This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ping.exe virus

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I seem to have picked up something that is using the ping.exe process to use up my CPU and memory. Also, when i try to open programs, an "open with" box appears instead of just opening the program. I have attached the DDS.txt log file below: . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20 Run by [removed] at 16:25:11 on 2011-12-20 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.428 [GMT -5:00] . AV: Symantec AntiVirus Corporate Edition *Enabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C} . ============== Running Processes =============== . C:WINDOWSsystem32ibmpmsvc.exe C:WINDOWSsystem32Ati2evxx.exe C:WINDOWSsystem32svchost -k DcomLaunch C:WINDOWSsystem32svchost -k rpcss C:WINDOWSSystem32svchost.exe -k netsvcs C:WINDOWSsystem32svchost.exe -k WudfServiceGroup C:Program FilesIntelWirelessBinEvtEng.exe C:WINDOWSsystem32Ati2evxx.exe C:WINDOWSExplorer.EXE C:Program FilesIntelWirelessBinS24EvMon.exe C:WINDOWSsystem32svchost.exe -k NetworkService C:WINDOWSsystem32svchost.exe -k LocalService C:Program FilesCommon FilesSymantec SharedccSetMgr.exe C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe C:WINDOWSsystem32svchost.exe -k LocalService C:WINDOWSsystem32IPSSVC.EXE C:Program FilesCommon FilesAppleMobile Device SupportAppleMobileDeviceService.exe C:Program FilesBonjourmDNSResponder.exe C:Program FilesSymantec AntiVirusDefWatch.exe C:WINDOWSsystem32svchost.exe -k hpdevmgmt C:WINDOWSSystem32svchost.exe -k HTTPFilter C:Program FilesJavajre6binjqs.exe C:WINDOWSSystem32svchost.exe -k HPZ12 C:PROGRA~1PHAROS~1CoreCTskMstr.exe C:WINDOWSSystem32svchost.exe -k HPZ12 C:Program FilesIntelWirelessBinRegSrvc.exe C:WINDOWSsystem32rpcnet.exe C:Program FilesSpyware DoctorpctsAuxs.exe C:Program FilesSpyware DoctorpctsSvc.exe C:WINDOWSsystem32svchost.exe -k netsvc C:Program FilesSpyware DoctorpctsTray.exe C:WINDOWSsystem32svchost.exe -k imgsvc c:program fileslenovosystem updatesuservice.exe C:WINDOWSSystem32TPHDEXLG.exe C:WINDOWSsystem32TpKmpSVC.exe C:Program FilesLenovoClient Security Solutiontvttcsd.exe C:Program FilesWindows Media PlayerWMPNetwk.exe C:Program FilesMozilla Firefoxfirefox.exe C:Program FilesMozilla Firefoxplugin-container.exe C:WINDOWSsystem32igfxsrvc.exe C:WINDOWSsystem32wbemwmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8 uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:program filescommon filesadobeacrobatactivexAcroIEHelperShim.dll BHO: {9D425283-D487-4337-BAB6-AB8354A81457} - No File BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:program filesjavajre6binjp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:program filesjavajre6libdeployjqsiejqs_plugin.dll BHO: Yontoo Layers: {fd72061e-9fde-484d-a58a-0bab4151cad8} - c:program filesyontoo layers runtimeYontooIEClient.dll TB: {9D425283-D487-4337-BAB6-AB8354A81457} - No File TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File uRun: [ctfmon.exe] c:windowssystem32ctfmon.exe uRun: [Google Update] "c:documents and settingslenovolocal settingsapplication datagoogleupdateGoogleUpdate.exe" /c uRun: [{78246C0B-BEF1-572E-4657-04D5D901DD61}] "c:documents and settingslenovoapplication dataelokdafeeq.exe" uRun: [Privacy Protection] c:documents and settingsall usersapplication dataprivacy.exe mRun: [SunJavaUpdateSched] "c:program filescommon filesjavajava updatejusched.exe" mRun: [QuickTime Task] "c:program filesquicktimeqttask.exe" -atboottime mRun: [iTunesHelper] "c:program filesitunesiTunesHelper.exe" mRun: [Adobe ARM] "c:program filescommon filesadobearm1.0AdobeARM.exe" mRun: [ISTray] "c:program filesspyware doctorpctsTray.exe" mRun: [KernelFaultCheck] %systemroot%system32dumprep 0 -k StartupFolder: c:docume~1alluse~1startm~1programsstartupmcafee~1.lnk - c:program filesmcafee security scan2.0.181SSScheduler.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:progra~1micros~2office12REFIEBAR.DLL LSP: mswsock.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.4.0/jinstall-1_4_0_01-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab TCP: DhcpNameServer = 192.168.15.1 TCP: Interfaces{83318968-D470-4F15-A672-02FC1A970039} : DhcpNameServer = 192.168.15.1 TCP: Interfaces{CC26ADA9-D178-47EA-A003-8AC6A8955E46} : DhcpNameServer = [removed] [removed] Handler: saphtmlp - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - Handler: sapr3 - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - Notify: AtiExtEvent - Ati2evxx.dll . ================= FIREFOX =================== . FF - ProfilePath - c:documents and settingslenovoapplication datamozillafirefoxprofiles25lywn56.default FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrie7&query;= FF - prefs.js: browser.startup.homepage - hxxps://mail.google.com/mail/u/0/?shva=1#inbox|https://tuportal3.temple.edu/cp/home/displaylogin|http://football.fantasysports.yahoo.com/f1/41894|http://www.cnn.com/|http://www.facebook.com/ FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?invocationType=bu10aiminstabie7&sredir;=2706&query;= FF - plugin: c:documents and settingslenovoapplication datamozillapluginsnpgoogletalk.dll FF - plugin: c:documents and settingslenovoapplication datamozillapluginsnpgoogletalk.dll FF - plugin: c:documents and settingslenovoapplication datamozillapluginsnpgtpo3dautoplugin.dll FF - plugin: c:documents and settingslenovolocal settingsapplication datagoogleupdate1.3.21.79npGoogleUpdate3.dll FF - plugin: c:program filesadobereader 10.0readerairnppdf32.dll FF - plugin: c:program filesgoogleupdate1.2.183.23npGoogleOneClick8.dll FF - plugin: c:program filesgoogleupdate1.2.183.29npGoogleOneClick8.dll FF - plugin: c:program filesjavajre6binnew_pluginnpdeployJava1.dll FF - plugin: c:program filesmozilla firefoxpluginsnpCouponPrinter.dll FF - plugin: c:program filesmozilla firefoxpluginsnpMozCouponPrinter.dll FF - plugin: c:program filesveetleplayernpvlc.dll FF - plugin: c:program filesveetlepluginsnpVeetle.dll FF - plugin: c:program filesveetlevlcbroadcastnpvbp.dll FF - plugin: c:program filesviewpointviewpoint media playernpViewpoint.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:program filesmozilla firefoxextensions{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:program filesmozilla firefoxextensions{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:program filesmozilla firefoxextensions{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:program filesmozilla firefoxextensions{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:program filesmozilla firefoxextensions{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:program filesmozilla firefoxextensions{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} FF - Ext: Java Quick Starter: [removed] - c:program filesjavajre6libdeployjqsff FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:windowsmicrosoft.netframeworkv3.5windows presentation foundationDotNetAssistantExtension FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%extensions{20a82645-c095-46ed-80e3-08825760534b} FF - Ext: vShare Plugin: vshareus@toolbar - %profile%extensionsvshareus@toolbar FF - Ext: Yontoo Layers: [removed] - %[removed] . —- FIREFOX POLICIES —- FF - user.js: network.cookie.cookieBehavior - 0 FF - user.js: privacy.clearOnShutdown.cookies - false FF - user.js: security.warn_viewing_mixed - false FF - user.js: security.warn_viewing_mixed.show_once - false FF - user.js: security.warn_submit_insecure - false FF - user.js: security.warn_submit_insecure.show_once - false . ============= SERVICES / DRIVERS =============== . R0 IKFileSec;File Security Driver;c:windowssystem32driversikfilesec.sys [2008-10-14 41864] R0 TPDIGIMN;TPDIGIMN;c:windowssystem32driversApsHM86.sys [2006-12-25 19760] R1 IKSysFlt;System Filter Driver;c:windowssystem32driversiksysflt.sys [2008-10-14 66952] R1 IKSysSec;System Security Driver;c:windowssystem32driversiksyssec.sys [2008-10-14 81288] R1 SAVRT;SAVRT;c:program filessymantec antivirussavrt.sys [2005-2-4 324232] R1 SAVRTPEL;SAVRTPEL;c:program filessymantec antivirusSavrtpel.sys [2005-2-4 53896] R2 ccEvtMgr;Symantec Event Manager;c:program filescommon filessymantec sharedccEvtMgr.exe [2005-4-8 185968] R2 ccSetMgr;Symantec Settings Manager;c:program filescommon filessymantec sharedccSetMgr.exe [2005-4-8 161392] R2 sdAuxService;PC Tools Auxiliary Service;c:program filesspyware doctorpctsAuxs.exe [2008-10-14 747912] R2 sdCoreService;PC Tools Security Service;c:program filesspyware doctorpctsSvc.exe [2008-10-14 946568] R2 smi2;smi2;c:program filessmi2smi2.sys [2006-7-14 3968] R2 SPService;SPService;c:windowssystem32svchost.exe -k netsvc [1980-1-1 14336] R3 NAVENG;NAVENG;c:progra~1common~1symant~1virusd~120090830.005naveng.sys [2009-8-31 84912] R3 NAVEX15;NAVEX15;c:progra~1common~1symant~1virusd~120090830.005navex15.sys [2009-8-31 1323568] S3 ASPI;Advanced SCSI Programming Interface Driver;c:windowssystem32driversASPI32.SYS [2010-8-2 16512] S3 ccPwdSvc;Symantec Password Validation;c:program filescommon filessymantec sharedccPwdSvc.exe [2005-4-8 83568] S3 McComponentHostService;McAfee Security Scan Component Host Service;c:program filesmcafee security scan2.0.181McCHSvc.exe [2010-1-15 227232] S3 SavRoam;SAVRoam;c:program filessymantec antivirusSavRoam.exe [2005-4-17 124608] S4 Symantec AntiVirus;Symantec AntiVirus;c:program filessymantec antivirusRtvscan.exe [2005-4-17 1706176] . =============== File Associations =============== . .exe=AyS . =============== Created Last 30 ================ . 2011-12-16 18:30:41 79872 —-a-w- c:windowssystem32jqQdD4.exe_ 2011-12-16 10:39:47 827392 —-a-r- c:documents and settingsall usersapplication dataprivacy.exe 2011-12-14 21:48:34 ——– d—–w- c:documents and settingslenovolocal settingsapplication dataIdentities 2011-12-14 21:46:50 ——– d—–w- c:documents and settingslenovoapplication dataElok 2011-12-14 21:46:50 ——– d—–w- c:documents and settingslenovoapplication dataAbyxl 2011-12-05 19:05:58 ——– d—–w- c:windowssystem32wbemrepositoryFS 2011-12-05 19:05:58 ——– d—–w- c:windowssystem32wbemRepository 2011-11-30 20:29:15 ——– d—–w- c:program filesYontoo Layers Runtime 2011-11-30 20:29:12 ——– d—–w- c:documents and settingsall usersapplication dataTarma Installer 2011-11-30 20:29:03 ——– d—–w- c:documents and settingslenovo.swt . ==================== Find3M ==================== . 2011-12-20 19:07:10 17920 —-a-w- c:windowssystem32rpcnetp.exe 2011-12-20 19:07:08 58288 —-a-w- c:windowssystem32rpcnet.dll 2011-12-14 20:12:43 17920 -c–a-w- c:windowssystem32rpcnetp.dll 2011-12-05 19:26:51 58288 ——w- c:windowssystem32rpcnet.exe 2011-11-20 17:51:38 414368 —-a-w- c:windowssystem32FlashPlayerCPLApp.cpl 2011-10-05 06:02:39 398760 —-a-r- c:windowssystem32cpnprt2.cid . ============= FINISH: 16:27:13.75 =============== I also ran GMER and attached Gmer.txt
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)











Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI