Does this sound like malware, or system file corruption?

General discussion and chat (archived)
User avatar
ron_1
Moon Magic practitioner
Moon Magic practitioner
Posts: 2860
Joined: 2012-06-28, 01:20

Does this sound like malware, or system file corruption?

Unread post by ron_1 » 2015-02-26, 02:46

Yesterday when I booted my computer, I got the "Windows is updating, do not turn off your computer (or whatever)" screen. Immediately I was concerned because I did not do any updates the day before, and I have updates set to notify, but not download, the updates. Eventually the log-in screen came up so I logged in and did what I was intending to do. Since I tend to be a little paranoid, when I was done I decided to do a Malwarebytes Anti-malware scan. I started the scan and left the room. Returning 5-10 minutes later, my computer was on the bios screen! I couldn't figure out how to get out of there, so I did a hard shutdown. I then restarted the computer and it booted normally (I mean other than getting the screen "Windows did not shut down properly"). I decided to try the scan again, but this time I first cleaned the drive using Ccleaner. After cleaning I noticed it deleted a larger amount than usual, about 750 megs. Upon close inspection, I notice one file was 700 megs, the CBS_log file under Windows System Log files. I did some quick research online and it seems the cbs log file is a Windows log file that lists system errors. Anyway, I did the MBAM scan and this time it completed, and came back clean. While doing the research on what is a cbs file, I also came across instructions on the "System File Check (SFC) scan." So I did that scan (verify only) and that scan came back "Windows did not find any integrity violations."

Being somewhat paranoid as already stated, today I did a whole C drive scan using 1) Windows Malicious Software Removal Tool; 2) MBAM (again); 3) Malwarebytes Anti-Rootkit; and 4) Avast; and all 4 came back clean.

So, as the header asks, does what happened to my computer yesterday sound like malware, or just a system file(s) corruption? It appears to me to be the latter, but I'd like the opinion of some experts (which I am not). Thanks.

superA

Re: Does this sound like malware, or system file corruption?

Unread post by superA » 2015-02-26, 08:29

Hi hellomustbegoing

..because I always like conspiracy theories..(and you rechecked that the setting in Windows Uptates is set to notify and havent changed),it seems to me that someone else played around with your pc,installed the updates and after shut it off.. :shh: :think:

User avatar
ron_1
Moon Magic practitioner
Moon Magic practitioner
Posts: 2860
Joined: 2012-06-28, 01:20

Re: Does this sound like malware, or system file corruption?

Unread post by ron_1 » 2015-02-27, 01:06

Nobody uses my computer but me. I just checked the setting in Windows updates; it's still on "check but let me choose when to download." I meant to do this yesterday but forgot. Thanks for reminding me.

User avatar
ron_1
Moon Magic practitioner
Moon Magic practitioner
Posts: 2860
Joined: 2012-06-28, 01:20

Re: Does this sound like malware, or system file corruption?

Unread post by ron_1 » 2015-02-27, 02:50

Should I take the lack of responses, save one, as an indication that I have nothing to worry about?

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35651
Joined: 2011-08-28, 17:27
Location: Motala, SE

Re: Does this sound like malware, or system file corruption?

Unread post by Moonchild » 2015-02-27, 11:09

helloimustbegoing wrote:Should I take the lack of responses, save one, as an indication that I have nothing to worry about?
You should take it as a fact that people don't spend every waking moment on the forum ;)

Unexpected behavior and unexpected reboots is never a good thing. I'd certainly make a thorough check for any sort of malware/trojans that may be present, double-check automatic updates settings, and in general do a full sweep of your system to see what's installed and running. Tools like process explorer may be your friend.
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

User avatar
Night Wing
Knows the dark side
Knows the dark side
Posts: 5174
Joined: 2011-10-03, 10:19
Location: Piney Woods of Southeast Texas, USA

Re: Does this sound like malware, or system file corruption?

Unread post by Night Wing » 2015-02-27, 12:47

@helloimustbegoing

Thought I would throw my two cents in on this topic.

I help out at a computer shop which is a half mile from my home. I do a lot of re-installing a straight Windows 7 operating system for people who want to re-install Windows 7 for some reason and don't want to use the recovery partition which contains all the original bloatware which came pre-installed on the computer when the computer was originally bought.

I also do all the updates from Microsoft. When I do those updates, I always use "Check for updates but let me choose to download and install them" instead of the default "Install updates automatically" in Windows Update. The automatic update prompt installs MS updates when the computer is shut down.

On some particular models of computers, some of the Microsoft security updates change the "Check for updates" prompt, back to "Install automatically". After each MS update install, I always have to go back to the Windows Update and make sure none of the MS security updates I've just installed haven't changed the Windows Update back to "automatic".

I think this is what happened to your computer in question.
Linux Mint 21.3 (Virginia) Xfce w/ Linux Pale Moon, Linux Waterfox, Linux SeaLion, Linux Firefox
MX Linux 23.2 (Libretto) Xfce w/ Linux Pale Moon, Linux Waterfox, Linux SeaLion, Linux Firefox
Linux Debian 12.5 (Bookworm) Xfce w/ Linux Pale Moon, Linux Waterfox, Linux SeaLion, Linux Firefox

User avatar
satrow
Forum staff
Forum staff
Posts: 1885
Joined: 2011-09-08, 11:27

Re: Does this sound like malware, or system file corruption?

Unread post by satrow » 2015-02-27, 13:31

Hmm, sounds right, there was one update in the last batch that had another update that was needed after a reboot, iirc.

gpatrick900

Re: Does this sound like malware, or system file corruption?

Unread post by gpatrick900 » 2015-02-27, 21:51

There are couple of things that can cause this. One is if you used disk clean-up and cleaned out the windows update files. The other is Microsoft updating windows update. Whenever, Microsoft updates windows update it is a forced update no mater what your setting is. I experienced both.

User avatar
ron_1
Moon Magic practitioner
Moon Magic practitioner
Posts: 2860
Joined: 2012-06-28, 01:20

Re: Does this sound like malware, or system file corruption?

Unread post by ron_1 » 2015-02-27, 23:37

satrow wrote:
there was one update in the last batch that had another update that was needed after a reboot
The day this happened I checked the history. The last Windows update installed was 2 days before. And I have Updates set to notify only anyway.
@Night Wing: I checked Updates and it is still set to notify only.
gpatrick900 wrote:
One is if you used disk clean-up and cleaned out the windows update files.
That would explain the Update screen on boot-up, but what about getting the bios screen during a MBAM scan?
Moonchild wrote:
You should take it as a fact that people don't spend every waking moment on the forum ;)
They don't?? :)

gpatrick900

Re: Does this sound like malware, or system file corruption?

Unread post by gpatrick900 » 2015-02-28, 01:12

I don't know what cause the bios screen to pop up.