This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ping.exe seems to be popular this month...

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Okay, so it hasn't started yet, but that's because I just restarted my computer, as it was becoming completely nonresponsive. I swear, my computer has picked up so many problems in the last few days I wouldn't know where to begin listing them. Oh! Wait, there it is! Ping just started again.

You know, you guys really are like exorcists of the modern day - except with science. Thank you so much for dedicating your time, knowledge & skills to the unenlightened

Here's my dds.txt log from DDS. Tell me what other information you need, & I'll get it for you right away.

—

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_24
Run by [removed] at 23:21:23 on 2011-11-21
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.986 [GMT -5:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\WINDOWS\svcs.exe
C:\Program Files\Soluto\SolutoService.exe
C:\Program Files\Soluto\soluto.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\NETGEAR\WNA3100\WifiSvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\TCB Networks\StrokeIt\StrokeIt.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\Creative\ShareDLL\CADI\NotiMan.exe
C:\Program Files\Everything\Everything.exe
C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe
C:\Program Files\Mozilla Firefox 4.0 Beta 4\firefox.exe
E:\Program files\CintaNotes_1_3\CintaNotes.exe
c:\windows\bricopacks\vista inspirat 2\ubericon\ubericon manager.exe
C:\Program Files\Mozilla Firefox 4.0 Beta 4\plugin-container.exe
c:\windows\bricopacks\vista inspirat 2\yzshadow\yzshadow.exe
C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe
C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
C:\WINDOWS\system32\taskmgr.exe
E:\PROGRA~1\BXNEWF~1\bxExpHelper.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\ping.exe
c:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Page_URL = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
mSearchAssistant = hxxp://www.google.com/ie
mURLSearchHooks: H - No File
mWinlogon: UIHost=c:\documents and settings\all users\application data\tuneup software\tu2011\winstyler\tu_logonui.exe
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\program files\soluto\soluto.exe /userinit
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: DivX Plus Web Player HTML5 : {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll
BHO: bxNewFolder: {51c8bca8-2524-4523-bf09-738c4eebfc58} - e:\progra~1\bxnewf~1\BXNEWF~1.DLL
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~4\office14\GROOVEEX.DLL
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~4\office14\URLREDIR.DLL
BHO: IeMonitorBho Class: {bf00e119-21a3-4fd1-b178-3b8537e75c92} - c:\program files\megaupload\mega manager\MegaIEMn.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: WinAVI FLVSense: {e8df67a1-b618-4f3f-9e7c-cbe175adef5b} - c:\program files\winavi flv converter\FLVTune.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 10\SnagitIEAddin.dll
TB: {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No File
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
uRun: [StrokeIt] c:\program files\tcb networks\strokeit\StrokeIt.exe
uRun: [Creative Detector] "c:\program files\creative\mediasource\detector\CTDetect.exe" /R
mRun: []
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [CTDVDDET] "c:\program files\creative\sound blaster x-fi\dvdaudio\CTDVDDET.EXE"
mRun: [VolPanel] "c:\program files\creative\sound blaster x-fi\volume panel\VolPanel.exe" /r
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [RCSystem] "c:\program files\creative\shared files\module loader\DLLML.exe" RCSystem * -Startup
mRun: [AudioDrvEmulator] "c:\program files\creative\shared files\module loader\dllml.exe" -1 audiodrvemulator "c:\program files\creative\shared files\module loader\audio emulator\AudDrvEm.dll"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRunOnce: "c:\windows\system32\rundll32.exe" "c:\program files\divx\divx plus player\dseplugins\Direct3DVideoOutput.dll",DllRegisterServer
mRunOnce: "c:\windows\system32\rundll32.exe" "c:\program files\divx\divx plus player\dseplugins\DivXDeinterlaceFilter.dll",DllRegisterServer
mRunOnce: "c:\windows\system32\rundll32.exe" "c:\program files\divx\divx plus player\dpxplugins\DPXBannerAdPlugin.dll",DllRegisterServer
mRunOnce: "c:\windows\system32\rundll32.exe" "c:\program files\divx\divx plus player\dpxplugins\DPXMediaManagerPlugin.dll",DllRegisterServer
StartupFolder: c:\docume~1\user\startm~1\programs\startup\stardo~1.lnk - c:\program files\stardock\objectdock\ObjectDock.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ultramon.lnk - c:\windows\installer\{83cccbdc-3a56-4f3b-89df-69386c3b7d62}\IcoUltraMon.ico
IE: &Download FLV by WinAVI… - c:\program files\winavi flv converter\flv_link.htm
IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: Download with Mipony - file://j:\my documents\mipony\browser\IEContext.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\micros~4\office14\ONBttnIE.dll/105
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {DE365254-2F9B-4908-9E3A-7AAA6EC90BCC} - {EC83A912-7EF4-410D-9CC7-3BDAA709CA71} - c:\program files\winavi flv converter\FLVTune.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F}
LSP: mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{3634A0A4-30C1-4E77-BF1E-5CE737B10AE9} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{826FFF1D-08E9-4276-BE9F-4A4934983662} : DhcpNameServer = 208.67.220.220,208.67.222.222
TCP: Interfaces\{CA811296-C351-41D1-B9BB-83BB876B590D} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{E7AB7A7F-3159-4C46-95C2-CAD4E3FE3211} : DhcpNameServer = 192.168.1.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
STS: FencesShlExt Class: {1984dd45-52cf-49cd-ab77-18f378fea264} - e:\program files\stardock\fences\FencesMenu.dll
STS: {1984D045-52CF-49cd-DB77-08F378FEA4DB} - No File
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~4\office14\GROOVEEX.DLL
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
IFEO: itunes.exe - "c:\program files\tuneup utilities 2011\TUAutoReactivator32.exe"
IFEO: lightscribecontrolpanel.exe - "c:\program files\tuneup utilities 2011\TUAutoReactivator32.exe"
IFEO: lslauncher.exe - "c:\program files\tuneup utilities 2011\TUAutoReactivator32.exe"
IFEO: quickcam.exe - "c:\program files\tuneup utilities 2011\TUAutoReactivator32.exe"
IFEO: softwareupdate.exe - "c:\program files\tuneup utilities 2011\TUAutoReactivator32.exe"
.
Note: multiple IFEO entries found. Please refer to Attach.txt
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\user\application data\mozilla\firefox\profiles\do7cd2nb.default\
FF - prefs.js: browser.startup.homepage - chrome://speeddial/content/speeddial.xul
FF - prefs.js: keyword.URL - hxxp://google.com/search?btnI=1&q=
FF - prefs.js: network.proxy.type - 0
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\user\local settings\application data\facebook\video\skype\npFacebookVideoCalling.dll
FF - plugin: c:\documents and settings\user\local settings\application data\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\progra~1\micros~4\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\micros~4\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll
FF - plugin: e:\program files\tracker software\pdf viewer\npPDFXCviewNPPlugin.dll
FF - plugin: e:\program files\videolan\vlc\npvlc.dll
.
—- FIREFOX POLICIES —-
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
FF - user.js: network.http.max-persistent-connections-per-server - 4
.
============= SERVICES / DRIVERS ===============
.
R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [2010-6-7 39472]
R0 Soluto;Soluto;c:\windows\system32\drivers\Soluto.sys [2011-9-8 51144]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 165648]
R1 MpKsl18972ba1;MpKsl18972ba1;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bd988f07-5b6d-47c1-b468-71be844bcce3}\MpKsl18972ba1.sys [2011-11-21 28752]
R1 vcdrom;Virtual CD-ROM Device Driver;c:\windows\system32\drivers\VCdRom.sys [2001-12-19 8576]
R2 UltraMonUtility;UltraMon Utility Driver;c:\program files\common files\realtime soft\ultramonmirrordrv\x32\UltraMonUtility.sys [2008-11-14 17184]
R3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;c:\windows\system32\drivers\bcmwlhigh5.sys [2010-12-22 642432]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\tuneup utilities 2011\TuneUpUtilitiesDriver32.sys [2010-10-7 10064]
S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys –> c:\windows\system32\drivers\Lbd.sys [?]
S1 MpKsl0cbd2938;MpKsl0cbd2938;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{6f8a70c2-a5d4-49fc-ae57-e098b9c8c738}\mpksl0cbd2938.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{6f8a70c2-a5d4-49fc-ae57-e098b9c8c738}\MpKsl0cbd2938.sys [?]
S1 MpKslacca5ef1;MpKslacca5ef1;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d8f66e22-081f-48cc-870d-fc2b231a8030}\mpkslacca5ef1.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d8f66e22-081f-48cc-870d-fc2b231a8030}\MpKslacca5ef1.sys [?]
S1 MpKsld2d1e502;MpKsld2d1e502;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b2072dbf-068b-48d6-9170-2709b9ba2992}\mpksld2d1e502.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b2072dbf-068b-48d6-9170-2709b9ba2992}\MpKsld2d1e502.sys [?]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\common files\adobe\adobe version cue cs4\server\bin\VersionCueCS4.exe [2008-8-15 284016]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\dragon age\bin_ship\daupdatersvc.service.exe [2009-12-15 25832]
S3 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-6-14 136176]
S3 gUSBSTOi;gUSBSTOi;\??\c:\docume~1\user\locals~1\temp\gusbstoi.sys –> c:\docume~1\user\locals~1\temp\gUSBSTOi.sys [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2010-1-21 30963576]
S3 NPF;Netgroup Packet Filter;c:\windows\system32\drivers\npf.sys [2010-12-22 50704]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2011-11-4 27064]
.
=============== File Associations ===============
.
.txt=
.
=============== Created Last 30 ================
.
2011-11-22 04:10:17 28752 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bd988f07-5b6d-47c1-b468-71be844bcce3}\MpKsl18972ba1.sys
2011-11-22 04:10:12 56200 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bd988f07-5b6d-47c1-b468-71be844bcce3}\offreg.dll
2011-11-20 05:55:03 6668624 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bd988f07-5b6d-47c1-b468-71be844bcce3}\mpengine.dll
2011-11-19 02:34:13 ——– d—–w- c:\program files\3DO
2011-11-17 13:58:56 508928 —-a-w- c:\windows\svcs.exe
2011-11-16 21:25:39 ——– d—–w- c:\windows\system32\wbem\repository\FS
2011-11-16 21:25:39 ——– d—–w- c:\windows\system32\wbem\Repository
2011-11-16 21:02:37 ——– d—–w- c:\documents and settings\user\application data\2890A
2011-11-16 21:02:36 ——– d—–w- c:\program files\LP
2011-11-15 15:28:17 ——– d—–w- c:\program files\common files\xing shared
2011-11-10 01:52:34 ——– d—–w- c:\program files\Microsoft CAPICOM 2.1.0.2
2011-11-06 21:46:18 6668624 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2011-11-05 21:43:59 274288 —-a-w- c:\windows\system32\mucltui.dll
2011-11-05 21:43:59 215920 —-a-w- c:\windows\system32\muweb.dll
2011-11-05 21:43:59 16736 —-a-w- c:\windows\system32\mucltui.dll.mui
2011-11-05 04:03:05 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-11-05 03:58:27 ——– d—–w- c:\program files\Microsoft Security Client
2011-11-05 02:11:25 27064 —-a-w- c:\windows\system32\drivers\revoflt.sys
2011-11-05 02:11:23 ——– d—–w- c:\program files\VS Revo Group
.
==================== Find3M ====================
.
2011-11-15 15:27:35 499712 —-a-w- c:\windows\system32\msvcp71.dll
2011-11-15 15:27:35 348160 —-a-w- c:\windows\system32\msvcr71.dll
2011-10-18 04:35:59 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-11 20:33:24 51144 —-a-w- c:\windows\system32\drivers\Soluto.sys
2011-10-10 14:22:41 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06:50 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41:20 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41:20 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-09 09:12:13 599040 —-a-w- c:\windows\system32\crypt32(3).dll
2011-09-07 19:53:30 60304 —-a-w- c:\documents and settings\user\g2mdlhlpx.exe
2011-09-06 23:07:42 240592 —-a-w- c:\windows\system32\nvdrsdb0.bin
2011-09-06 23:07:42 1 —-a-w- c:\windows\system32\nvdrssel.bin
2011-09-06 23:07:41 240592 —-a-w- c:\windows\system32\nvdrsdb1.bin
2011-09-06 13:20:51 1858944 —-a-w- c:\windows\system32\win32k.sys
.
============= FINISH: 23:23:19.76 ===============

Thanks again.
Here's a list of known problems. The alert sound rings without prompting every so often. After shutting down my computer it does not power down without manually turning off the power switch (If this turns out to mean I need a new power supply, I can live with that) Hidden processes pop up like crazy (or rather, don't, because they're hidden). The more that pop up, the less responsive my internet becomes. Ping.exe will not close. Pop-ups appear in new tabs on Firefox (have not tested in other browsers.) Upon restarting my computer (see above), it frequently blue screens three - five times before reaching the password screen. Again, I initially thought this was a problem with the power supply.
Hi Devon Underwood,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Not alot showing there. Let's give this a try:

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Wow, that is a powerful program. Let's see: 1) computer powered down & restarted all on its own. 2) It took ComboFix a while to run through & delete everything. 3) I'd be willing to bet that's fixed everything, but tell me if you'd like me to run more scans or if I need to do anything else; here's the log: Thank you so much, by the way.

Attachments:

Devon Underwood,

Let's get on online scan:

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!


Also, please let me know how things seem to be running.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI