1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

Boot Issues - Possible Malware?

Discussion in 'General Malware And Security' started by IvyNoire, Jul 19, 2012.

  1. IvyNoire

    IvyNoire Registered Members

    Joined:
    Jul 19, 2012
    Messages:
    28
    Location:
    United States
    Operating System:
    Windows Vista Enterprise
    Hello, if this problem was addressed, I'm sorry for missing the topic for it. I have an acer aspire 5050-3371 that has windows vista 32 bit version on it. The problems started when I was browsing a forum and accidentally clicked on something. I cancelled the first part of it but accepted the one from adobe since I recognized the brand. Since then I have been getting the blue screen of death. I've tried a system restore and a factory restore but no luck. On a side note, the error message mentioned a problem with a .dll but now it says . sys. It shuts off before I can see it all. I am out of options and would really appreciate any assistance. Thank you.
    Some additional info: technical information: *** stop: 0x0000007e (0xc0000005, 0xf78cd160, 0xf790f870, 0xf790f56c)

    *** kdcom.dll - address f78cd160 base at f78cc000, datestamp 4f8f0f42


    That is what is written on the blue screen.
     
  2. BeeCeeBee

    BeeCeeBee ADMINISTRATOR IN MEMORY

    Joined:
    Apr 20, 2009
    Messages:
    7,201
    Location:
    New Jersey "Stronger than the Storm"
    Operating System:
    Windows 7
    I have a few questions for you.

    1. Are you able to boot to the advanced boot options menu? (Tap F8 repeatedly when your computer starts to boot. If you get the loading windows screen you will need to go back and try again)

    2. If the answer is yes, (the screen is black and has several options the first being safe mode.) is there an option to "Repair My Computer" or something similar?

    Regardless of your answer select "Last Known Good Configuration" by navigating with the arrows and press enter. Does that work? Eiter way let us know about the advanced boot options. If last known good config works, great!
     
  3. IvyNoire

    IvyNoire Registered Members

    Joined:
    Jul 19, 2012
    Messages:
    28
    Location:
    United States
    Operating System:
    Windows Vista Enterprise
    Hello and thanks for the reponse. I will have to try it once my laptop stop shutting down.
     
  4. BeeCeeBee

    BeeCeeBee ADMINISTRATOR IN MEMORY

    Joined:
    Apr 20, 2009
    Messages:
    7,201
    Location:
    New Jersey "Stronger than the Storm"
    Operating System:
    Windows 7
    I don't fully understand that reply.
     
  5. IvyNoire

    IvyNoire Registered Members

    Joined:
    Jul 19, 2012
    Messages:
    28
    Location:
    United States
    Operating System:
    Windows Vista Enterprise
    Sorry. Sometimes my laptop shuts down by itself due to heat, etc. Sometimes I have to wait a few minutes before I can start it up. I was able to start it up with the option you suggested. Is there something else I have to do?
     
  6. IvyNoire

    IvyNoire Registered Members

    Joined:
    Jul 19, 2012
    Messages:
    28
    Location:
    United States
    Operating System:
    Windows Vista Enterprise
    If there is an edit option, I did not see it because I'm on my iPod. I am not sure if I have to mention this but when I booted to the last known configuration, I cannot access the Internet and the system configuration utility is being blocked at start up.
     
  7. BeeCeeBee

    BeeCeeBee ADMINISTRATOR IN MEMORY

    Joined:
    Apr 20, 2009
    Messages:
    7,201
    Location:
    New Jersey "Stronger than the Storm"
    Operating System:
    Windows 7
    There is a strong possibility that you may have a malware infection but before we go that route let me just make sure that we understand where things are.

    If I get you right you have booted into last known good configuration and while it boots you are having internet issues and cannot get into certain tools, is that correct?

    Have you tried a system restore?
     
  8. IvyNoire

    IvyNoire Registered Members

    Joined:
    Jul 19, 2012
    Messages:
    28
    Location:
    United States
    Operating System:
    Windows Vista Enterprise
    That's correct. I tried system restore there is no restore point to go to. I tried factory restore but I get an error message. When I go to system restore it says: system restore does not appear to be functioning correctly on this system. The volume shadow copy service used by system restore is not working.
     
  9. BeeCeeBee

    BeeCeeBee ADMINISTRATOR IN MEMORY

    Joined:
    Apr 20, 2009
    Messages:
    7,201
    Location:
    New Jersey "Stronger than the Storm"
    Operating System:
    Windows 7
    For those who may be confused, I changed the Title to this thread. :)

    @ IvyNoir: What,if any, malware protection are you using? Antivirus etc?
     
  10. IvyNoire

    IvyNoire Registered Members

    Joined:
    Jul 19, 2012
    Messages:
    28
    Location:
    United States
    Operating System:
    Windows Vista Enterprise
    Windows defender
     
  11. BeeCeeBee

    BeeCeeBee ADMINISTRATOR IN MEMORY

    Joined:
    Apr 20, 2009
    Messages:
    7,201
    Location:
    New Jersey "Stronger than the Storm"
    Operating System:
    Windows 7
    If all you have is windows defender and nothing else that may be the cause of your current problem. You need to have a good antivirus program as well as a good antimalware program.

    There are many free AV programs but for now I would simply install Microsoft Security Essentials as well as the free version of Malwarebytes. If you are unable to gt on the internet with the computer in question than you need to download the programs from another machine and save the download to a flash drive. Insert the flashdrive into the bad machine and install the programs from there. Once they are installed scan your system thoroughly with both programs. Hopefully that may find the source of your problems. Otherwise you will need to either work with our excellent Malware Removal team or reinstall the whole thing and possibly lose data.

    I would back up or copy everything that is important to you (Data not programs) on an external drive or some DVDs.

    When I get back in a short while I can send you links to the download sites for the programs but they are easily googled.
     
  12. IvyNoire

    IvyNoire Registered Members

    Joined:
    Jul 19, 2012
    Messages:
    28
    Location:
    United States
    Operating System:
    Windows Vista Enterprise
    I will go search them on my fiancée's computer then report the results after I install and run them. Thanks so much.
     
  13. BeeCeeBee

    BeeCeeBee ADMINISTRATOR IN MEMORY

    Joined:
    Apr 20, 2009
    Messages:
    7,201
    Location:
    New Jersey "Stronger than the Storm"
    Operating System:
    Windows 7
    Run full scans with each program. It will take hours but what else does that machine have to do? If you can't get them to run report back on that too.
     
  14. IvyNoire

    IvyNoire Registered Members

    Joined:
    Jul 19, 2012
    Messages:
    28
    Location:
    United States
    Operating System:
    Windows Vista Enterprise
    The drive for the flash drive is not showing. I only see the c drive, d drive and the cd drive when I look for it.
     
  15. BeeCeeBee

    BeeCeeBee ADMINISTRATOR IN MEMORY

    Joined:
    Apr 20, 2009
    Messages:
    7,201
    Location:
    New Jersey "Stronger than the Storm"
    Operating System:
    Windows 7
    Oh boy! Do you get a new hardware beep and/or icon when you insert the drive? Have you tried every usb port available to you? Do you know how to get to your device manager? If so are there any warning icons (Exclamation points) near the usb ports?

    One easy way to get to the device manager is to right click on your "Computer" icon and select "manage" then select Device Manager from the left column.
     
  16. IvyNoire

    IvyNoire Registered Members

    Joined:
    Jul 19, 2012
    Messages:
    28
    Location:
    United States
    Operating System:
    Windows Vista Enterprise
    What I did is restart it in safe mode and ran the non updated version of malwarebytes. I'm having trouble finding a link to download microsoft security essentials because my fiancee's has windows 7 and my laptop runs windows vista and the official site only gives me the download options for windows 7
     
  17. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    and did MBAM manage to remove anything?
    Start Malwarebytes AntiMalware.
    Click on the logs tab.
    The logs are date stamped ... double click on the log that showed any infection items.

    .

    It'll open in notepad.

    Please copy/paste the report in your next reply.

    Instead of selecting Safe Mode..... try selecting Safe Mode with Networking.
    This is basically safe mode but should also enable the internet connection.
    Using this may let you update MBAM.
     
    Last edited by a moderator: Feb 4, 2014
  18. IvyNoire

    IvyNoire Registered Members

    Joined:
    Jul 19, 2012
    Messages:
    28
    Location:
    United States
    Operating System:
    Windows Vista Enterprise
    Here's the report: malwarebytes Anti-malware (trial) 1.62.0.1300
    Database version v2012.07.03.05
    Windows vista x86 NTFS (safe mode)
    Internet explored 7.0.6000.17037
    Kimberly :: Kimberly-PC

    Protection: Disabled

    7/19/2012 1:01:22 pm
    mbam-log-2012-07-19 (13-01-22).txt

    scan type: Full scan (C:\|D:\|)
    Scan options enabled: Memory | Startup | Registry | File system | Heuristics/Extra |
    Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 364086
    Time elapsed: 1 hour(s), 6 minutes(s), 29 second(s)
    Memory Processes Detected: 1
    F:\Setup.exe (PUP.Bundle.Installer.OI) -> 1292 -> Delete on reboot.
    Memory Modules Detected: 0
    (No malicious items detected)
    Registry Keys Detected: 1
    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
    (PUP.Mywebsearch) -> Quarantined and deleted successfully.
    Registry values Detected: 0
    Registry Data Items Detected: 0
    Folders Detected: 0
    Files Detected: 1
    F:\Setup.exe (PUP.Bundle.Installer.OI) -> Quarantined and Deleted successfully.
    (end)
     
  19. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Thanks for the report IvyNoire

    That database is about 2 weeks old, so should be ok for now.
    Did you try and boot into Safe Mode with Networking?
    Do you get a connection?
     
  20. IvyNoire

    IvyNoire Registered Members

    Joined:
    Jul 19, 2012
    Messages:
    28
    Location:
    United States
    Operating System:
    Windows Vista Enterprise
    I still cannot get a connection and my sound also does noy work. Even in safe mode with networking.
     

Share This Page