you can get the error report from a BSOD. Right click my computer and choose properties/advanced tab and in startup and recovery, uncheck the box to restart on errors.
     
  14. ChicagoWinters

    ChicagoWinters Private E-2

    Update: I am having no "intermittent link failure" problems in Firefox. I've reinstalled AVG and all components are working correctly now. Finally able to turn Windows Firewall back on. Apparently I had completely shut it off, not just enabled/disabled.

    Still getting message "display driver stopped responding and has recovered" but that seems to be specifically a NVIDIA problem so I'm going to check out the Software forum on this site. Thanks ever so much for your time and ALL the help you've given me. You can close this post. --ChicagoWinters
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. Hope you get the driver issue straightened out.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds