This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ping.exe Problem (100% CPU Usage)

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have the same problem as http://forums.whatthetech.com/index.php?sh…120890&st=0.
i tried the first step which is running the combofix. and now im kinda lost of what should i do next. im now dowloading avira and malwarebytes which is the steps that ONewbieO was asked to do.
I just want to know if i am doing the right thing or i skipped some of the important steps?

My ComboFix log is as below


ComboFix 11-11-01.04 - NiZoRa 11/01/2011 23:06:55.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.4073.2792 [GMT 4:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\ShoppingReport2
c:\program files (x86)\ShoppingReport2\Bin\2.7.37\ShoppingReport.dll
c:\program files (x86)\ShoppingReport2\Uninst.exe
c:\users\NiZoRa\AppData\Roaming\NiZoRalog.dat
c:\users\NiZoRa\AppData\Roaming\Win32UpdateClient\svchost.exe
c:\windows\System64
G:\install.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-10-01 to 2011-11-01 )))))))))))))))))))))))))))))))
.
.
2011-11-01 18:38 . 2011-10-27 18:55 275456 —-a-w- c:\program files\wintask.exe
2011-10-26 23:18 . 2011-11-01 15:28 ——– d—–w- c:\program files (x86)\Origin Games
2011-10-26 09:22 . 2011-11-01 16:15 ——– d—–w- c:\program files (x86)\Common Files\BioWare
2011-10-26 07:24 . 2011-08-13 05:27 6144 —-a-w- c:\program files\Internet Explorer\iecompat.dll
2011-10-26 07:24 . 2011-08-13 04:18 6144 —-a-w- c:\program files (x86)\Internet Explorer\iecompat.dll
2011-10-24 05:26 . 2008-07-12 04:18 3851784 —-a-w- c:\windows\SysWow64\D3DX9_39.dll
2011-10-14 02:14 . 2011-10-14 02:14 ——– d—–w- c:\programdata\Nexon
2011-10-14 00:31 . 2011-11-01 18:38 ——– d—–w- c:\users\NiZoRa\AppData\Local\PMB Files
2011-10-14 00:31 . 2011-10-14 00:33 ——– d—–w- c:\programdata\PMB Files
2011-10-14 00:31 . 2011-10-14 00:31 ——– d—–w- c:\program files (x86)\Pando Networks
2011-10-13 03:48 . 2011-08-17 05:26 613888 —-a-w- c:\windows\system32\psisdecd.dll
2011-10-13 03:48 . 2011-08-17 05:25 108032 —-a-w- c:\windows\system32\psisrndr.ax
2011-10-13 03:48 . 2011-08-17 04:24 465408 —-a-w- c:\windows\SysWow64\psisdecd.dll
2011-10-13 03:48 . 2011-08-17 04:19 75776 —-a-w- c:\windows\SysWow64\psisrndr.ax
2011-10-13 03:48 . 2011-08-27 05:37 861696 —-a-w- c:\windows\system32\oleaut32.dll
2011-10-13 03:48 . 2011-08-27 05:37 331776 —-a-w- c:\windows\system32\oleacc.dll
2011-10-13 03:48 . 2011-08-27 04:26 571904 —-a-w- c:\windows\SysWow64\oleaut32.dll
2011-10-13 03:48 . 2011-08-27 04:26 233472 —-a-w- c:\windows\SysWow64\oleacc.dll
2011-10-10 13:52 . 2011-10-10 13:52 ——– d—–w- c:\program files (x86)\Razer
2011-10-03 20:29 . 2011-09-12 08:35 17351304 —-a-r- c:\programdata\Microsoft\Windows\Start Menu\Programs\Skype\Skype.exe
2011-10-03 20:05 . 2011-10-03 20:05 297967 —-a-w- c:\users\NiZoRa\empties.bat
2011-10-03 18:00 . 2011-10-26 06:44 ——– d—–w- c:\users\NiZoRa\AppData\Roaming\Tropico 4
2011-10-03 17:58 . 2011-10-03 17:58 ——– d—–w- c:\users\NiZoRa\AppData\Roaming\Kalypso Media
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-01 19:10 . 2011-08-01 23:41 42496 —-a-w- c:\windows\system32\drivers\oem-drv64.sys
2011-09-30 14:15 . 2011-09-30 14:15 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll
2011-09-29 16:12 . 2011-09-29 16:12 189248 —-a-w- c:\windows\SysWow64\PnkBstrB.exe
2011-09-29 16:12 . 2011-09-29 16:12 189248 —-a-w- c:\windows\SysWow64\PnkBstrB.ex0
2011-09-29 16:12 . 2011-09-29 16:12 75136 —-a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-09-22 22:41 . 2011-09-30 14:29 7580992 —-a-w- c:\windows\system32\nvcuda.dll
2011-09-22 22:41 . 2011-09-30 14:29 7183168 —-a-w- c:\windows\SysWow64\nvwgf2um.dll
2011-09-22 22:41 . 2011-09-30 14:29 68928 —-a-w- c:\windows\system32\OpenCL.dll
2011-09-22 22:41 . 2011-09-30 14:29 61248 —-a-w- c:\windows\SysWow64\OpenCL.dll
2011-09-22 22:41 . 2011-09-30 14:29 5576000 —-a-w- c:\windows\SysWow64\nvcuda.dll
2011-09-22 22:41 . 2011-09-30 14:29 2542912 —-a-w- c:\windows\system32\nvcuvid.dll
2011-09-22 22:41 . 2011-09-30 14:29 24796480 —-a-w- c:\windows\system32\nvcompiler.dll
2011-09-22 22:41 . 2011-09-30 14:29 24743232 —-a-w- c:\windows\system32\nvoglv64.dll
2011-09-22 22:41 . 2011-09-30 14:29 2458432 —-a-w- c:\windows\SysWow64\nvapi.dll
2011-09-22 22:41 . 2011-09-30 14:29 2401088 —-a-w- c:\windows\SysWow64\nvcuvid.dll
2011-09-22 22:41 . 2011-09-30 14:29 2232128 —-a-w- c:\windows\system32\nvcuvenc.dll
2011-09-22 22:41 . 2011-09-30 14:29 2099520 —-a-w- c:\windows\SysWow64\nvcuvenc.dll
2011-09-22 22:41 . 2011-09-30 14:29 18870592 —-a-w- c:\windows\SysWow64\nvoglv32.dll
2011-09-22 22:41 . 2011-09-30 14:29 17248576 —-a-w- c:\windows\SysWow64\nvcompiler.dll
2011-09-22 22:41 . 2011-09-30 14:29 15688512 —-a-w- c:\windows\system32\nvd3dumx.dll
2011-09-22 22:41 . 2011-09-30 14:29 1533248 —-a-w- c:\windows\system32\nvdispco64.dll
2011-09-22 22:41 . 2011-09-30 14:29 1454400 —-a-w- c:\windows\system32\nvgenco64.dll
2011-09-22 22:41 . 2011-09-30 14:29 12961088 —-a-w- c:\windows\system32\drivers\nvlddmkm.sys
2011-09-22 22:41 . 2011-08-01 09:07 837952 —-a-w- c:\windows\system32\easyupdatusapiu64.dll
2011-09-22 22:41 . 2011-08-01 09:07 5067584 —-a-w- c:\windows\system32\nvsvc64.dll
2011-09-22 22:41 . 2011-08-01 09:07 222528 —-a-w- c:\windows\system32\nvmctray.dll
2011-09-22 22:41 . 2011-08-01 09:07 1640768 —-a-w- c:\windows\system32\nvvsvc.exe
2011-09-22 22:41 . 2011-08-01 09:07 137536 —-a-w- c:\windows\system32\nvshext.dll
2011-09-22 22:41 . 2011-08-01 09:07 10406208 —-a-w- c:\windows\system32\nvcpl.dll
2011-09-22 22:41 . 2011-05-20 22:01 8930624 —-a-w- c:\windows\system32\nvwgf2umx.dll
2011-09-22 22:41 . 2011-05-20 22:01 2808640 —-a-w- c:\windows\system32\nvapi64.dll
2011-09-22 22:41 . 2011-05-20 22:01 13200704 —-a-w- c:\windows\SysWow64\nvd3dum.dll
2011-09-22 08:29 . 2011-09-22 08:29 321856 —-a-w- c:\windows\SysWow64\nvStreaming.exe
2011-09-15 18:39 . 2011-08-01 08:06 404640 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-09-09 13:06 . 2010-11-21 03:23 2851840 —-a-w- c:\windows\system32\themeui.dll
2011-09-09 13:06 . 2009-07-13 23:55 332288 —-a-w- c:\windows\system32\uxtheme.dll
2011-09-09 13:06 . 2009-07-13 23:54 44544 —-a-w- c:\windows\system32\themeservice.dll
2011-08-20 08:59 . 2011-08-03 11:18 1025664 —-a-w- c:\windows\PE_Rom.dll
2011-08-20 08:59 . 2011-08-20 08:59 1072032 —-a-w- c:\windows\PE_File.dll
.
.
——- Sigcheck ——-
Note: Unsigned files aren't necessarily malware.
.
[7] 2011-02-26 . 3B69712041F3D63605529BD66DC00C48 . 2871808 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[-] 2011-02-25 . FD785DEAFFA3416F17A44CB7EADF8A8D . 2712064 . . [6.1.7600.16385] .. c:\windows\explorer.exe
[7] 2011-02-25 . 332FEAB1435662FC6C672E25BEB37BE3 . 2871808 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[7] 2010-11-21 . AC4C51EB24AA95B77F705AB159189E24 . 2872320 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\progra~2\Yahoo!\Companion\Installs\cpn0\YTNavAssist.dll" [2011-03-16 214840]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{A31F34A1-EBD2-45A2-BF6D-231C1B987CC8}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —ha-w- c:\users\NiZoRa\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —ha-w- c:\users\NiZoRa\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —ha-w- c:\users\NiZoRa\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\Steam.exe" [2011-09-08 1242448]
"uTorrent"="c:\program files (x86)\uTorrent\uTorrent.exe" [2011-10-22 641400]
"Facebook Update"="c:\users\NiZoRa\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2011-08-01 137536]
"RocketDock"="c:\program files (x86)\RocketDock\RocketDock.exe" [2007-09-02 495616]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-10-13 17351304]
"EADM"="c:\program files (x86)\Origin\Origin.exe" [2011-10-20 28651144]
"Pando Media Booster"="c:\program files (x86)\Pando Networks\Media Booster\PMB.exe" [2011-10-14 3077528]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ASUS ShellProcess Execute"="c:\program files (x86)\ASUS\AI Suite II\ASUS Mobilink\Simulator\AsShellProcess.exe" [2010-09-28 252544]
"WZCSLDR2"="c:\program files (x86)\D-Link\DWA-525 revA\WZCSLDR2.exe" [2010-04-22 122880]
"D-Link D-Link DWA-525"="c:\program files (x86)\D-Link\DWA-525 revA\AirNCFG.exe" [2010-04-22 1015808]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-04-27 113288]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Razer Blackwidow Driver"="c:\program files (x86)\Razer\BlackWidow\BlackwidowTray.exe" [2011-05-16 887696]
"wintask"="c:\program files\wintask.exe" [2011-10-27 275456]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
2;2 D_Link_DWA-525;D_Link_DWA-525 Service;c:\program files (x86)\D-Link\DWA-525 revA\ANIWZCSdS.exe [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 D_Link_DWA-525_WPS;D_Link_DWA-525_WPS Service;c:\program files (x86)\D-Link\DWA-525 revA\ANIWConnService.exe [2010-04-22 40960]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-24 136176]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-09-22 2253120]
R3 ALSysIO;ALSysIO;c:\users\NiZoRa\AppData\Local\Temp\ALSysIO64.sys [x]
R3 ArvoFltr;ROCCAT Arvo;c:\windows\system32\drivers\ArvoFltr.sys [x]
R3 ATHDFU;Atheros Valkyrie USB BootROM;c:\windows\system32\Drivers\AthDfu.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-24 136176]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [x]
S0 mv91xx;mv91xx;c:\windows\system32\DRIVERS\mv91xx.sys [x]
S0 oem-drv64;OEM-SLP2.1 Driver (HPD64);c:\windows\system32\DRIVERS\oem-drv64.sys [x]
S1 anodlwf;ANOD Network Security Filter driver;c:\windows\system32\DRIVERS\anodlwfx.sys [x]
S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 asComSvc;ASUS Com Service;c:\program files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe [2010-11-03 918144]
S2 asHmComSvc;ASUS HM Com Service;c:\program files (x86)\ASUS\AAHM\1.00.10\aaHMSvc.exe [2010-11-03 909440]
S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [2010-10-21 586880]
S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe [2010-10-27 52896]
S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-09-22 381248]
S2 Winstep Xtreme Service;Winstep Xtreme Service;c:\program files (x86)\Winstep\WsxService [x]
S3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys [x]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys [x]
S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys [x]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys [x]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys [x]
S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys [x]
S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys [x]
S3 ICCWDT;Intel® Watchdog Timer Driver (Intel® WDT);c:\windows\system32\DRIVERS\ICCWDT.sys [x]
S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 netr28x;D-Link 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\Dnetr28x.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 RzSynapse;Razer Driver;c:\windows\system32\DRIVERS\RzSynapse.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-01 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-68764378-3937284872-4174403659-1000Core.job
- c:\users\NiZoRa\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-08-01 12:17]
.
2011-11-01 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-68764378-3937284872-4174403659-1000UA.job
- c:\users\NiZoRa\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-08-01 12:17]
.
2011-11-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-24 04:23]
.
2011-11-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-24 04:23]
.
2011-11-01 c:\windows\Tasks\RockMeltUpdateTaskUserS-1-5-21-68764378-3937284872-4174403659-1000Core.job
- c:\users\NiZoRa\AppData\Local\RockMelt\Update\RockMeltUpdate.exe [2011-08-01 08:06]
.
2011-11-01 c:\windows\Tasks\RockMeltUpdateTaskUserS-1-5-21-68764378-3937284872-4174403659-1000UA.job
- c:\users\NiZoRa\AppData\Local\RockMelt\Update\RockMeltUpdate.exe [2011-08-01 08:06]
.
.
——— x86-64 ———–
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 —ha-w- c:\users\NiZoRa\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 —ha-w- c:\users\NiZoRa\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 —ha-w- c:\users\NiZoRa\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 —ha-w- c:\users\NiZoRa\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-11-02 11545192]
"AtherosBtStack"="c:\program files (x86)\Bluetooth Suite\BtvStack.exe" [2010-10-27 613536]
"AthBtTray"="c:\program files (x86)\Bluetooth Suite\AthBtTray.exe" [2010-10-27 379040]
"New Value E9F9700F0989D08E330283E38A6F69B9E67EC66C"="c:\program files\Rainmeter\Rainmeter.exe" [2011-07-31 102912]
"combofix"="c:\combofix\CF11946.3XE" [2010-11-21 345088]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files (x86)\Stardock\Fences\FencesMenu64.dll" [2010-06-22 253288]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
——- Supplementary Scan ——-
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.yahoo.com/?ilc=8&fr=mkg029
mStart Page = hxxp://www.yahoo.com/?ilc=8&fr=mkg029
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Download all with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dllink.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{16F67AB5-626F-411B-B20D-462C4BF27DF3}: NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{7B8ECE31-E650-4EC1-A156-3D1C750EAC99}: NameServer = 8.8.8.8,8.8.8.4
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
AddRemove-PunkBusterSvc - c:\program files (x86)\Origin Games\???? Battlefield 3\pbsvc.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winstep Xtreme Service]
"ImagePath"="c:\program files (x86)\Winstep\WsxService"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10v_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10v_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
———————— Other Running Processes ————————
.
c:\program files (x86)\ASUS\AI Suite II\DIGI+ VRM\VRMHelp.exe
c:\program files (x86)\ASUS\AI Suite II\AsRoutineController.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\windows\SysWOW64\PnkBstrB.exe
c:\program files (x86)\Winstep\WsxService.exe
c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
.
**************************************************************************
.
Completion time: 2011-11-01 23:13:21 - machine was rebooted
ComboFix-quarantined-files.txt 2011-11-01 19:13
.
Pre-Run: 42,338,422,784 bytes free
Post-Run: 42,428,030,976 bytes free
.
- - End Of File - - 61D5ECE649FA4122F3651DAFDF610298

Im hoping that u could really help me with this. Cause i cannot stand seeing my processor at 100% usage all time.
Hi NiZoRa,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

We recommend that you do not run tools such as ComboFix unless specifically requested. We like to do diagnostics first. That being said… it appears that you were able to run CF without any ill effects… so lets continue.

uTorrent.exe
You have uTorrent.exe, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm://http://www.techweb.com/wire/1605005…cles/art053.htm


I would recommend that you uninstall uTorrent.exe, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.

Let's get an online scan.

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI