This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ping.exe

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hey, a process named ping.exe seems to be hogging all of my CPU, getting up to about 99% in some instances. i had basically this same problem a couple of days ago
but instead with svchost.exe, but that seemed to solve itself somehow, so now im wondering how to get rid of this :D any help would be much appreciated.

OTL scans:
OTL logfile created on: 11/11/2011 3:08:20 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\ozzy.NICK\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.46 Gb Available Physical Memory | 73.04% Memory free
3.85 Gb Paging File | 3.41 Gb Available in Paging File | 88.78% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 322.46 Gb Free Space | 69.23% Space Free | Partition Type: NTFS

Computer Name: NICK | User Name: ozzy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\ozzy.NICK\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
PRC - C:\Program Files\Ralink\Common\RaUI.exe (Ralink Technology, Corp.)
PRC - C:\Program Files\Ralink\Common\RaRegistry.exe (Ralink Technology, Corp.)
PRC - C:\WINDOWS\system32\WgaTray.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
PRC - C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe (Symantec Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Ralink\Common\RaWLAPI.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\WINDOWS\system32\DiagFunc.dll ()
MOD - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()


========== Win32 Services (SafeList) ==========

SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (nosGetPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (RalinkRegistryWriter) – C:\Program Files\Ralink\Common\RaRegistry.exe (Ralink Technology, Corp.)
SRV - (npggsvc) – C:\WINDOWS\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (sdCoreService) – C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
SRV - (sdAuxService) – C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (RPCQT) Remote Procedure Call (CQTPM) – C:\WINDOWS\system32\Rpcqt.dll (Garena Online PTE LTD)
SRV - (IJPLMSVC) – C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
SRV - (Norton Ghost) – C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe (Symantec Corporation)
SRV - (GEARSecurity) – C:\WINDOWS\system32\gearsec.exe (GEAR Software)


========== Driver Services (SafeList) ==========

DRV - (gdrv) – C:\WINDOWS\gdrv.sys (Windows ® 2000 DDK provider)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (SCDEmu) – C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (rt2870) – C:\WINDOWS\system32\drivers\rt2870.sys (Ralink Technology, Corp.)
DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (Scutum50) – C:\WINDOWS\system32\drivers\Scutum50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (TfSysMon) – C:\WINDOWS\system32\drivers\TfSysMon.sys (PC Tools)
DRV - (TfNetMon) – C:\WINDOWS\system32\drivers\TfNetMon.sys (PC Tools)
DRV - (TfFsMon) – C:\WINDOWS\system32\drivers\TfFsMon.sys (PC Tools)
DRV - (pctgntdi) – C:\WINDOWS\system32\drivers\pctgntdi.sys (PC Tools)
DRV - (pctplsg) – C:\WINDOWS\system32\drivers\pctplsg.sys (PC Tools)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (L1e) – C:\WINDOWS\system32\drivers\l1e51x86.sys (Atheros Communications, Inc.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (VIAHdAudAddService) – C:\WINDOWS\system32\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV - (sscdmdm) – C:\WINDOWS\system32\drivers\sscdmdm.sys (MCCI Corporation)
DRV - (sscdmdfl) – C:\WINDOWS\system32\drivers\sscdmdfl.sys (MCCI Corporation)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – C:\WINDOWS\system32\drivers\sscdbus.sys (MCCI Corporation)
DRV - (AtcL002) – C:\WINDOWS\system32\drivers\l251x86.sys (Atheros Communications)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\AtiHdAud.sys (ATI Research Inc.)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (RT25USBAP) – C:\WINDOWS\system32\drivers\RT25USBAP.SYS (Ralink Technology Inc.)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (PQIMount) – C:\WINDOWS\System32\drivers\PQIMount.sys (PowerQuest Corporation)
DRV - (PQV2i) – C:\WINDOWS\System32\drivers\PQV2i.sys (StorageCraft)
DRV - (ASPI) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: [removed]:1.0

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6E19037A-12E3-4295-8915-ED48BC341614}: C:\Program Files\RelevantKnowledge
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/02 19:44:35 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/29 16:56:34 | 000,000,000 | —D | M]

[2011/11/06 13:30:49 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\ozzy.NICK\Application Data\Mozilla\Extensions
[2011/11/10 23:08:47 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\ozzy.NICK\Application Data\Mozilla\Firefox\Profiles\90i0j0ku.default\extensions
[2011/11/06 13:31:17 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\ozzy.NICK\Application Data\Mozilla\Firefox\Profiles\90i0j0ku.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/11/10 23:08:47 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/06/12 13:09:26 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/19 05:53:46 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/11/16 16:58:26 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/09/09 18:06:54 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2009/09/16 11:46:14 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQLS\x00\x00\x00\x00
hey, a process named ping.exe seems to be hogging all of my CPU, getting up to about 99% in some instances. i had basically this same problem a couple of days ago
but instead with svchost.exe, but that seemed to solve itself somehow, so now im wondering how to get rid of this :D any help would be much appreciated.

OTL scans:
OTL logfile created on: 11/11/2011 3:08:20 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\ozzy.NICK\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.46 Gb Available Physical Memory | 73.04% Memory free
3.85 Gb Paging File | 3.41 Gb Available in Paging File | 88.78% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 322.46 Gb Free Space | 69.23% Space Free | Partition Type: NTFS

Computer Name: NICK | User Name: ozzy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\ozzy.NICK\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
PRC - C:\Program Files\Ralink\Common\RaUI.exe (Ralink Technology, Corp.)
PRC - C:\Program Files\Ralink\Common\RaRegistry.exe (Ralink Technology, Corp.)
PRC - C:\WINDOWS\system32\WgaTray.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
PRC - C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe (Symantec Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Ralink\Common\RaWLAPI.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\WINDOWS\system32\DiagFunc.dll ()
MOD - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()


========== Win32 Services (SafeList) ==========

SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (nosGetPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (RalinkRegistryWriter) – C:\Program Files\Ralink\Common\RaRegistry.exe (Ralink Technology, Corp.)
SRV - (npggsvc) – C:\WINDOWS\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (sdCoreService) – C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
SRV - (sdAuxService) – C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (RPCQT) Remote Procedure Call (CQTPM) – C:\WINDOWS\system32\Rpcqt.dll (Garena Online PTE LTD)
SRV - (IJPLMSVC) – C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
SRV - (Norton Ghost) – C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe (Symantec Corporation)
SRV - (GEARSecurity) – C:\WINDOWS\system32\gearsec.exe (GEAR Software)


========== Driver Services (SafeList) ==========

DRV - (gdrv) – C:\WINDOWS\gdrv.sys (Windows ® 2000 DDK provider)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (SCDEmu) – C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (rt2870) – C:\WINDOWS\system32\drivers\rt2870.sys (Ralink Technology, Corp.)
DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (Scutum50) – C:\WINDOWS\system32\drivers\Scutum50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (TfSysMon) – C:\WINDOWS\system32\drivers\TfSysMon.sys (PC Tools)
DRV - (TfNetMon) – C:\WINDOWS\system32\drivers\TfNetMon.sys (PC Tools)
DRV - (TfFsMon) – C:\WINDOWS\system32\drivers\TfFsMon.sys (PC Tools)
DRV - (pctgntdi) – C:\WINDOWS\system32\drivers\pctgntdi.sys (PC Tools)
DRV - (pctplsg) – C:\WINDOWS\system32\drivers\pctplsg.sys (PC Tools)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (L1e) – C:\WINDOWS\system32\drivers\l1e51x86.sys (Atheros Communications, Inc.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (VIAHdAudAddService) – C:\WINDOWS\system32\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV - (sscdmdm) – C:\WINDOWS\system32\drivers\sscdmdm.sys (MCCI Corporation)
DRV - (sscdmdfl) – C:\WINDOWS\system32\drivers\sscdmdfl.sys (MCCI Corporation)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – C:\WINDOWS\system32\drivers\sscdbus.sys (MCCI Corporation)
DRV - (AtcL002) – C:\WINDOWS\system32\drivers\l251x86.sys (Atheros Communications)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\AtiHdAud.sys (ATI Research Inc.)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (RT25USBAP) – C:\WINDOWS\system32\drivers\RT25USBAP.SYS (Ralink Technology Inc.)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (PQIMount) – C:\WINDOWS\System32\drivers\PQIMount.sys (PowerQuest Corporation)
DRV - (PQV2i) – C:\WINDOWS\System32\drivers\PQV2i.sys (StorageCraft)
DRV - (ASPI) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: [removed]:1.0

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6E19037A-12E3-4295-8915-ED48BC341614}: C:\Program Files\RelevantKnowledge
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/02 19:44:35 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/29 16:56:34 | 000,000,000 | —D | M]

[2011/11/06 13:30:49 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\ozzy.NICK\Application Data\Mozilla\Extensions
[2011/11/10 23:08:47 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\ozzy.NICK\Application Data\Mozilla\Firefox\Profiles\90i0j0ku.default\extensions
[2011/11/06 13:31:17 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\ozzy.NICK\Application Data\Mozilla\Firefox\Profiles\90i0j0ku.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/11/10 23:08:47 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/06/12 13:09:26 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/19 05:53:46 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/11/16 16:58:26 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/09/09 18:06:54 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2009/09/16 11:46:14 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/05/LS\x00\x00\x00\x00
hey, a process named ping.exe seems to be hogging all of my CPU, getting up to about 99% in some instances. i had basically this same problem a couple of days ago
but instead with svchost.exe, but that seemed to solve itself somehow, so now im wondering how to get rid of this :D any help would be much appreciated.

OTL scans:
OTL logfile created on: 11/11/2011 3:08:20 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\ozzy.NICK\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.46 Gb Available Physical Memory | 73.04% Memory free
3.85 Gb Paging File | 3.41 Gb Available in Paging File | 88.78% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 322.46 Gb Free Space | 69.23% Space Free | Partition Type: NTFS

Computer Name: NICK | User Name: ozzy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\ozzy.NICK\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
PRC - C:\Program Files\Ralink\Common\RaUI.exe (Ralink Technology, Corp.)
PRC - C:\Program Files\Ralink\Common\RaRegistry.exe (Ralink Technology, Corp.)
PRC - C:\WINDOWS\system32\WgaTray.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
PRC - C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe (Symantec Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Ralink\Common\RaWLAPI.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\WINDOWS\system32\DiagFunc.dll ()
MOD - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()


========== Win32 Services (SafeList) ==========

SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (nosGetPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (RalinkRegistryWriter) – C:\Program Files\Ralink\Common\RaRegistry.exe (Ralink Technology, Corp.)
SRV - (npggsvc) – C:\WINDOWS\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (sdCoreService) – C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
SRV - (sdAuxService) – C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (RPCQT) Remote Procedure Call (CQTPM) – C:\WINDOWS\system32\Rpcqt.dll (Garena Online PTE LTD)
SRV - (IJPLMSVC) – C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
SRV - (Norton Ghost) – C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe (Symantec Corporation)
SRV - (GEARSecurity) – C:\WINDOWS\system32\gearsec.exe (GEAR Software)


========== Driver Services (SafeList) ==========

DRV - (gdrv) – C:\WINDOWS\gdrv.sys (Windows ® 2000 DDK provider)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (SCDEmu) – C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (rt2870) – C:\WINDOWS\system32\drivers\rt2870.sys (Ralink Technology, Corp.)
DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (Scutum50) – C:\WINDOWS\system32\drivers\Scutum50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (TfSysMon) – C:\WINDOWS\system32\drivers\TfSysMon.sys (PC Tools)
DRV - (TfNetMon) – C:\WINDOWS\system32\drivers\TfNetMon.sys (PC Tools)
DRV - (TfFsMon) – C:\WINDOWS\system32\drivers\TfFsMon.sys (PC Tools)
DRV - (pctgntdi) – C:\WINDOWS\system32\drivers\pctgntdi.sys (PC Tools)
DRV - (pctplsg) – C:\WINDOWS\system32\drivers\pctplsg.sys (PC Tools)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (L1e) – C:\WINDOWS\system32\drivers\l1e51x86.sys (Atheros Communications, Inc.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (VIAHdAudAddService) – C:\WINDOWS\system32\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV - (sscdmdm) – C:\WINDOWS\system32\drivers\sscdmdm.sys (MCCI Corporation)
DRV - (sscdmdfl) – C:\WINDOWS\system32\drivers\sscdmdfl.sys (MCCI Corporation)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – C:\WINDOWS\system32\drivers\sscdbus.sys (MCCI Corporation)
DRV - (AtcL002) – C:\WINDOWS\system32\drivers\l251x86.sys (Atheros Communications)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\AtiHdAud.sys (ATI Research Inc.)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (RT25USBAP) – C:\WINDOWS\system32\drivers\RT25USBAP.SYS (Ralink Technology Inc.)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (PQIMount) – C:\WINDOWS\System32\drivers\PQIMount.sys (PowerQuest Corporation)
DRV - (PQV2i) – C:\WINDOWS\System32\drivers\PQV2i.sys (StorageCraft)
DRV - (ASPI) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: [removed]:1.0

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6E19037A-12E3-4295-8915-ED48BC341614}: C:\Program Files\RelevantKnowledge
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/02 19:44:35 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/29 16:56:34 | 000,000,000 | —D | M]

[2011/11/06 13:30:49 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\ozzy.NICK\Application Data\Mozilla\Extensions
[2011/11/10 23:08:47 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\ozzy.NICK\Application Data\Mozilla\Firefox\Profiles\90i0j0ku.default\extensions
[2011/11/06 13:31:17 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\ozzy.NICK\Application Data\Mozilla\Firefox\Profiles\90i0j0ku.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/11/10 23:08:47 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/06/12 13:09:26 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/19 05:53:46 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/11/16 16:58:26 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/09/09 18:06:54 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2009/09/16 11:46:14 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/05/LS\x00\x00\x00\x00
hey, a process named ping.exe seems to be hogging all of my CPU, getting up to about 99% in some instances. i had basically this same problem a couple of days ago
but instead with svchost.exe, but that seemed to solve itself somehow, so now im wondering how to get rid of this :D any help would be much appreciated.

OTL scans:
OTL logfile created on: 11/11/2011 3:08:20 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\ozzy.NICK\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.46 Gb Available Physical Memory | 73.04% Memory free
3.85 Gb Paging File | 3.41 Gb Available in Paging File | 88.78% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 322.46 Gb Free Space | 69.23% Space Free | Partition Type: NTFS

Computer Name: NICK | User Name: ozzy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\ozzy.NICK\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
PRC - C:\Program Files\Ralink\Common\RaUI.exe (Ralink Technology, Corp.)
PRC - C:\Program Files\Ralink\Common\RaRegistry.exe (Ralink Technology, Corp.)
PRC - C:\WINDOWS\system32\WgaTray.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
PRC - C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe (Symantec Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Ralink\Common\RaWLAPI.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\WINDOWS\system32\DiagFunc.dll ()
MOD - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()


========== Win32 Services (SafeList) ==========

SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (nosGetPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (RalinkRegistryWriter) – C:\Program Files\Ralink\Common\RaRegistry.exe (Ralink Technology, Corp.)
SRV - (npggsvc) – C:\WINDOWS\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (sdCoreService) – C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
SRV - (sdAuxService) – C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (RPCQT) Remote Procedure Call (CQTPM) – C:\WINDOWS\system32\Rpcqt.dll (Garena Online PTE LTD)
SRV - (IJPLMSVC) – C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
SRV - (Norton Ghost) – C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe (Symantec Corporation)
SRV - (GEARSecurity) – C:\WINDOWS\system32\gearsec.exe (GEAR Software)


========== Driver Services (SafeList) ==========

DRV - (gdrv) – C:\WINDOWS\gdrv.sys (Windows ® 2000 DDK provider)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (SCDEmu) – C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (rt2870) – C:\WINDOWS\system32\drivers\rt2870.sys (Ralink Technology, Corp.)
DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (Scutum50) – C:\WINDOWS\system32\drivers\Scutum50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (TfSysMon) – C:\WINDOWS\system32\drivers\TfSysMon.sys (PC Tools)
DRV - (TfNetMon) – C:\WINDOWS\system32\drivers\TfNetMon.sys (PC Tools)
DRV - (TfFsMon) – C:\WINDOWS\system32\drivers\TfFsMon.sys (PC Tools)
DRV - (pctgntdi) – C:\WINDOWS\system32\drivers\pctgntdi.sys (PC Tools)
DRV - (pctplsg) – C:\WINDOWS\system32\drivers\pctplsg.sys (PC Tools)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (L1e) – C:\WINDOWS\system32\drivers\l1e51x86.sys (Atheros Communications, Inc.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (VIAHdAudAddService) – C:\WINDOWS\system32\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV - (sscdmdm) – C:\WINDOWS\system32\drivers\sscdmdm.sys (MCCI Corporation)
DRV - (sscdmdfl) – C:\WINDOWS\system32\drivers\sscdmdfl.sys (MCCI Corporation)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – C:\WINDOWS\system32\drivers\sscdbus.sys (MCCI Corporation)
DRV - (AtcL002) – C:\WINDOWS\system32\drivers\l251x86.sys (Atheros Communications)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\AtiHdAud.sys (ATI Research Inc.)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (RT25USBAP) – C:\WINDOWS\system32\drivers\RT25USBAP.SYS (Ralink Technology Inc.)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (PQIMount) – C:\WINDOWS\System32\drivers\PQIMount.sys (PowerQuest Corporation)
DRV - (PQV2i) – C:\WINDOWS\System32\drivers\PQV2i.sys (StorageCraft)
DRV - (ASPI) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: [removed]:1.0

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6E19037A-12E3-4295-8915-ED48BC341614}: C:\Program Files\RelevantKnowledge
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/02 19:44:35 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/29 16:56:34 | 000,000,000 | —D | M]

[2011/11/06 13:30:49 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\ozzy.NICK\Application Data\Mozilla\Extensions
[2011/11/10 23:08:47 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\ozzy.NICK\Application Data\Mozilla\Firefox\Profiles\90i0j0ku.default\extensions
[2011/11/06 13:31:17 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\ozzy.NICK\Application Data\Mozilla\Firefox\Profiles\90i0j0ku.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/11/10 23:08:47 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/06/12 13:09:26 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/19 05:53:46 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/11/16 16:58:26 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/09/09 18:06:54 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2009/09/16 11:46:14 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQLS\x00\x00\x00\x00
:welcome:

First off do not start any new topics, just reply to this one.


Your OTL log is not complete, lets do this

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]






Download DDS from one of the links below to your desktop

Link 1
Link 2

  • Double click the tool to run it.
  • A black Screen will open, just read the contents and do nothing.
  • When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
  • Copy/Paste the contents of 'DDS.txt' into your post.
  • 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)
Hey thank you for the reply, sorry for the multi posts, my computer bugged out, aswMBR log aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-11-15 20:49:51 —————————– 20:49:51.437 OS Version: Windows 5.1.2600 Service Pack 3 20:49:51.437 Number of processors: 2 586 0xF0D 20:49:51.437 ComputerName: NICK UserName: ozzy 20:49:52.250 Initialize success 20:49:55.437 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-3 20:49:55.437 Disk 0 Vendor: SAMSUNG_HD501LJ CR100-13 Size: 476938MB BusType: 3 20:49:57.453 Disk 0 MBR read successfully 20:49:57.453 Disk 0 MBR scan 20:49:57.453 Disk 0 Windows XP default MBR code 20:49:57.453 Disk 0 scanning sectors +976768065 20:49:57.500 Disk 0 scanning C:\WINDOWS\system32\drivers 20:50:01.750 Service scanning 20:50:02.750 Modules scanning 20:50:06.218 Disk 0 trace - called modules: 20:50:06.234 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS 20:50:06.234 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a924ab8] 20:50:06.234 3 CLASSPNP.SYS[f74c7fd7] -> nt!IofCallDriver -> \Device\0000006c[0x8a93c030] 20:50:06.234 5 ACPI.sys[f735e620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T1L0-3[0x8a933d98] 20:50:06.234 Scan finished successfully 20:50:14.093 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\ozzy.NICK\Desktop\MBR.dat" 20:50:14.093 The log file has been saved successfully to "C:\Documents and Settings\ozzy.NICK\Desktop\aswMBR.txt" DDS.txt . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_26 Run by [removed] at 20:50:33 on 2011-11-15 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1364 [GMT 8:00] . AV: PC Cleaners *Disabled/Updated* {737A8864-C2D9-4337-B49A-B5E35815B9BB} AV: Spyware Doctor with AntiVirus *Disabled/Updated* {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6} . ============== Running Processes =============== . C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe C:\WINDOWS\system32\Ati2evxx.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE C:\WINDOWS\system32\WgaTray.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe C:\Program Files\Canon\MyPrinter\BJMyPrt.exe C:\Program Files\PowerISO\PWRISOVM.EXE C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files\uTorrent\uTorrent.exe C:\Documents and Settings\All Users\Application Data\privacy.exe C:\Program Files\Ralink\Common\RaUI.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Ralink\Common\RaRegistry.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\wuauclt.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Documents and Settings\ozzy.NICK\Desktop\aswMBR.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: StylerToolBar: {d2f8f919-690b-4ea2-9fa7-a203d1e04f75} - c:\program files\styler\tb\StylerTB.dll uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe" /MINIMIZED uRun: [Privacy Protection] c:\documents and settings\all users\application data\privacy.exe /min uRun: [{CAC85C4F-E744-83E4-AE22-728446EE6BC4}] "c:\documents and settings\ozzy.nick\application data\opuqade\yqpoma.exe" mRun: [HDAudDeck] c:\program files\via\viaudioi\hdadeck\HDeck.exe 1 mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [SkyTel] SkyTel.EXE mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe" mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe" mRun: [AdobeCS5ServiceManager] "c:\program files\common files\adobe\cs5servicemanager\CS5ServiceManager.exe" -launchedbylogin mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray dRun: [Disker] rundll32.exe c:\windows\temp\HIMYM.DLL,DW dRunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N dRunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ralink~1.lnk - c:\program files\ralink\common\RaUI.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1220497227843 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab TCP: DhcpNameServer = 10.0.0.138 TCP: Interfaces\{2681C208-7CFD-4E4D-9486-824C5A3E80E7} : DhcpNameServer = [removed] [removed] TCP: Interfaces\{89B7D5C0-5322-4F90-B770-5AA29917E5FA} : DhcpNameServer = 10.0.0.138 TCP: Interfaces\{D5619DF4-FBBD-457D-AA6D-2837E87989A5} : DhcpNameServer = 192.168.1.254 Notify: AtiExtEvent - Ati2evxx.dll Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SSODL: mgxfebsq - {9E58F60B-F1F8-4255-BCCF-D38409C016AE} - c:\windows\mgxfebsq.dll SSODL: dtseqrxk - {CB736207-F469-40B3-BB20-82CE5602E4F6} - c:\windows\dtseqrxk.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\ozzy.nick\application data\mozilla\firefox\profiles\90i0j0ku.default\ FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension FF - Ext: Java Quick Starter: [removed] - c:\program files\java\jre6\lib\deploy\jqs\ff FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} . —- FIREFOX POLICIES —- FF - user.js: network.cookie.cookieBehavior - 0 FF - user.js: privacy.clearOnShutdown.cookies - false FF - user.js: security.warn_viewing_mixed - false FF - user.js: security.warn_viewing_mixed.show_once - false FF - user.js: security.warn_submit_insecure - false FF - user.js: security.warn_submit_insecure.show_once - false . ============= SERVICES / DRIVERS =============== . R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-3-30 206256] R0 PQV2i;PQV2i;c:\windows\system32\drivers\PQV2i.sys [2004-7-29 138780] R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2009-3-31 51488] R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2009-3-31 39200] R1 PQIMount;PQIMount;c:\windows\system32\drivers\PQIMount.sys [2004-7-29 46779] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-11-11 366152] R2 RalinkRegistryWriter;Ralink Registry Writer;c:\program files\ralink\common\RaRegistry.exe [2011-11-8 185632] R2 RPCQT;Remote Procedure Call (CQTPM);c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336] R2 Scutum50;Scutum50 NDIS Protocol Driver;c:\windows\system32\drivers\Scutum50.sys [2011-11-8 19072] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-11-11 22216] R3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [2011-11-8 818976] S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [2009-2-17 16512] S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\garena\safedrv.sys –> c:\program files\garena\safedrv.sys [?] S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2008-4-14 14336] S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2008-9-20 348752] S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2008-9-20 1097096] S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2009-3-31 33056] S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2008-7-24 215936] S4 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service –> c:\windows\system32\GameMon.des -service [?] S4 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2009-3-30 159600] S4 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [2009-3-30 64392] . =============== Created Last 30 ================ . 2011-11-14 22:07:46 ——– d—–w- c:\documents and settings\ozzy.nick\local settings\application data\Identities 2011-11-14 22:07:40 ——– d—–w- c:\documents and settings\ozzy.nick\application data\Opuqade 2011-11-14 22:07:40 ——– d—–w- c:\documents and settings\ozzy.nick\application data\Amt 2011-11-14 03:12:15 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-11-12 09:51:14 824320 —-a-w- c:\documents and settings\all users\application data\privacy.exe 2011-11-11 01:13:27 22216 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-11-11 01:13:27 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2011-11-09 23:15:06 ——– d—–w- c:\documents and settings\ozzy.nick\application data\Malwarebytes 2011-11-09 07:13:24 ——– d—–w- c:\program files\Easeware 2011-11-09 07:08:07 ——– d—–w- c:\program files\DriverGuide DriverScan 2011-11-08 12:43:00 800128 —-a-w- c:\windows\system32\Scutum.dll 2011-11-08 12:43:00 200704 —-a-w- c:\windows\system32\ssleay32.dll 2011-11-08 12:43:00 19072 —-a-w- c:\windows\system32\drivers\Scutum50.sys 2011-11-08 12:43:00 180224 —-a-w- c:\windows\system32\W32N55.dll 2011-11-08 12:43:00 152968 —-a-w- c:\windows\system32\RalinkGina.dll 2011-11-08 12:43:00 147456 —-a-w- c:\windows\system32\DiagFunc.dll 2011-11-08 12:43:00 1085440 —-a-w- c:\windows\system32\libeay32.dll 2011-11-08 12:42:41 818976 —-a-w- c:\windows\system32\drivers\rt2870.sys 2011-11-08 12:42:41 226592 —-a-w- c:\windows\system32\RaCoInst.dll 2011-11-08 12:42:41 ——– d—–w- c:\program files\Ralink 2011-11-08 12:42:41 ——– d—–w- c:\documents and settings\all users\application data\Ralink Driver 2011-11-07 10:58:06 ——– d—–w- c:\documents and settings\ozzy.nick\local settings\application data\uTorrent 2011-11-07 10:58:06 ——– d—–w- c:\documents and settings\ozzy.nick\application data\uTorrent 2011-11-06 05:30:18 ——– d—–w- c:\documents and settings\ozzy.nick\local settings\application data\Mozilla 2011-11-06 05:29:52 ——– d—–w- c:\documents and settings\ozzy.nick\local settings\application data\Apple Computer 2011-11-06 05:29:48 ——– d—–w- c:\documents and settings\ozzy.nick\local settings\application data\Adobe 2011-11-04 04:11:26 207400 —-a-r- c:\windows\GSetup.exe 2011-10-23 08:22:08 ——– d—–w- c:\program files\tamasoftware . ==================== Find3M ==================== . 2011-11-04 04:11:31 17488 -c–a-w- c:\windows\gdrv.sys 2011-10-10 14:22:41 692736 —-a-w- c:\windows\system32\inetcomm.dll 2011-09-26 03:41:20 611328 —-a-w- c:\windows\system32\uiautomationcore.dll 2011-09-26 03:41:20 220160 —-a-w- c:\windows\system32\oleacc.dll 2011-09-26 03:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll 2011-09-15 12:28:24 5356304 —-a-w- c:\windows\uninst.exe 2011-09-09 09:12:13 599040 —-a-w- c:\windows\system32\crypt32.dll 2011-09-09 08:49:35 0 —-a-w- c:\documents and settings\all users\application data\xxfg.exe 2011-09-09 08:49:35 0 —-a-w- c:\documents and settings\all users\application data\wcpx.exe 2011-09-09 08:49:35 0 —-a-w- c:\documents and settings\all users\application data\mkct.exe 2011-09-09 08:49:35 0 —-a-w- c:\documents and settings\all users\application data\ilbd.exe 2011-09-06 13:20:51 1858944 —-a-w- c:\windows\system32\win32k.sys 2011-08-17 13:49:54 138496 —-a-w- c:\windows\system32\drivers\afd.sys 2008-03-02 19:46:00 307200 -c–a-w- c:\program files\xp-AntiSpy.exe . ============= FINISH: 20:57:47.18 =============== The attached file is not compressed exactly as directed, when i clicked "send to" compressed (zipped) folder, didn't show, i hope this method will suffice

Attachments:

Looks like you may have a Rogue Spyware program installed plus some questionable items, lets do this

Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please
Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8136 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.13 11/16/2011 10:00:05 PM mbam-log-2011-11-16 (22-00-05).txt Scan type: Quick scan Objects scanned: 187168 Time elapsed: 9 minute(s), 16 second(s) Memory Processes Infected: 1 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 2 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 8 Memory Processes Infected: c:\documents and settings\all users\application data\privacy.exe (Exploit.Drop.Gen) -> 620 -> Unloaded process successfully. Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Privacy Protection (Exploit.Drop.Gen) -> Value: Privacy Protection -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\{CAC85C4F-E744-83E4-AE22-728446EE6BC4} (Trojan.Agent) -> Value: {CAC85C4F-E744-83E4-AE22-728446EE6BC4} -> Delete on reboot. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\documents and settings\all users\application data\privacy.exe (Exploit.Drop.Gen) -> Quarantined and deleted successfully. c:\documents and settings\ozzy.nick\application data\Opuqade\yqpoma.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\documents and settings\ozzy.nick\local settings\Temp\0.04875413265439921.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\documents and settings\ozzy.nick\local settings\Temp\107.tmp (Exploit.Drop.Gen) -> Quarantined and deleted successfully. c:\documents and settings\ozzy.nick\local settings\Temp\~!#105.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\documents and settings\ozzy.nick\local settings\Temp\~!#106.tmp (Exploit.Drop.Gen) -> Quarantined and deleted successfully. c:\documents and settings\ozzy.nick\local settings\temporary internet files\Content.IE5\IFWH0CDS\about[1].exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\documents and settings\ozzy.nick\local settings\Temp\0.2972344627468566.exe (Exploit.Drop.2) -> Quarantined and deleted successfully.
Great


ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
Please make sure you include the following items in your next post:
The log that was produced after running ESET Online Scanner.
Thanks for the constant help, sorry i cant reply quickly, been very busy with work. Eset scan C:\Documents and Settings\ozzy\Application Data\Ipmuuri\ewcoyqv.exe a variant of Win32/Kryptik.USN trojan C:\Documents and Settings\ozzy\Application Data\Sun\Java\Deployment\cache\6.0\10\7baa570a-55d279a7 a variant of Java/TrojanDownloader.OpenStream.NCM trojan C:\Documents and Settings\ozzy\Application Data\Sun\Java\Deployment\cache\6.0\54\36ced9b6-7cac025c Java/Agent.DU trojan C:\Documents and Settings\ozzy\Desktop\Sony_VegasPro8_DVDArchitect45_SoundForge9_CRACK.exe probably a variant of Win32/Agent.BCOVDCM trojan C:\Documents and Settings\ozzy\Desktop\Mike\Sony Vegas Pro 9.0c (Incl. Instructions, Patcher, Keygen)\Patcher and Keygen\Keygen\KEYGEN.EXE a variant of Win32/Keygen.AR application C:\Documents and Settings\ozzy\Desktop\Mike\Sony Vegas Pro 9.0c (Incl. Instructions, Patcher, Keygen)\Patcher and Keygen\Patcher\Patcher.EXE probably a variant of Win32/Agent.BCOVDCM trojan C:\Documents and Settings\ozzy\Local Settings\Application Data\Mozilla\Firefox\Profiles\0axz50oo.default\Cache\490DABAFd01 JS/TrojanClicker.Agent.NCQ trojan C:\Documents and Settings\ozzy\Local Settings\Temp\jar_cache8059826502169027620.tmp multiple threats C:\Documents and Settings\ozzy\My Documents\Downloads\Sony Vegas Pro 9.0 Crack Only.zip multiple threats C:\Documents and Settings\ozzy\My Documents\Downloads\Sony Vegas Pro 9.0c (Incl. Instructions, Patcher, Keygen)-TastyTeo.rar multiple threats C:\Documents and Settings\ozzy\My Documents\Downloads\Sony_VegasPro8_DVDArchitect45_SoundForge9_CRACK.exe probably a variant of Win32/Agent.BCOVDCM trojan C:\Documents and Settings\ozzy\My Documents\Downloads\Sony Vegas PRO 10.0e Build 737738 x86 + keygen\Keygen.rar a variant of Win32/Packed.VMProtect.AAD trojan C:\Documents and Settings\ozzy.NICK\Application Data\Sun\Java\Deployment\cache\6.0\12\3423a40c-64b8aa03 Java/Agent.DW trojan C:\Documents and Settings\ozzy.NICK\Application Data\Sun\Java\Deployment\cache\6.0\32\7a80ca60-2da0e7b0 a variant of Java/Agent.DW trojan C:\Documents and Settings\ozzy.NICK\Application Data\Sun\Java\Deployment\cache\6.0\57\2e965379-2534f8de a variant of Win32/Kryptik.VLA trojan C:\Documents and Settings\ozzy.NICK\Local Settings\Temp\~!#104.tmp a variant of Win32/Kryptik.VHY trojan
Not a problem with the replies, we all get busy

Download CKScanner by askey127 from Here & save it to your Desktop.
  • Doubleclick CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
CKScanner - Additional Security Risks - These are not necessarily bad c:\documents and settings\ozzy\desktop\sony_vegaspro8_dvdarchitect45_soundforge9_crack.exe c:\documents and settings\ozzy\desktop\mike\acekard\the legend of zelda spirit tracks (u) (xenophobia cracked).rar c:\documents and settings\ozzy\desktop\mike\sony vegas pro 9.0c (incl. instructions, patcher, keygen)\instructions important!.txt c:\documents and settings\ozzy\desktop\mike\sony vegas pro 9.0c (incl. instructions, patcher, keygen)\patcher and keygen\thumbs.db c:\documents and settings\ozzy\desktop\mike\sony vegas pro 9.0c (incl. instructions, patcher, keygen)\patcher and keygen\keygen\keygen.exe c:\documents and settings\ozzy\desktop\mike\sony vegas pro 9.0c (incl. instructions, patcher, keygen)\patcher and keygen\patcher\patcher.exe c:\documents and settings\ozzy\desktop\mike\sony vegas pro 9.0c (incl. instructions, patcher, keygen)\setup\setup x32.exe c:\documents and settings\ozzy\desktop\mike\sony vegas pro 9.0c (incl. instructions, patcher, keygen)\setup\setup x64.exe c:\documents and settings\ozzy\desktop\torrents\tv\walking dead\the walking dead season 1 complete hdtv + extras (behind the scenes etc)\tsv torrents\advanced systemcare pro v3.3.4 - cracked.torrent c:\documents and settings\ozzy\desktop\torrents\tv\walking dead\the walking dead season 1 complete hdtv + extras (behind the scenes etc)\tsv torrents\microsoft office 2010 professional plus - cracked.torrent c:\documents and settings\ozzy\desktop\torrents\tv\walking dead\the walking dead season 1 complete hdtv + extras (behind the scenes etc)\tsv torrents\sony vegas movie studio hd platinum - cracked.torrent c:\documents and settings\ozzy\desktop\torrents\tv\walking dead\the walking dead season 1 complete hdtv + extras (behind the scenes etc)\tsv torrents\windows 7 ultimate - 32 bit (auto activation) - cracked.torrent c:\documents and settings\ozzy\my documents\downloads\sony vegas pro 9.0 crack only.zip c:\documents and settings\ozzy\my documents\downloads\sony vegas pro 9.0c (incl. instructions, patcher, keygen)-tastyteo.rar c:\documents and settings\ozzy\my documents\downloads\sony_vegaspro8_dvdarchitect45_soundforge9_crack.exe c:\documents and settings\ozzy\my documents\downloads\sony vegas pro 10.0e build 737738 x86 + keygen\keygen.rar c:\documents and settings\ozzy\my documents\downloads\sony vegas pro 10.0e build 737738 x86 + keygen\vegaspro100e_32bit.exe c:\program files\garena\plugins\ui\avoidcrackplugin.dll c:\program files\garena classic\plugins\ui\avoidcrackplugin.dll c:\program files\image-line\hardcore\presets\i cracked my tube!.hdprg c:\program files\image-line\sawer\presets\ambient\mc cracked.sawer c:\program files\world of warcraft\interface\addons\wowpro_dailies\alliance\cracker_baradin.lua c:\program files\world of warcraft\interface\addons\wowpro_dailies\horde\cracker_hellscream.lua c:\program files\world of warcraft\interface\addons\wowpro_dailies\neutral\cracker_frenzy.lua c:\program files\world of warcraft\interface\addons\wowpro_dailies\neutral\cracker_oracles.lua c:\program files\world of warcraft\interface\addons\wowpro_leveling\alliance\30_35_crackerhead22_hinterlands.lua c:\program files\world of warcraft\interface\addons\wowpro_leveling\alliance\45_48_crackerhead22_badlands.lua c:\program files\world of warcraft\interface\addons\wowpro_leveling\alliance\50_52_crackerhead22_burning_steppes.lua c:\program files\world of warcraft\interface\addons\wowpro_leveling\alliance\52_54_crackerhead22_swamp_of_sorrows.lua c:\program files\world of warcraft\interface\addons\wowpro_leveling\alliance\54_58_crackerhead22_blasted_lands.lua c:\program files\world of warcraft\interface\addons\wowpro_leveling\alliance\70_70_crackerhead22_shadowmoon.lua c:\program files\world of warcraft\interface\addons\wowpro_leveling\horde\70_70_crackerhead22_shadowmoon.lua c:\program files\world of warcraft\interface\addons\wowpro_leveling\neutral\40_45_crackerhead22_eastern_plaguelands.lua c:\program files\world of warcraft\interface\addons\wowpro_leveling\neutral\48_50_crackerhead22_searing_gorge.lua c:\program files\world of warcraft\interface\addons\wowpro_leveling\neutral\69_70_crackerhead22_netherstorm.lua c:\windows\prefetch\warcraft3 keygen.exe-26f74101.pf scanner sequence 3.ZZ.11.WTAPRF —– EOF —–
You have a pretty nice collection of illegal software on your system, this is how you infected your computer, besides it being illegal, cracked/keygens are one of the fastest ways of infecting your system, 100% of illegal software contains some form of malicious code. This forum as well as all the other malware removal forums do not support the use of illegal software, except for there removal, if I was to continue helping you it could be construed in the eyes of the law as aiding and abetting a crime. If you you want to continue, what I need you to do is to look through the CKScanner log and uninstall all the illegal software that you have downloaded and installed . After you uninstall them all, run CKScanner again and post a new log. If I dont hear back from you in 24 hours this thread will be closed and no more help will be offered.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI