This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

ping.exe running constantly using resources [Closed]

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ping.exe has been running and using quite a bit of memory. it I delete it from the task manager it just reappears. Please help! Thanks. I ran DDS below . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 6.0.2900.5512 Run by [removed] at 2:49:10 on 2011-12-24 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.292 [GMT -8:00] . AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\cisvc.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\svchost.exe -k netsvc svchost.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\system32\cidaemon.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\WINDOWS\eHome\ehmsas.exe C:\WINDOWS\vVX3000.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\OpenOffice.org 3\program\soffice.exe C:\Program Files\OpenOffice.org 3\program\soffice.bin C:\Program Files\Java\jre6\bin\jucheck.exe C:\WINDOWS\system32\notepad.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\WINDOWS\system32\taskmgr.exe C:\WINDOWS\System32\ping.exe . ============== Pseudo HJT Report =============== . uInternet Settings,ProxyServer = http=127.0.0.1:55111 uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized uRun: [Google Update] "c:\documents and settings\new owner\local settings\application data\google\update\GoogleUpdate.exe" /c mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [VX3000] c:\windows\vVX3000.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t StartupFolder: c:\docume~1\newown~1\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll LSP: mswsock.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{DFE41E37-AB72-4B08-B113-C0E35BE419FF} : DhcpNameServer = 192.168.1.1 Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Notify: igfxcui - igfxdev.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\new owner\application data\mozilla\firefox\profiles\wj2lxh4g.default\ FF - component: c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll FF - plugin: c:\documents and settings\new owner\local settings\application data\google\update\1.3.21.79\npGoogleUpdate3.dll . ============= SERVICES / DRIVERS =============== . R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165648] R1 MpKslbab6528b;MpKslbab6528b;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ef8a4874-c0b2-433b-ab91-6f3d89283697}\MpKslbab6528b.sys [2011-12-23 29904] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] R2 SPService;SPService;c:\windows\system32\svchost.exe -k netsvc [2004-8-10 14336] R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8192su.sys [2011-5-26 602912] S1 MpKsl0336a3f5;MpKsl0336a3f5;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5b253b70-1319-4ed8-97a4-29bc3e72dda7}\mpksl0336a3f5.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5b253b70-1319-4ed8-97a4-29bc3e72dda7}\MpKsl0336a3f5.sys [?] S1 MpKsl1eb924c4;MpKsl1eb924c4;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5b253b70-1319-4ed8-97a4-29bc3e72dda7}\mpksl1eb924c4.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5b253b70-1319-4ed8-97a4-29bc3e72dda7}\MpKsl1eb924c4.sys [?] S1 MpKsl260fde2e;MpKsl260fde2e;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{4c62e5e8-1e0e-4077-be0c-4a3688a5f41f}\mpksl260fde2e.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{4c62e5e8-1e0e-4077-be0c-4a3688a5f41f}\MpKsl260fde2e.sys [?] S1 MpKsl436bbb83;MpKsl436bbb83;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0f50651b-e44a-4b74-b032-082888fcb5b6}\mpksl436bbb83.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0f50651b-e44a-4b74-b032-082888fcb5b6}\MpKsl436bbb83.sys [?] S1 MpKsl53f1d746;MpKsl53f1d746;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fb213ef3-348b-46f6-b67c-2e3f4e046d61}\mpksl53f1d746.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fb213ef3-348b-46f6-b67c-2e3f4e046d61}\MpKsl53f1d746.sys [?] S1 MpKsl56d50922;MpKsl56d50922;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c46285ab-84db-4b03-9130-799552d944ce}\mpksl56d50922.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c46285ab-84db-4b03-9130-799552d944ce}\MpKsl56d50922.sys [?] S1 MpKsl707eb4ad;MpKsl707eb4ad;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0dfd5040-9725-4314-b08b-52779c4c4487}\mpksl707eb4ad.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0dfd5040-9725-4314-b08b-52779c4c4487}\MpKsl707eb4ad.sys [?] S1 MpKslb7e1e5fa;MpKslb7e1e5fa;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5b253b70-1319-4ed8-97a4-29bc3e72dda7}\mpkslb7e1e5fa.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5b253b70-1319-4ed8-97a4-29bc3e72dda7}\MpKslb7e1e5fa.sys [?] S1 MpKsld4b4da69;MpKsld4b4da69;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5b253b70-1319-4ed8-97a4-29bc3e72dda7}\mpksld4b4da69.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5b253b70-1319-4ed8-97a4-29bc3e72dda7}\MpKsld4b4da69.sys [?] S3 SG760_XP;SAGEM 802.11g XG760 1211 Driver;c:\windows\system32\drivers\WlanUZXP.sys [2005-5-14 260608] . =============== Created Last 30 ================ . 2011-12-23 15:55:01 29904 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ef8a4874-c0b2-433b-ab91-6f3d89283697}\MpKslbab6528b.sys 2011-12-23 15:54:40 56200 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ef8a4874-c0b2-433b-ab91-6f3d89283697}\offreg.dll 2011-12-23 15:54:28 6823496 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ef8a4874-c0b2-433b-ab91-6f3d89283697}\mpengine.dll 2011-12-19 14:26:29 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll 2011-12-19 14:26:25 89048 —-a-w- c:\program files\mozilla firefox\libEGL.dll 2011-12-19 14:26:25 801752 —-a-w- c:\program files\mozilla firefox\mozsqlite3.dll 2011-12-19 14:26:25 478168 —-a-w- c:\program files\mozilla firefox\libGLESv2.dll 2011-12-19 14:26:25 2106216 —-a-w- c:\program files\mozilla firefox\D3DCompiler_43.dll 2011-12-19 14:26:25 1998168 —-a-w- c:\program files\mozilla firefox\d3dx9_43.dll 2011-12-19 14:26:25 1989592 —-a-w- c:\program files\mozilla firefox\mozjs.dll 2011-12-19 14:26:25 15832 —-a-w- c:\program files\mozilla firefox\mozalloc.dll 2011-12-19 14:05:11 ——– d—–w- c:\windows\system32\wbem\repository\FS 2011-12-19 14:05:11 ——– d—–w- c:\windows\system32\wbem\Repository 2011-12-19 13:55:50 ——– d—–w- c:\program files\Bonjour 2011-12-16 14:56:06 ——– d—–w- C:\phone 2011-12-16 11:01:36 ——– d—–w- c:\documents and settings\new owner\local settings\application data\PCHealth 2011-12-08 02:41:47 ——– d—–w- c:\program files\LSoft Technologies 2011-12-08 01:16:46 ——– d—–w- c:\documents and settings\new owner\local settings\application data\Opera 2011-12-07 22:26:49 ——– d—–w- c:\windows\pss 2011-12-04 23:49:27 2572 —-a-w- c:\windows\system32\PerfStringBackup.TMP . ==================== Find3M ==================== . 2011-12-21 20:34:00 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-11-23 13:25:32 1859584 —-a-w- c:\windows\system32\win32k.sys 2011-11-01 20:35:20 81920 —-a-w- c:\windows\system32\ieencode.dll 2011-11-01 20:35:20 667136 —-a-w- c:\windows\system32\wininet.dll 2011-11-01 20:35:20 61952 —-a-w- c:\windows\system32\tdc.ocx 2011-11-01 16:07:10 1288704 —-a-w- c:\windows\system32\ole32.dll 2011-11-01 15:02:49 369664 —-a-w- c:\windows\system32\html.iec 2011-10-28 05:31:48 33280 —-a-w- c:\windows\system32\csrsrv.dll 2011-10-25 13:33:08 2192768 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-10-25 12:52:03 2069376 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-10-15 01:38:00 456192 —-a-w- c:\windows\system32\encdec.dll 2011-10-10 14:22:41 692736 —-a-w- c:\windows\system32\inetcomm.dll 2011-10-06 20:37:02 0 —ha-w- c:\documents and settings\new owner\dkplxyoxrs.tmp 2011-09-28 07:06:50 599040 —-a-w- c:\windows\system32\crypt32.dll 2011-09-28 07:06:50 599040 —-a-w- c:\windows\system32\crypt32(2)(3).dll 2011-09-26 19:41:20 611328 ——w- c:\windows\system32\uiautomationcore.dll 2011-09-26 19:41:20 220160 —-a-w- c:\windows\system32\oleacc.dll 2011-09-26 19:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll . ============= FINISH: 2:53:15.96 ===============
Hello and Welcome to WhatTheTech Forums

My name is BlackPegasus and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested




DDS produces two logs the DDS.txt and Attach.txt. Please post the Attach.txt if you didn't save it please run DDS again and then post both logs.

Did you deliberately set this proxy yourself?
uInternet Settings,ProxyServer = http=127.0.0.1:55111

NEXT

Please download aswMBR to your desktop.
  • Double click the aswMBR.exe icon to run it
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.



Summary of the logs I need from you in your next post:

Attach.txt
aswMBR log
Answer about the proxy
. DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 6.0.2900.5512 Run by [removed] at 11:06:47 on 2011-12-25 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.248 [GMT -8:00] . AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\cisvc.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe C:\WINDOWS\system32\svchost.exe -k netsvc svchost.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Microsoft Security Client\msseces.exe C:\WINDOWS\vVX3000.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\OpenOffice.org 3\program\soffice.exe C:\Program Files\OpenOffice.org 3\program\soffice.bin C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\Movie Maker\moviemk.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\system32\cidaemon.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\igfxsrvc.exe C:\WINDOWS\system32\msiexec.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\WINDOWS\system32\taskmgr.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\WINDOWS\System32\ping.exe . ============== Pseudo HJT Report =============== . uInternet Settings,ProxyServer = http=127.0.0.1:55111 uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized uRun: [Google Update] "c:\documents and settings\new owner\local settings\application data\google\update\GoogleUpdate.exe" /c mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [VX3000] c:\windows\vVX3000.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t StartupFolder: c:\docume~1\newown~1\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll LSP: mswsock.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{DFE41E37-AB72-4B08-B113-C0E35BE419FF} : DhcpNameServer = 192.168.1.1 Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Notify: igfxcui - igfxdev.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\new owner\application data\mozilla\firefox\profiles\wj2lxh4g.default\ FF - component: c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll FF - plugin: c:\documents and settings\new owner\local settings\application data\google\update\1.3.21.79\npGoogleUpdate3.dll . ============= SERVICES / DRIVERS =============== . R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165648] R1 MpKsl3be37561;MpKsl3be37561;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3dd95790-3a98-4960-9576-5e95aae37a5b}\MpKsl3be37561.sys [2011-12-24 29904] R1 MpKsl8202126e;MpKsl8202126e;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3dd95790-3a98-4960-9576-5e95aae37a5b}\MpKsl8202126e.sys [2011-12-25 29904] R1 MpKslc3019d9e;MpKslc3019d9e;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3dd95790-3a98-4960-9576-5e95aae37a5b}\MpKslc3019d9e.sys [2011-12-25 29904] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] R2 SPService;SPService;c:\windows\system32\svchost.exe -k netsvc [2004-8-10 14336] R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8192su.sys [2011-5-26 602912] S1 MpKsl0336a3f5;MpKsl0336a3f5;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5b253b70-1319-4ed8-97a4-29bc3e72dda7}\mpksl0336a3f5.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5b253b70-1319-4ed8-97a4-29bc3e72dda7}\MpKsl0336a3f5.sys [?] S1 MpKsl1eb924c4;MpKsl1eb924c4;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5b253b70-1319-4ed8-97a4-29bc3e72dda7}\mpksl1eb924c4.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5b253b70-1319-4ed8-97a4-29bc3e72dda7}\MpKsl1eb924c4.sys [?] S1 MpKsl260fde2e;MpKsl260fde2e;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{4c62e5e8-1e0e-4077-be0c-4a3688a5f41f}\mpksl260fde2e.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{4c62e5e8-1e0e-4077-be0c-4a3688a5f41f}\MpKsl260fde2e.sys [?] S1 MpKsl436bbb83;MpKsl436bbb83;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0f50651b-e44a-4b74-b032-082888fcb5b6}\mpksl436bbb83.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0f50651b-e44a-4b74-b032-082888fcb5b6}\MpKsl436bbb83.sys [?] S1 MpKsl53f1d746;MpKsl53f1d746;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fb213ef3-348b-46f6-b67c-2e3f4e046d61}\mpksl53f1d746.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fb213ef3-348b-46f6-b67c-2e3f4e046d61}\MpKsl53f1d746.sys [?] S1 MpKsl56d50922;MpKsl56d50922;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c46285ab-84db-4b03-9130-799552d944ce}\mpksl56d50922.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c46285ab-84db-4b03-9130-799552d944ce}\MpKsl56d50922.sys [?] S1 MpKsl707eb4ad;MpKsl707eb4ad;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0dfd5040-9725-4314-b08b-52779c4c4487}\mpksl707eb4ad.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0dfd5040-9725-4314-b08b-52779c4c4487}\MpKsl707eb4ad.sys [?] S1 MpKslb7e1e5fa;MpKslb7e1e5fa;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5b253b70-1319-4ed8-97a4-29bc3e72dda7}\mpkslb7e1e5fa.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5b253b70-1319-4ed8-97a4-29bc3e72dda7}\MpKslb7e1e5fa.sys [?] S1 MpKsld4b4da69;MpKsld4b4da69;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5b253b70-1319-4ed8-97a4-29bc3e72dda7}\mpksld4b4da69.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5b253b70-1319-4ed8-97a4-29bc3e72dda7}\MpKsld4b4da69.sys [?] S3 SG760_XP;SAGEM 802.11g XG760 1211 Driver;c:\windows\system32\drivers\WlanUZXP.sys [2005-5-14 260608] . =============== Created Last 30 ================ . 2011-12-25 18:10:59 ——– d—–w- C:\folder 2011-12-25 16:50:14 29904 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3dd95790-3a98-4960-9576-5e95aae37a5b}\MpKslc3019d9e.sys 2011-12-25 13:57:34 29904 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3dd95790-3a98-4960-9576-5e95aae37a5b}\MpKsl8202126e.sys 2011-12-24 15:48:18 29904 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3dd95790-3a98-4960-9576-5e95aae37a5b}\MpKsl3be37561.sys 2011-12-24 15:47:05 56200 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3dd95790-3a98-4960-9576-5e95aae37a5b}\offreg.dll 2011-12-24 15:46:55 6823496 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3dd95790-3a98-4960-9576-5e95aae37a5b}\mpengine.dll 2011-12-24 11:04:23 18 —-a-w- C:\whatthetech.com 2011-12-19 14:26:29 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll 2011-12-19 14:26:25 89048 —-a-w- c:\program files\mozilla firefox\libEGL.dll 2011-12-19 14:26:25 801752 —-a-w- c:\program files\mozilla firefox\mozsqlite3.dll 2011-12-19 14:26:25 478168 —-a-w- c:\program files\mozilla firefox\libGLESv2.dll 2011-12-19 14:26:25 2106216 —-a-w- c:\program files\mozilla firefox\D3DCompiler_43.dll 2011-12-19 14:26:25 1998168 —-a-w- c:\program files\mozilla firefox\d3dx9_43.dll 2011-12-19 14:26:25 1989592 —-a-w- c:\program files\mozilla firefox\mozjs.dll 2011-12-19 14:26:25 15832 —-a-w- c:\program files\mozilla firefox\mozalloc.dll 2011-12-19 14:05:11 ——– d—–w- c:\windows\system32\wbem\repository\FS 2011-12-19 14:05:11 ——– d—–w- c:\windows\system32\wbem\Repository 2011-12-19 13:55:50 ——– d—–w- c:\program files\Bonjour 2011-12-16 14:56:06 ——– d—–w- C:\phone 2011-12-16 11:01:36 ——– d—–w- c:\documents and settings\new owner\local settings\application data\PCHealth 2011-12-08 02:41:47 ——– d—–w- c:\program files\LSoft Technologies 2011-12-08 01:16:46 ——– d—–w- c:\documents and settings\new owner\local settings\application data\Opera 2011-12-07 22:26:49 ——– d—–w- c:\windows\pss 2011-12-04 23:49:27 2572 —-a-w- c:\windows\system32\PerfStringBackup.TMP . ==================== Find3M ==================== . 2011-12-21 20:34:00 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-11-23 13:25:32 1859584 —-a-w- c:\windows\system32\win32k.sys 2011-11-01 20:35:20 81920 —-a-w- c:\windows\system32\ieencode.dll 2011-11-01 20:35:20 667136 —-a-w- c:\windows\system32\wininet.dll 2011-11-01 20:35:20 61952 —-a-w- c:\windows\system32\tdc.ocx 2011-11-01 16:07:10 1288704 —-a-w- c:\windows\system32\ole32.dll 2011-11-01 15:02:49 369664 —-a-w- c:\windows\system32\html.iec 2011-10-28 05:31:48 33280 —-a-w- c:\windows\system32\csrsrv.dll 2011-10-25 13:33:08 2192768 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-10-25 12:52:03 2069376 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-10-15 01:38:00 456192 —-a-w- c:\windows\system32\encdec.dll 2011-10-10 14:22:41 692736 —-a-w- c:\windows\system32\inetcomm.dll 2011-10-06 20:37:02 0 —ha-w- c:\documents and settings\new owner\dkplxyoxrs.tmp 2011-09-28 07:06:50 599040 —-a-w- c:\windows\system32\crypt32.dll 2011-09-28 07:06:50 599040 —-a-w- c:\windows\system32\crypt32(2)(3).dll 2011-09-26 19:41:20 611328 ——w- c:\windows\system32\uiautomationcore.dll 2011-09-26 19:41:20 220160 —-a-w- c:\windows\system32\oleacc.dll 2011-09-26 19:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll . ============= FINISH: 11:09:34.61 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 4/23/2011 10:54:51 AM System Uptime: 12/25/2011 8:47:52 AM (3 hours ago) . Motherboard: Dell Inc. | | 0JC474 Processor: Intel® Pentium® 4 CPU 2.80GHz | Microprocessor | 2792/800mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 74 GiB total, 33.001 GiB free. D: is CDROM () . ==== Disabled Device Manager Items ============= . Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: Intel® PRO/100 VE Network Connection Device ID: PCI\VEN_8086&DEV_1064&SUBSYS_01C41028&REV_04\4&10BD256C&0&40F0 Manufacturer: Intel Name: Intel® PRO/100 VE Network Connection PNP Device ID: PCI\VEN_8086&DEV_1064&SUBSYS_01C41028&REV_04\4&10BD256C&0&40F0 Service: E100B . ==== System Restore Points =================== . RP220: 10/12/2011 3:00:13 AM - Software Distribution Service 3.0 RP221: 10/13/2011 3:30:06 AM - System Checkpoint RP222: 10/13/2011 3:32:27 AM - Software Distribution Service 3.0 RP223: 10/14/2011 3:33:05 AM - Software Distribution Service 3.0 RP224: 10/15/2011 3:32:03 AM - Software Distribution Service 3.0 RP225: 10/16/2011 1:42:53 AM - Software Distribution Service 3.0 RP226: 10/17/2011 2:30:04 AM - System Checkpoint RP227: 10/17/2011 3:32:08 AM - Software Distribution Service 3.0 RP228: 10/18/2011 5:09:08 AM - System Checkpoint RP229: 10/19/2011 5:51:24 AM - System Checkpoint RP230: 10/19/2011 8:06:31 PM - Software Distribution Service 3.0 RP231: 10/20/2011 8:06:22 PM - Software Distribution Service 3.0 RP232: 10/21/2011 8:06:10 PM - Software Distribution Service 3.0 RP233: 10/22/2011 8:06:09 PM - Software Distribution Service 3.0 RP234: 10/23/2011 2:07:38 AM - Software Distribution Service 3.0 RP235: 10/24/2011 3:03:37 AM - System Checkpoint RP236: 10/25/2011 3:36:54 AM - System Checkpoint RP237: 10/26/2011 3:52:06 AM - System Checkpoint RP238: 10/26/2011 10:55:17 AM - Software Distribution Service 3.0 RP239: 10/27/2011 10:54:40 AM - Software Distribution Service 3.0 RP240: 10/28/2011 10:54:25 AM - Software Distribution Service 3.0 RP241: 10/29/2011 10:54:34 AM - Software Distribution Service 3.0 RP242: 10/30/2011 1:56:02 AM - Software Distribution Service 3.0 RP243: 10/30/2011 10:54:16 AM - Software Distribution Service 3.0 RP244: 10/31/2011 12:00:10 PM - System Checkpoint RP245: 11/1/2011 10:54:40 AM - Software Distribution Service 3.0 RP246: 11/2/2011 10:54:24 AM - Software Distribution Service 3.0 RP247: 11/3/2011 10:54:22 AM - Software Distribution Service 3.0 RP248: 11/4/2011 10:54:56 AM - Software Distribution Service 3.0 RP249: 11/5/2011 10:54:58 AM - Software Distribution Service 3.0 RP250: 11/6/2011 12:50:51 AM - Software Distribution Service 3.0 RP251: 11/6/2011 10:54:10 AM - Software Distribution Service 3.0 RP252: 11/7/2011 10:54:29 AM - Software Distribution Service 3.0 RP253: 11/8/2011 10:54:30 AM - Software Distribution Service 3.0 RP254: 11/9/2011 3:00:14 AM - Software Distribution Service 3.0 RP255: 11/9/2011 10:54:42 AM - Software Distribution Service 3.0 RP256: 11/10/2011 11:01:51 AM - System Checkpoint RP257: 11/11/2011 8:05:30 AM - Software Distribution Service 3.0 RP258: 11/12/2011 3:00:14 AM - Software Distribution Service 3.0 RP259: 11/13/2011 1:43:50 AM - Software Distribution Service 3.0 RP260: 11/14/2011 3:08:52 AM - System Checkpoint RP261: 11/14/2011 4:18:15 AM - Software Distribution Service 3.0 RP262: 11/15/2011 4:34:49 AM - System Checkpoint RP263: 11/15/2011 11:37:31 AM - Software Distribution Service 3.0 RP264: 11/16/2011 11:53:18 AM - System Checkpoint RP265: 11/17/2011 4:55:19 AM - Software Distribution Service 3.0 RP266: 11/18/2011 4:55:06 AM - Software Distribution Service 3.0 RP267: 11/19/2011 4:54:55 AM - Software Distribution Service 3.0 RP268: 11/20/2011 1:33:44 AM - Software Distribution Service 3.0 RP269: 11/21/2011 1:53:09 AM - System Checkpoint RP270: 11/21/2011 4:54:59 AM - Software Distribution Service 3.0 RP271: 11/22/2011 4:55:00 AM - Software Distribution Service 3.0 RP272: 11/23/2011 5:27:07 AM - System Checkpoint RP273: 11/23/2011 8:04:20 AM - Software Distribution Service 3.0 RP274: 11/24/2011 7:58:55 AM - Software Distribution Service 3.0 RP275: 11/25/2011 7:58:53 AM - Software Distribution Service 3.0 RP276: 11/26/2011 7:58:57 AM - Software Distribution Service 3.0 RP277: 11/27/2011 2:08:15 AM - Software Distribution Service 3.0 RP278: 11/27/2011 7:58:50 AM - Software Distribution Service 3.0 RP279: 11/27/2011 9:42:38 AM - Restore Operation RP280: 11/28/2011 9:49:07 AM - System Checkpoint RP281: 11/28/2011 9:56:25 AM - Software Distribution Service 3.0 RP282: 11/29/2011 10:33:19 AM - System Checkpoint RP283: 11/29/2011 1:35:37 PM - Software Distribution Service 3.0 RP284: 11/30/2011 1:35:30 PM - Software Distribution Service 3.0 RP285: 12/1/2011 1:35:39 PM - Software Distribution Service 3.0 RP286: 12/2/2011 1:35:44 PM - Software Distribution Service 3.0 RP287: 12/3/2011 3:38:34 PM - System Checkpoint RP288: 12/4/2011 1:06:50 AM - Software Distribution Service 3.0 RP289: 12/4/2011 3:32:16 PM - Restore Operation RP290: 12/5/2011 3:00:19 AM - Software Distribution Service 3.0 RP291: 12/6/2011 3:02:10 AM - System Checkpoint RP292: 12/6/2011 11:58:59 AM - Restore Operation RP293: 12/6/2011 1:24:55 PM - Removed Bonjour RP294: 12/6/2011 9:35:52 PM - Software Distribution Service 3.0 RP295: 12/7/2011 12:19:46 PM - Software Distribution Service 3.0 RP296: 12/7/2011 6:41:47 PM - Installed Active@ ISO Burner RP297: 12/7/2011 6:41:57 PM - SPTD setup V1.62 RP298: 12/8/2011 3:00:14 AM - Software Distribution Service 3.0 RP299: 12/9/2011 10:28:18 AM - System Checkpoint RP300: 12/11/2011 3:14:54 AM - System Checkpoint RP301: 12/12/2011 3:52:40 AM - System Checkpoint RP302: 12/13/2011 6:19:07 AM - System Checkpoint RP303: 12/14/2011 6:51:34 AM - System Checkpoint RP304: 12/15/2011 9:17:34 PM - System Checkpoint RP305: 12/16/2011 3:00:16 AM - Software Distribution Service 3.0 RP306: 12/17/2011 8:23:47 AM - System Checkpoint RP307: 12/18/2011 10:41:58 AM - System Checkpoint RP308: 12/19/2011 5:16:36 AM - Software Distribution Service 3.0 RP309: 12/19/2011 5:42:55 AM - Restore Operation RP310: 12/20/2011 3:00:31 AM - Software Distribution Service 3.0 RP311: 12/20/2011 6:27:12 AM - Software Distribution Service 3.0 RP312: 12/21/2011 3:00:37 AM - Software Distribution Service 3.0 RP313: 12/21/2011 7:45:17 AM - Software Distribution Service 3.0 RP314: 12/22/2011 7:47:35 AM - Software Distribution Service 3.0 RP315: 12/23/2011 7:54:21 AM - Software Distribution Service 3.0 RP316: 12/24/2011 7:46:47 AM - Software Distribution Service 3.0 RP317: 12/25/2011 8:00:45 AM - System Checkpoint . ==== Installed Programs ====================== . Adobe Flash Player 11 Plugin Adobe Reader 9 Apple Application Support Apple Mobile Device Support Apple Software Update ATI - Software Uninstall Utility Bonjour Conexant D850 56K V.9x DFVc Modem Dell Resource CD Dziobas Rar Player 0.009.51 ESPNMotion GemMaster Mystic Google Chrome Hotfix for Windows Media Player 10 (KB903157) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB2570791) Hotfix for Windows XP (KB2633952) Hotfix for Windows XP (KB952287) Intel® Graphics Media Accelerator Driver Intel® PRO Network Connections Drivers Java™ 6 Update 16 Microsoft .NET Framework 1.0 Hotfix (KB2572066) Microsoft .NET Framework 1.0 Hotfix (KB953295) Microsoft .NET Framework 1.0 Hotfix (KB979904) Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB2572067) Microsoft Antimalware Microsoft Application Error Reporting Microsoft Office 2000 Professional Microsoft Security Client Microsoft Security Essentials Mozilla Firefox 8.0.1 (x86 en-US) Need For Speed II SE Network Play System (Patching) OpenOffice.org 3.1 Otto PowerDVD 5.7 QuickTime S.T.A.L.K.E.R. - Clear Sky SAMSUNG CDMA Modem Driver Set Security Update for Microsoft Windows (KB2564958) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476490) Security Update for Windows XP (KB2476687) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2497640) Security Update for Windows XP (KB2503658) Security Update for Windows XP (KB2503665) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2506223) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2507938) Security Update for Windows XP (KB2508272) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2510581) Security Update for Windows XP (KB2511455) Security Update for Windows XP (KB2524375) Security Update for Windows XP (KB2530548) Security Update for Windows XP (KB2535512) Security Update for Windows XP (KB2536276-v2) Security Update for Windows XP (KB2536276) Security Update for Windows XP (KB2544521) Security Update for Windows XP (KB2544893-v2) Security Update for Windows XP (KB2544893) Security Update for Windows XP (KB2555917) Security Update for Windows XP (KB2559049) Security Update for Windows XP (KB2562937) Security Update for Windows XP (KB2566454) Security Update for Windows XP (KB2567680) Security Update for Windows XP (KB2570222) Security Update for Windows XP (KB2570947) Security Update for Windows XP (KB2592799) Security Update for Windows XP (KB2618444) Security Update for Windows XP (KB2618451) Security Update for Windows XP (KB2620712) Security Update for Windows XP (KB2624667) Security Update for Windows XP (KB2633171) Security Update for Windows XP (KB2639417) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982665) SigmaTel Audio Skype Toolbars Skype™ 5.3 Sonic Encoders The Sims Update for Windows XP (KB2345886) Update for Windows XP (KB2541763) Update for Windows XP (KB2607712) Update for Windows XP (KB2616676) Update for Windows XP (KB2641690) Update for Windows XP (KB898461) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Update Rollup 2 for Windows XP Media Center Edition 2005 VLC media player 1.1.11 WebFldrs XP Whats Love Screensaver Windows Genuine Advantage Validation Tool (KB892130) Windows Media Format Runtime Windows XP Media Center Edition 2005 KB2502898 Windows XP Media Center Edition 2005 KB2619340 Windows XP Media Center Edition 2005 KB973768 Windows XP Service Pack 3 . ==== Event Viewer Messages From Past Week ======== . 12/24/2011 4:45:01 AM, error: Schedule [7901] - The At58.job command failed to start due to the following error: %%2147942402 12/24/2011 3:45:00 AM, error: Schedule [7901] - The At8.job command failed to start due to the following error: %%2147942402 12/23/2011 6:45:00 AM, error: Schedule [7901] - The At14.job command failed to start due to the following error: %%2147942402 12/23/2011 6:03:09 AM, error: Service Control Manager [7023] - The Network Location Awareness (NLA) service terminated with the following error: The specified procedure could not be found. 12/22/2011 6:45:00 AM, error: Schedule [7901] - The At13.job command failed to start due to the following error: %%2147942402 12/22/2011 5:45:00 AM, error: Schedule [7901] - The At12.job command failed to start due to the following error: %%2147942402 12/22/2011 5:45:00 AM, error: Schedule [7901] - The At11.job command failed to start due to the following error: %%2147942402 12/22/2011 4:45:00 AM, error: Schedule [7901] - The At10.job command failed to start due to the following error: %%2147942402 12/22/2011 3:45:00 AM, error: Schedule [7901] - The At7.job command failed to start due to the following error: %%2147942402 12/22/2011 12:45:00 AM, error: Schedule [7901] - The At1.job command failed to start due to the following error: %%2147942402 12/21/2011 9:45:00 PM, error: Schedule [7901] - The At44.job command failed to start due to the following error: %%2147942402 12/21/2011 9:45:00 PM, error: Schedule [7901] - The At43.job command failed to start due to the following error: %%2147942402 12/21/2011 8:45:00 PM, error: Schedule [7901] - The At42.job command failed to start due to the following error: %%2147942402 12/21/2011 8:45:00 PM, error: Schedule [7901] - The At41.job command failed to start due to the following error: %%2147942402 12/21/2011 8:45:00 AM, error: Schedule [7901] - The At18.job command failed to start due to the following error: %%2147942402 12/21/2011 8:45:00 AM, error: Schedule [7901] - The At17.job command failed to start due to the following error: %%2147942402 12/21/2011 7:45:00 PM, error: Schedule [7901] - The At40.job command failed to start due to the following error: %%2147942402 12/21/2011 7:45:00 PM, error: Schedule [7901] - The At39.job command failed to start due to the following error: %%2147942402 12/21/2011 6:45:00 PM, error: Schedule [7901] - The At38.job command failed to start due to the following error: %%2147942402 12/21/2011 6:45:00 PM, error: Schedule [7901] - The At37.job command failed to start due to the following error: %%2147942402 12/21/2011 5:45:00 PM, error: Schedule [7901] - The At36.job command failed to start due to the following error: %%2147942402 12/21/2011 5:45:00 PM, error: Schedule [7901] - The At35.job command failed to start due to the following error: %%2147942402 12/21/2011 4:45:00 PM, error: Schedule [7901] - The At34.job command failed to start due to the following error: %%2147942402 12/21/2011 4:45:00 PM, error: Schedule [7901] - The At33.job command failed to start due to the following error: %%2147942402 12/21/2011 3:45:00 PM, error: Schedule [7901] - The At32.job command failed to start due to the following error: %%2147942402 12/21/2011 3:45:00 PM, error: Schedule [7901] - The At31.job command failed to start due to the following error: %%2147942402 12/21/2011 2:45:00 PM, error: Schedule [7901] - The At30.job command failed to start due to the following error: %%2147942402 12/21/2011 2:45:00 PM, error: Schedule [7901] - The At29.job command failed to start due to the following error: %%2147942402 12/21/2011 12:45:00 PM, error: Schedule [7901] - The At26.job command failed to start due to the following error: %%2147942402 12/21/2011 12:45:00 PM, error: Schedule [7901] - The At25.job command failed to start due to the following error: %%2147942402 12/21/2011 11:45:00 PM, error: Schedule [7901] - The At48.job command failed to start due to the following error: %%2147942402 12/21/2011 11:45:00 PM, error: Schedule [7901] - The At47.job command failed to start due to the following error: %%2147942402 12/21/2011 11:45:00 AM, error: Schedule [7901] - The At24.job command failed to start due to the following error: %%2147942402 12/21/2011 11:45:00 AM, error: Schedule [7901] - The At23.job command failed to start due to the following error: %%2147942402 12/21/2011 10:45:00 PM, error: Schedule [7901] - The At46.job command failed to start due to the following error: %%2147942402 12/21/2011 10:45:00 PM, error: Schedule [7901] - The At45.job command failed to start due to the following error: %%2147942402 12/21/2011 10:45:00 AM, error: Schedule [7901] - The At22.job command failed to start due to the following error: %%2147942402 12/21/2011 10:45:00 AM, error: Schedule [7901] - The At21.job command failed to start due to the following error: %%2147942402 12/21/2011 1:45:00 PM, error: Schedule [7901] - The At28.job command failed to start due to the following error: %%2147942402 12/21/2011 1:45:00 PM, error: Schedule [7901] - The At27.job command failed to start due to the following error: %%2147942402 12/20/2011 9:45:00 AM, error: Schedule [7901] - The At20.job command failed to start due to the following error: %%2147942402 12/20/2011 9:45:00 AM, error: Schedule [7901] - The At19.job command failed to start due to the following error: %%2147942402 12/20/2011 12:45:00 AM, error: Schedule [7901] - The At2.job command failed to start due to the following error: %%2147942402 12/19/2011 4:45:00 AM, error: Schedule [7901] - The At9.job command failed to start due to the following error: %%2147942402 . ==== End Of File =========================== aswMBR version 0.9.9.1120 Copyright© 2011 AVAST Software Run date: 2011-12-25 11:10:30 —————————– 11:10:30.368 OS Version: Windows 5.1.2600 Service Pack 3 11:10:30.368 Number of processors: 1 586 0x409 11:10:30.368 ComputerName: HELLO UserName: 11:10:31.118 Initialize success 11:50:41.352 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e 11:50:41.384 Disk 0 Vendor: WDC_WD800JD-75MSA3 10.01E04 Size: 76293MB BusType: 3 11:50:43.415 Disk 0 MBR read successfully 11:50:43.415 Disk 0 MBR scan 11:50:43.415 Disk 0 Windows XP default MBR code 11:50:43.415 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 76285 MB offset 63 11:50:43.415 Disk 0 scanning sectors +156232125 11:50:43.587 Disk 0 scanning C:\WINDOWS\system32\drivers 11:50:50.790 Service scanning 11:50:51.243 Service MpKslc3019d9e c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3DD95790-3A98-4960-9576-5E95AAE37A5B}\MpKslc3019d9e.sys **LOCKED** 32 11:50:51.899 Modules scanning 11:50:56.665 Module: C:\WINDOWS\system32\DRIVERS\cdrom.sys **SUSPICIOUS** 11:51:20.962 Disk 0 trace - called modules: 11:51:20.977 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x862e6f10]<< 11:51:21.337 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x865a8ab8] 11:51:21.352 3 CLASSPNP.SYS[f75fefd7] -> nt!IofCallDriver -> [0x861e0f08] 11:51:21.352 \Driver\00001126[0x861e2be0] -> IRP_MJ_CREATE -> 0x862e6f10 11:51:21.352 Scan finished successfully 11:51:39.071 Disk 0 MBR has been saved successfully to "C:\MBR.dat" 11:51:39.087 The log file has been saved successfully to "C:\aswMBR.txt"
Hi marcn,

**WARNING** Unfortunately one or more of the infections I have identified are Backdoor Trojans, IRCBots or other Malware capable of stealing very important information. You need to stop using all Internet Banking sites, change passwords to all sites with sensitive information from a clean computer and phone your bank to inform them that you may be a victim of identify theft. More often than not, we advise users that a full reinstallation of their Operating System is the only way to ensure that their computer will ever be 100% clean again.

It looks as if you have the ZeroAccess Rootkit on your system. It is an extremely nasty piece of malware that may take quite some time to remove depending on how it has infected your system. During the cleaning (if you choose to do so) you may even lose your internet access.

If you would like to format and reinstall your Operating System please let me know and I can assist you with that.

If you would like to continue with the cleaning, please continue with the following instructions and I will be more than happy to help.

=================

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
  • Only if Malicious objects are found then ensure Cure is selected
  • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
A copy of the log will be saved automatically to the root of the drive (typically C:\)

=================
NEXT

Download and Run ComboFix
  • Please download ComboFix from one of the following links.

    Link 1.

    Link 2.

    **IMPORTANT !!! Save ComboFix.exe to your Desktop**
  • Please disable any Antivirus or Firewall you have active, as shown in this topic. Please close all open application windows.
  • Double click on ComboFix.exe & follow the prompts
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console
[external image: Posted Image]
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the contents of C:\ComboFix.txt in your next reply

Notes:
1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Summary of the logs I need from you in your next post:
TDSSKiller log
ComboFix

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI