Fujitsu Lifebook N Series NH570 Laptop turns off suddenly

January 17, 2015 at 18:57:02
Specs: Win 7 ultimate
Hey and thanks for paying attention. My laptop has been turning itself off suddenly even when plugged in. By myself and Google, I couldn't figure out the problem to the issue. Ive tried taking out the main battery and run on AC power; issue still occurs.
When i turn it back on, the battery states 100%. When I launch a game like Vindictus, the laptop turns off again.

Overheating is not a problem because I tested with my hands.
It is a Lifebook N Series NH570 made in 2010.
Can you guys please tell me other things to test my laptop for the issue before I waste money on an extra AC adapter/battery that I hope it even arrives to my house.

message edited by DoEqual


See More: Fujitsu Lifebook N Series NH570 Laptop turns off suddenly

Report •


#1
January 17, 2015 at 20:33:36
Let me have a look at these logs for clues,

Please download Farbar Recovery Scan Tool and save it onto your Desktop. If your default download location is not the Desktop, drag it out of it's location onto the Desktop.
http://www.bleepingcomputer.com/dow...
If we have to run Farbar more than once, refer this SS.
http://i.imgur.com/yUxNw0j.gif
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) on the Desktop.
The first time the tool is run, it makes also another log (Addition.txt).
The logs are large, upload them using this, or upload to a site of your choosing. No account needed. Give us the links please.
http://www.zippyshare.com/
Instructions on how to use ZippyShare.
http://i.imgur.com/naG6t2T.gif
http://i.imgur.com/Vi9ZdIh.gif
http://i.imgur.com/1IZu5kP.gif


Report •

#2
January 18, 2015 at 08:41:53
Hands will not tell you if an internal component, such as the CPU, is overheating. This program will:
http://www.cpuid.com/

It is possible Farbar Recovery Scan Tool also checks temperatures - Johnw will advise.

Always pop back and let us know the outcome - thanks


Report •

#3
January 18, 2015 at 09:28:16
Sorry for the delay. The frequency of my laptop turning off is increasing, and the duration it stays idle is even shorter every time. Now only time can tell its fate.

I'd like to also mention that when I tried to launch Vindictus this morning again, it runs really well and smooth for the first 3 mins and then it started to slowly skip frames, therefore turning itself off.


Report •

Related Solutions

#4
January 18, 2015 at 09:36:57
That is very much what happens with overheating. To keep the ball rolling until Johnw returns, run the program in my link at #2 and see what the temperatures look like, particularly the CPU.

Always pop back and let us know the outcome - thanks

message edited by Derek


Report •

#5
January 18, 2015 at 10:00:01
I deeply appreciate your advice.

Core 0 : ~39C
Core 1 : ~42 - 48 C

And it just shuts off again while I was reading the temperatures.


Report •

#6
January 18, 2015 at 10:15:28
Thanks

I don't believe the temperatures posted should cause issues but it was best to check. Two things now come to mind, either malware or a hardware issue. The power adapter would not be on the top of my list.

Always pop back and let us know the outcome - thanks

message edited by Derek


Report •

#7
January 18, 2015 at 10:25:21
As Johnw should now be sleeping (about 2:25 am in his place), run MalwareBytes on it. Download from green button top right, here:
http://filehippo.com/download_malwa...
Before running the Threat Scan, go to Settings (at top) > Detection and Protection (at left) and put a check mark in "Scan for rootkits".

If it finds anything please copy/paste the log on here.

Always pop back and let us know the outcome - thanks


Report •

#8
January 18, 2015 at 11:17:09
Here are the FRST files:
http://www44.zippyshare.com/v/19C2s...
http://www44.zippyshare.com/v/G1XMS...

And Malwarebytes have found many non-malware files solely relating to SearchProtect.


Report •

#9
January 18, 2015 at 11:48:43
Please copy/paste the MalwareBytes log on here.

Also download and Save the file from here:
http://www.bleepingcomputer.com/dow...
Find the ADWCleaner download file and double click it to run the Scan (it is very quick). Please copy/paste the log for that on here too.

Always pop back and let us know the outcome - thanks


Report •

#10
January 18, 2015 at 13:49:25
Here you go:

Malwarebytes: http://www65.zippyshare.com/v/6ynjH...
AdwCleaner: http://www65.zippyshare.com/v/e9vfu...
*I have not clicked Clean nor Uninstall for AdwCleaner*

Thanks for helping me this far, I can't wait for this to be fixed.


Report •

#11
January 18, 2015 at 13:57:40
"*I have not clicked Clean nor Uninstall for AdwCleaner*"
Only click Clean & post the new log please.

message edited by Johnw


Report •

#12
January 18, 2015 at 14:12:01
Wow, ADWCleaner found a lot.

Always pop back and let us know the outcome - thanks


Report •

#13
January 18, 2015 at 16:53:17
haha I'm glad that it is.

I hope this one is different (cleaned)(auto-opened when rebooted): http://www44.zippyshare.com/v/ZEoWy...


Report •

#14
January 18, 2015 at 16:58:35
Run Junkware Removal Tool
http://www.softpedia.com/get/Securi...
http://www.bleepingcomputer.com/dow...
http://thisisudax.blogspot.com.au/2...
Download Junkware Removal Tool onto your Desktop. If your default download location is not the Desktop, drag it out of it's location onto the Desktop.
Warning! Once the scan is complete JRT will shut down your browser with NO warning.
Shut down your protection software now to avoid potential conflicts.
Temporarily disable your antivirus and any antispyware real time protection before performing a scan.
Click this link to see a list of security programs that should be disabled and how to disable them.
http://www.bleepingcomputer.com/for...
http://www.techsupportforum.com/for...
Run the tool by double-clicking it. If you are using Windows Vista or Windows 7/8, right-click JRT and select Run as Administrator.
The tool will open and start scanning your system.
Please be patient as this can take a while to complete depending on your system's specifications.
On completion, a log (JRT.txt) is saved onto your Desktop and will automatically open.
Copy and Paste the contents of the JRT.txt log please.

Report •

#15
January 18, 2015 at 17:42:54
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.1 (12.28.2014:1)
OS: Windows 7 Ultimate x64
Ran by duynguyen on 01/18/2015 Sun at 17:04:42.17
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


~~~ Services

~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
Successfully deleted [Registry Value] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs\\bProtectTabs

~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110211671166}
Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{84BFE29A-8139-402a-B2A4-C23AE9E1A75F}
Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{84BFE29A-8139-402a-B2A4-C23AE9E1A75F}
Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0C21091-FF8E-432C-9006-0540E81BA9D7}
Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{D0C21091-FF8E-432C-9006-0540E81BA9D7}
Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{84BFE29A-8139-402a-B2A4-C23AE9E1A75F}
Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{84BFE29A-8139-402a-B2A4-C23AE9E1A75F}
Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0C21091-FF8E-432C-9006-0540E81BA9D7}
Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{D0C21091-FF8E-432C-9006-0540E81BA9D7}

~~~ Files

~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\tencent"
Successfully deleted: [Folder] "C:\Users\duynguyen\AppData\Roaming\tencent"
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"

~~~ Event Viewer Logs were cleared

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 01/18/2015 Sun at 17:16:25.84
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Report •

#16
January 18, 2015 at 17:54:11
"I hope this one is different"
No, refer my screenshot.

http://i.imgur.com/phb9znS.gif


Report •

#17
January 18, 2015 at 18:07:16
Run RogueKiller
http://www.softpedia.com/get/Securi...
http://majorgeeks.com/RogueKiller_d...
http://www.geekstogo.com/forum/file...
http://tigzy.geekstogo.com/roguekil...
http://www.sur-la-toile.com/RogueKi...
User Guide
http://www.adlice.com/softwares/rog...
Official tutorial
http://www.adlice.com/softwares/rog...
How to Temporarily Disable your Anti-virus
http://www.bleepingcomputer.com/for...
http://www.techsupportforum.com/for...
If RogueKiller won't run, open IE & turn off SmartScreen Filter.
http://windows.microsoft.com/en-AU/...
Download & SAVE to your Desktop. If your default download location is not the Desktop, drag it out of it's location onto the Desktop.
Quit all programs that you may have started.
Shutdown your antivirus to avoid any conflicts.
Please disconnect any USB or external drives from the computer before you run this scan!
For Vista or Windows 7/8, right-click and select "Run as Administrator to start"

For Windows XP, double-click to start.
Wait until Prescan has finished ...
Then Click on "Scan" button
Wait until the Status box shows "Scan Finished"
Click on "Delete"
Wait until the Status box shows "Deleting Finished"
Click on "Report" and Copy & Paste the content of the Notepad into your next reply.
The log should be found in RKreport[1].txt on your Desktop.
Exit/Close RogueKiller.
When completed make sure to re-enable your antivirus.

Report •

#18
January 18, 2015 at 19:22:37

Report •

#19
January 18, 2015 at 19:35:47
Copy & Paste the text below ( starting closeprocesses: ), save it into Notepad on your Desktop & name it fixlist.txt
NOTE: It is important that Notepad is used. The fix will not work if Word or some other program is used.
NOTE: It is important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system.

closeprocesses:
emptytemp:
Assistant (HKLM-x32\...\{5F189DF5-2D05-472B-9091-84D9848AE48B}{699fd52f}) (Version: - Verified Publisher) <==== ATTENTION
GreatArcadeHits (HKU\S-1-5-21-3241693270-3966368004-441874098-1000\...\{856AD396-519D-4C7A-BED6-6785F64924BC}) (Version: 1.0 - GreatArcadeHits) <==== ATTENTION
GreatArcadeHits (HKU\S-1-5-21-3241693270-3966368004-441874098-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\{856AD396-519D-4C7A-BED6-6785F64924BC}) (Version: 1.0 - GreatArcadeHits) <==== ATTENTION
GreATSSave4U (HKLM-x32\...\{45606A90-3363-3A3B-1C15-C40E77F4DAA0}) (Version: - GraeaattSavee4U) <==== ATTENTION
Iminent (x32 Version: 6.42.32.0 - Iminent) Hidden <==== ATTENTION
IObit Apps Toolbar v10.3 (HKLM-x32\...\{9192EBE9-2C4E-4C69-8ED8-CC0CCBFDBB62}) (Version: 10.3 - Spigot, Inc.) <==== ATTENTION
IsAvver (HKLM-x32\...\{F1422DAA-0829-09A1-7536-73936CAB8FFA}) (Version: - ISavuEr) <==== ATTENTION
LPT System Updater Service (x32 Version: 1.0.0.0 - LPT) Hidden <==== ATTENTIONn
Mu Tam Quôc Ex703 (HKLM-x32\...\Mu Tam Quôc Ex703) (Version: Ex703 - Mu Tam Quôc Ex703) <==== ATTENTION!
RandeOumPriceo (HKLM-x32\...\{8E8C2E2D-7F21-2CF5-0ADB-64935121ECF0}) (Version: - RandomPrice) <==== ATTENTION
Search Protect (HKLM-x32\...\SearchProtect) (Version: 2.20.0.406 - Client Connect LTD) <==== ATTENTION
Search Protection (HKU\S-1-5-21-3241693270-3966368004-441874098-1000\...\Search Protection) (Version: 10.7.0.1 - Spigot, Inc.) <==== ATTENTION
Search Protection (HKU\S-1-5-21-3241693270-3966368004-441874098-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Search Protection) (Version: 10.7.0.1 - Spigot, Inc.) <==== ATTENTION
Snap.Do (HKLM-x32\...\{3A014A11-3D9E-44BD-9431-2DB67F752CB9}) (Version: 11.32.1.16055 - ReSoft Ltd.) <==== ATTENTION
Snap.Do Engine (HKU\S-1-5-21-3241693270-3966368004-441874098-1000\...\{b7da1097-95c5-4748-8dae-604fb7183c99}) (Version: 11.32.1.16055 - ReSoft Ltd.) <==== ATTENTION
Snap.Do Engine (HKU\S-1-5-21-3241693270-3966368004-441874098-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\{b7da1097-95c5-4748-8dae-604fb7183c99}) (Version: 11.32.1.16055 - ReSoft Ltd.) <==== ATTENTION
Wajam (HKLM-x32\...\Wajam) (Version: 2.06 - Wajam) <==== ATTENTION!
WSE_Lasaoren (HKLM-x32\...\WSE_Lasaoren) (Version: - WSE_Lasaoren) <==== ATTENTION!
Yontoo 1.12.02 (HKLM\...\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}) (Version: 1.12.02 - Yontoo LLC) <==== ATTENTION
Task: {0242FD34-B6E2-46E1-AB8A-DC0A85AE0F5A} - System32\Tasks\GreatArcadeHits => C:\Users\duynguyen\AppData\Local\GreatArcadeHits\GAHUpdate.exe <==== ATTENTION
Task: {1CAC79F0-8C3C-4E41-8597-B0B68835A5D4} - System32\Tasks\bench-S-1-5-21-3241693270-3966368004-441874098-1000 => C:\Program Files (x86)\Bench\Updater\updater.exe <==== ATTENTION
Task: {294C36C7-622E-4FA8-8B2E-908D3CBD5E7B} - System32\Tasks\RegClean Pro_UPDATES => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe <==== ATTENTION
Task: {50B9F4BC-AC41-4CB0-8460-61840BC3B3BF} - System32\Tasks\RegClean Pro_DEFAULT => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe <==== ATTENTION
Task: {5E065564-2B44-4A9D-AEA0-AE8F72668C98} - System32\Tasks\RegClean Pro => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe <==== ATTENTION
Task: {7C715B80-F291-4F25-A03D-F4652C862AC9} - System32\Tasks\Advanced System Protector_startup => C:\Program Files (x86)\Advanced System Protector\AdvancedSystemProtector.exe <==== ATTENTION
Task: {82BE627C-3B05-4A2D-827C-BD0735AA2568} - System32\Tasks\Advanced System Protector => C:\Program Files (x86)\RegClean Pro\SystweakASP.exe <==== ATTENTION
Task: {A0F78A01-1BCB-4F70-A7A4-FE67EA78ED68} - System32\Tasks\AmiUpdXp => C:\Users\duynguyen\AppData\Local\162\a17451.exe <==== ATTENTION
Task: {C56E69D6-2B9D-4615-8535-C371574DD2EB} - System32\Tasks\GC_Informer => %LOCALAPPDATA%\GCC\Controller.exe <==== ATTENTION
Task: {D84841BB-F997-48D0-BD71-84F40AC13553} - System32\Tasks\GC_Scheduler => %LOCALAPPDATA%\GCC\Controller.exe <==== ATTENTION
Task: {D876B3BA-8C40-4AFB-8F32-93278378CF63} - System32\Tasks\RegCure Pro_sch_FFADD251-0D49-11E4-8929-A3F2B50963EC => C:\Program Files (x86)\ParetoLogic\RegCure Pro\RegCurePro.exe [2014-11-18] (ParetoLogic, Inc.) <==== ATTENTION
Task: {DD578E35-EEB6-4A7A-9AA0-1D5A3EE62A65} - System32\Tasks\Microsoft\Windows\Maintenance\UP_Scheduler => %LOCALAPPDATA%\GCC\Controller.exe <==== ATTENTION
Task: {FAC4272A-E8C2-4801-A506-85AEF8F17F66} - System32\Tasks\bench-sys => C:\Program Files (x86)\Bench\Updater\updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\AmiUpdXp.job => C:\Users\duynguyen\AppData\Local\162\a17451.exe <==== ATTENTION
Task: C:\Windows\Tasks\bench-S-1-5-21-3241693270-3966368004-441874098-1000.job => C:\Program Files (x86)\Bench\Updater\updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\bench-sys.job => C:\Program Files (x86)\Bench\Updater\updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\GreatArcadeHits.job => C:\Users\duynguyen\AppData\Local\GreatArcadeHits\GAHUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\RegClean Pro_DEFAULT.job => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe <==== ATTENTION
Task: C:\Windows\Tasks\RegClean Pro_UPDATES.job => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe <==== ATTENTION
Task: C:\Windows\Tasks\RegCure Pro_sch_FFADD251-0D49-11E4-8929-A3F2B50963EC.job => C:\Program Files (x86)\ParetoLogic\RegCure Pro\RegCurePro.exe <==== ATTENTION
AlternateDataStreams: C:\ProgramData\TEMP:0888F409
AlternateDataStreams: C:\ProgramData\TEMP:3440EB47
AlternateDataStreams: C:\ProgramData\TEMP:54D4173A
AlternateDataStreams: C:\ProgramData\TEMP:66633281
AlternateDataStreams: C:\Users\Public\DRM:احتضان
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Winlogon: [Userinit] userinit.exe,c:\program files (x86)\mobogenie\updatemobogeniesrv.exe,c:\games\mafia ii\pc\mafia2srv.exe,c:\users\duyngu~1\appdata\local\gcc\chrome~1\chromesrv.exe [X]
HKU\S-1-5-21-3241693270-3966368004-441874098-1000\...\Run: [AdobeBridge] => [X]
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
SearchScopes: HKLM-x32 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?p=mKO_AwFzX...
SearchScopes: HKLM-x32 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?p=mKO_AwFzX...
SearchScopes: HKU\.DEFAULT -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?p=mKO_AwFzX...
SearchScopes: HKU\.DEFAULT -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?p=mKO_AwFzX...
SearchScopes: HKU\S-1-5-21-3241693270-3966368004-441874098-1000 -> DefaultScope {A89B9BD5-B06A-4C55-A956-6AD6DA33CF59} URL = http://search.yahoo.com/search?fr=c...
SearchScopes: HKU\S-1-5-21-3241693270-3966368004-441874098-1000 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?p=mKO_AwFzX...
SearchScopes: HKU\S-1-5-21-3241693270-3966368004-441874098-1000 -> {A89B9BD5-B06A-4C55-A956-6AD6DA33CF59} URL = http://search.yahoo.com/search?fr=c...
BHO: IsAvver -> {92ABEB8A-DC58-A2BD-B48B-BB10867FFB4B} -> C:\ProgramData\IsAvver\kl6_k.x64.dll No File
BHO: IMinent WebBooster (BHO) -> {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} -> No File
BHO: RandeOumPriceo -> {A598603E-AFB0-7F9C-2407-73DB3781E384} -> C:\ProgramData\RandeOumPriceo\KJ9sqyXsAU.x64.dll No File
BHO-x32: No Name -> {11111111-1111-1111-1111-110211671166} -> No File
BHO-x32: No Name -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> No File
BHO-x32: No Name -> {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} -> No File
BHO-x32: Wajam -> {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} -> C:\Program Files (x86)\Wajam\IE\priam_bho.dll No File
BHO-x32: GreatArcadeHits Add-on -> {D0C21091-FF8E-432C-9006-0540E81BA9D7} -> No File
BHO-x32: BonanzaDeals -> {fe063412-bea4-4d76-8ed3-183be6220d17} -> No File
Toolbar: HKLM - Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\system32\mscoree.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll No File
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @ogplanet.com/npOGPPlugin -> C:\Windows\system32\npOGPPlugin.dll No File
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> C:\Games\Arc\Arc\Plugins\npArcPluginFF.dll No File
FF Plugin-x32: @real.com/nppl3260;version=16.0.3.51 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll No File
FF Plugin-x32: @real.com/nprpplugin;version=16.0.3.51 -> c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll No File
FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll No File
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll No File
FF Plugin HKU\S-1-5-21-3241693270-3966368004-441874098-1000: @tightropeinteractive.com/Plugin -> C:\Users\duynguyen\AppData\Local\TNT2\2.0.0.1599\npTNT2.dll No File
FF Plugin HKU\S-1-5-21-3241693270-3966368004-441874098-1000: @tnt2ghost.com/Plugin -> C:\Users\duynguyen\AppData\Local\TNT2\2.0.0.1599\npTNT2ghost.dll No File
FF Plugin HKU\S-1-5-21-3241693270-3966368004-441874098-1000: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin HKU\S-1-5-21-3241693270-3966368004-441874098-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File
S2 ADExchange; C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe [X]
S3 ArcService; C:\Games\Arc\Arc\ArcService.exe [X]
S2 Bonjour Service; "C:\Program Files\Bonjour\mDNSResponder.exe" [X]
S3 BRSptSvc; "C:\ProgramData\BitRaider\BRSptSvc.exe" [X]
S2 BstHdAndroidSvc; "C:\Program Files (x86)\BlueStacks\HD-Service.exe" BstHdAndroidSvc Android [X]
S2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [X]
S2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [X]
S3 Desura Install Service; C:\Program Files (x86)\Common Files\Desura\desura_service.exe [X]
S3 GameConsoleService; "C:\Program Files (x86)\WildGames\Game Console - WildGames\GameConsoleService.exe" [X]
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
S2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [X]
S2 LPTSystemUpdater; "C:\Program Files (x86)\LPT\srpts.exe" [X] <==== ATTENTION
S3 Origin Client Service; C:\Games\Origin\OriginClientService.exe [X]
S2 WajamUpdaterV3; "C:\Program Files (x86)\Wajam\Updater\WajamUpdaterV3.exe" [X] <==== ATTENTION
S3 BRDriver64; \??\C:\ProgramData\BitRaider\BRDriver64.sys [X]
S2 BstHdDrv; \??\C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [X]
S3 cpuz138; \??\C:\Users\DUYNGU~1\AppData\Local\Temp\cpuz138\cpuz138_x64.sys [X]
S3 dk; \??\C:\AeriaGames\DK Online\DKOnline\avital\dkol64.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 hxsyol; \??\C:\Games\AuraKingdom\avital\hxsy64.sys [X]
S3 OSFMount; \??\C:\My Programs\OSFMount\OSFMount.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S1 ttnfd; system32\drivers\ttnfd.sys [X]
S3 usj; \??\C:\AeriaGames\EdenEternal\avital\ussjcs64.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 WinRing0_1_2_0; \??\C:\Program Files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys [X]
S3 X6va011; \??\C:\Windows\SysWOW64\Drivers\X6va011 [X]
S3 X6va012; \??\C:\Windows\SysWOW64\Drivers\X6va012 [X]
S3 X6va015; \??\C:\Windows\SysWOW64\Drivers\X6va015 [X]
S3 X6va016; \??\C:\Windows\SysWOW64\Drivers\X6va016 [X]
S3 X6va017; \??\C:\Windows\SysWOW64\Drivers\X6va017 [X]
S3 X6va021; \??\C:\Windows\SysWOW64\Drivers\X6va021 [X]
S3 X6va022; \??\C:\Windows\SysWOW64\Drivers\X6va022 [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
C:\Users\duynguyen\AppData\Local\Temp\68ba3ab3bf5898994267ee9768c87abb.dll
C:\Users\duynguyen\AppData\Local\Temp\bassmod.dll
C:\Users\duynguyen\AppData\Local\Temp\bdfilters.dll
C:\Users\duynguyen\AppData\Local\Temp\EBU8FE.EXE
C:\Users\duynguyen\AppData\Local\Temp\EBUDDE.DLL
C:\Users\duynguyen\AppData\Local\Temp\FreemakeVideoConverter_4.1.4.3.exe
C:\Users\duynguyen\AppData\Local\Temp\ICReinstall_iTunes_Setup.exe
C:\Users\duynguyen\AppData\Local\Temp\InstallIMVU_510.26.exe
C:\Users\duynguyen\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
C:\Users\duynguyen\AppData\Local\Temp\NGMDll.dll
C:\Users\duynguyen\AppData\Local\Temp\NGMResource.dll
C:\Users\duynguyen\AppData\Local\Temp\nv3DVStreaming.dll
C:\Users\duynguyen\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\duynguyen\AppData\Local\Temp\nvSCPAPISvr.exe
C:\Users\duynguyen\AppData\Local\Temp\nvStereoApiI.dll
C:\Users\duynguyen\AppData\Local\Temp\nvStInst.exe
C:\Users\duynguyen\AppData\Local\Temp\RSPUpgradeInstaller.exe
C:\Users\duynguyen\AppData\Local\Temp\SearchProtectionSetup.exe
C:\Users\duynguyen\AppData\Local\Temp\SkypeSetup.exe
C:\Users\duynguyen\AppData\Local\Temp\sp-downloader.exe
C:\Users\duynguyen\AppData\Local\Temp\SRLDetectionLibrary4748232217532548526.dll
C:\Users\duynguyen\AppData\Local\Temp\SymCCIS.dll
C:\Users\duynguyen\AppData\Local\Temp\unicows.dll
C:\Users\duynguyen\AppData\Local\Temp\UNINSTALL.EXE


Report •

#20
January 18, 2015 at 19:47:33
What do I do next after creating fixlist.txt?

Report •

#21
January 18, 2015 at 20:01:20
Opp's Sorry.

Run FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that, let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please Copy & Paste the contents into your reply.


Report •

#22
January 18, 2015 at 20:18:26
It was too long: http://www1.zippyshare.com/v/MF9teq...

Report •

#23
January 18, 2015 at 20:23:31
Open Malwarebytes, Update & then scan again please. You can now disable > Rootkits: Enabled

Copy & Paste the contents of the new log please.


Report •

#24
January 18, 2015 at 21:07:28
http://www64.zippyshare.com/v/OmouD...

Report •

#25
January 18, 2015 at 21:16:00
You have installed the Premium version, which is a very good & can be run in conjuction with your current Anti-Virus ( AV ) If you don't want to buy it, do this to avoid the purchase nag screens.
Open Malwarebytes, on the Dashboard, click on ‘End Free Trial’ link which, then will be instantly converted to the free version.

What we have been doing is uncovering the malware etc. layer by layer.
What issues do you have now?


Report •

#26
January 18, 2015 at 21:20:24
I will definitely buy this software, it has proven very useful.
I will check back with you first thing in the morning.

Report •

#27
January 18, 2015 at 21:22:26
That last Malwarebytes log, did you quaratine everything.?

From the Farbar log.
EmptyTemp: => Removed 21.4 GB temporary data. Way, way too much.
Your settings are too high, how are you going for time, I'm in this time zone.
http://www.timeanddate.com/worldclo...


Report •

#28
January 18, 2015 at 21:35:06
Yes I made sure the whole list was set to Quarantine.

What did you mean by my settings were too high?

My time line:http://www.timeanddate.com/worldclo...

message edited by DoEqual


Report •

#29
January 18, 2015 at 21:45:15
"What did you mean by my settings were too high?"
Anything to do with temp files, can be set to a size limit.

I like your idea of tomorrow, gives me time to prep.


Report •

#30
January 19, 2015 at 06:49:36
It HAS been that the CPU is overheating. It reached 100C while Vindictus was playing and turns off by itself. How can I fix this?

I think this is probably why: http://imgur.com/HFcvOQU
After cleaning the fan, it started up like normal, but problem still persists during launch of Vindictus.
Particularly, when the laptop turns off, left batty light turns orange, then the right battery light turns red, then both are orange. Right one eventually turns off and left one stayed orange. After a couple min, the left one turns blue.
Both of these lights are next to the power button.

message edited by DoEqual


Report •

#31
January 19, 2015 at 14:14:06
Overheating on a laptop usually is just dust clogging the vents and/or ducts. Blow out all with a can of compressed air that is sold for this purpose from a computer store or office supply store.
Also make sure that the laptop is on a hard surface with the bottom and side vents clear of obstruction. Some programs use CPU more continuously so heat is more of an issue than office programs or web browsing so it is more important to keep these vents clear.

You have to be a little bit crazy to keep you from going insane.


Report •

#32
January 19, 2015 at 14:24:29
"What did you mean by my settings were too high?"

Remove old and redundant versions of the Java Runtime Environment:
http://www.softpedia.com/get/System...
http://www.freewarefiles.com/JavaRa...
http://www.freewarefiles.com/screen...
http://singularlabs.com/software/ja...

Next, Reduce your Java Cache
http://steveshank.com/cgi-bin/artic...

Managing your Internet Explorer Temporary Internet Files
http://www.bleepingcomputer.com/tut...
Amount of Disk Space to Use.
This shows the amount of disk space that will be allocated for your Temporary Internet Files. By default Windows uses 10 percent of your Windows system partition. This amount can be significant if you use the 10 percent model. It is advised that you change this setting to a lower number such as 50 MB.

Change Firefox to the same 50 mb setting.
Tools > Options > Advanced > Network > Offline Storage

message edited by Johnw


Report •

#33
Report •

#34
January 19, 2015 at 14:30:27
A bit more on the dust topic.
Under the CPU fan is a heat sink, which can get mighty clogged. Without removing anything apply your compressed air through and around the fan. This will clear the bulk of it away.

Always pop back and let us know the outcome - thanks


Report •

#35
January 19, 2015 at 19:34:24
The problem still occurs as the laptop kept turning off randomly.

But thanks to John, reboot and launching Firefox is much faster.
I will choose the best answer later.


Report •

#36
January 19, 2015 at 20:22:28
Run Disk Cleanup
http://windows.microsoft.com/en-au/...

Report •

#37
February 2, 2015 at 18:41:12
Hey guys I'm back finally after a long break. I've checked all that I need to fix on my laptop on my own.
I left it to a nearby proffesional which he changed the thermal paste of both the cpu and gpu which I'm sure he put the right amount because he's work for Frys as tech for 2 years.
Laptop fan is working perfectly fine, a cooling pad with a plastic net under the laptop, and a small fan at the rear where the air outflow is, yet the problem still persists.

At the time this stupid event has happened, I installed Razer Cortex, which I'm least concerned about it overheating my computer, and it was 20C cold outside. I also installed and ran Vindictus perfectly fine 1 day before. Besides that, nothing else is crucial to this problem came to mind.

My question is, why does my cpu and gpu starts to suddenly overheat and shuts the computer off by itself at the worse time possible? And how to fix it?

message edited by DoEqual


Report •

#38
February 2, 2015 at 18:47:05
"why does my cpu and gpu starts to suddenly overheat"
Have you definite evidence of that?

Always pop back and let us know the outcome - thanks


Report •

#39
February 2, 2015 at 18:52:07
I have no proof that the temps I read right now are higher than the previous temps, because I've never checked my temps before until I was introduced to cpuid and speed fan. But suddenly overheating is what I believe to be the problem.

message edited by DoEqual


Report •

#40
February 2, 2015 at 19:04:53
Restart and let us have the temperature readings immediately after a shutdown due to a crash. Does this shutdown usually happen after a long period of heavy usage?

Dust blockages and thermal compound application summarise the reasons for overheating.

What I am wondering is whether the shutting down is due to overheating at all - there are other possible causes. Malware is one of them and ADWCleaner previously found quite a lot. I'm not sure if Johnw had finished malware cleaning - maybe he'll pop back into this post and let us know.

Unfortunately all we really know for certain is that it is shutting down, so either hardware or software could be the cause. You could look in Events to see if any error is reported at exactly the time it shut down - there might be some clues there.

Always pop back and let us know the outcome - thanks

message edited by Derek


Report •

#41
February 2, 2015 at 19:19:25
The shutdown is due to temps reaching 50~60C.
This shutdown usually happens when launching heavy games like Vindictus and Path Of Exile on normal settings.
Shutdown does not happen when idle or watching YouTube or check Facebook or have Razer Comms running or check email(this is all of what I do all of the time on my laptop, and it was perfectly fine with all running at the same time in the past).
Right now, with just playing a video that's over 1GB can shutdown my laptop. I believe the reason is that the cpu is not getting enough cold air while its preparing such video, therefore gave up and shuts the laptop down.
How do I locate Events?

message edited by DoEqual


Report •

#42
February 2, 2015 at 19:25:18
Just type Event Viewer in search. You normally see it as soon as you've typed in Ev. You usually see a stack of errors and warnings (Windows minor bugs) so concentrate only on those who's times coincide with a shutdown.

50-60C is a bit cosy but not usually enough to cause shutdown. Was that for the CPU and if so what does the spec say for it (Google might help)?

Always pop back and let us know the outcome - thanks

message edited by Derek


Report •

#43
February 2, 2015 at 20:21:09
I will list all the event ID's since the last shutdown:
41
55
1001
2505
4321
6008
11
2511

That is for both cpu and gpu when launching a game.
I'm assuming this is spec:
Intel i5 430M 2.27GHz
GeForce GT 330M
4Gb Ram


Report •

#44
February 2, 2015 at 21:07:22
The logs are detailed in Farbar.

Download the latest version & run Farbar again please, follow this SS & upload the 2 new logs.
http://i.imgur.com/i3fg3Pf.gif


Report •

#45
Report •

#46
February 2, 2015 at 21:36:30
To get your house in order, lets start at the first set of errors.

"Faulty Device Manager Devices"
Go into Device Manager & on the drivers that are not installed, click "Update Driver", which starts the Hardware Update wizard.


Report •

#47
February 3, 2015 at 15:16:34
How do I find drivers that are not installed? There are only categories with + button drop downs.
I clicked find update on my cpu and gpu, and it's taking a long time to load.

Report •

#48
February 3, 2015 at 15:25:55
Give me a SS ( screenshot ) of Device manager please.

Report •

#49
February 3, 2015 at 15:43:27
http://imgur.com/uy3meQG

Report •

#50
February 3, 2015 at 16:01:35
Refer SS.

http://i.imgur.com/U7VFhlu.gif


Report •

#51
February 3, 2015 at 16:17:07
Got to go out soon, if you are looking Derek, can you take over please.

Report •

#52
February 3, 2015 at 16:52:47
John
I'm heading for a time limiting period - long winter drive involving a funeral and 3 overnight stays, so I must get my late hours in better order pronto.

DoEqual
Go to each of the expanded out areas, right click on each item and select Uninstall. If you see any request to remove software then DON'T let it. Restart the computer. The computer will initiate the drivers again When it has settled go back to Device Manager. If it looks any different at all (less than the three yellow errors) then please post another Device Manager screen shot.

Quickly going back to Events we discussed earlier. We don't need all the event errors after boot up. What is needed is to note the exact time of the next shutdown crash, rest the computer for say 10 minutes, then power on and see what errors show at or near the time of the shutdown crash only. That will pinpoint the error(s) that are associated with it. The numbers and a screenshot of that information might help.

Really must go now (00.52 am UK time - early night LOL).

Always pop back and let us know the outcome - thanks

message edited by Derek


Report •

#53
February 3, 2015 at 16:55:30
Everything is fine now since I told it to the location of the drivers to install. There are no more yellow errors.
I will press back if problem is still there.

message edited by DoEqual


Report •

Ask Question