PandaSteve
Topic Starter
Hi,
I seem to have picked up something that is using the ping.exe process to use up my CPU and memory.
Also, when i try to open programs, an "open with" box appears instead of just opening the program.
I have attached the DDS.txt log file below:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
Run by [removed] at 16:25:11 on 2011-12-20
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.428 [GMT -5:00]
.
AV: Symantec AntiVirus Corporate Edition *Enabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
.
============== Running Processes ===============
.
C:WINDOWSsystem32ibmpmsvc.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSsystem32svchost -k DcomLaunch
C:WINDOWSsystem32svchost -k rpcss
C:WINDOWSSystem32svchost.exe -k netsvcs
C:WINDOWSsystem32svchost.exe -k WudfServiceGroup
C:Program FilesIntelWirelessBinEvtEng.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSExplorer.EXE
C:Program FilesIntelWirelessBinS24EvMon.exe
C:WINDOWSsystem32svchost.exe -k NetworkService
C:WINDOWSsystem32svchost.exe -k LocalService
C:Program FilesCommon FilesSymantec SharedccSetMgr.exe
C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
C:WINDOWSsystem32svchost.exe -k LocalService
C:WINDOWSsystem32IPSSVC.EXE
C:Program FilesCommon FilesAppleMobile Device SupportAppleMobileDeviceService.exe
C:Program FilesBonjourmDNSResponder.exe
C:Program FilesSymantec AntiVirusDefWatch.exe
C:WINDOWSsystem32svchost.exe -k hpdevmgmt
C:WINDOWSSystem32svchost.exe -k HTTPFilter
C:Program FilesJavajre6binjqs.exe
C:WINDOWSSystem32svchost.exe -k HPZ12
C:PROGRA~1PHAROS~1CoreCTskMstr.exe
C:WINDOWSSystem32svchost.exe -k HPZ12
C:Program FilesIntelWirelessBinRegSrvc.exe
C:WINDOWSsystem32rpcnet.exe
C:Program FilesSpyware DoctorpctsAuxs.exe
C:Program FilesSpyware DoctorpctsSvc.exe
C:WINDOWSsystem32svchost.exe -k netsvc
C:Program FilesSpyware DoctorpctsTray.exe
C:WINDOWSsystem32svchost.exe -k imgsvc
c:program fileslenovosystem updatesuservice.exe
C:WINDOWSSystem32TPHDEXLG.exe
C:WINDOWSsystem32TpKmpSVC.exe
C:Program FilesLenovoClient Security Solutiontvttcsd.exe
C:Program FilesWindows Media PlayerWMPNetwk.exe
C:Program FilesMozilla Firefoxfirefox.exe
C:Program FilesMozilla Firefoxplugin-container.exe
C:WINDOWSsystem32igfxsrvc.exe
C:WINDOWSsystem32wbemwmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:program filescommon filesadobeacrobatactivexAcroIEHelperShim.dll
BHO: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:program filesjavajre6binjp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:program filesjavajre6libdeployjqsiejqs_plugin.dll
BHO: Yontoo Layers: {fd72061e-9fde-484d-a58a-0bab4151cad8} - c:program filesyontoo layers runtimeYontooIEClient.dll
TB: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
uRun: [ctfmon.exe] c:windowssystem32ctfmon.exe
uRun: [Google Update] "c:documents and settingslenovolocal settingsapplication datagoogleupdateGoogleUpdate.exe" /c
uRun: [{78246C0B-BEF1-572E-4657-04D5D901DD61}] "c:documents and settingslenovoapplication dataelokdafeeq.exe"
uRun: [Privacy Protection] c:documents and settingsall usersapplication dataprivacy.exe
mRun: [SunJavaUpdateSched] "c:program filescommon filesjavajava updatejusched.exe"
mRun: [QuickTime Task] "c:program filesquicktimeqttask.exe" -atboottime
mRun: [iTunesHelper] "c:program filesitunesiTunesHelper.exe"
mRun: [Adobe ARM] "c:program filescommon filesadobearm1.0AdobeARM.exe"
mRun: [ISTray] "c:program filesspyware doctorpctsTray.exe"
mRun: [KernelFaultCheck] %systemroot%system32dumprep 0 -k
StartupFolder: c:docume~1alluse~1startm~1programsstartupmcafee~1.lnk - c:program filesmcafee security scan2.0.181SSScheduler.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:progra~1micros~2office12REFIEBAR.DLL
LSP: mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.4.0/jinstall-1_4_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
TCP: DhcpNameServer = 192.168.15.1
TCP: Interfaces{83318968-D470-4F15-A672-02FC1A970039} : DhcpNameServer = 192.168.15.1
TCP: Interfaces{CC26ADA9-D178-47EA-A003-8AC6A8955E46} : DhcpNameServer = [removed] [removed]
Handler: saphtmlp - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} -
Handler: sapr3 - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} -
Notify: AtiExtEvent - Ati2evxx.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:documents and settingslenovoapplication datamozillafirefoxprofiles25lywn56.default
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrie7&query;=
FF - prefs.js: browser.startup.homepage - hxxps://mail.google.com/mail/u/0/?shva=1#inbox|https://tuportal3.temple.edu/cp/home/displaylogin|http://football.fantasysports.yahoo.com/f1/41894|http://www.cnn.com/|http://www.facebook.com/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?invocationType=bu10aiminstabie7&sredir;=2706&query;=
FF - plugin: c:documents and settingslenovoapplication datamozillapluginsnpgoogletalk.dll
FF - plugin: c:documents and settingslenovoapplication datamozillapluginsnpgoogletalk.dll
FF - plugin: c:documents and settingslenovoapplication datamozillapluginsnpgtpo3dautoplugin.dll
FF - plugin: c:documents and settingslenovolocal settingsapplication datagoogleupdate1.3.21.79npGoogleUpdate3.dll
FF - plugin: c:program filesadobereader 10.0readerairnppdf32.dll
FF - plugin: c:program filesgoogleupdate1.2.183.23npGoogleOneClick8.dll
FF - plugin: c:program filesgoogleupdate1.2.183.29npGoogleOneClick8.dll
FF - plugin: c:program filesjavajre6binnew_pluginnpdeployJava1.dll
FF - plugin: c:program filesmozilla firefoxpluginsnpCouponPrinter.dll
FF - plugin: c:program filesmozilla firefoxpluginsnpMozCouponPrinter.dll
FF - plugin: c:program filesveetleplayernpvlc.dll
FF - plugin: c:program filesveetlepluginsnpVeetle.dll
FF - plugin: c:program filesveetlevlcbroadcastnpvbp.dll
FF - plugin: c:program filesviewpointviewpoint media playernpViewpoint.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:program filesmozilla firefoxextensions{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:program filesmozilla firefoxextensions{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:program filesmozilla firefoxextensions{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:program filesmozilla firefoxextensions{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:program filesmozilla firefoxextensions{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:program filesmozilla firefoxextensions{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: [removed] - c:program filesjavajre6libdeployjqsff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:windowsmicrosoft.netframeworkv3.5windows presentation foundationDotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%extensions{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: vShare Plugin: vshareus@toolbar - %profile%extensionsvshareus@toolbar
FF - Ext: Yontoo Layers: [removed] - %[removed]
.
—- FIREFOX POLICIES —-
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
============= SERVICES / DRIVERS ===============
.
R0 IKFileSec;File Security Driver;c:windowssystem32driversikfilesec.sys [2008-10-14 41864]
R0 TPDIGIMN;TPDIGIMN;c:windowssystem32driversApsHM86.sys [2006-12-25 19760]
R1 IKSysFlt;System Filter Driver;c:windowssystem32driversiksysflt.sys [2008-10-14 66952]
R1 IKSysSec;System Security Driver;c:windowssystem32driversiksyssec.sys [2008-10-14 81288]
R1 SAVRT;SAVRT;c:program filessymantec antivirussavrt.sys [2005-2-4 324232]
R1 SAVRTPEL;SAVRTPEL;c:program filessymantec antivirusSavrtpel.sys [2005-2-4 53896]
R2 ccEvtMgr;Symantec Event Manager;c:program filescommon filessymantec sharedccEvtMgr.exe [2005-4-8 185968]
R2 ccSetMgr;Symantec Settings Manager;c:program filescommon filessymantec sharedccSetMgr.exe [2005-4-8 161392]
R2 sdAuxService;PC Tools Auxiliary Service;c:program filesspyware doctorpctsAuxs.exe [2008-10-14 747912]
R2 sdCoreService;PC Tools Security Service;c:program filesspyware doctorpctsSvc.exe [2008-10-14 946568]
R2 smi2;smi2;c:program filessmi2smi2.sys [2006-7-14 3968]
R2 SPService;SPService;c:windowssystem32svchost.exe -k netsvc [1980-1-1 14336]
R3 NAVENG;NAVENG;c:progra~1common~1symant~1virusd~120090830.005naveng.sys [2009-8-31 84912]
R3 NAVEX15;NAVEX15;c:progra~1common~1symant~1virusd~120090830.005navex15.sys [2009-8-31 1323568]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:windowssystem32driversASPI32.SYS [2010-8-2 16512]
S3 ccPwdSvc;Symantec Password Validation;c:program filescommon filessymantec sharedccPwdSvc.exe [2005-4-8 83568]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:program filesmcafee security scan2.0.181McCHSvc.exe [2010-1-15 227232]
S3 SavRoam;SAVRoam;c:program filessymantec antivirusSavRoam.exe [2005-4-17 124608]
S4 Symantec AntiVirus;Symantec AntiVirus;c:program filessymantec antivirusRtvscan.exe [2005-4-17 1706176]
.
=============== File Associations ===============
.
.exe=AyS
.
=============== Created Last 30 ================
.
2011-12-16 18:30:41 79872 —-a-w- c:windowssystem32jqQdD4.exe_
2011-12-16 10:39:47 827392 —-a-r- c:documents and settingsall usersapplication dataprivacy.exe
2011-12-14 21:48:34 ——– d—–w- c:documents and settingslenovolocal settingsapplication dataIdentities
2011-12-14 21:46:50 ——– d—–w- c:documents and settingslenovoapplication dataElok
2011-12-14 21:46:50 ——– d—–w- c:documents and settingslenovoapplication dataAbyxl
2011-12-05 19:05:58 ——– d—–w- c:windowssystem32wbemrepositoryFS
2011-12-05 19:05:58 ——– d—–w- c:windowssystem32wbemRepository
2011-11-30 20:29:15 ——– d—–w- c:program filesYontoo Layers Runtime
2011-11-30 20:29:12 ——– d—–w- c:documents and settingsall usersapplication dataTarma Installer
2011-11-30 20:29:03 ——– d—–w- c:documents and settingslenovo.swt
.
==================== Find3M ====================
.
2011-12-20 19:07:10 17920 —-a-w- c:windowssystem32rpcnetp.exe
2011-12-20 19:07:08 58288 —-a-w- c:windowssystem32rpcnet.dll
2011-12-14 20:12:43 17920 -c–a-w- c:windowssystem32rpcnetp.dll
2011-12-05 19:26:51 58288 ——w- c:windowssystem32rpcnet.exe
2011-11-20 17:51:38 414368 —-a-w- c:windowssystem32FlashPlayerCPLApp.cpl
2011-10-05 06:02:39 398760 —-a-r- c:windowssystem32cpnprt2.cid
.
============= FINISH: 16:27:13.75 ===============
I also ran GMER and attached Gmer.txt