Virus, hardware and now combofix problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by snickerdoodle, Nov 28, 2009.

  1. snickerdoodle

    snickerdoodle Private E-2

    My daughter has an Acer aspire 5520 laptop running Vista, 2.33 gigahertz AMD Turion 64 X2. She was clean and running fine until her first week of college when trying to get onto their wireless network. She had not (!) done the most recent MS updates, which it forced her to do first, had AVG 8.5/Spybot/Spyware blaster and windows firewall installed. It seemed to get hung up or take a veeerrry long time to update (she had only needed a few, some of which were optional), and she finally got it to load their software to run sometime the next day. However, when doing her scans immed afterwards, she found Spybot had detected Virtumonde in her registry and quarantined it. She had the option of running their (the college's) Norton or her AVG and stayed w/AVG.

    Fast forward a bit later, first sign of trouble was apparently when starting up, when it would get hung up, or would constantly turn on and off. Her computer does a start up repair, and though she says she didn’t use it, when unable to repair it offers system restore option.

    Next problem is finding her wireless connection, which indicated that there was no wireless card installed.

    Finally, she noticed it wasn’t reading her CD/DVD when she tried to use it.

    She brought it home Halloween weekend and after searching for driver/programs, I tried to reload the driver program from Acer for the wireless network, and it said it couldn’t be loaded because there was no card inserted. Searched EVERYTHING I could find and ran a BelArc report looking for hardware/programs for the CD drive and wireless, etc. and there is no indication of it having a CDRom drive or a wireless card (Says the hard drive is healthy though). She can’t find !!!! her original belarc report, which would have told me exactly what had originally been on there (told her how important it was to put it somewhere safe!) No sign of active virus, thought maybe something came loose or beginning of a hardware issue so hubby opened up the case and looked – nothing looked wrong (to a newbie anyway). Couldn’t find anything else to do – she took it back to school with her. Even tho it wasn't helpful for e-mail, she could still do her research papers until I could get my hands on it again. Had intended to do the read & run me and see if you guys found any sign of trouble from the virtumonde, as I was confused as to why her restore points seemed to disappear and other glitchy things were happening if this was just a wireless/cd rom issue.

    Thanksgiving and she's home and now it's unable to start normally MOST of the time and still no wireless and CD. Her uncle (just grad'td school for desktop computer stuff) took a look at it, discovered the original system restore point and did that (I would have waited to see what you recommended), but still found it wouldn't recognize CD or wireless. Thought the start-up was okay for a few hours, but then it started to do it's thing again (either stalling, or just turning on and off). After I reloaded the new AVG9, unistalled old expired Norton, did all the MS updates and made user changes, etc. you recommend, I ran addt’l virus scans (Windows live, etc.), did the read and run me first, and downloaded SASe, malwarebytes, etc., and nothing seems to be turning up in those scans; When I got to the step where I run Combofix (had a problem with getting the two anti-spyware to turn off (newly dowloaded AVG9-didn't know it had antispyware, and the superantispyware requested by read and run me) - combofix started to run and though I had the step-by-step directions up on MY computer, I noticed her computer didn't ask me to back up the windows registry or install the recovery console before it was up and running. It seemed to do the AutoScan quickly, completed all 50 stages, and then I placed a copy of that report on the desktop along with the other two.

    Then the problems really started::cry Would not allow me to unzip the RootRepeal (access is denied). Tried to go to IE to download from majorgeeks again in case it was corrupted and got the message "Illegal operation attempted on a registry key that has been marked for deletion." Also get that message when I try to use the e-mail, open the control panel, open MGtools.exe to run it, etc., etc. Tried to reboot and follow instructions for manually restoring IE, but of course, that didn't work. Still same message about registry keys being marked for deletion! :(

    I WAS able to use my thumbdrive to get her reports and will attach the three I could get before this problem started. There IS still actually an original system restore point (the rest seemed to disappear when I originally looked and she swears she didn't use any of them)and I do have the ability to back up to factory default because, of course it can't read any CD's . If it is virus or software issues, she’s prepared to wipe the hardrive and start over (she DID do a good job of always backing up her stuff). My concern is whether it is even going to work in the state it is now in after combofix, and if it turns out it's hardware-related. (I have just enough knowledge to get myself in trouble, and not enough to get back out!) The hardware end is all TOTALLY new to me - don't even know where the card would be and what it would look like! Please help!!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This was probably the best thing to try if System Restore option was possible, since your problems do not appear to be malware. It may be due to an update especially if one of the updates was a hardware type update. Never ever use hardware updates offered at MS Update. Only get updates for your PC hardware via the PC manufacturer. This may be why you have problems with your wireless connecton now and perhaps the CD too.


    As stated above, this would have been the choice since there is no malware or potentially backing out all updates including the installation of AVG9 to see what happens.

    Sounds like an incomplete uninstall/install which has affected the registry. Since these messages do not point out which registry keys are mark for deletion, it is difficult to impossible to find out on your own what needs to be fixed. This is where a Restore Point would come in handy to return the restristy to a point in time before the problem. You could go back to your first restore point again if you wish, but I think you are heading towards a reinstall.

    It is not from an infection. You were done in by some update.

    You need to post in the Software Forum for help on reinstalling. Or if you wish to try to fix the hardware problems post in the Hardware Forum, but you will have great difficult trying to repair things without a CD drive that works. If you have a factory recovery CD or partition, that may be your best course.
     
  3. snickerdoodle

    snickerdoodle Private E-2

    Okay, please tell me I have something more than an expensive paperweight on my hands! Since we'd already tried the system recovery to no avail, and only at that point reinstalled the MS updates (will take the hardware one into future advisement) I decided to do the factory default recovery from the partition, since we can't use the CD drive. It did the recovery just fine, said it was successfully installed and rebooted. Power on/power off/power on/power off... not a good sign right from the start. Hoped it just needed to reboot the first time to take effect, but then it just kept going (15 mins at least). I held the power button down for 4 secs to get it to stop and rebooted.... STOP message 0x0000005C (0x0000010B; 0x00000003; 0x00000000;0x00000000). Now it won't do anything, including even power off (I just unplugged it from the wall, it's running on the battery for now). Please tell me what I need to do next: I am thinking that this could not be software, after all? Do I need to refer to the Hardware forum? I have no idea what to do now. Thanks so much for your efforts and your patience!
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You will have to post in either the Hardware Forum or at Dell. As I said before, I think you have an issue due to downloading a hardware update via MS rather than from Dell and were biiten by this. Read the 2nd message in the below thread which basically repeats what I said:

    http://en.community.dell.com/forums/t/19249776.aspx

    This not the same exact laptop or company as you but the problem and error message are the same.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds