Options

frequent audio-video glitches and crashes - piano_p

Hello again,

I am afraid my pc is in need of assistance again and I ask for your help. The problem is that 1-2 weeks ago my pc started getting rather more slow, regarding the windows boot process and browsing with firefox. Even when moving the cursor around will often appear to lose/skip frames.

This last week I started noticing glitches in winamp: when I play music, quite often the sound becomes rather electronic, robotic and there are distortions in the sound. These have been increasing in frequency, and this problem has started happening when playing video on the web, for example in youtube, and when I watch .avi video files with windows media player or other programs like VLC or Media Player Classic.

I also notice crashes during the boot process, and after I manage to successfully boot I get the 'windows has recovered from a critical error' error message, quite a lot.
Some of these symptoms, but not at such an alarming frequency, I had about a month ago. The problem is worse now. Note however that occasionally playback will be okay, e.x. when listening to internet radio with winamp or when watching a video on yahoo news. Youtube seems to be affected the most, but not constantly: sometimes the sound will start playing in a garbled way, but smooth out -more or less- after some minutes of playing.

Here's the hijackthis log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:08:52 μμ, on 17/9/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.gr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Συνδέσεις
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [RegKillElbyCheck] "C:\Program Files\Elaborate Bytes\DVD Region Killer\ElbyCheck.exe" /L RegKill
O4 - HKLM\..\Run: [RegKillTray] "C:\Program Files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://maps.flash.gr/inc/activex/mgaxctrl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1194553914580
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe

--
End of file - 7980 bytes


PS I should add that since my last thread I haven't installed any new hardware or software, or visited any new pages than I used to, and that I've taken all the safety steps advised at the previous thread, quite a few of which I previously followed anyway. My pc is rather old and I would like your experienced view if it is perhaps any malware or other glaring software problem before I resort to sending it to a hardware doctor.

Comments

  • edited September 2009
    Hello. :)

    I see no major problems with your HJT log.

    Let's have you go HERE to run Panda ActiveScan 2.0
    • Click the big green Scan now button
    • If it wants to install an ActiveX component allow it
    • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
    • Once the scan is completed, please hit the notepad icon next to the text Export to:
    • Save it to a convenient location such as your Desktop
    • Post the contents of the ActiveScan.txt in your next reply.
  • edited September 2009
    Hello and thanks for your assistance. Furthermore, I see you're a Warcraft fan, which is a plus!

    The problem is that this test is taking too long and while it runs, the computer runs very, very slow; preventing me from using it for more essential tasks I would like to do. Within 20 minutes or so of starting the test, I've reached 24% and from that point it goes as fast as a thoroughly drunk snail. It's been running for 8 hours now and it's at 35%. I am disheartened.

    Yesterday, I tried it for the first time, but again after nearly 8 hours, it was at around 30%, but I had to shut down the computer, because I needed to sleep and the pc is making too much noise.

    40396581.th.jpg

    To give you an idea of the current test status, have a look at this image. When I had to shut down the test yesterday, even though I had one vulnerability and one suspicious file detected, when I aborted the test, I got a congratulatory message saying that my pc was free of infections.

    So, could you please offer any advice as to how I can make this test run faster?


    Oh, and as Katana has noted in my earlier thread, it could very well be a hardware problem. My pc is rather old and at the moment there's quite a lot of humidity where I live.
  • edited September 2009
    Oh boy, it finally finished after about 12 hours. I seem to have infected files, suspicious files and one vulnerability.

    Here's the log:


    ;***********************************************************************************************************************************************************************************
    ANALYSIS: 2009-09-19 23:17:06
    PROTECTIONS: 1
    MALWARE: 6
    SUSPECTS: 4
    ;***********************************************************************************************************************************************************************************
    PROTECTIONS
    Description Version Active Updated
    ;===================================================================================================================================================================================
    ESET Smart Security 3.0 3.0 Yes Yes
    ;===================================================================================================================================================================================
    MALWARE
    Id Description Type Active Severity Disinfectable Disinfected Location
    ;===================================================================================================================================================================================
    00400035 Adware/SaveNow Adware No 0 No No E:\System Volume Information\_restore{E39F291E-E2CD-4219-80CA-D980B00CFB85}\RP481\A0212983.exe[BSplayer_WhenUSave_InstallerInst.exe]
    00674637 Adware/WhenUSearch Adware No 0 No No E:\System Volume Information\_restore{E39F291E-E2CD-4219-80CA-D980B00CFB85}\RP481\A0212983.exe[BSplayer_WhenUSave_InstallerInst.exe][BSplayer_WhenUSave_InstallerInst.exe][BSplayer_WhenUSave_Installer.exe]
    01262593 Application/NirCmd.A HackTools No 0 No No E:\Utilities\ComboFix.exe[E:\Utilities\ComboFix.exe][nircmd.exe]
    03074964 Trj/CI.A Virus/Trojan No 0 Yes No E:\System Volume Information\_restore{E39F291E-E2CD-4219-80CA-D980B00CFB85}\RP481\A0214235.exe
    03899005 Generic Malware Virus/Trojan No 0 No No E:\Utilities\ComboFix.exe[E:\Utilities\ComboFix.exe][ntp.exe]
    03919041 Generic Malware Virus/Trojan No 0 Yes No E:\System Volume Information\_restore{E39F291E-E2CD-4219-80CA-D980B00CFB85}\RP481\A0214319.exe
    03919041 Generic Malware Virus/Trojan No 0 Yes No E:\System Volume Information\_restore{E39F291E-E2CD-4219-80CA-D980B00CFB85}\RP481\A0214234.exe
    ;===================================================================================================================================================================================
    SUSPECTS
    Sent Location
    ;===================================================================================================================================================================================
    No C:\Program Files\RADVideo\radinfo.exe
    No E:\System Volume Information\_restore{E39F291E-E2CD-4219-80CA-D980B00CFB85}\RP481\A0212977.exe
    No E:\System Volume Information\_restore{E39F291E-E2CD-4219-80CA-D980B00CFB85}\RP481\A0214885.exe
    No E:\System Volume Information\_restore{E39F291E-E2CD-4219-80CA-D980B00CFB85}\RP481\A0214957.exe
    ;===================================================================================================================================================================================
    VULNERABILITIES
    Id Severity Description
    ;===================================================================================================================================================================================
    120815 HIGH MS06-022
    ;===================================================================================================================================================================================
  • edited September 2009
    Please go to http://virusscan.jotti.org , click on Browse, and upload the following file for analysis:

    C:\Program Files\RADVideo\radinfo.exe

    Then click Submit. Allow the file to be scanned, and then please Copy/Paste the results here for me to see.

    If Jotti is busy, please go to http://www.virustotal.com.
  • edited September 2009
    I did the first test and it found nothing.

    link to test results
  • edited September 2009
    OK I see nothing wrong with your PC.

    It's time to remove ComboFix.

    Go to to Start > Run
    Type in box

    combofix /u

    Note: the space between the X and the /u

    Press Enter.

    This command will:

    Delete the following:
    ComboFix and its associated files and folders.
    VundoFix backups, if present
    The C:\Deckard folder, if present
    The C:_OtMoveIt folder, if present

    Reset the clock settings.
    Hide file extensions, if required.
    Hide System/Hidden files, if required.
    Reset System Restore.


    Even if you have no more queries, I would appreciate if you can reply once more to this thread so that I will be able to have this archived. Thanks. :)
  • edited September 2009
    When I went to the Start -> Run option, combofix /u was already saved there from the last time I ran it. So, now windows cannot find combofix, much less uninstall it.

    Also: what about the suspicious files, the infected files and the vulnerability detected by Panda ActiveScan 2.0?


    Finally, could you estimate what the problem is? I still will always get these audio glitches, both when I stream audio (e.x. in youtube videos or with internet radio via winamp) and during normal audio playback (e.x. when I play audio files in winamp or when I play video files in windows media player), but they 'miraculously' disappear if I keep playing the audio for more than 10 minutes; the problem will seem to fix itself somehow.
  • edited September 2009
    When I went to the Start -> Run option, combofix /u was already saved there from the last time I ran it. So, now windows cannot find combofix, much less uninstall it.
    OK then just delete ComboFix.
    Also: what about the suspicious files, the infected files and the vulnerability detected by Panda ActiveScan 2.0?
    Everything else detected is in your old System Restore points.
    Combofix /u was supposed to have cleared that, but since it won't work now you can flush it manually using the instructions here:
    http://safecomputing.umn.edu/guides/systemrestore.html

    Finally, could you estimate what the problem is? I still will always get these audio glitches, both when I stream audio (e.x. in youtube videos or with internet radio via winamp) and during normal audio playback (e.x. when I play audio files in winamp or when I play video files in windows media player), but they 'miraculously' disappear if I keep playing the audio for more than 10 minutes; the problem will seem to fix itself somehow.
    You may want to post this problem in another section of Icrontic. :)
  • edited September 2009
    1) Yes, but how?

    2) Done.

    After this, I think this thread can be closed. Thank you for your time and effort with this matter. Thank you very much!
  • edited September 2009
    Sorry for the late reply.

    Delete this file:
    E:\Utilities\ComboFix.exe
  • edited September 2009
    Thank you very much for everything. You could now close this thread if you wished so. Thanks again!
  • edited September 2009
    Glad we could be of assistance! This topic is now closed.

    If I have helped you, please consider making a personal donation (Paypal) to me at parasite[AT]parasitedb.com.
    To support Icrontic, click here:
    http://icrontic.com/support
    Donations are entirely voluntary in nature and will have no bearing on the future help that you may receive.

    If you wish to reopen your topic, please send a Private Message (PM) to Trogan or me with a link to your thread.

    If you are not the user who started this thread, you must start your own Thread instead :)
Sign In or Register to comment.