Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Laptop making random "boing" sounds


  • This topic is locked This topic is locked
4 replies to this topic

#1 lakerbob

lakerbob

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:11:13 AM

Posted 02 April 2010 - 09:37 PM

Hello All,

My Dell Inspiron laptop running xp recently began making random "boing" noises. It does this at seemingly random intervals, sometimes several times an hour, or only once every hour or two. No rhyme nor reason, happens whether I'm using it or not. Here's my logs:

DDS (Ver_10-03-17.01) - NTFSx86
Run by Brennan at 19:27:58.37 on Fri 04/02/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.116 [GMT -7:00]

AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
svchost.exe
svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Brennan\Desktop\Downloads\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
uRun: [RoboForm] "c:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe"
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
IE: Customize Menu - file://c:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Fill Forms - file://c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {7F9DB11C-E358-4ca6-A83D-ACC663939424} - {9999A076-A9E2-4C99-8A2B-632FC9429223} - c:\program files\bonjour\ExplorerPlugin.dll
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1222144777562
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15111/CTPID.cab
Notify: AtiExtEvent - Ati2evxx.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\brennan\applic~1\mozilla\firefox\profiles\ua65bdpq.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?client=firefox-a&rls=org.mozilla:en-US:official&channel=s&hl=en&btnG=Google+Search&source=iglk
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

---- FIREFOX POLICIES ----
FF - user.js: general.useragent.extra.zencast - Creative ZENcast v2.01.01
============= SERVICES / DRIVERS ===============

R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-6-18 149040]

=============== Created Last 30 ================

2010-03-30 02:36:32 0 d-sh--w- c:\documents and settings\brennan\IECompatCache
2010-03-30 02:31:06 30 ----a-w- c:\windows\system32\brss01a.ini
2010-03-30 02:31:05 184 ----a-w- c:\windows\system32\brsvc01a.bsi
2010-03-30 02:31:04 419 ----a-w- c:\windows\BRWMARK.INI
2010-03-30 02:31:04 27 ----a-w- c:\windows\BRPP2KA.INI
2010-03-30 02:01:03 0 d-----w- c:\program files\Canon
2010-03-30 01:58:07 389180 ----a-w- c:\windows\system32\UCS32P.DLL
2010-03-30 01:58:06 40960 ----a-w- c:\windows\system32\CNQU77.DLL
2010-03-30 01:58:05 274432 ----a-w- c:\windows\system32\CNQL1208.dll
2010-03-30 01:58:05 0 d--h--w- C:\CanoScan
2010-03-30 01:46:50 32128 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2010-03-30 01:46:50 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2010-03-21 20:17:03 0 d-----w- C:\fca834c5d1dae1defc839ad94f
2010-03-21 20:16:08 1089593 -c----w- c:\windows\system32\dllcache\ntprint.cat
2010-03-16 02:05:57 0 d-----w- c:\windows\system32\XPSViewer
2010-03-16 02:03:25 117760 ------w- c:\windows\system32\prntvpt.dll
2010-03-16 02:03:24 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-03-16 02:03:23 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-03-16 02:03:23 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-03-16 02:03:23 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-03-16 02:03:22 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-03-16 02:03:22 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-03-16 02:03:20 0 d-----w- C:\f87a32a0f63d6e993d
2010-03-12 16:36:19 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2010-03-04 22:07:16 0 d-----w- c:\program files\Thomson Reuters

==================== Find3M ====================

2010-02-25 06:24:37 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-24 17:16:06 181632 ------w- c:\windows\system32\MpSigStub.exe

============= FINISH: 19:29:01.13 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 lakerbob

lakerbob
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:11:13 AM

Posted 03 April 2010 - 05:42 PM

any ideas anyone?

#3 lakerbob

lakerbob
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:11:13 AM

Posted 04 April 2010 - 01:09 PM

nevermind, it was googlebar gmail notifier

Attached Files


Edited by lakerbob, 04 April 2010 - 01:35 PM.


#4 Blade81

Blade81

    Bleepin' Rocker


  • Malware Response Team
  • 6,465 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:09:13 PM

Posted 07 April 2010 - 06:53 AM

Glad to hear it was nothing serious smile.gif

Your logs look ok but some updating to software there is needed. Please run Secunia vulnerability check here and fix its findings. It's recommended to run the check once or twice a month.

Microsoft Windows Insider MVP 2016-2017

Microsoft MVP Consumer Security 2008-2015
UNITE member since 2006
unite_blue.png

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.


#5 Blade81

Blade81

    Bleepin' Rocker


  • Malware Response Team
  • 6,465 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:09:13 PM

Posted 12 April 2010 - 12:01 PM

Since this issue appears to be resolved ... this Topic has been closed.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

Microsoft Windows Insider MVP 2016-2017

Microsoft MVP Consumer Security 2008-2015
UNITE member since 2006
unite_blue.png

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users