Laptop left on overnight, shuts off on own. When I bootup in Morning says problem shutting down and

Discussion in 'Windows 7 Help and Support' started by msinger70, Jul 20, 2012.

  1. msinger70

    msinger70 New Member

    Joined:
    Jul 20, 2012
    Messages:
    16
    Likes Received:
    0
    Laptop left on overnight, shuts off on own. When I bootup in Morning says problem shutting down and suggests I start windows in safe mode.

    It used to just hybernate. I would turn back on normally in the morning.

    I recently had a virus I removed that almost caused me to lose my hard drive.

    Then I was getting an error message everytime I started up that System couldn't find qwscn.ddl. I removed that ddl.

    Any advice would be great.

    Thanks

    Matt
     
  2. Dillon

    Dillon New Member

    Joined:
    Jul 20, 2012
    Messages:
    8
    Likes Received:
    0
    Hi Matt! Excuse me as I am a newbie to this forum, but I am experienced with Windows 7, this is normally the procedure of what happens when a laptop gets so hot that it resets itself. I would suggest going to hibernate mode.

    Try doing this and post the results.
     
  3. msinger70

    msinger70 New Member

    Joined:
    Jul 20, 2012
    Messages:
    16
    Likes Received:
    0
    Hey Dillon,

    It is set to hibernate after some time so I'm still a little baffled. I will try to keep an eye on it tonight and see if it gets hot or is not hibernating anymore.
     
  4. Saltgrass

    Saltgrass Excellent Member
    Microsoft Community Contributor

    Joined:
    Oct 16, 2009
    Messages:
    15,157
    Likes Received:
    393
    I will assumed you mistyped qwscn.ddl, but when dealing with viruses, you never know for sure.

    It seems your system is looking for the library. I suppose you do not know what utility needs it, or might it be connected to the virus?

    You could check msconfig.exe to see if it is being started there. Maybe if will give some more info.

    If you can't find any reference to it, there is another program you can download from Microsoft (Sysinternals) called Autoruns, that gives much more info than does msconfig.exe.
     
  5. msinger70

    msinger70 New Member

    Joined:
    Jul 20, 2012
    Messages:
    16
    Likes Received:
    0
    where do I look on msconfig.exe and what am I looking for?
     
  6. Saltgrass

    Saltgrass Excellent Member
    Microsoft Community Contributor

    Joined:
    Oct 16, 2009
    Messages:
    15,157
    Likes Received:
    393
    Use the start menu search box and type msconfig and hit enter.

    Go to the Startip tab and see of the driver is listed. If it is, uncheck it and reboot.

    If it isn't shown, you may want to use the Autoruns utility that will show you where it is trying to start.
     
  7. msinger70

    msinger70 New Member

    Joined:
    Jul 20, 2012
    Messages:
    16
    Likes Received:
    0
    Sorry if I sound stupid but which driver? I did uncheck one called Wikaaqzyy (C:\Users\Matt\AppData\Roaming\Ywebx\zuyv.exe) that was unknown. it is now checked again (which I didn't do).


    Also, my computer shut down on its own again last night and it wasn't hot.
     
  8. Saltgrass

    Saltgrass Excellent Member
    Microsoft Community Contributor

    Joined:
    Oct 16, 2009
    Messages:
    15,157
    Likes Received:
    393
    It doesn't look like you got rid of the virus..what anti-virus are you running, and have you tried any others, like Malwarebytes?
     
  9. msinger70

    msinger70 New Member

    Joined:
    Jul 20, 2012
    Messages:
    16
    Likes Received:
    0
    Malewarebytes is what I use
     
  10. nmsuk

    nmsuk Windows Forum Admin
    Staff Member Premium Supporter

    Joined:
    Sep 7, 2009
    Messages:
    2,708
    Likes Received:
    195
    Have you tried running Malwarebytes in safe mode? It should pick off anything it couldn't in windows proper.
     
    1 person likes this.
  11. Saltgrass

    Saltgrass Excellent Member
    Microsoft Community Contributor

    Joined:
    Oct 16, 2009
    Messages:
    15,157
    Likes Received:
    393
    If MSE or Malwarebytes, you may want to try a bootable version. If you go to the link, you can download, and then burn a bootable version of MSE to check your system during the boot process. Maybe it will find something.

    What is Windows Defender Offline?

    Hopefully nmsuk's suggestion will shed some light on the situation.
     
  12. msinger70

    msinger70 New Member

    Joined:
    Jul 20, 2012
    Messages:
    16
    Likes Received:
    0
    Just did and it didn't find anything.
     
  13. Saltgrass

    Saltgrass Excellent Member
    Microsoft Community Contributor

    Joined:
    Oct 16, 2009
    Messages:
    15,157
    Likes Received:
    393
    Viruses will usually protect themselves by installing another version that will re-install the first one. Sort of a backup system which has to be removed the same as the original.

    I would have hoped one of the two virus scanners you use would have found and removed the entire virus. But both MSE and Malwarebytes allows you to scan a single file. If you select the Wikaaqzyy file/folder (or the other one), and right click, you should have that option.

    In msconfig, the registry location of the entries is given. If Wikaaqzyy is still showing up, where in the registry is it located? A trick is to double click the column dividers to get the columns to expand to the needed width. You should be able to see the full registry entry and check to see if it is there.

    Do you remember if your first attempt to remove the virus ever identified it?
     
  14. msinger70

    msinger70 New Member

    Joined:
    Jul 20, 2012
    Messages:
    16
    Likes Received:
    0
    It removed the virus and on the next day removed 2 more with the same name. The virus was called Rogue.fakeHDD. The place where Wikaaqzyy is = C:\Users\Matt\AppData\Roaming\Ywebx\zuyv.exe. Malwarebytes found nothing on this.

    The .dll file I removed I did by following someone's instructions on Youtube.
     
  15. msinger70

    msinger70 New Member

    Joined:
    Jul 20, 2012
    Messages:
    16
    Likes Received:
    0
    To remove ther RunDDL Error I ran Regedit -->HKEY_CURRENT_USER-->Software-->Microsoft-->Windows-->current version-->Run-->qwscn.ddl --> Select it, Delete and OK.
     
  16. Saltgrass

    Saltgrass Excellent Member
    Microsoft Community Contributor

    Joined:
    Oct 16, 2009
    Messages:
    15,157
    Likes Received:
    393
    I am afraid I will not be much help in removing a virus, or what is left. I checked the name you gave and it appears to be a fake virus given by some sites to get you to let them check your system. But the Malwarebytes site indicates it can remove the virus completely. As with any type of virus, you really can't predict what it might be actually doing.

    I am still a little confused as to your spelling of qwscn.ddl is correct or you are just mistyping it.

    After you used regedit to remove the qwscn.ddl, has it come back?

    You may want to try renaming the Ywebx folder to see if it helps. If it is part of a virus which is still active, it may return with a different name.

    But again, I don't have much experience removing viruses.
     
  17. bassfisher6522

    bassfisher6522 Essential Member

    Joined:
    Aug 27, 2008
    Messages:
    4,878
    Likes Received:
    317
    Hey Saltgrass, has the OP tried running Malwarebytes, full scan in safe mode?
     
  18. Saltgrass

    Saltgrass Excellent Member
    Microsoft Community Contributor

    Joined:
    Oct 16, 2009
    Messages:
    15,157
    Likes Received:
    393
    From his responses, I think he has. I am thinking the fact part of the virus was removed, that Malwarebytes cannot recognize it.

    I am not even sure it is a virus, but it certainly looks like it. Any suggestions, since I am sure I have missed many contingencies?
     
  19. bassfisher6522

    bassfisher6522 Essential Member

    Joined:
    Aug 27, 2008
    Messages:
    4,878
    Likes Received:
    317
    I would re-run Malwarebytes in safe mode along with Super antivirus, Spybot S&D and Adware in safe mode doing full system scans. Also Kaperskys TDSSKiller in safe mode, you might try combofix as well in safe mode.
     

Share This Page

Loading...