Zefie
Topic Starter
Hello once again!
This is my second time finding PING.exe in my task manager… I don't know what happened. Yesterday my laptop was working perfectly fine, but this morning, I opened my laptop and went on facebook, and then my laptop started lagging a lot. So I checked Task Manager and found my old enemy PING.exe sitting right there …
I really need help on removing PING.exe. Please help me!
!
By the way, to get things started I figured I'd run ComboFix
!
Here's my log for ComboFix:
ComboFix 12-01-21.01 - Lily 01/21/2012 12:27:24.5.2 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3003.1525 [GMT -5:00]
Running from: c:usersLilyDesktopComboFix.exe
AV: avast! Internet Security *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
AV: Norton Internet Security *Enabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}
FW: avast! Internet Security *Disabled* {FB460EB6-4C6D-E564-6BF5-EEEF2B44B473}
FW: Norton Internet Security *Disabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E}
SP: avast! Internet Security *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Norton Internet Security *Disabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:usersLilyDocuments~WRL2728.tmp
c:windowsassemblytemp@
c:windowsassemblytempbckfg.tmp
c:windowsassemblytempcfg.ini
c:windowsassemblytempkeywords
c:windowsassemblytempkwrd.dll
c:windowssystem32consrv.dll
c:windowssystem32java.exe
c:windowsSystem64
.
.
((((((((((((((((((((((((( Files Created from 2011-12-21 to 2012-01-21 )))))))))))))))))))))))))))))))
.
.
2012-01-21 17:35 . 2012-01-21 17:35 ——– d—–w- c:windowssystem32configsystemprofileAppDataLocaltemp
2012-01-21 17:35 . 2012-01-21 17:35 ——– d—–w- c:usersPublicAppDataLocaltemp
2012-01-21 17:35 . 2012-01-21 17:35 ——– d—–w- c:usersDefaultAppDataLocaltemp
2012-01-21 17:35 . 2012-01-21 17:35 ——– d—–w- c:usersAdministratorAppDataLocaltemp
2012-01-13 03:45 . 2012-01-13 04:22 ——– d—–w- c:usersLilyAppDataRoamingPhotoScape
2012-01-13 03:45 . 2012-01-13 03:45 ——– d—–w- c:program files (x86)PhotoScape
2012-01-11 15:26 . 2011-10-26 05:22 366592 —-a-w- c:windowssystem32qdvd.dll
2012-01-11 15:26 . 2011-10-26 05:22 1572864 —-a-w- c:windowssystem32quartz.dll
2012-01-11 15:26 . 2011-10-26 04:28 1328640 —-a-w- c:windowsSysWow64quartz.dll
2012-01-11 15:26 . 2011-10-26 04:28 514560 —-a-w- c:windowsSysWow64qdvd.dll
2012-01-11 15:26 . 2011-11-19 15:07 77312 —-a-w- c:windowssystem32packager.dll
2012-01-11 15:26 . 2011-11-19 14:06 67072 —-a-w- c:windowsSysWow64packager.dll
2012-01-11 15:26 . 2011-11-17 07:14 1739160 —-a-w- c:windowssystem32ntdll.dll
2012-01-11 15:26 . 2011-11-17 05:41 1292592 —-a-w- c:windowsSysWow64ntdll.dll
2012-01-10 16:37 . 2012-01-10 16:41 ——– d—–w- c:programdataMessenger Plus!
2012-01-10 16:36 . 2012-01-10 16:36 ——– d—–w- c:program files (x86)Yuna Software
2012-01-08 18:57 . 2012-01-08 18:57 626688 —-a-w- c:program files (x86)Mozilla Firefoxmsvcr80.dll
2012-01-08 18:57 . 2012-01-08 18:57 548864 —-a-w- c:program files (x86)Mozilla Firefoxmsvcp80.dll
2012-01-08 18:57 . 2012-01-08 18:57 479232 —-a-w- c:program files (x86)Mozilla Firefoxmsvcm80.dll
2012-01-08 18:57 . 2012-01-08 18:57 43992 —-a-w- c:program files (x86)Mozilla Firefoxmozutils.dll
2011-12-25 06:09 . 2011-12-25 08:30 ——– d—–w- c:program files (x86)Common FilesSteam
2011-12-25 06:09 . 2012-01-04 00:31 ——– d—–w- c:program files (x86)Steam
2011-12-25 05:24 . 2011-12-25 05:24 ——– d—–w- c:usersLilyAppDataLocalMumble
2011-12-25 05:12 . 2011-12-25 05:26 ——– d—–w- c:usersLilyAppDataRoamingMumble
2011-12-25 05:10 . 2011-12-25 05:12 ——– d—–w- c:program files (x86)Mumble
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-24 05:00 . 2011-12-15 03:58 3141632 —-a-w- c:windowssystem32win32k.sys
2011-11-21 11:40 . 2011-12-02 23:30 8822856 —-a-w- c:programdataMicrosoftWindows DefenderDefinition Updates{A129D275-EED2-4C2F-B818-EAA4B6B0D4D4}mpengine.dll
2011-11-05 05:26 . 2011-12-15 03:57 1197568 —-a-w- c:windowssystem32wininet.dll
2011-11-05 05:23 . 2011-12-15 03:57 57856 —-a-w- c:windowssystem32licmgr10.dll
2011-11-05 05:17 . 2011-12-15 03:57 2048 —-a-w- c:windowssystem32tzres.dll
2011-11-05 04:35 . 2011-12-15 03:57 981504 —-a-w- c:windowsSysWow64wininet.dll
2011-11-05 04:34 . 2011-12-15 03:57 44544 —-a-w- c:windowsSysWow64licmgr10.dll
2011-11-05 04:30 . 2011-12-15 03:57 2048 —-a-w- c:windowsSysWow64tzres.dll
2011-11-05 04:07 . 2011-12-15 03:57 482816 —-a-w- c:windowssystem32html.iec
2011-11-05 03:28 . 2011-12-15 03:57 386048 —-a-w- c:windowsSysWow64html.iec
2011-11-05 03:25 . 2011-12-15 03:57 1638912 —-a-w- c:windowssystem32mshtml.tlb
2011-11-05 02:55 . 2011-12-15 03:57 1638912 —-a-w- c:windowsSysWow64mshtml.tlb
2011-10-26 05:19 . 2011-12-15 03:58 43520 —-a-w- c:windowssystem32csrsrv.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINESOFTWAREWow6432NodeMicrosoftWindowsCurrentVersionRun]
"WirelessAssistant"="c:program files (x86)Hewlett-PackardHP Wireless AssistantHPWAMain.exe" [2009-07-23 498744]
"PlusService"="c:program files (x86)Yuna SoftwareMessenger Plus!PlusService.exe" [2011-10-24 801792]
.
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionpoliciessystem]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:windowsMicrosoft.NETFrameworkv4.0.30319mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:windowsMicrosoft.NETFramework64v4.0.30319mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:program files (x86)GoogleUpdateGoogleUpdate.exe [2011-08-22 136176]
R3 EagleX64;EagleX64;c:windowssystem32driversEagleX64.sys [x]
R3 gupdatem;Google Update Service (gupdatem);c:program files (x86)GoogleUpdateGoogleUpdate.exe [2011-08-22 136176]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:windowssystem32Driversnx6000.sys [x]
R3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:windowssystem32DRIVERSnetw5v64.sys [x]
R3 osppsvc;Office Software Protection Platform;c:program filesCommon FilesMicrosoft SharedOfficeSoftwareProtectionPlatformOSPPSVC.EXE [2010-01-10 4925184]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:windowssystem32DriversRtsUStor.sys [2009-09-23 225280]
R3 SrvHsfHDA;SrvHsfHDA;c:windowssystem32DRIVERSVSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:windowssystem32DRIVERSVSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:windowssystem32DRIVERSVSTCNXT6.SYS [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:windowssystem32Driversusbaapl64.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:windowssystem32WatWatAdminSvc.exe [x]
R3 X6va005;X6va005;c:usersLilyAppDataLocalTemp\005E5ED.tmp [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:windowssystem32DRIVERSyk62x64.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:windowssystem32DRIVERSvwififlt.sys [x]
S2 AERTFilters;Andrea RT Filters Service;c:program filesRealtekAudioHDAAERTSr64.exe [2009-11-18 98208]
S2 cvhsvc;Client Virtualization Handler;c:program files (x86)Common FilesMicrosoft SharedVirtualization HandlerCVHSVC.EXE [2010-10-20 821664]
S2 HP Support Assistant Service;HP Support Assistant Service;c:program files (x86)Hewlett-PackardHP Support Frameworkhpsa_service.exe [2011-06-21 85560]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:program files (x86)Hewlett-PackardSharedHPDrvMntSvc.exe [2011-03-28 94264]
S2 HPWMISVC;HPWMISVC;c:program filesHewlett-PackardHP Quick LaunchHPWMISVC.exe [2010-01-18 20480]
S2 sftlist;Application Virtualization Client;c:program files (x86)Microsoft Application Virtualization Clientsftlist.exe [2010-09-14 508264]
S3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:windowssystem32driversIntcHdmi.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:windowssystem32DRIVERSRt64win7.sys [x]
S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:windowssystem32DRIVERSrtl8192se.sys [x]
S3 Sftfs;Sftfs;c:windowssystem32DRIVERSSftfslh.sys [x]
S3 Sftplay;Sftplay;c:windowssystem32DRIVERSSftplaylh.sys [x]
S3 Sftredir;Sftredir;c:windowssystem32DRIVERSSftredirlh.sys [x]
S3 Sftvol;Sftvol;c:windowssystem32DRIVERSSftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:program files (x86)Microsoft Application Virtualization Clientsftvsa.exe [2010-09-14 219496]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-21 c:windowsTasksGoogleUpdateTaskMachineCore.job
- c:program files (x86)GoogleUpdateGoogleUpdate.exe [2011-08-22 02:47]
.
2012-01-21 c:windowsTasksGoogleUpdateTaskMachineUA.job
- c:program files (x86)GoogleUpdateGoogleUpdate.exe [2011-08-22 02:47]
.
2012-01-17 c:windowsTasksHPCeeScheduleForLily.job
- c:program files (x86)Hewlett-PackardHP CeementHPCEE.exe [2009-10-07 11:22]
.
.
——— x86-64 ———–
.
.
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"IgfxTray"="c:windowssystem32igfxtray.exe" [2010-03-05 166424]
"Persistence"="c:windowssystem32igfxpers.exe" [2010-03-05 410648]
"RTHDVCPL"="c:program filesRealtekAudioHDARtkNGUI64.exe" [2010-01-29 6160928]
"RtkOSD"="c:program files (x86)RealtekAudioOSDRtVOsd64.exe" [2010-01-13 995840]
"combofix"="c:combofixCF6873.3XE" [2009-07-14 344576]
.
——- Supplementary Scan ——-
.
uLocal Page = c:windowssystem32blank.htm
mLocal Page = c:windowsSysWOW64blank.htm
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:usersLilyAppDataRoamingMozillaFirefoxProfilesjdvv19p5.default
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource;=3&q;={searchTerms}
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/redirector/sredir?sredir=2706&invocationType;=tb50-ff-aim-ab-en-us&tb;_uuid=20110821044524515&tb;_oid=21-08-2011&tb;_mrud=21-08-2011&query;=
FF - prefs.js: network.proxy.type - 0
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false
FF - user.js: browser.sessionstore.resume_from_crash - false
.
- - - - ORPHANS REMOVED - - - -
.
ShellIconOverlayIdentifiers-{F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE} - (no file)
HKLM-Run-SynTPEnh - c:program files (x86)SynapticsSynTPSynTPEnh.exe
AddRemove-{CA43FE4F-9FF2-4AD7-88F0-CC3BAC17B226} - c:program files (x86)InstallShield Installation Information{CA43FE4F-9FF2-4AD7-88F0-CC3BAC17B226}setup.exe
.
.
.
[HKEY_LOCAL_MACHINEsystemControlSet001servicesX6va005]
"ImagePath"="??c:usersLilyAppDataLocalTemp\005E5ED.tmp"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:Windowssystem32MacromedFlashFlashUtil10e.exe,-101"
.
[HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}LocalServer32]
@="c:WindowsSysWow64MacromedFlashFlashUtil10e.exe"
.
[HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB6E-AE6D-11cf-96B8-444553540000}InprocServer32]
@="c:WindowsSysWow64MacromedFlashFlash10e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB6E-AE6D-11cf-96B8-444553540000}MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB6E-AE6D-11cf-96B8-444553540000}ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB6E-AE6D-11cf-96B8-444553540000}ToolboxBitmap32]
@="c:WindowsSysWow64MacromedFlashFlash10e.ocx, 1"
.
[HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB6E-AE6D-11cf-96B8-444553540000}TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB6E-AE6D-11cf-96B8-444553540000}Version]
@="1.0"
.
[HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB6E-AE6D-11cf-96B8-444553540000}VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB70-AE6D-11cf-96B8-444553540000}InprocServer32]
@="c:WindowsSysWow64MacromedFlashFlash10e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB70-AE6D-11cf-96B8-444553540000}ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB70-AE6D-11cf-96B8-444553540000}ToolboxBitmap32]
@="c:WindowsSysWow64MacromedFlashFlash10e.ocx, 1"
.
[HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB70-AE6D-11cf-96B8-444553540000}TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB70-AE6D-11cf-96B8-444553540000}Version]
@="1.0"
.
[HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeCLSID{D27CDB70-AE6D-11cf-96B8-444553540000}VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeInterface{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeInterface{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINEsoftwareClassesWow6432NodeInterface{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINEsystemControlSet001ControlPCWSecurity]
@Denied: (Full) (Everyone)
.
———————— Other Running Processes ————————
.
c:program files (x86)Common FilesAppleMobile Device SupportAppleMobileDeviceService.exe
c:program files (x86)CyberLinkShared filesRichVideo.exe
.
**************************************************************************
.
Completion time: 2012-01-21 12:45:17 - machine was rebooted
ComboFix-quarantined-files.txt 2012-01-21 17:45
.
Pre-Run: 212,498,993,152 bytes free
Post-Run: 212,167,852,032 bytes free
.
- - End Of File - - 71AE9A3C9C38EF715DB5B28367E85DD5
And, this is DDS log with its Attachment. (I don't know if I'm doing this right or not, I'm just a bit too worried atm)
!
DDS log:
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_26
Run by [removed] at 12:51:06 on 2012-01-21
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3003.1861 [GMT -5:00]
.
AV: avast! Internet Security *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
AV: Norton Internet Security *Enabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}
SP: avast! Internet Security *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Internet Security *Disabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}
FW: Norton Internet Security *Disabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E}
FW: avast! Internet Security *Disabled* {FB460EB6-4C6D-E564-6BF5-EEEF2B44B473}
.
============== Running Processes ===============
.
C:Windowssystem32wininit.exe
C:Windowssystem32lsm.exe
C:Windowssystem32svchost.exe -k DcomLaunch
C:Windowssystem32svchost.exe -k RPCSS
C:WindowsSystem32svchost.exe -k LocalServiceNetworkRestricted
C:WindowsSystem32svchost.exe -k LocalSystemNetworkRestricted
C:Windowssystem32svchost.exe -k netsvcs
C:Windowssystem32svchost.exe -k LocalService
C:Windowssystem32svchost.exe -k NetworkService
C:WindowsSystem32spoolsv.exe
C:Windowssystem32svchost.exe -k LocalServiceNoNetwork
C:Windowssystem32svchost.exe -k LocalServiceAndNoImpersonation
C:Program FilesRealtekAudioHDAAERTSr64.exe
C:Program Files (x86)Common FilesAppleMobile Device SupportAppleMobileDeviceService.exe
C:Program FilesBonjourmDNSResponder.exe
C:Program Files (x86)Hewlett-PackardSharedHPDrvMntSvc.exe
C:Program FilesHewlett-PackardHP Quick LaunchHPWMISVC.exe
C:Program FilesMicrosoft LifeCamMSCamS64.exe
C:Windowssystem32svchost.exe -k NetworkServiceNetworkRestricted
C:Program Files (x86)CyberLinkShared filesRichVideo.exe
C:Program Files (x86)Microsoft Application Virtualization Clientsftvsa.exe
C:Windowssystem32svchost.exe -k imgsvc
C:Program Files (x86)Microsoft Application Virtualization Clientsftlist.exe
C:Program Files (x86)Common FilesMicrosoft SharedVirtualization HandlerCVHSVC.EXE
C:Program Files (x86)Hewlett-PackardHP Support Frameworkhpsa_service.exe
C:Program FilesWindows Media Playerwmpnetwk.exe
C:Windowssystem32SearchIndexer.exe
C:Windowssystem32taskhost.exe
C:Windowssystem32Dwm.exe
C:WindowsExplorer.EXE
C:WindowsSystem32igfxtray.exe
C:WindowsSystem32igfxpers.exe
C:Program FilesSynapticsSynTPSynTPEnh.exe
C:Program FilesRealtekAudioHDARtkNGUI64.exe
C:Program FilesSynapticsSynTPSynTPHelper.exe
C:Program Files (x86)RealtekAudioOSDRtVOsd64.exe
C:Program Files (x86)Yuna SoftwareMessenger Plus!PlusService.exe
C:WindowsSystem32svchost.exe -k LocalServicePeerNet
C:Windowssystem32wuauclt.exe
C:Program Files (x86)Mozilla Firefoxfirefox.exe
C:Windowssystem32SearchProtocolHost.exe
C:Windowssystem32SearchFilterHost.exe
C:WindowsSysWOW64cmd.exe
C:Windowssystem32conhost.exe
C:WindowsSysWOW64cscript.exe
C:Windowssystem32wbemwmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - C:Program Files (x86)HPDigital ImagingSmart Web Printinghpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:Program Files (x86)Common FilesAdobeAcrobatActiveXAcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:Program Files (x86)Common FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:Program Files (x86)SkypeToolbarsInternet Explorerskypeieplugin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:Program Files (x86)Javajre6binjp2ssv.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:Program Files (x86)HPDigital ImagingSmart Web Printinghpswp_BHO.dll
mRun: [WirelessAssistant] C:Program Files (x86)Hewlett-PackardHP Wireless AssistantHPWAMain.exe
mRun: [PlusService] C:Program Files (x86)Yuna SoftwareMessenger Plus!PlusService.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:Program Files (x86)Windows LiveWriterWriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:Program Files (x86)SkypeToolbarsInternet Explorerskypeieplugin.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:Program Files (x86)HPDigital ImagingSmart Web Printinghpswp_BHO.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces{04EB6DFB-DBFD-4450-A2BA-30E06A43B528} : DhcpNameServer = 192.168.1.1
TCP: Interfaces{F1D0DCCB-1BC2-4BC1-9FCD-34B1DC76C3C1} : DhcpNameServer = 192.168.1.1
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:Program Files (x86)SkypeToolbarsInternet Explorerskypeieplugin.dll
BHO-X64: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:Program Files (x86)HPDigital ImagingSmart Web Printinghpswp_printenhancer.dll
BHO-X64: HP Print Enhancer - No File
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:Program Files (x86)Common FilesAdobeAcrobatActiveXAcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO-X64: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program Files (x86)Common FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:Program Files (x86)SkypeToolbarsInternet Explorerskypeieplugin.dll
BHO-X64: SkypeIEPluginBHO - No File
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program Files (x86)Javajre6binjp2ssv.dll
BHO-X64: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:Program Files (x86)HPDigital ImagingSmart Web Printinghpswp_BHO.dll
BHO-X64: HP Smart BHO Class - No File
mRun-x64: [WirelessAssistant] C:Program Files (x86)Hewlett-PackardHP Wireless AssistantHPWAMain.exe
mRun-x64: [PlusService] C:Program Files (x86)Yuna SoftwareMessenger Plus!PlusService.exe
Hosts: 216.240.133.193 www.google-analytics.com.
Hosts: 216.240.133.193 ad-emea.doubleclick.net.
Hosts: 216.240.133.193 www.statcounter.com.
Hosts: 69.72.252.254 www.google-analytics.com.
Hosts: 69.72.252.254 ad-emea.doubleclick.net.
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
================= FIREFOX ===================
.
FF - ProfilePath - C:UsersLilyAppDataRoamingMozillaFirefoxProfilesjdvv19p5.default
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource;=3&q;={searchTerms}
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/redirector/sredir?sredir=2706&invocationType;=tb50-ff-aim-ab-en-us&tb;_uuid=20110821044524515&tb;_oid=21-08-2011&tb;_mrud=21-08-2011&query;=
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:PROGRA~2MICROS~3Office14NPSPWRAP.DLL
FF - plugin: C:Program Files (x86)GoogleUpdate1.3.21.93npGoogleUpdate3.dll
FF - plugin: C:Program Files (x86)Javajre6binnew_pluginnpdeployJava1.dll
FF - plugin: c:Program Files (x86)Microsoft Silverlight4.0.60831.0npctrlui.dll
FF - plugin: C:Program Files (x86)Mozilla Firefoxpluginsnpdnu.dll
FF - plugin: C:Program Files (x86)Mozilla Firefoxpluginsnpdnupdater2.dll
FF - plugin: C:Program Files (x86)Pando NetworksMedia BoosternpPandoWebPlugin.dll
FF - plugin: C:Program Files (x86)Windows LivePhoto GalleryNPWLPG.dll
FF - plugin: C:ProgramDataNexonUSNGMnpNxGameUS.dll
FF - plugin: C:WindowsSysWOW64AdobeDirectornp32dsw.dll
FF - plugin: C:WindowsSysWOW64MacromedFlashNPSWF32.dll
.
—- FIREFOX POLICIES —-
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false
FF - user.js: browser.sessionstore.resume_from_crash - false
.
============= SERVICES / DRIVERS ===============
.
R1 vwififlt;Virtual WiFi Filter Driver;C:Windowssystem32DRIVERSvwififlt.sys –> C:Windowssystem32DRIVERSvwififlt.sys [?]
R2 AERTFilters;Andrea RT Filters Service;C:Program FilesRealtekAudioHDAAERTSr64.exe [2010-8-31 98208]
R2 cvhsvc;Client Virtualization Handler;C:Program Files (x86)Common Filesmicrosoft sharedVirtualization HandlerCVHSVC.EXE [2010-10-20 821664]
R2 HP Support Assistant Service;HP Support Assistant Service;C:Program Files (x86)Hewlett-PackardHP Support FrameworkHPSA_Service.exe [2011-6-21 85560]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:Program Files (x86)Hewlett-PackardSharedHPDrvMntSvc.exe [2011-3-28 94264]
R2 HPWMISVC;HPWMISVC;C:Program FilesHewlett-PackardHP Quick LaunchHPWMISVC.exe [2010-1-18 20480]
R2 sftlist;Application Virtualization Client;C:Program Files (x86)Microsoft Application Virtualization Clientsftlist.exe [2010-9-14 508264]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;C:Windowssystem32driversIntcHdmi.sys –> C:Windowssystem32driversIntcHdmi.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:Windowssystem32DRIVERSRt64win7.sys –> C:Windowssystem32DRIVERSRt64win7.sys [?]
R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;C:Windowssystem32DRIVERSrtl8192se.sys –> C:Windowssystem32DRIVERSrtl8192se.sys [?]
R3 Sftfs;Sftfs;C:Windowssystem32DRIVERSSftfslh.sys –> C:Windowssystem32DRIVERSSftfslh.sys [?]
R3 Sftplay;Sftplay;C:Windowssystem32DRIVERSSftplaylh.sys –> C:Windowssystem32DRIVERSSftplaylh.sys [?]
R3 Sftredir;Sftredir;C:Windowssystem32DRIVERSSftredirlh.sys –> C:Windowssystem32DRIVERSSftredirlh.sys [?]
R3 Sftvol;Sftvol;C:Windowssystem32DRIVERSSftvollh.sys –> C:Windowssystem32DRIVERSSftvollh.sys [?]
R3 sftvsa;Application Virtualization Service Agent;C:Program Files (x86)Microsoft Application Virtualization Clientsftvsa.exe [2010-9-14 219496]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:WindowsMicrosoft.NETFrameworkv4.0.30319mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:WindowsMicrosoft.NETFramework64v4.0.30319mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:Program Files (x86)GoogleUpdateGoogleUpdate.exe [2011-8-21 136176]
S3 gupdatem;Google Update Service (gupdatem);C:Program Files (x86)GoogleUpdateGoogleUpdate.exe [2011-8-21 136176]
S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;C:Windowssystem32Driversnx6000.sys –> C:Windowssystem32Driversnx6000.sys [?]
S3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:Windowssystem32DRIVERSnetw5v64.sys –> C:Windowssystem32DRIVERSnetw5v64.sys [?]
S3 osppsvc;Office Software Protection Platform;C:Program FilesCommon FilesMicrosoft SharedOfficeSoftwareProtectionPlatformOSPPSVC.EXE [2010-1-9 4925184]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:WindowsSystem32driversRtsUStor.sys [2010-8-31 225280]
S3 SrvHsfHDA;SrvHsfHDA;C:Windowssystem32DRIVERSVSTAZL6.SYS –> C:Windowssystem32DRIVERSVSTAZL6.SYS [?]
S3 SrvHsfV92;SrvHsfV92;C:Windowssystem32DRIVERSVSTDPV6.SYS –> C:Windowssystem32DRIVERSVSTDPV6.SYS [?]
S3 SrvHsfWinac;SrvHsfWinac;C:Windowssystem32DRIVERSVSTCNXT6.SYS –> C:Windowssystem32DRIVERSVSTCNXT6.SYS [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:Windowssystem32Driversusbaapl64.sys –> C:Windowssystem32Driversusbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:Windowssystem32WatWatAdminSvc.exe –> C:Windowssystem32WatWatAdminSvc.exe [?]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:Windowssystem32DRIVERSyk62x64.sys –> C:Windowssystem32DRIVERSyk62x64.sys [?]
.
=============== Created Last 30 ================
.
2012-01-21 17:25:35 98816 —-a-w- C:Windowssed.exe
2012-01-21 17:25:35 518144 —-a-w- C:WindowsSWREG.exe
2012-01-21 17:25:35 256000 —-a-w- C:WindowsPEV.exe
2012-01-21 17:25:35 208896 —-a-w- C:WindowsMBR.exe
2012-01-13 03:45:37 ——– d—–w- C:UsersLilyAppDataRoamingPhotoScape
2012-01-13 03:45:25 ——– d—–w- C:Program Files (x86)PhotoScape
2012-01-11 15:26:48 514560 —-a-w- C:WindowsSysWow64qdvd.dll
2012-01-11 15:26:48 366592 —-a-w- C:WindowsSystem32qdvd.dll
2012-01-11 15:26:48 1572864 —-a-w- C:WindowsSystem32quartz.dll
2012-01-11 15:26:48 1328640 —-a-w- C:WindowsSysWow64quartz.dll
2012-01-11 15:26:45 77312 —-a-w- C:WindowsSystem32packager.dll
2012-01-11 15:26:45 67072 —-a-w- C:WindowsSysWow64packager.dll
2012-01-11 15:26:45 1739160 —-a-w- C:WindowsSystem32ntdll.dll
2012-01-11 15:26:45 1292592 —-a-w- C:WindowsSysWow64ntdll.dll
2012-01-10 16:37:00 ——– d—–w- C:ProgramDataMessenger Plus!
2012-01-10 16:36:45 ——– d—–w- C:Program Files (x86)Yuna Software
2012-01-08 18:57:39 626688 —-a-w- C:Program Files (x86)Mozilla Firefoxmsvcr80.dll
2012-01-08 18:57:39 548864 —-a-w- C:Program Files (x86)Mozilla Firefoxmsvcp80.dll
2012-01-08 18:57:39 479232 —-a-w- C:Program Files (x86)Mozilla Firefoxmsvcm80.dll
2012-01-08 18:57:39 43992 —-a-w- C:Program Files (x86)Mozilla Firefoxmozutils.dll
2011-12-25 06:09:59 ——– d—–w- C:Program Files (x86)Common FilesSteam
2011-12-25 06:09:57 ——– d—–w- C:Program Files (x86)Steam
2011-12-25 05:24:09 ——– d—–w- C:UsersLilyAppDataLocalMumble
2011-12-25 05:12:34 ——– d—–w- C:UsersLilyAppDataRoamingMumble
2011-12-25 05:10:36 ——– d—–w- C:Program Files (x86)Mumble
.
==================== Find3M ====================
.
2011-11-24 05:00:47 3141632 —-a-w- C:WindowsSystem32win32k.sys
2011-11-05 05:26:29 1197568 —-a-w- C:WindowsSystem32wininet.dll
2011-11-05 05:23:10 57856 —-a-w- C:WindowsSystem32licmgr10.dll
2011-11-05 05:17:42 2048 —-a-w- C:WindowsSystem32tzres.dll
2011-11-05 04:35:50 981504 —-a-w- C:WindowsSysWow64wininet.dll
2011-11-05 04:34:15 44544 —-a-w- C:WindowsSysWow64licmgr10.dll
2011-11-05 04:30:11 2048 —-a-w- C:WindowsSysWow64tzres.dll
2011-11-05 04:07:32 482816 —-a-w- C:WindowsSystem32html.iec
2011-11-05 03:28:41 386048 —-a-w- C:WindowsSysWow64html.iec
2011-11-05 03:25:44 1638912 —-a-w- C:WindowsSystem32mshtml.tlb
2011-11-05 02:55:38 1638912 —-a-w- C:WindowsSysWow64mshtml.tlb
2011-10-26 05:19:07 43520 —-a-w- C:WindowsSystem32csrsrv.dll
.
============= FINISH: 12:51:25.52 ===============
If anything, I can start from the beginning following your instructions. 