also @ TechSpot: Android 4.0: Tracking Ice Cream Sandwich's Availability on Smartphones

TechSpot

[Solved] Computer freezing a lot + noises

Discussion in 'Virus and Malware Removal' started by hongtd, Nov 29, 2010.

Thread Status:
Not open for further replies.
  1. hongtd Newcomer, in training

    QuickScan Beta 32-bit v0.9.9.57
    -------------------------------
    Scan date: Sun Dec 05 21:58:04 2010
    Machine ID: 52B8ED91



    No infection found.
    -------------------



    Processes
    ---------
    hpwuSchd Application 2180 C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
    AVG IDS 1984 C:\Program Files (x86)\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
    AVG IDS 3860 C:\Program Files (x86)\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
    AVG Internet Security 3984 C:\Program Files (x86)\AVG\AVG9\avgam.exe
    AVG Internet Security 2428 C:\Program Files (x86)\AVG\AVG9\avgtray.exe
    AVG Internet Security 2292 C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
    Boingo Wi-Fi 3104 C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe
    CCP 3452 C:\Program Files (x86)\Sony\SmartWi Connection Utility\CCP.exe
    DivX Update 2676 C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
    Firefox 4312 C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    Firefox 6812 C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
    Google Chrome 1280 C:\Users\Tony\AppData\Local\Google\Chrome\Application\chrome.exe
    Google Chrome 2888 C:\Users\Tony\AppData\Local\Google\Chrome\Application\chrome.exe
    Google Chrome 2196 C:\Users\Tony\AppData\Local\Google\Chrome\Application\chrome.exe
    Google Chrome 6748 C:\Users\Tony\AppData\Local\Google\Chrome\Application\chrome.exe
    Google Chrome 6120 C:\Users\Tony\AppData\Local\Google\Chrome\Application\chrome.exe
    Google Update 2812 C:\Users\Tony\AppData\Local\Google\Update\1.2.183.39\GoogleCrashHandler.exe
    GPCore COM object 568 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
    HP Digital Imaging 4936 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
    HP Digital Imaging 3120 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
    HP Digital Imaging 2856 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
    HP Smart Web Printing 3364 C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_clipbook.exe
    ISB Utility 2612 C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
    iTunes 3160 C:\Program Files (x86)\iTunes\iTunesHelper.exe
    Java(TM) Platform SE Auto Updater 2 0 1308 C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    MgiSvr 4188 C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
    Microsoft® Windows® Operating System 4388 C:\Windows\SysWOW64\dllhost.exe
    Microsoft® Windows® Operating System 3496 C:\Windows\SysWOW64\svchost.exe
    PowerManager 5300 C:\Program Files (x86)\Sony\SmartWi Connection Utility\PowerManager.exe
    QUALCOMM Gobi Download Service 3732 C:\QUALCOMM\QDLService\QDLService.exe
    RAID Event Monitor 2168 C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    RAID Monitor 4544 C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
    RealPlayer (32-bit) 2824 C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
    Registry Mum 3912 C:\Program Files (x86)\Registry Mum\RegistryMumService.exe
    RightMark CPU Clock Utility 2056 C:\Program Files (x86)\RMClock\RMClock.exe
    SmartWi Connection Utility 4428 C:\Program Files (x86)\Sony\SmartWi Connection Utility\SmartWi.exe
    ThirdPartyAppMgr 5284 C:\Program Files (x86)\Sony\SmartWi Connection Utility\ThirdPartyAppMgr.exe
    VAIO Content Folder Watcher 4260 C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
    VAIO Entertainment 4928 C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
    VAIO Entertainment 4288 C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
    VAIO Event Service 4228 C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
    VAIO Event Service 4632 C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
    µTorrent 2748 C:\Program Files (x86)\uTorrent\uTorrent.exe


    Network activity
    ----------------
    Process firefox.exe (4312) connected on port 80 (HTTP) --> 204.2.249.75
    Process firefox.exe (4312) connected on port 80 (HTTP) --> 204.2.249.41
    Process firefox.exe (4312) connected on port 80 (HTTP) --> 74.125.229.4
    Process firefox.exe (4312) connected on port 80 (HTTP) --> 66.220.149.11
    Process firefox.exe (4312) connected on port 80 (HTTP) --> 204.2.249.8
    Process firefox.exe (4312) connected on port 80 (HTTP) --> 74.125.45.102
    Process chrome.exe (6748) connected on port 80 (HTTP) --> 74.125.229.19
    Process chrome.exe (6748) connected on port 80 (HTTP) --> 74.125.229.16
    Process chrome.exe (6748) connected on port 80 (HTTP) --> 74.125.229.16
    Process chrome.exe (6748) connected on port 80 (HTTP) --> 74.125.229.16
    Process chrome.exe (6748) connected on port 443 (HTTP over SSL) --> 74.125.45.95
    Process chrome.exe (6748) connected on port 80 (HTTP) --> 204.2.249.8
    Process chrome.exe (6748) connected on port 80 (HTTP) --> 204.2.249.66
    Process chrome.exe (6748) connected on port 80 (HTTP) --> 74.125.229.4
    Process chrome.exe (6748) connected on port 443 (HTTP over SSL) --> 74.125.229.16
    Process chrome.exe (6748) connected on port 80 (HTTP) --> 66.220.149.18
    Process chrome.exe (6748) connected on port 80 (HTTP) --> 209.170.117.66
    Process chrome.exe (6748) connected on port 80 (HTTP) --> 204.2.249.41
    Process chrome.exe (6748) connected on port 80 (HTTP) --> 204.2.249.41
    Process chrome.exe (6748) connected on port 80 (HTTP) --> 204.2.249.41
    Process chrome.exe (6748) connected on port 443 (HTTP over SSL) --> 74.125.229.11
    Process chrome.exe (6748) connected on port 443 (HTTP over SSL) --> 74.125.45.132
    Process chrome.exe (6748) connected on port 80 (HTTP) --> 66.235.143.118

    Process uTorrent.exe (2748) listens on ports: 18588
    Process VCSW.exe (4928) listens on ports: 51493


    Autoruns and critical files
    ---------------------------
    hpwuSchd Application C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
    Adobe Acrobat C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
    Adobe Reader and Acrobat Manager C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    AVG Internet Security C:\Program Files (x86)\AVG\AVG9\avgtray.exe
    Boingo.lnk C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk
    DivX Update C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
    Google Update C:\Users\Tony\AppData\Local\Google\Update\GoogleUpdate.exe
    HP Digital Imaging C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
    HpqSRmon Application C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
    ISB Utility C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
    iTunes C:\Program Files (x86)\iTunes\iTunesHelper.exe
    Java(TM) Platform SE Auto Updater 2 0 C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    Microsoft Office 2010 c:\program files (x86)\microsoft office\office14\grooveex.dll
    Microsoft® Windows® Operating System c:\windows\system32\userinit.exe
    QuickTime C:\Program Files (x86)\QuickTime\QTTask.exe
    RE.exe C:\Program Files\Registry Easy\RE.exe
    RealPlayer (32-bit) C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
    RightMark CPU Clock Utility Launcher C:\Program Files (x86)\RMClock\RMClockLauncher.exe
    SmartWi Helper C:\Program Files (x86)\Sony\SmartWi Connection Utility\SmartWiHelper.exe
    VAIO Event Service C:\Windows\system32\VESWinlogon.dll
    Windows Live Messenger C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
    µTorrent C:\Program Files (x86)\uTorrent\uTorrent.exe


    Browser plugins
    ---------------
    AcroIEHelperShim Library c:\program files (x86)\common files\adobe\acrobat\activex\acroiehelpershim.dll
    Adobe Acrobat C:\Program Files (x86)\Internet Explorer\plugins\nppdf32.dll
    Adobe Acrobat C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll
    AVG Internet Security c:\program files (x86)\avg\avg9\avgssie.dll
    BitDefender QuickScan C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie\0.9.9.57_0\npqscan.dll
    BitDefender QuickScan C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie\0.9.9.57_0\npqslauncher.dll
    Bonjour C:\Program Files (x86)\Bonjour\mdnsNSP.dll
    DivX Web Player C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
    downloadUpdater C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll
    downloadUpdater2 C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll
    getPlusPlus for Adobe 16248 C:\Program Files (x86)\Mozilla Firefox\plugins\np_gp.dll
    Google Update C:\Users\Tony\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll
    HP Smart Web Printing c:\program files (x86)\hp\digital imaging\smart web printing\hpswp_bho.dll
    HP Smart Web Printing c:\program files (x86)\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
    INIwallet60 ActiveX Control Module C:\Windows\Downloaded Program Files\INIwallet60.ocx
    Java Deployment Toolkit 6.0.220.4 C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
    Java(TM) Platform SE 6 U22 c:\program files (x86)\java\jre6\bin\jp2ssv.dll
    Java(TM) Platform SE 6 U22 C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
    Microsoft Office 2010 c:\program files (x86)\microsoft office\office14\grooveex.dll
    Microsoft Office 2010 C:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL
    Microsoft Office 2010 C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL
    Microsoft Office 2010 c:\program files (x86)\microsoft office\office14\urlredir.dll
    Microsoft® CoReXT c:\program files (x86)\common files\microsoft shared\windows live\windowslivelogin.dll
    Microsoft® CoReXT C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL
    Microsoft® Windows Media Player Firefox C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
    Microsoft® Windows® Operating System C:\Windows\System32\mswsock.dll
    Microsoft® Windows® Operating System C:\Windows\system32\napinsp.dll
    Microsoft® Windows® Operating System C:\Windows\system32\NLAapi.dll
    Microsoft® Windows® Operating System C:\Windows\system32\pnrpnsp.dll
    Microsoft® Windows® Operating System C:\Windows\System32\winrnr.dll
    Microsoft® Windows® Operating System C:\Windows\system32\wshbth.dll
    Mozilla Default Plug-in C:\Program Files (x86)\Mozilla Firefox\plugins\npnul32.dll
    npitunes.dll C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
    NPSWF32.dll C:\Windows\system32\Macromed\Flash\NPSWF32.dll
    NPWebSLLauncher.dll C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
    QuickTime Plug-in 7.6.8 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin.dll
    QuickTime Plug-in 7.6.8 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin2.dll
    QuickTime Plug-in 7.6.8 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin3.dll
    QuickTime Plug-in 7.6.8 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin4.dll
    QuickTime Plug-in 7.6.8 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin5.dll
    QuickTime Plug-in 7.6.8 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin6.dll
    QuickTime Plug-in 7.6.8 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin7.dll
    QuickTime Plug-in 7.6.8 C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
    QuickTime Plug-in 7.6.8 C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
    QuickTime Plug-in 7.6.8 C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
    QuickTime Plug-in 7.6.8 C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
    QuickTime Plug-in 7.6.8 C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
    QuickTime Plug-in 7.6.8 C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
    QuickTime Plug-in 7.6.8 C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
    RealJukebox NS Plugin C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll
    RealJukebox NS Plugin C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll
    RealPlayer Version Plugin C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll
    RealPlayer Version Plugin C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll
    RealPlayer(tm) G2 LiveConnect-Enabled P C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll
    RealPlayer(tm) G2 LiveConnect-Enabled P C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll
    SBS Starter ActiveX Control Module C:\Users\Tony\AppData\Local\AFCSBS\npAFCSbsStarter.dll
    SBS Starter ActiveX Control Module C:\Windows\Downloaded Program Files\AFCSbsStarter.ocx
    Silverlight Plug-In c:\Program Files (x86)\Microsoft Silverlight\4.0.50917.0\npctrl.dll
    Windows® Internet Explorer c:\windows\syswow64\ieframe.dll


    Scan
    ----


    No file uploaded.

    Scan finished - communication took 5 sec
    Total traffic - 0.08 MB sent, 1.40 KB recvd
    Scanned 1125 files and modules - 37 seconds

    ==============================================================================
  2. Broni Malware Annihilator

    Your computer is clean [IMG]

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

    Run OTL

    • Under the Custom Scans/Fixes box at the bottom, paste in the following:

    Code:
    :OTL
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post resulting log.

    2. Now, we'll remove all tools, we used during our cleaning process

    Clean up with OTL:

    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    3. Make sure, Windows Updates are current.

    4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC) weekly.

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. Run defrag at your convenience.

    11. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

    12. Please, let me know, how your computer is doing.
  3. hongtd Newcomer, in training

    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Public

    User: Tony
    ->Temp folder emptied: 383490 bytes
    ->Temporary Internet Files folder emptied: 5097112 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 101882273 bytes
    ->Google Chrome cache emptied: 8188902 bytes
    ->Flash cache emptied: 1131 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 74441 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 110.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default

    User: Default User

    User: Public

    User: Tony
    ->Flash cache emptied: 0 bytes

    Total Flash Files Cleaned = 0.00 mb

    Restore point Set: OTL Restore Point

    OTL by OldTimer - Version 3.2.17.3 log created on 12052010_221704

    Files\Folders moved on Reboot...
    C:\Users\Tony\AppData\Local\Temp\Composition Symbols for Profesora Botero.doc moved successfully.
    C:\Users\Tony\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
    File\Folder C:\Users\Tony\AppData\Local\Temp\~DF28D30BE025EB5F0A.TMP not found!
    File\Folder C:\Users\Tony\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{57696C3A-D36C-4361-8136-EACE71E8082F}.tmp not found!
    File\Folder C:\Users\Tony\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{81F71B34-3593-4DA8-A5DD-4CB619BE6C4E}.tmp not found!
    File\Folder C:\Users\Tony\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{A380163B-9398-4B6D-9547-C7B37689A205}.tmp not found!

    Registry entries deleted on Reboot...
  4. hongtd Newcomer, in training

    jeez this is so weird... its suddenly normal again... was there even something wrong with the computer?
  5. Broni Malware Annihilator

    I don't know what to tell you.
    There was only one bad entry removed by MBAM.
    Maybe....you know, when you feel bad and you finally decide to go to see a doctor, you already feel better.....LOL
  6. hongtd Newcomer, in training

    hahahhaha well thank you very much anyway for helping!! :D
  7. Broni Malware Annihilator

    You're very welcome [IMG]
  8. hongtd Newcomer, in training

    hi again.... hahah

    the problem has resurfaced although not as severe.....

    i clicked on VAIO care and instead of launching the application, a box poped up saying
    "External component has thrown an exception"

    and another box saying

    "to run VAIO care program, you need to log in to Windows with an account that has administrator privileges. VAIO care will exit."


    so could it be that some of my applications are bugged and that is why my computer is freezing a lot? the CPU usage is almost always below 10% and about 2GB of my 4gb is usually used. is there a program that can debug programs? like the VAIO care.
  9. Broni Malware Annihilator

    Well, it's hard to say...
    If something like that happened just once, I wouldn't worry much about it.
    Keep me posted...
  10. hongtd Newcomer, in training

    this is actually happening every time i click on vaio care. i used to use this program once a week to clean up my computer before my laptop started to act weird.

    also my computer still freezes A LOT. dont really think its a virus since we've done plenty of virus scans already. could it be a physical hard drive problem? because when it freezes, the hard drive light doesnt blink but stays on the whole time its frozen.
  11. Broni Malware Annihilator

    At this point.....

    In this forum, we make sure, your computer is free of malware and your computer is clean :)
    Because the access to malware forum is very limited, your best option is to create new topic about your current issue, at Windows section.
    You'll get more attention.
  12. hongtd Newcomer, in training

    oh wow. didnt even see this website had that section haha

    yeah ill do that and thanks so much for your help! :D
  13. Broni Malware Annihilator

    You're very welcome [IMG]
Thread Status:
Not open for further replies.