Unhealthy Vista, BSOD & Failing Updates

Discussion in 'Malware Help (A Specialist Will Reply)' started by buffer1984, Nov 24, 2012.

  1. buffer1984

    buffer1984 Private E-2

    Received an HP Pavilion dv6000 laptop which hadn't been used for about 2 yrs.

    Reported issues:
    Wi-fi button showing Orange light even when in "on" mode.

    Vista hasn't been updated for years - though file 'updates being installed' message showed up during shutdown.

    On running 'PC Health Check' in 'Troubleshooting & Support' several tasks required urgent attention, including 'Hp Active Support Library' update, which unfortunately kept failing. (error 2908: could not register component) Now Health Check doesn't load up as it did first.

    On trying to log off from Admin a/c {2 A/c's: 1) Admin-Password protected & 2) Guest} computer crashes with blue screen.

    Tried downloading and installing driver updates with SlimDrivers but during installation of nVidia caused BSOD.

    No antivirus, malware or spyware detector had been installed. The laptop had met with a problem in the past, about 4-5 yrs back. Then the computer technician had installed Sophos Antivirus. That too has long since been updated and scanned for use. Sophos has been uninstalled.

    Cd burning software Roxio unable to detect Drive though Windows Explorer did detect it.

    Action Taken so far:
    Referred to Malware Removal Guide but failed to follow instructions as given. I truly apologise for this negligence as i couldn't gauge the intensity of the problem. I ran RogueKiller but deleted the earlier log after i tried fixing some errors. HitmanPro gave me 3 results of which 2 had been ignored and the third, which i believe wasn't a threat, was deleted. Rest of the logs from scans are available. I redid RogueKiller and HitmanPro for the logs.

    Installed SpywareBlaster and Spybot and ran scans. Installed Avira Antivirus and ran scan. 40 viruses detected, which after cleaning, the Wi-fi problem was solved.

    Additional Info:
    A complete scan of System Information(Advance) done with Tweaking.com available.
    There is a D: partition with "HP Recovery".
    I have another desktop computer available with internet.

    Please Help! Thanks.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now go to this MGTools and download the new version of MGtools.exe. Overwrite your previous MGtools.exe file with this one.

    Run the new C:\MGTools.exe and attach the new C:\MGlogs.zip
     
  3. buffer1984

    buffer1984 Private E-2

    Many thanks to you Kestrel13! for replying. I've attached the new MGlogs as required.
    Awaiting further instructions.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not seeing any malware really.

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode

    Rerun Hitman and have it delete the following:

    • C:\ProgramData\{FC0EF073-EDB5-4CBE-B92D-5CE9A223F37B}\OFFLINE\EB91CE86\3E688669\stbdl.exe
    • C:\ProgramData\{FC0EF073-EDB5-4CBE-B92D-5CE9A223F37B}\OFFLINE\B75FA91E\3E688669\stbsvc.exe

    Also have it delete any items under the heading Potential Unwanted Programs.

    Now rescan with Hitman again and attach that log.
     
  5. buffer1984

    buffer1984 Private E-2

    1. Used Msconfig.exe to enable Normal Startup and restarted comp.

    2. Right clicked and ran as Admin - scanned with HitmanPro and results showed 4 detections of which stbdl.exe & stbsvc.exe was deleted whereas 1 was reproted as a Trojan but it was Tweaking.com - simple system tweaker and another was named s/ (i think it was a key class) titled softonic which was ignored. There was no heading found - Potential Unwanted Programs.

    3. Without rebooting Reran HitmanPro for obtaining log but halfway through, the system crashed with the Blue Screen of Death. On restarting Windows normally, tried again to scan with HitmanPro and at 49% (c:\Users\User\AppData\Local\Temp\is-8A306.tmp\mbam-setup.tmp) a message appeared saying that HitmanPro needs to shut as there is a problem. I clicked to check for online solutions and I've pasted the given directions in notepad attached to this post. Sorry but I am unable to acquire a new log from HitmanPro.

    I also have some additional inputs to share with you:

    The Wi-fi problem "orange light in 'On' mode" had reappeared after I'd disabled Avira Antivirus when it required important updating. I then ran the Avira update and the Wi-fi was back on to blue. Afterwards the problem came back again and has remained that way. So now I have no Wi-fi.

    I've noticed that the battery runs low and drains off quite easily.

    Was informed that the motherboard that came originally with the laptop had been replaced as there was a defect. I don't know if the laptop would still be holding any hardware problems though the (drivers)device manager shows a very clean setup list.

    I'm very suspicious of virus and malware activity and maybe, as you say, incase these have been cleared (by having run the initial scans), Vista needs repairing and restoring. I remember earlier whenever Xp had problems I would follow the Malware Removal Guide for cleaning the problems and later run ComboFix which made the System running like new. I wonder if this machine will ever react to such a cure which never requires formatting or the Windows OS DVD.

    I'm quite concerned about the frequent system crashes.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  7. buffer1984

    buffer1984 Private E-2

    The MGlogs.zip file is attached.
    I'd first run it with Avira Enabled and it blocked one of the scans, so I ran it again after disabling it. I hope that wouldn't make a difference. Thanks.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Does this folder exist?

    C:\ProgramData\{FC0EF073-EDB5-4CBE-B92D-5CE9A223F37B}
     
  9. buffer1984

    buffer1984 Private E-2

    Yes, the folder exists

    What is the next step sir? Does the problem seem too severe?
    Thanks again for helping and also for your time. :)
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

     
  11. buffer1984

    buffer1984 Private E-2

    Hi Kestrel13!,
    :-o I truly apologise for my mistake and you are very kind & understanding for not taking offence either.

    I did as you asked me, to check for the 2 files:
    C:\ProgramData\{FC0EF073-EDB5-4CBE-B92D-5CE9A223F37B}\OFFLINE\EB91CE86\3E688669\stbdl.exe
    C:\ProgramData\{FC0EF073-EDB5-4CBE-B92D-5CE9A223F37B}\OFFLINE\B75FA91E\3E688669\stbsvc.exe

    The files don't exist.

    On transferring to the Software forum - does it require me to take a different approach towards explaining the difficulties I face? I mean, would this thread still hold good in there or would it end here? Please guide me to do the needful.:wave
    Thanks again for your help.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can link the guys and gals in the software forum to this thread here so they can check if need be. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  13. buffer1984

    buffer1984 Private E-2

    Just confirming whether I'm Malware free now and if it is OK to post in the software forums.

    This maybe software related: I read the article about "cleaning a compromised system" and felt that it was applicable in my case where the Vista system hasn't been updated for long. Does this mean that I have to go for a format and a clean install? I'll ask this in the software forum as well.:(

    Should I rerun all of the scans once i.e Avira AntiVirus, IObit Malware, Spybot? The Wi-fi problem got me :confused - again Software related?

    I'm Grateful for your help. Thanks.:)
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, software related. Please post there. :) Thanks.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds