This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ping.exe problems with CPU usage [Closed]

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, First off, thanks for spending time to help me out. Anyway a couple days ago I believe I got the Win 7 antivirus 2012 virus. I downloaded Malwarebytes to get rid of it and thought I was ok, but now after a while, sometimes my laptop runs really slow. Task manager shows ping.exe spiking in CPU usage like crazy. Here is what I got from DDS. . DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_24 Run by [removed] at 18:43:27 on 2011-12-22 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3831.2317 [GMT -8:00] . SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\WUDFHost.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\nvvsvc.exe C:\Windows\system32\WLANExt.exe C:\Windows\system32\conhost.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\AppleOSSMgr.exe C:\Windows\system32\AppleTimeSrv.exe C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\WUDFHost.exe C:\Windows\system32\svchost.exe -k bthsvcs C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe C:\Windows\system32\sppsvc.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Boot Camp\Bootcamp.exe C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe C:\Program Files (x86)\NCSoft\Launcher\NCLauncher.exe C:\Windows\system32\wuauclt.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Windows\SysWOW64\ping.exe C:\Windows\system32\conhost.exe C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.45\deploy\LoLLauncher.exe C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTo0.dll uURLSearchHooks: H - No File mURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTo0.dll mWinlogon: Userinit=userinit.exe BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll BHO: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTo0.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTo0.dll uRun: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe uRun: [PlayNC Launcher] uRun: [NCsoft Launcher] C:\Program Files (x86)\NCSoft\Launcher\NCLauncher.exe /Minimized uRun: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe uPolicies-explorer: HideSCAHealth = 1 (0x1) mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll LSP: C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll LSP: mswsock.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {B3E32D88-8E7F-468F-B0E2-3A300FD4A82C} - hxxp://myitlab.pearsoned.com/Pegasus/Modules/SIMIntegration/Resources/ax/stub.cab DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 192.168.1.1 [removed] [removed] TCP: Interfaces\{ACCF5366-8889-4E3F-8271-93B26C2BFB0E} : DhcpNameServer = 192.168.1.1 [removed] [removed] TCP: Interfaces\{ACCF5366-8889-4E3F-8271-93B26C2BFB0E}\2656F5E6963656F547F6F5D656 : DhcpNameServer = 10.0.0.1 TCP: Interfaces\{ACCF5366-8889-4E3F-8271-93B26C2BFB0E}\7596D2547555D2163636563737 : DhcpNameServer = 10.1.1.81 10.1.1.82 10.1.1.83 TCP: Interfaces\{AF45C68B-18BC-480B-B48E-303990C8A21C} : DhcpNameServer = [removed] [removed] Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll SubSystems: Windows = basesrv,1 winsrv:UserServerDllInitialization,3 consrv:ConServerDllInitialization,2 sxssrv,4 BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO-X64: AcroIEHelperStub - No File BHO-X64: Skype Plug-In: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll BHO-X64: SkypeIEPluginBHO - No File BHO-X64: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTo0.dll BHO-X64: uTorrentBar - No File BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB-X64: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTo0.dll mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\egrepo\AppData\Roaming\Mozilla\Firefox\Profiles\43o2v6nm.default\ FF - prefs.js: network.proxy.type - 0 FF - component: C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll FF - component: C:\Users\egrepo\AppData\Roaming\Mozilla\Firefox\Profiles\43o2v6nm.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCore.dll FF - component: C:\Users\egrepo\AppData\Roaming\Mozilla\Firefox\Profiles\43o2v6nm.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko19.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll FF - plugin: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll FF - plugin: C:\Users\egrepo\AppData\Roaming\Kalydo\KalydoPlayer\npkalydo.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Skype extension: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} FF - Ext: uTorrentBar Community Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - %profile%\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} . ============= SERVICES / DRIVERS =============== . R0 AppleHFS;AppleHFS;C:\Windows\system32\drivers\AppleHFS.sys –> C:\Windows\system32\drivers\AppleHFS.sys [?] R0 AppleMNT;AppleMNT;C:\Windows\system32\drivers\AppleMNT.sys –> C:\Windows\system32\drivers\AppleMNT.sys [?] R0 PCTCore;PCTools KDS;C:\Windows\system32\drivers\PCTCore64.sys –> C:\Windows\system32\drivers\PCTCore64.sys [?] R0 pctDS;PC Tools Data Store;C:\Windows\system32\drivers\pctDS64.sys –> C:\Windows\system32\drivers\pctDS64.sys [?] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys –> C:\Windows\system32\DRIVERS\vwififlt.sys [?] R2 AppleOSSMgr;Apple OS Switch Manager;C:\Windows\system32\AppleOSSMgr.exe –> C:\Windows\system32\AppleOSSMgr.exe [?] R2 AppleTimeSrv;Apple Time Service;C:\Windows\system32\AppleTimeSrv.exe –> C:\Windows\system32\AppleTimeSrv.exe [?] R2 KeyAgent;KeyAgent;\??\C:\Windows\system32\drivers\KeyAgent.sys –> C:\Windows\system32\drivers\KeyAgent.sys [?] R2 MacHALDriver;Mac HAL;\??\C:\Windows\system32\drivers\MacHALDriver.sys –> C:\Windows\system32\drivers\MacHALDriver.sys [?] R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-12-20 366152] R3 acpials;ALS Sensor Filter;C:\Windows\system32\DRIVERS\acpials.sys –> C:\Windows\system32\DRIVERS\acpials.sys [?] R3 AppleBtBc;Apple Broadcom Built-in Bluetooth;C:\Windows\system32\DRIVERS\AppleBtBc.sys –> C:\Windows\system32\DRIVERS\AppleBtBc.sys [?] R3 applemtm;Apple Multitouch Mouse;C:\Windows\system32\DRIVERS\applemtm.sys –> C:\Windows\system32\DRIVERS\applemtm.sys [?] R3 applemtp;Apple Multitouch;C:\Windows\system32\DRIVERS\applemtp.sys –> C:\Windows\system32\DRIVERS\applemtp.sys [?] R3 CirrusFilter;CS420xLowerFilter;C:\Windows\system32\DRIVERS\CS420x64.sys –> C:\Windows\system32\DRIVERS\CS420x64.sys [?] R3 IRRemoteFlt;IR Receiver Filter Driver;C:\Windows\system32\DRIVERS\IRFilter.sys –> C:\Windows\system32\DRIVERS\IRFilter.sys [?] R3 KeyMagic;USB Keyboard HID Filter;C:\Windows\system32\DRIVERS\KeyMagic.sys –> C:\Windows\system32\DRIVERS\KeyMagic.sys [?] R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys –> C:\Windows\system32\drivers\mbam.sys [?] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys –> C:\Windows\system32\drivers\nvhda64v.sys [?] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys –> C:\Windows\system32\DRIVERS\vwifimp.sys [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-1-13 136176] S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-1-13 136176] S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-1-15 227232] S3 sdAuxService;PC Tools Auxiliary Service;C:\Program Files (x86)\PC Tools Security\pctsAuxs.exe [2011-12-20 366840] S3 sdCoreService;PC Tools Security Service;C:\Program Files (x86)\PC Tools Security\pctsSvc.exe [2011-12-20 1150936] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?] S3 WSDPrintDevice;WSD Print Support via UMB;C:\Windows\system32\DRIVERS\WSDPrint.sys –> C:\Windows\system32\DRIVERS\WSDPrint.sys [?] S3 WSDScan;WSD Scan Support via UMB;C:\Windows\system32\DRIVERS\WSDScan.sys –> C:\Windows\system32\DRIVERS\WSDScan.sys [?] . =============== Created Last 30 ================ . 2011-12-21 04:32:47 ——– d—–w- C:\Users\egrepo\AppData\Roaming\Malwarebytes 2011-12-21 04:32:39 ——– d—–w- C:\ProgramData\Malwarebytes 2011-12-21 04:32:35 25416 —-a-w- C:\Windows\System32\drivers\mbam.sys 2011-12-21 04:32:35 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2011-12-20 22:57:45 ——– d–h–w- C:\$AVG 2011-12-20 22:36:10 ——– d—–w- C:\ProgramData\AVG Secure Search 2011-12-20 22:36:06 ——– d—–w- C:\Program Files (x86)\Common Files\AVG Secure Search 2011-12-20 22:36:05 ——– d—–w- C:\Program Files (x86)\AVG Secure Search 2011-12-20 22:35:20 ——– d—–w- C:\Users\egrepo\AppData\Roaming\AVG2012 2011-12-20 22:34:17 ——– d–h–w- C:\ProgramData\Common Files 2011-12-20 22:33:51 ——– d—–w- C:\Windows\SysWow64\drivers\AVG 2011-12-20 22:32:58 ——– d—–w- C:\Windows\System32\drivers\AVG 2011-12-20 22:32:58 ——– d—–w- C:\ProgramData\AVG2012 2011-12-20 22:30:43 ——– d—–w- C:\Program Files (x86)\AVG 2011-12-20 22:23:19 ——– d—–w- C:\ProgramData\MFAData 2011-12-20 22:01:19 816016 —-a-w- C:\Windows\System32\drivers\pctEFA64.sys 2011-12-20 22:01:19 452872 —-a-w- C:\Windows\System32\drivers\pctDS64.sys 2011-12-20 22:01:19 334976 —-a-w- C:\Windows\System32\drivers\pctgntdi64.sys 2011-12-20 22:01:19 137704 —-a-w- C:\Windows\System32\drivers\pctwfpfilter64.sys 2011-12-20 22:01:16 257232 —-a-w- C:\Windows\System32\drivers\PCTCore64.sys 2011-12-20 22:01:14 92896 —-a-w- C:\Windows\System32\drivers\pctplsg64.sys 2011-12-20 22:01:10 ——– d—–w- C:\Users\egrepo\AppData\Roaming\PC Tools 2011-12-20 22:01:10 ——– d—–w- C:\Program Files (x86)\PC Tools Security 2011-12-20 22:01:10 ——– d—–w- C:\Program Files (x86)\Common Files\PC Tools 2011-12-20 21:57:14 ——– d—–w- C:\ProgramData\PC Tools 2011-12-20 21:14:21 ——– d—–we C:\Windows\system64 2011-12-16 03:17:25 3141632 —-a-w- C:\Windows\System32\win32k.sys 2011-12-16 03:17:24 723456 —-a-w- C:\Windows\System32\EncDec.dll 2011-12-16 03:17:23 534528 —-a-w- C:\Windows\SysWow64\EncDec.dll 2011-12-16 03:17:19 2048 —-a-w- C:\Windows\SysWow64\tzres.dll 2011-12-16 03:17:18 2048 —-a-w- C:\Windows\System32\tzres.dll . ==================== Find3M ==================== . 2011-11-05 05:26:29 1197568 —-a-w- C:\Windows\System32\wininet.dll 2011-11-05 05:23:10 57856 —-a-w- C:\Windows\System32\licmgr10.dll 2011-11-05 04:35:50 981504 —-a-w- C:\Windows\SysWow64\wininet.dll 2011-11-05 04:34:15 44544 —-a-w- C:\Windows\SysWow64\licmgr10.dll 2011-11-05 04:07:32 482816 —-a-w- C:\Windows\System32\html.iec 2011-11-05 03:28:41 386048 —-a-w- C:\Windows\SysWow64\html.iec 2011-11-05 03:25:44 1638912 —-a-w- C:\Windows\System32\mshtml.tlb 2011-11-05 02:55:38 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2011-10-26 05:19:07 43520 —-a-w- C:\Windows\System32\csrsrv.dll 2011-09-29 16:24:44 1897328 —-a-w- C:\Windows\System32\drivers\tcpip.sys . ============= FINISH: 18:45:02.95 ===============
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Watch Topic button to the right of your topic title and then choosing the notification method ( Recommended: Inmediate Notification)
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———-

**WARNING**Unfortunately one or more of the infections I have identified are Backdoor Trojans, IRCBots or other Malware capable of stealing very important information. You need to stop using all Internet Banking sites, change passwords to all sites with sensitive information from a clean computer and phone your bank to inform them that you may be a victim of identify theft. More often than not, we advise users that a full reinstallation of their Operating System is the only way to ensure that their computer will ever be 100% clean again.

Unfortunately I have found what is known as the ZeroAccess rootkit on your system. It is an especially nasty infection that can take quite some time to clean as well as may have damaged your system files itself. As a warning, during the cleaning (if you choose to do so) you may lose internet access with this computer and in the end we may need to reinstall the operating system anyway depending on the extent of the infection.

If you would like to format and reinstall your Operating System please let me know and we can assist you with that.

If you would like to continue with the cleaning, please continue with the following instructions and I will be more than happy to help. :)
———-

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Right-click and Run as Administrator TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
———-

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
————-

If you have decided to continue with cleaning please post the logs created by TDSSKiller and ComboFix. :)
Okay so Im posting from the Macbook part of my laptop because right after I used the combofix program to get the log, it rebooted my system, but when I got back to the desktop, I could not get on to the internet with mozilla or internet explorer. it said I was connected to the internet like usual, I would open the browser and it would just be a blank white screen and did nothing. even if I clicked on bookmarked links. Im not too sure how to get those logs to you if I cant get online on my bootcamp Windows side of this laptop..
Hi, Ok…reboot your system again then boot into Safe Mode with Networking. You said that you already ran ComboFix? Look in your C:\ folder and you should find the ComboFix log there. Post that log into your next reply along with the TDSSKiller log. If you still have problems let me know exactly what is happening on your system. :)
Just tried going on the Internet after safe mode with networking and the browser still doesn't work. When I try to go to a site, it just says "Done" on the loading bar at the bottom left and doesn't do anything. Any ideas on what I can do?
Hi egrepo, Ok…you may need to use a USB drive to transfer the tools and the logs from the infected computer to a clean computer unfortunately. I believe that this is a symptom of this infection that I told you about.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI