This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ping.exe Once Again... [Closed]

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello once again! This is my second time finding PING.exe in my task manager… I don't know what happened. Yesterday my laptop was working perfectly fine, but this morning, I opened my laptop and went on facebook, and then my laptop started lagging a lot. So I checked Task Manager and found my old enemy PING.exe sitting right there … I really need help on removing PING.exe. Please help me! :( ! By the way, to get things started I figured I'd run ComboFix :( ! Here's my log for ComboFix: ComboFix 12-01-21.01 - Lily 01/21/2012 12:27:24.5.2 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3003.1525 [GMT -5:00] Running from: c:usersLilyDesktopComboFix.exe AV: avast! Internet Security *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308} AV: Norton Internet Security *Enabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855} FW: avast! Internet Security *Disabled* {FB460EB6-4C6D-E564-6BF5-EEEF2B44B473} FW: Norton Internet Security *Disabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E} SP: avast! Internet Security *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5} SP: Norton Internet Security *Disabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:usersLilyDocuments~WRL2728.tmp c:windowsassemblytemp@ c:windowsassemblytempbckfg.tmp c:windowsassemblytempcfg.ini c:windowsassemblytempkeywords c:windowsassemblytempkwrd.dll c:windowssystem32consrv.dll c:windowssystem32java.exe c:windowsSystem64 . . ((((((((((((((((((((((((( Files Created from 2011-12-21 to 2012-01-21 ))))))))))))))))))))))))))))))) . . 2012-01-21 17:35 . 2012-01-21 17:35 ——– d—–w- c:windowssystem32configsystemprofileAppDataLocaltemp 2012-01-21 17:35 . 2012-01-21 17:35 ——– d—–w- c:usersPublicAppDataLocaltemp 2012-01-21 17:35 . 2012-01-21 17:35 ——– d—–w- c:usersDefaultAppDataLocaltemp 2012-01-21 17:35 . 2012-01-21 17:35 ——– d—–w- c:usersAdministratorAppDataLocaltemp 2012-01-13 03:45 . 2012-01-13 04:22 ——– d—–w- c:usersLilyAppDataRoamingPhotoScape 2012-01-13 03:45 . 2012-01-13 03:45 ——– d—–w- c:program files (x86)PhotoScape 2012-01-11 15:26 . 2011-10-26 05:22 366592 —-a-w- c:windowssystem32qdvd.dll 2012-01-11 15:26 . 2011-10-26 05:22 1572864 —-a-w- c:windowssystem32quartz.dll 2012-01-11 15:26 . 2011-10-26 04:28 1328640 —-a-w- c:windowsSysWow64quartz.dll 2012-01-11 15:26 . 2011-10-26 04:28 514560 —-a-w- c:windowsSysWow64qdvd.dll 2012-01-11 15:26 . 2011-11-19 15:07 77312 —-a-w- c:windowssystem32packager.dll 2012-01-11 15:26 . 2011-11-19 14:06 67072 —-a-w- c:windowsSysWow64packager.dll 2012-01-11 15:26 . 2011-11-17 07:14 1739160 —-a-w- c:windowssystem32ntdll.dll 2012-01-11 15:26 . 2011-11-17 05:41 1292592 —-a-w- c:windowsSysWow64ntdll.dll 2012-01-10 16:37 . 2012-01-10 16:41 ——– d—–w- c:programdataMessenger Plus! 2012-01-10 16:36 . 2012-01-10 16:36 ——– d—–w- c:program files (x86)Yuna Software 2012-01-08 18:57 . 2012-01-08 18:57 626688 —-a-w- c:program files (x86)Mozilla Firefoxmsvcr80.dll 2012-01-08 18:57 . 2012-01-08 18:57 548864 —-a-w- c:program files (x86)Mozilla Firefoxmsvcp80.dll 2012-01-08 18:57 . 2012-01-08 18:57 479232 —-a-w- c:program files (x86)Mozilla Firefoxmsvcm80.dll 2012-01-08 18:57 . 2012-01-08 18:57 43992 —-a-w- c:program files (x86)Mozilla Firefoxmozutils.dll 2011-12-25 06:09 . 2011-12-25 08:30 ——– d—–w- c:program files (x86)Common FilesSteam 2011-12-25 06:09 . 2012-01-04 00:31 ——– d—–w- c:program files (x86)Steam 2011-12-25 05:24 . 2011-12-25 05:24 ——– d—–w- c:usersLilyAppDataLocalMumble 2011-12-25 05:12 . 2011-12-25 05:26 ——– d—–w- c:usersLilyAppDataRoamingMumble 2011-12-25 05:10 . 2011-12-25 05:12 ——– d—–w- c:program files (x86)Mumble . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-11-24 05:00 . 2011-12-15 03:58 3141632 —-a-w- c:windowssystem32win32k.sys 2011-11-21 11:40 . 2011-12-02 23:30 8822856 —-a-w- c:programdataMicrosoftWindows DefenderDefinition Updates{A129D275-EED2-4C2F-B818-EAA4B6B0D4D4}mpengine.dll 2011-11-05 05:26 . 2011-12-15 03:57 1197568 —-a-w- c:windowssystem32wininet.dll 2011-11-05 05:23 . 2011-12-15 03:57 57856 —-a-w- c:windowssystem32licmgr10.dll 2011-11-05 05:17 . 2011-12-15 03:57 2048 —-a-w- c:windowssystem32tzres.dll 2011-11-05 04:35 . 2011-12-15 03:57 981504 —-a-w- c:windowsSysWow64wininet.dll 2011-11-05 04:34 . 2011-12-15 03:57 44544 —-a-w- c:windowsSysWow64licmgr10.dll 2011-11-05 04:30 . 2011-12-15 03:57 2048 —-a-w- c:windowsSysWow64tzres.dll 2011-11-05 04:07 . 2011-12-15 03:57 482816 —-a-w- c:windowssystem32html.iec 2011-11-05 03:28 . 2011-12-15 03:57 386048 —-a-w- c:windowsSysWow64html.iec 2011-11-05 03:25 . 2011-12-15 03:57 1638912 —-a-w- c:windowssystem32mshtml.tlb 2011-11-05 02:55 . 2011-12-15 03:57 1638912 —-a-w- c:windowsSysWow64mshtml.tlb 2011-10-26 05:19 . 2011-12-15 03:58 43520 —-a-w- c:windowssystem32csrsrv.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINESOFTWAREWow6432NodeMicrosoftWindowsCurrentVersionRun] "WirelessAssistant"="c:program files (x86)Hewlett-PackardHP Wireless AssistantHPWAMain.exe" [2009-07-23 498744] "PlusService"="c:program files (x86)Yuna SoftwareMessenger Plus!PlusService.exe" [2011-10-24 801792] . [HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionpoliciessystem] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:windowsMicrosoft.NETFrameworkv4.0.30319mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:windowsMicrosoft.NETFramework64v4.0.30319mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:program files (x86)GoogleUpdateGoogleUpdate.exe [2011-08-22 136176] R3 EagleX64;EagleX64;c:windowssystem32driversEagleX64.sys [x] R3 gupdatem;Google Update Service (gupdatem);c:program files (x86)GoogleUpdateGoogleUpdate.exe [2011-08-22 136176] R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:windowssystem32Driversnx6000.sys [x] R3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:windowssystem32DRIVERSnetw5v64.sys [x] R3 osppsvc;Office Software Protection Platform;c:program filesCommon FilesMicrosoft SharedOfficeSoftwareProtectionPlatformOSPPSVC.EXE [2010-01-10 4925184] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:windowssystem32DriversRtsUStor.sys [2009-09-23 225280] R3 SrvHsfHDA;SrvHsfHDA;c:windowssystem32DRIVERSVSTAZL6.SYS [x] R3 SrvHsfV92;SrvHsfV92;c:windowssystem32DRIVERSVSTDPV6.SYS [x] R3 SrvHsfWinac;SrvHsfWinac;c:windowssystem32DRIVERSVSTCNXT6.SYS [x] R3 USBAAPL64;Apple Mobile USB Driver;c:windowssystem32Driversusbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:windowssystem32WatWatAdminSvc.exe [x] R3 X6va005;X6va005;c:usersLilyAppDataLocalTemp\005E5ED.tmp [x] R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:windowssystem32DRIVERSyk62x64.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:windowssystem32DRIVERSvwififlt.sys [x] S2 AERTFilters;Andrea RT Filters Service;c:program filesRealtekAudioHDAAERTSr64.exe [2009-11-18 98208] S2 cvhsvc;Client Virtualization Handler;c:program files (x86)Common FilesMicrosoft SharedVirtualization HandlerCVHSVC.EXE [2010-10-20 821664] S2 HP Support Assistant Service;HP Support Assistant Service;c:program files (x86)Hewlett-PackardHP Support Frameworkhpsa_service.exe [2011-06-21 85560] S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:program files (x86)Hewlett-PackardSharedHPDrvMntSvc.exe [2011-03-28 94264] S2 HPWMISVC;HPWMISVC;c:program filesHewlett-PackardHP Quick LaunchHPWMISVC.exe [2010-01-18 20480] S2 sftlist;Application Virtualization Client;c:program files (x86)Microsoft Application Virtualization Clientsftlist.exe [2010-09-14 508264] S3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:windowssystem32driversIntcHdmi.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:windowssystem32DRIVERSRt64win7.sys [x] S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:windowssystem32DRIVERSrtl8192se.sys [x] S3 Sftfs;Sftfs;c:windowssystem32DRIVERSSftfslh.sys [x] S3 Sftplay;Sftplay;c:windowssystem32DRIVERSSftplaylh.sys [x] S3 Sftredir;Sftredir;c:windowssystem32DRIVERSSftredirlh.sys [x] S3 Sftvol;Sftvol;c:windowssystem32DRIVERSSftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:program files (x86)Microsoft Application Virtualization Clientsftvsa.exe [2010-09-14 219496] . . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL . Contents of the 'Scheduled Tasks' folder . 2012-01-21 c:windowsTasksGoogleUpdateTaskMachineCore.job - c:program files (x86)GoogleUpdateGoogleUpdate.exe [2011-08-22 02:47] . 2012-01-21 c:windowsTasksGoogleUpdateTaskMachineUA.job - c:program files (x86)GoogleUpdateGoogleUpdate.exe [2011-08-22 02:47] . 2012-01-17 c:windowsTasksHPCeeScheduleForLily.job - c:program files (x86)Hewlett-PackardHP CeementHPCEE.exe [2009-10-07 11:22] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun] "IgfxTray"="c:windowssystem32igfxtray.exe" [2010-03-05 166424] "Persistence"="c:windowssystem32igfxpers.exe" [2010-03-05 410648] "RTHDVCPL"="c:program filesRealtekAudioHDARtkNGUI64.exe" [2010-01-29 6160928] "RtkOSD"="c:program files (x86)RealtekAudioOSDRtVOsd64.exe" [2010-01-13 995840] "combofix"="c:combofixCF6873.3XE" [2009-07-14 344576] . ——- Supplementary Scan ——- . uLocal Page = c:windowssystem32blank.htm mLocal Page = c:windowsSysWOW64blank.htm uInternet Settings,ProxyOverride = *.local TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:usersLilyAppDataRoamingMozillaFirefoxProfilesjdvv19p5.default FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource;=3&q;={searchTerms} FF - prefs.js: browser.search.selectedEngine - FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/redirector/sredir?sredir=2706&invocationType;=tb50-ff-aim-ab-en-us&tb;_uuid=20110821044524515&tb;_oid=21-08-2011&tb;_mrud=21-08-2011&query;= FF - prefs.js: network.proxy.type - 0 FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false FF - user.js: browser.sessionstore.resume_from_crash - false . - - - - ORPHANS REMOVED - - - - . ShellIconOverlayIdentifiers-{F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE} - (no file) HKLM-Run-SynTPEnh - c:program files (x86)SynapticsSynTPSynTPEnh.exe AddRemove-{CA43FE4F-9FF2-4AD7-88F0-CC3BAC17B226} - c:program files (x86)InstallShield Installation Information{CA43FE4F-9FF2-4AD7-88F0-CC3BAC17B226}setup.exe . . . [HKEY_LOCAL_MACHINEsystemControlSet001servicesX6va005] "ImagePath"="??c:usersLilyAppDataLocalTemp\005E5ED.tmp" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:Windowssystem32MacromedFlashFlashUtil10e.exe,-101" . [HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}LocalServer32] @="c:WindowsSysWow64MacromedFlashFlashUtil10e.exe" . [HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB6E-AE6D-11cf-96B8-444553540000}InprocServer32] @="c:WindowsSysWow64MacromedFlashFlash10e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB6E-AE6D-11cf-96B8-444553540000}MiscStatus] @="0" . [HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB6E-AE6D-11cf-96B8-444553540000}ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB6E-AE6D-11cf-96B8-444553540000}ToolboxBitmap32] @="c:WindowsSysWow64MacromedFlashFlash10e.ocx, 1" . [HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB6E-AE6D-11cf-96B8-444553540000}TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB6E-AE6D-11cf-96B8-444553540000}Version] @="1.0" . [HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB6E-AE6D-11cf-96B8-444553540000}VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB70-AE6D-11cf-96B8-444553540000}InprocServer32] @="c:WindowsSysWow64MacromedFlashFlash10e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB70-AE6D-11cf-96B8-444553540000}ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB70-AE6D-11cf-96B8-444553540000}ToolboxBitmap32] @="c:WindowsSysWow64MacromedFlashFlash10e.ocx, 1" . [HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB70-AE6D-11cf-96B8-444553540000}TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB70-AE6D-11cf-96B8-444553540000}Version] @="1.0" . [HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB70-AE6D-11cf-96B8-444553540000}VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeInterface{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}] @Denied: (A 2) (Everyone) @="IFlashBroker3" . [HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeInterface{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeInterface{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINEsystemControlSet001ControlPCWSecurity] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:program files (x86)Common FilesAppleMobile Device SupportAppleMobileDeviceService.exe c:program files (x86)CyberLinkShared filesRichVideo.exe . ************************************************************************** . Completion time: 2012-01-21 12:45:17 - machine was rebooted ComboFix-quarantined-files.txt 2012-01-21 17:45 . Pre-Run: 212,498,993,152 bytes free Post-Run: 212,167,852,032 bytes free . - - End Of File - - 71AE9A3C9C38EF715DB5B28367E85DD5 And, this is DDS log with its Attachment. (I don't know if I'm doing this right or not, I'm just a bit too worried atm) :( ! DDS log: . DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_26 Run by [removed] at 12:51:06 on 2012-01-21 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3003.1861 [GMT -5:00] . AV: avast! Internet Security *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308} AV: Norton Internet Security *Enabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855} SP: avast! Internet Security *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Norton Internet Security *Disabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8} FW: Norton Internet Security *Disabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E} FW: avast! Internet Security *Disabled* {FB460EB6-4C6D-E564-6BF5-EEEF2B44B473} . ============== Running Processes =============== . C:Windowssystem32wininit.exe C:Windowssystem32lsm.exe C:Windowssystem32svchost.exe -k DcomLaunch C:Windowssystem32svchost.exe -k RPCSS C:WindowsSystem32svchost.exe -k LocalServiceNetworkRestricted C:WindowsSystem32svchost.exe -k LocalSystemNetworkRestricted C:Windowssystem32svchost.exe -k netsvcs C:Windowssystem32svchost.exe -k LocalService C:Windowssystem32svchost.exe -k NetworkService C:WindowsSystem32spoolsv.exe C:Windowssystem32svchost.exe -k LocalServiceNoNetwork C:Windowssystem32svchost.exe -k LocalServiceAndNoImpersonation C:Program FilesRealtekAudioHDAAERTSr64.exe C:Program Files (x86)Common FilesAppleMobile Device SupportAppleMobileDeviceService.exe C:Program FilesBonjourmDNSResponder.exe C:Program Files (x86)Hewlett-PackardSharedHPDrvMntSvc.exe C:Program FilesHewlett-PackardHP Quick LaunchHPWMISVC.exe C:Program FilesMicrosoft LifeCamMSCamS64.exe C:Windowssystem32svchost.exe -k NetworkServiceNetworkRestricted C:Program Files (x86)CyberLinkShared filesRichVideo.exe C:Program Files (x86)Microsoft Application Virtualization Clientsftvsa.exe C:Windowssystem32svchost.exe -k imgsvc C:Program Files (x86)Microsoft Application Virtualization Clientsftlist.exe C:Program Files (x86)Common FilesMicrosoft SharedVirtualization HandlerCVHSVC.EXE C:Program Files (x86)Hewlett-PackardHP Support Frameworkhpsa_service.exe C:Program FilesWindows Media Playerwmpnetwk.exe C:Windowssystem32SearchIndexer.exe C:Windowssystem32taskhost.exe C:Windowssystem32Dwm.exe C:WindowsExplorer.EXE C:WindowsSystem32igfxtray.exe C:WindowsSystem32igfxpers.exe C:Program FilesSynapticsSynTPSynTPEnh.exe C:Program FilesRealtekAudioHDARtkNGUI64.exe C:Program FilesSynapticsSynTPSynTPHelper.exe C:Program Files (x86)RealtekAudioOSDRtVOsd64.exe C:Program Files (x86)Yuna SoftwareMessenger Plus!PlusService.exe C:WindowsSystem32svchost.exe -k LocalServicePeerNet C:Windowssystem32wuauclt.exe C:Program Files (x86)Mozilla Firefoxfirefox.exe C:Windowssystem32SearchProtocolHost.exe C:Windowssystem32SearchFilterHost.exe C:WindowsSysWOW64cmd.exe C:Windowssystem32conhost.exe C:WindowsSysWOW64cscript.exe C:Windowssystem32wbemwmiprvse.exe . ============== Pseudo HJT Report =============== . uInternet Settings,ProxyOverride = *.local BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - C:Program Files (x86)HPDigital ImagingSmart Web Printinghpswp_printenhancer.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:Program Files (x86)Common FilesAdobeAcrobatActiveXAcroIEHelperShim.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:Program Files (x86)Common FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:Program Files (x86)SkypeToolbarsInternet Explorerskypeieplugin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:Program Files (x86)Javajre6binjp2ssv.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:Program Files (x86)HPDigital ImagingSmart Web Printinghpswp_BHO.dll mRun: [WirelessAssistant] C:Program Files (x86)Hewlett-PackardHP Wireless AssistantHPWAMain.exe mRun: [PlusService] C:Program Files (x86)Yuna SoftwareMessenger Plus!PlusService.exe mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:Program Files (x86)Windows LiveWriterWriterBrowserExtension.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:Program Files (x86)SkypeToolbarsInternet Explorerskypeieplugin.dll IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:Program Files (x86)HPDigital ImagingSmart Web Printinghpswp_BHO.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces{04EB6DFB-DBFD-4450-A2BA-30E06A43B528} : DhcpNameServer = 192.168.1.1 TCP: Interfaces{F1D0DCCB-1BC2-4BC1-9FCD-34B1DC76C3C1} : DhcpNameServer = 192.168.1.1 Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:Program Files (x86)SkypeToolbarsInternet Explorerskypeieplugin.dll BHO-X64: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:Program Files (x86)HPDigital ImagingSmart Web Printinghpswp_printenhancer.dll BHO-X64: HP Print Enhancer - No File BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:Program Files (x86)Common FilesAdobeAcrobatActiveXAcroIEHelperShim.dll BHO-X64: AcroIEHelperStub - No File BHO-X64: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO-X64: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program Files (x86)Common FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:Program Files (x86)SkypeToolbarsInternet Explorerskypeieplugin.dll BHO-X64: SkypeIEPluginBHO - No File BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program Files (x86)Javajre6binjp2ssv.dll BHO-X64: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:Program Files (x86)HPDigital ImagingSmart Web Printinghpswp_BHO.dll BHO-X64: HP Smart BHO Class - No File mRun-x64: [WirelessAssistant] C:Program Files (x86)Hewlett-PackardHP Wireless AssistantHPWAMain.exe mRun-x64: [PlusService] C:Program Files (x86)Yuna SoftwareMessenger Plus!PlusService.exe Hosts: 216.240.133.193 www.google-analytics.com. Hosts: 216.240.133.193 ad-emea.doubleclick.net. Hosts: 216.240.133.193 www.statcounter.com. Hosts: 69.72.252.254 www.google-analytics.com. Hosts: 69.72.252.254 ad-emea.doubleclick.net. . Note: multiple HOSTS entries found. Please refer to Attach.txt . ================= FIREFOX =================== . FF - ProfilePath - C:UsersLilyAppDataRoamingMozillaFirefoxProfilesjdvv19p5.default FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource;=3&q;={searchTerms} FF - prefs.js: browser.search.selectedEngine - FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/redirector/sredir?sredir=2706&invocationType;=tb50-ff-aim-ab-en-us&tb;_uuid=20110821044524515&tb;_oid=21-08-2011&tb;_mrud=21-08-2011&query;= FF - prefs.js: network.proxy.type - 0 FF - plugin: C:PROGRA~2MICROS~3Office14NPSPWRAP.DLL FF - plugin: C:Program Files (x86)GoogleUpdate1.3.21.93npGoogleUpdate3.dll FF - plugin: C:Program Files (x86)Javajre6binnew_pluginnpdeployJava1.dll FF - plugin: c:Program Files (x86)Microsoft Silverlight4.0.60831.0npctrlui.dll FF - plugin: C:Program Files (x86)Mozilla Firefoxpluginsnpdnu.dll FF - plugin: C:Program Files (x86)Mozilla Firefoxpluginsnpdnupdater2.dll FF - plugin: C:Program Files (x86)Pando NetworksMedia BoosternpPandoWebPlugin.dll FF - plugin: C:Program Files (x86)Windows LivePhoto GalleryNPWLPG.dll FF - plugin: C:ProgramDataNexonUSNGMnpNxGameUS.dll FF - plugin: C:WindowsSysWOW64AdobeDirectornp32dsw.dll FF - plugin: C:WindowsSysWOW64MacromedFlashNPSWF32.dll . —- FIREFOX POLICIES —- FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false FF - user.js: browser.sessionstore.resume_from_crash - false . ============= SERVICES / DRIVERS =============== . R1 vwififlt;Virtual WiFi Filter Driver;C:Windowssystem32DRIVERSvwififlt.sys –> C:Windowssystem32DRIVERSvwififlt.sys [?] R2 AERTFilters;Andrea RT Filters Service;C:Program FilesRealtekAudioHDAAERTSr64.exe [2010-8-31 98208] R2 cvhsvc;Client Virtualization Handler;C:Program Files (x86)Common Filesmicrosoft sharedVirtualization HandlerCVHSVC.EXE [2010-10-20 821664] R2 HP Support Assistant Service;HP Support Assistant Service;C:Program Files (x86)Hewlett-PackardHP Support FrameworkHPSA_Service.exe [2011-6-21 85560] R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:Program Files (x86)Hewlett-PackardSharedHPDrvMntSvc.exe [2011-3-28 94264] R2 HPWMISVC;HPWMISVC;C:Program FilesHewlett-PackardHP Quick LaunchHPWMISVC.exe [2010-1-18 20480] R2 sftlist;Application Virtualization Client;C:Program Files (x86)Microsoft Application Virtualization Clientsftlist.exe [2010-9-14 508264] R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;C:Windowssystem32driversIntcHdmi.sys –> C:Windowssystem32driversIntcHdmi.sys [?] R3 RTL8167;Realtek 8167 NT Driver;C:Windowssystem32DRIVERSRt64win7.sys –> C:Windowssystem32DRIVERSRt64win7.sys [?] R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;C:Windowssystem32DRIVERSrtl8192se.sys –> C:Windowssystem32DRIVERSrtl8192se.sys [?] R3 Sftfs;Sftfs;C:Windowssystem32DRIVERSSftfslh.sys –> C:Windowssystem32DRIVERSSftfslh.sys [?] R3 Sftplay;Sftplay;C:Windowssystem32DRIVERSSftplaylh.sys –> C:Windowssystem32DRIVERSSftplaylh.sys [?] R3 Sftredir;Sftredir;C:Windowssystem32DRIVERSSftredirlh.sys –> C:Windowssystem32DRIVERSSftredirlh.sys [?] R3 Sftvol;Sftvol;C:Windowssystem32DRIVERSSftvollh.sys –> C:Windowssystem32DRIVERSSftvollh.sys [?] R3 sftvsa;Application Virtualization Service Agent;C:Program Files (x86)Microsoft Application Virtualization Clientsftvsa.exe [2010-9-14 219496] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:WindowsMicrosoft.NETFrameworkv4.0.30319mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:WindowsMicrosoft.NETFramework64v4.0.30319mscorsvw.exe [2010-3-18 138576] S2 gupdate;Google Update Service (gupdate);C:Program Files (x86)GoogleUpdateGoogleUpdate.exe [2011-8-21 136176] S3 gupdatem;Google Update Service (gupdatem);C:Program Files (x86)GoogleUpdateGoogleUpdate.exe [2011-8-21 136176] S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;C:Windowssystem32Driversnx6000.sys –> C:Windowssystem32Driversnx6000.sys [?] S3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:Windowssystem32DRIVERSnetw5v64.sys –> C:Windowssystem32DRIVERSnetw5v64.sys [?] S3 osppsvc;Office Software Protection Platform;C:Program FilesCommon FilesMicrosoft SharedOfficeSoftwareProtectionPlatformOSPPSVC.EXE [2010-1-9 4925184] S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:WindowsSystem32driversRtsUStor.sys [2010-8-31 225280] S3 SrvHsfHDA;SrvHsfHDA;C:Windowssystem32DRIVERSVSTAZL6.SYS –> C:Windowssystem32DRIVERSVSTAZL6.SYS [?] S3 SrvHsfV92;SrvHsfV92;C:Windowssystem32DRIVERSVSTDPV6.SYS –> C:Windowssystem32DRIVERSVSTDPV6.SYS [?] S3 SrvHsfWinac;SrvHsfWinac;C:Windowssystem32DRIVERSVSTCNXT6.SYS –> C:Windowssystem32DRIVERSVSTCNXT6.SYS [?] S3 USBAAPL64;Apple Mobile USB Driver;C:Windowssystem32Driversusbaapl64.sys –> C:Windowssystem32Driversusbaapl64.sys [?] S3 WatAdminSvc;Windows Activation Technologies Service;C:Windowssystem32WatWatAdminSvc.exe –> C:Windowssystem32WatWatAdminSvc.exe [?] S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:Windowssystem32DRIVERSyk62x64.sys –> C:Windowssystem32DRIVERSyk62x64.sys [?] . =============== Created Last 30 ================ . 2012-01-21 17:25:35 98816 —-a-w- C:Windowssed.exe 2012-01-21 17:25:35 518144 —-a-w- C:WindowsSWREG.exe 2012-01-21 17:25:35 256000 —-a-w- C:WindowsPEV.exe 2012-01-21 17:25:35 208896 —-a-w- C:WindowsMBR.exe 2012-01-13 03:45:37 ——– d—–w- C:UsersLilyAppDataRoamingPhotoScape 2012-01-13 03:45:25 ——– d—–w- C:Program Files (x86)PhotoScape 2012-01-11 15:26:48 514560 —-a-w- C:WindowsSysWow64qdvd.dll 2012-01-11 15:26:48 366592 —-a-w- C:WindowsSystem32qdvd.dll 2012-01-11 15:26:48 1572864 —-a-w- C:WindowsSystem32quartz.dll 2012-01-11 15:26:48 1328640 —-a-w- C:WindowsSysWow64quartz.dll 2012-01-11 15:26:45 77312 —-a-w- C:WindowsSystem32packager.dll 2012-01-11 15:26:45 67072 —-a-w- C:WindowsSysWow64packager.dll 2012-01-11 15:26:45 1739160 —-a-w- C:WindowsSystem32ntdll.dll 2012-01-11 15:26:45 1292592 —-a-w- C:WindowsSysWow64ntdll.dll 2012-01-10 16:37:00 ——– d—–w- C:ProgramDataMessenger Plus! 2012-01-10 16:36:45 ——– d—–w- C:Program Files (x86)Yuna Software 2012-01-08 18:57:39 626688 —-a-w- C:Program Files (x86)Mozilla Firefoxmsvcr80.dll 2012-01-08 18:57:39 548864 —-a-w- C:Program Files (x86)Mozilla Firefoxmsvcp80.dll 2012-01-08 18:57:39 479232 —-a-w- C:Program Files (x86)Mozilla Firefoxmsvcm80.dll 2012-01-08 18:57:39 43992 —-a-w- C:Program Files (x86)Mozilla Firefoxmozutils.dll 2011-12-25 06:09:59 ——– d—–w- C:Program Files (x86)Common FilesSteam 2011-12-25 06:09:57 ——– d—–w- C:Program Files (x86)Steam 2011-12-25 05:24:09 ——– d—–w- C:UsersLilyAppDataLocalMumble 2011-12-25 05:12:34 ——– d—–w- C:UsersLilyAppDataRoamingMumble 2011-12-25 05:10:36 ——– d—–w- C:Program Files (x86)Mumble . ==================== Find3M ==================== . 2011-11-24 05:00:47 3141632 —-a-w- C:WindowsSystem32win32k.sys 2011-11-05 05:26:29 1197568 —-a-w- C:WindowsSystem32wininet.dll 2011-11-05 05:23:10 57856 —-a-w- C:WindowsSystem32licmgr10.dll 2011-11-05 05:17:42 2048 —-a-w- C:WindowsSystem32tzres.dll 2011-11-05 04:35:50 981504 —-a-w- C:WindowsSysWow64wininet.dll 2011-11-05 04:34:15 44544 —-a-w- C:WindowsSysWow64licmgr10.dll 2011-11-05 04:30:11 2048 —-a-w- C:WindowsSysWow64tzres.dll 2011-11-05 04:07:32 482816 —-a-w- C:WindowsSystem32html.iec 2011-11-05 03:28:41 386048 —-a-w- C:WindowsSysWow64html.iec 2011-11-05 03:25:44 1638912 —-a-w- C:WindowsSystem32mshtml.tlb 2011-11-05 02:55:38 1638912 —-a-w- C:WindowsSysWow64mshtml.tlb 2011-10-26 05:19:07 43520 —-a-w- C:WindowsSystem32csrsrv.dll . ============= FINISH: 12:51:25.52 =============== If anything, I can start from the beginning following your instructions. :(

Attachments:

Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———-

First we need to make all files and folders VISIBLE:

  • Go to Start >> Control Panel >> Folder Options >> View
  • Choose to "show hidden files and folders,"
  • Uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
  • Close the window with ok
———-

I should mention that you should not run ComboFix unless under the direction of a trained malware remover. It could completely ruin your system if used incorrectly.
———-


Please download aswMBR to your desktop.

  • Right click and Run as Administrator the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

In your next reply please post the log created by aswMBR.exe. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI