Page 1 of 4 1234 LastLast
Results 1 to 10 of 31

Thread: Ping.exe

  1. #1
    Junior Member
    Join Date
    Dec 2011
    Posts
    21

    Default Ping.exe

    Hi,
    I would be grateful for any help you can offer. Ping.exe keeps starting up and is consuming system resources. Here is my DDS log


    .
    DDS (Ver_2011-08-26.01) - NTFSx86
    Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.5.0_12
    Run by tfarrell at 10:46:12 on 2011-12-07
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.821 [GMT -7:00]
    .
    AV: ESET NOD32 Antivirus 4.2 *Enabled/Outdated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
    .
    ============== Running Processes ===============
    .
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
    svchost.exe
    C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
    C:\WINDOWS\system32\agrsmsvc.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\ColdFusion9\solr\solr.exe
    C:\ColdFusion9\jnbridge\CFDotNetsvc.exe
    C:\ColdFusion9\runtime\jre\bin\java.exe
    C:\ColdFusion9\jnbridge\JNBDotNetSide.exe
    C:\ColdFusion9\runtime\bin\jrunsvc.exe
    C:\ColdFusion9\db\slserver54\bin\swagent.exe
    C:\ColdFusion9\runtime\bin\jrun.exe
    C:\ColdFusion9\db\slserver54\bin\swstrtr.exe
    C:\ColdFusion9\db\slserver54\bin\swsoc.exe
    C:\ColdFusion9\verity\k2\_nti40\bin\k2admin.exe
    C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
    C:\WINDOWS\system32\ifxspmgt.exe
    C:\WINDOWS\system32\IFXTCS.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
    C:\Program Files\Novatel Wireless\Novacore\Server\NvtlSrvr.exe
    C:\WINDOWS\system32\IfxPsdSv.exe
    C:\WINDOWS\System32\svchost.exe -k Sqlses
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\ColdFusion9\verity\k2\_nti40\bin\k2server.exe
    C:\ColdFusion9\verity\k2\_nti40\bin\k2index.exe
    C:\Program Files\Citrix\ICA Client\ssonsvr.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
    C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    C:\Program Files\Evernote\Evernote\EvernoteClipper.exe
    C:\Program Files\Microsoft Office 2010\Office14\ONENOTEM.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    svchost.exe -m
    C:\Program Files\Safari\Safari.exe
    C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\Safari\Safari.exe
    C:\Program Files\Microsoft Office 2010\Office14\OUTLOOK.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\WINDOWS\System32\ping.exe
    C:\WINDOWS\system32\SearchProtocolHost.exe
    .
    ============== Pseudo HJT Report ===============
    .
    mWindow Title =
    uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
    uInternet Settings,ProxyOverride = *.local
    uURLSearchHooks: YTNavAssist.YTNavAssistPlugin Class: {81017ea9-9aa8-4a6a-9734-7af40e7d593f} - c:\progra~1\yahoo!\companion\installs\cpn0\YTNavAssist.dll
    mURLSearchHooks: YTNavAssist.YTNavAssistPlugin Class: {81017ea9-9aa8-4a6a-9734-7af40e7d593f} - c:\progra~1\yahoo!\companion\installs\cpn0\YTNavAssist.dll
    BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\npdivx32.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: DivX HiQ: {593ddec6-7468-4cdd-90e1-42dadaa222e9} - c:\program files\divx\divx plus web player\npdivx32.dll
    BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_12\bin\ssv.dll
    BHO: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7018.1622\swg.dll
    BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\mi7967~1\office14\URLREDIR.DLL
    BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn0\YTSingleInstance.dll
    TB: pdfforge Toolbar: {b922d405-6d13-4a2b-ae89-08a030da4402} - c:\program files\pdfforge toolbar\ie\4.3\pdfforgeToolbarIE.dll
    TB: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
    TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
    uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    mRun: [Cpqset] c:\program files\hpq\default settings\cpqset.exe
    mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start
    mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
    mRun: [FRYMXINS] "c:\program files\ati technologies\fire gl 3d studio max\atiimxgl"
    mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
    mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
    mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
    mRun: [PTHOSTTR] c:\program files\hewlett-packard\hp protecttools security manager\PTHOSTTR.EXE /Start
    mRun: [IFXSPMGT] c:\windows\system32\ifxspmgt.exe /NotifyLogon
    mRun: [Recguard] c:\windows\sminst\Recguard.exe
    mRun: [Reminder] c:\windows\creator\Remind_XP.exe
    mRun: [Scheduler] c:\windows\sminst\Scheduler.exe
    mRun: [BSDAppUpdater] c:\program files\common files\bsd\appupdater\BSDChecker.exe
    mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
    mRun: [Sprint SmartView] "c:\program files\sprint\sprint smartview\SprintSV.exe" -a
    mRun: [RDVCHG] "c:\program files\sprint\sprint smartview\RDVCHG.exe"
    mRun: [ConnectionCenter] "c:\program files\citrix\ica client\concentr.exe" /startup
    mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.5.0_12\bin\jusched.exe"
    mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
    mRun: [EEventManager] "c:\program files\epson software\event manager\EEventManager.exe"
    mRun: [SynTPStart] c:\program files\synaptics\syntp\SynTPStart.exe
    mRun: [BCSSync] "c:\program files\microsoft office 2010\office14\BCSSync.exe" /DelayServices
    mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
    mRun: [LWS] c:\program files\logitech\lws\webcam software\LWS.exe -hide
    mRun: [Nikon Message Center 2] c:\program files\nikon\nikon message center 2\NkMC2.exe -s
    mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
    mRun: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
    mRunOnce: [SpybotDeletingA1528] command.com /c del "c:\program files\free offers from freeze.com\control.txt"
    mRunOnce: [SpybotDeletingC333] cmd.exe /c del "c:\program files\free offers from freeze.com\control.txt"
    mRunOnce: [SpybotDeletingA6697] command.com /c del "c:\program files\free offers from freeze.com\dolphinico.ico"
    mRunOnce: [SpybotDeletingC3713] cmd.exe /c del "c:\program files\free offers from freeze.com\dolphinico.ico"
    StartupFolder: c:\docume~1\tfarre~1.lt-\startm~1\programs\startup\everno~1.lnk - c:\program files\evernote\evernote\EvernoteClipper.exe
    StartupFolder: c:\docume~1\tfarre~1.lt-\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office 2010\office14\ONENOTEM.EXE
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\servic~1.lnk - c:\program files\microsoft sql server\80\tools\binn\sqlmangr.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
    mPolicies-explorer: DisableLocalMachineRunOnce = 1 (0x1)
    mPolicies-explorer: DisableLocalMachineRun = 1 (0x1)
    IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://c:\program files\evernote\evernote\EvernoteIE.dll/204
    IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0012-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_12\bin\ssv.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office 2010\office14\ONBttnIE.dll
    IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office 2010\office14\ONBttnIELinkedNotes.dll
    IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    LSP: mswsock.dll
    DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.6.0.cab
    DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1297226283656
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1312306304906
    DPF: {707ABFC2-1D27-4A10-A6E4-6BE6BDF9FB11} - hxxp://dscmtn4/vc/UltraMJCamX.ocx
    DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_12-windows-i586.cab
    DPF: {CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA} - hxxp://dscmtn4/vc/jinstall-1_5_0_12-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_12-windows-i586.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    TCP: DhcpNameServer = 192.168.2.1 75.75.75.75
    TCP: Interfaces\{5179EC27-0321-4423-852A-713092ABFA0D} : DhcpNameServer = 192.168.2.1 75.75.75.75
    Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
    Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
    Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
    Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
    Notify: Asynchronous - sqlesw32.dll
    Notify: AtiExtEvent - Ati2evxx.dll
    Notify: sqlesw32 - sqlesw32.dll
    Notify: Sqlseses - sqlesw32.dll
    Notify: }{|·¦w71@ÚºÿÁ - sqlesw32.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
    Hosts: 127.0.0.1 www.spywareinfo.com
    .
    ============= SERVICES / DRIVERS ===============
    .
    R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2010-7-29 115008]
    R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2010-8-3 95896]
    R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [2007-7-24 38816]
    R2 CF9Solr;ColdFusion 9 Solr Service;c:\coldfusion9\solr\solr.exe -zglaxservice cf9solr --> c:\coldfusion9\solr\solr.exe -zglaxservice CF9Solr [?]
    R2 ColdFusion 9 .NET Service;ColdFusion 9 .NET Service;c:\coldfusion9\jnbridge\CFDotNetsvc.exe [2011-5-10 77824]
    R2 ColdFusion 9 Application Server;ColdFusion 9 Application Server;c:\coldfusion9\runtime\bin\jrunsvc.exe [2011-5-10 58880]
    R2 ColdFusion 9 ODBC Agent;ColdFusion 9 ODBC Agent;c:\coldfusion9\db\slserver54\bin\swagent.exe "coldfusion 9 odbc agent" --> c:\coldfusion9\db\slserver54\bin\swagent.exe ColdFusion 9 ODBC Agent [?]
    R2 ColdFusion 9 ODBC Server;ColdFusion 9 ODBC Server;c:\coldfusion9\db\slserver54\bin\swstrtr.exe "coldfusion 9 odbc server" --> c:\coldfusion9\db\slserver54\bin\swstrtr.exe ColdFusion 9 ODBC Server [?]
    R2 ColdFusion 9 Search Server;ColdFusion 9 Search Server;c:\coldfusion9\verity\k2\_nti40\bin\k2admin.exe [2011-5-10 3677616]
    R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2010-8-12 810144]
    R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-6-13 366152]
    R2 NvtlService;NovaCore SDK Service;c:\program files\novatel wireless\novacore\server\NvtlSrvr.exe [2010-1-11 82944]
    R2 SqlCSS;SQL Server EXPRESS;c:\windows\system32\svchost.exe -k Sqlses [2006-2-28 14336]
    R2 UMVPFSrv;UMVPFSrv;c:\program files\common files\logishrd\lvmvfm\UMVPFSrv.exe [2011-8-19 450848]
    R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [2011-2-8 97280]
    R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2007-7-24 41216]
    R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-6-13 22216]
    R3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
    S0 SMR210;Symantec SMR Utility Service 2.1.0;c:\windows\system32\drivers\smr210.sys --> c:\windows\system32\drivers\SMR210.SYS [?]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-2-14 136176]
    S3 CompFilter;UVCCompositeFilter;c:\windows\system32\drivers\lvbusflt.sys [2011-8-19 22176]
    S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-2-14 136176]
    S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\drivers\nwusbser2.sys [2010-12-15 174720]
    S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2006-2-28 14336]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
    .
    =============== Created Last 30 ================
    .
    2011-12-04 17:31:29 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2011-12-04 17:31:29 -------- d-----w- c:\documents and settings\all users\application data\Spybot - Search & Destroy
    2011-12-03 23:57:53 -------- d-----w- c:\documents and settings\tfarrell.lt-0603\application data\Tific
    2011-12-03 23:57:52 -------- d-----w- c:\documents and settings\tfarrell.lt-0603\local settings\application data\Symantec
    2011-12-03 20:18:50 14744 ----a-w- c:\documents and settings\tfarrell.lt-0603\application data\microsoft\identitycrl\production\ppcrlconfig.dll
    2011-12-03 20:17:34 -------- d-----w- c:\program files\MSECache
    2011-12-03 19:53:05 -------- d-----w- c:\documents and settings\tfarrell.lt-0603\local settings\application data\NPE
    2011-12-03 19:52:25 -------- d-----w- c:\program files\Norton Power Eraser
    2011-12-03 19:15:22 -------- d-----w- c:\program files\SpyBot
    2011-12-03 19:12:18 388096 ----a-r- c:\documents and settings\tfarrell.lt-0603\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
    2011-12-03 19:12:18 -------- d-----w- c:\program files\Trend Micro
    2011-12-03 19:11:49 1402880 ----a-w- C:\HiJackThis.msi
    2011-12-03 18:27:51 -------- d--h--w- c:\windows\PIF
    2011-12-03 17:56:43 53248 ----a-w- c:\windows\system32\6to4v32.dll
    2011-12-03 17:56:42 37888 ----a-w- c:\windows\system32\sqlesw32.dll
    2011-12-03 17:56:42 156672 ----a-w- c:\windows\system32\sqlcsw32.dll
    2011-12-03 10:11:22 116224 ----a-w- c:\windows\system32\5T740.com
    2011-12-03 07:39:45 -------- d-----w- c:\documents and settings\all users\application data\IObit
    2011-12-03 07:39:41 -------- d-----w- c:\program files\IObit
    2011-12-02 17:13:53 116224 ----a-w- c:\windows\system32\5T740.com_
    2011-12-01 21:08:35 751616 ----a-w- C:\roguekiller.exe
    2011-12-01 21:02:33 -------- d-----w- C:\RK_Quarantine
    2011-12-01 20:32:59 709968 ----a-w- c:\windows\is-BVQM3.exe
    2011-11-30 23:38:39 -------- d-----w- c:\documents and settings\tfarrell.lt-0603\application data\pdfforge
    2011-11-30 23:38:34 662288 ----a-w- c:\windows\system32\MSCOMCT2.OCX
    2011-11-30 23:38:34 137000 ----a-w- c:\windows\system32\MSMAPI32.OCX
    2011-11-30 23:38:34 116224 ----a-w- c:\windows\system32\pdfcmnnt.dll
    2011-11-30 23:38:33 23552 ----a-w- c:\windows\system32\MSMPIDE.DLL
    2011-11-29 21:27:08 -------- d-----w- c:\documents and settings\tfarrell.lt-0603\Bluetooth Software
    2011-11-19 20:44:44 -------- d-----w- c:\program files\File Type Assistant
    2011-11-19 20:40:18 -------- d-----w- C:\Torrent
    2011-11-17 19:21:52 -------- d-----w- C:\Vail Resorts
    2011-11-15 16:27:05 -------- d-----w- C:\e
    2011-11-15 16:27:05 -------- d-----w- C:\Data
    2011-11-15 00:15:29 -------- d-----w- c:\program files\iPod
    2011-11-15 00:15:24 -------- d-----w- c:\program files\iTunes
    2011-11-07 21:17:13 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll
    2011-11-07 21:17:13 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
    2011-11-07 21:17:13 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
    2011-11-07 21:17:13 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
    2011-11-07 21:17:13 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
    2011-11-07 21:17:13 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
    2011-11-07 21:17:13 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
    2011-11-07 21:03:43 -------- d-----w- c:\program files\Bonjour
    .
    ==================== Find3M ====================
    .
    2011-11-12 22:12:18 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2011-10-24 21:29:02 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
    2011-10-24 21:29:02 69632 ----a-w- c:\windows\system32\QuickTime.qts
    2011-09-27 19:21:33 106496 ----a-w- c:\windows\system32\ATL71.DLL
    .
    ============= FINISH: 10:48:23.57 ===============

  2. #2
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,066

    Default

    hi livinginmtn,

    Your post is a few days old. If you still need help simply reply back.
    How Can I Reduce My Risk?

  3. #3
    Junior Member
    Join Date
    Dec 2011
    Posts
    21

    Default Ping.exe

    Hi, i have been travelling. Yes, I still need help. My situation is that i became infected with the 2012 Xp security virus. I downloaded spybot and hijack this. I was successful in removing the security virus but I bel;ieve that it was masking my real problem. I think i have a hijack virus. Some of my hotmail contacts have received spurious emails from that account. Now ping.exe is continually launching, gradually consuming memory and system resources until my laptop ginnds to a halt. Spybot seems to be blocking the access to the internet.

  4. #4
    Junior Member
    Join Date
    Dec 2011
    Posts
    21

    Default Ping.exe

    The last statement may be misleading. Spybot is preventing the virus from access the internet. I have just removed ping.exe with taskmgr and it was over 400k in resources after being connected via wifi for 5 minutes.

    Thanks for any help you can offer.

  5. #5
    Junior Member
    Join Date
    Dec 2011
    Posts
    21

    Default Ping.exe

    This is what netstat show after 10 minutes of connection.

    TCP lt-0603:30606 www.007guard.com:2449 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2455 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2459 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2461 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2463 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2467 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2473 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2477 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2479 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2481 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2483 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2485 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2487 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2491 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2493 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2501 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2503 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2509 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2511 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2513 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2515 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2519 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2521 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2524 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2526 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2530 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2532 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2536 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2538 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2542 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2544 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2546 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2548 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2550 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2552 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2554 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2556 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2558 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2560 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2562 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2564 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2566 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2568 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2570 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2572 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2574 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2576 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2578 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2580 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2586 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2588 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2590 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2592 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2594 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2596 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2598 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2606 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2608 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2610 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2612 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2614 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2616 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2618 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2624 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2626 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2628 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2630 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2634 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2638 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2642 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2644 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2646 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2648 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2654 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2656 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2660 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2662 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2664 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2666 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2668 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2670 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2672 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2678 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2680 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2682 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2684 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2688 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2690 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2692 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2694 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2696 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2698 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2700 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2706 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2712 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2714 FIN_WAIT_2
    TCP lt-0603:30606 www.007guard.com:2716 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2718 FIN_WAIT_2
    TCP lt-0603:30606 www.007guard.com:2720 FIN_WAIT_2
    TCP lt-0603:30606 www.007guard.com:2726 FIN_WAIT_2
    TCP lt-0603:30606 www.007guard.com:2728 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2730 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2732 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2734 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2736 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2738 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2742 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2744 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2758 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2760 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2766 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2772 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2774 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2776 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2778 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2780 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2782 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2784 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2786 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2788 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2790 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2792 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2798 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2802 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2804 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2808 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2810 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2812 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2814 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2816 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2818 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2820 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2822 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2824 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2826 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2828 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2830 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2832 FIN_WAIT_2
    TCP lt-0603:30606 www.007guard.com:2834 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2836 FIN_WAIT_2
    TCP lt-0603:30606 www.007guard.com:2838 FIN_WAIT_2
    TCP lt-0603:30606 www.007guard.com:2846 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2848 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2850 TIME_WAIT
    TCP lt-0603:30606 www.007guard.com:2854 FIN_WAIT_2
    TCP lt-0603:30606 www.007guard.com:2858 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2860 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2862 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2868 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2870 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2872 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2880 ESTABLISHED
    TCP lt-0603:30606 www.007guard.com:2890 ESTABLISHED
    TCP lt-0603:2268 72.32.153.177:http LAST_ACK
    TCP lt-0603:2319 211-111-162-69.static.reverse.lstn.net:http CLO
    SE_WAIT
    TCP lt-0603:2328 .:http TIME_WAIT
    TCP lt-0603:2330 199.59.241.250:http TIME_WAIT
    TCP lt-0603:2334 68.169.92.55:http TIME_WAIT
    TCP lt-0603:2342 ec2-50-19-109-125.compute-1.amazonaws.com:http
    ESTABLISHED
    TCP lt-0603:2344 ec2-107-20-156-112.compute-1.amazonaws.com:http
    ESTABLISHED
    TCP lt-0603:2346 .:http TIME_WAIT
    TCP lt-0603:2350 pz-in-f95.1e100.net:http ESTABLISHED
    TCP lt-0603:2354 nuq04s06-in-f13.1e100.net:http ESTABLISHED
    TCP lt-0603:2356 nuq04s06-in-f13.1e100.net:http ESTABLISHED
    TCP lt-0603:2358 www-da1.adobe.com:http ESTABLISHED
    TCP lt-0603:2360 a23-3-68-107.deploy.akamaitechnologies.com:http
    ESTABLISHED
    TCP lt-0603:2366 .:http TIME_WAIT
    TCP lt-0603:2368 199.59.241.250:http TIME_WAIT
    TCP lt-0603:2376 a96-17-239-139.deploy.akamaitechnologies.com:htt
    ps ESTABLISHED
    TCP lt-0603:2378 www-11-05-prn1.facebook.com:https ESTABLISHED
    TCP lt-0603:2410 208.81.191.113:http ESTABLISHED
    TCP lt-0603:2428 a23-3-68-107.deploy.akamaitechnologies.com:http
    ESTABLISHED
    TCP lt-0603:2450 a23-3-68-114.deploy.akamaitechnologies.com:http
    ESTABLISHED
    TCP lt-0603:2460 74.114.28.200:http ESTABLISHED
    TCP lt-0603:2462 nuq04s07-in-f27.1e100.net:http ESTABLISHED
    TCP lt-0603:2464 www-11-05-prn1.facebook.com:http ESTABLISHED
    TCP lt-0603:2478 nuq04s07-in-f27.1e100.net:http ESTABLISHED
    TCP lt-0603:2480 208.81.191.113:http ESTABLISHED
    TCP lt-0603:2482 nuq04s06-in-f27.1e100.net:http ESTABLISHED
    TCP lt-0603:2484 nuq04s06-in-f27.1e100.net:http ESTABLISHED
    TCP lt-0603:2486 a96-17-227-24.deploy.akamaitechnologies.com:http
    ESTABLISHED
    TCP lt-0603:2492 ec2-184-73-247-213.compute-1.amazonaws.com:http
    ESTABLISHED
    TCP lt-0603:2494 a23-3-68-136.deploy.akamaitechnologies.com:http
    ESTABLISHED
    TCP lt-0603:2496 .:http TIME_WAIT
    TCP lt-0603:2498 parkwebwin-v02.prod.mesa1.secureserver.net:http
    CLOSING
    TCP lt-0603:2504 66.150.149.23:http ESTABLISHED
    TCP lt-0603:2510 66.150.149.23:http ESTABLISHED
    TCP lt-0603:2512 98.129.232.76:http ESTABLISHED
    TCP lt-0603:2514 ec2-184-73-170-119.compute-1.amazonaws.com:http
    ESTABLISHED
    TCP lt-0603:2516 a23-3-68-136.deploy.akamaitechnologies.com:http
    ESTABLISHED
    TCP lt-0603:2539 a23-3-68-114.deploy.akamaitechnologies.com:http
    ESTABLISHED
    TCP lt-0603:2551 a23-3-68-112.deploy.akamaitechnologies.com:http
    ESTABLISHED
    TCP lt-0603:2553 a23-3-68-112.deploy.akamaitechnologies.com:http
    ESTABLISHED
    TCP lt-0603:2565 ec2-107-22-189-186.compute-1.amazonaws.com:http
    ESTABLISHED
    TCP lt-0603:2567 a23-3-68-123.deploy.akamaitechnologies.com:http
    ESTABLISHED
    TCP lt-0603:2569 a23-3-68-123.deploy.akamaitechnologies.com:http
    ESTABLISHED
    TCP lt-0603:2575 ec2-107-22-189-186.compute-1.amazonaws.com:http
    ESTABLISHED
    TCP lt-0603:2587 a23-3-68-145.deploy.akamaitechnologies.com:http
    ESTABLISHED
    TCP lt-0603:2591 74.200.209.252:http ESTABLISHED
    TCP lt-0603:2599 a23-3-68-146.deploy.akamaitechnologies.com:http
    ESTABLISHED
    TCP lt-0603:2607 a23-3-68-113.deploy.akamaitechnologies.com:http
    ESTABLISHED
    TCP lt-0603:2627 a23-3-68-145.deploy.akamaitechnologies.com:http
    ESTABLISHED
    TCP lt-0603:2637 .:http TIME_WAIT
    TCP lt-0603:2641 213.174.148.3:http TIME_WAIT
    TCP lt-0603:2655 ec2-50-19-225-159.compute-1.amazonaws.com:http
    ESTABLISHED
    TCP lt-0603:2665 76.74.136.93:http ESTABLISHED
    TCP lt-0603:2673 76.74.136.96:http ESTABLISHED
    TCP lt-0603:2679 a23-3-68-99.deploy.akamaitechnologies.com:http
    ESTABLISHED
    TCP lt-0603:2681 a23-3-68-145.deploy.akamaitechnologies.com:http
    ESTABLISHED
    TCP lt-0603:2683 a23-3-68-145.deploy.akamaitechnologies.com:http
    ESTABLISHED
    TCP lt-0603:2685 a23-3-68-99.deploy.akamaitechnologies.com:http
    ESTABLISHED
    TCP lt-0603:2689 a23-3-68-99.deploy.akamaitechnologies.com:http
    ESTABLISHED
    TCP lt-0603:2693 a23-3-68-145.deploy.akamaitechnologies.com:http
    ESTABLISHED
    TCP lt-0603:2695 a23-3-68-99.deploy.akamaitechnologies.com:http
    ESTABLISHED
    TCP lt-0603:2697 a23-3-68-130.deploy.akamaitechnologies.com:http
    ESTABLISHED
    TCP lt-0603:2699 a23-3-68-130.deploy.akamaitechnologies.com:http
    ESTABLISHED
    TCP lt-0603:2707 a23-3-68-115.deploy.akamaitechnologies.com:http
    ESTABLISHED
    TCP lt-0603:2713 a23-3-12-202.deploy.akamaitechnologies.com:http
    ESTABLISHED
    TCP lt-0603:2715 64.210.61.140:http CLOSE_WAIT
    TCP lt-0603:2717 mpr2.ngd.vip.bf1.yahoo.com:http ESTABLISHED
    TCP lt-0603:2719 64.210.61.140:http CLOSE_WAIT
    TCP lt-0603:2723 64.210.61.136:http CLOSE_WAIT
    TCP lt-0603:2727 64.210.61.136:http CLOSE_WAIT
    TCP lt-0603:2729 mpr2.ngd.vip.bf1.yahoo.com:http ESTABLISHED
    TCP lt-0603:2731 ec2-174-129-203-211.compute-1.amazonaws.com:http
    ESTABLISHED
    TCP lt-0603:2735 js-pd03.revsci.net:http ESTABLISHED
    TCP lt-0603:2737 a23-3-68-138.deploy.akamaitechnologies.com:http
    ESTABLISHED
    TCP lt-0603:2739 a23-3-68-145.deploy.akamaitechnologies.com:http
    ESTABLISHED
    TCP lt-0603:2741 208.71.125.1:http TIME_WAIT
    TCP lt-0603:2759 cust-69.194.143.60.switchnap.com:http ESTABLISH
    ED
    TCP lt-0603:2761 cust-69.194.143.60.switchnap.com:http ESTABLISH
    ED
    TCP lt-0603:2769 208.71.125.1:http TIME_WAIT
    TCP lt-0603:2779 ec2-174-129-203-211.compute-1.amazonaws.com:http
    ESTABLISHED
    TCP lt-0603:2787 crispwireless.net:http ESTABLISHED
    TCP lt-0603:2801 .:http TIME_WAIT
    TCP lt-0603:2807 213.174.148.3:http TIME_WAIT
    TCP lt-0603:2815 74.217.78.140:http ESTABLISHED
    TCP lt-0603:2825 74.217.78.140:http ESTABLISHED
    TCP lt-0603:2827 crispwireless.net:http ESTABLISHED
    TCP lt-0603:2829 93.184.216.169:http ESTABLISHED
    TCP lt-0603:2831 93.184.216.169:http ESTABLISHED
    TCP lt-0603:2833 72.21.91.19:http CLOSE_WAIT
    TCP lt-0603:2837 66.45.56.124:http CLOSE_WAIT
    TCP lt-0603:2839 66.45.56.124:http CLOSE_WAIT
    TCP lt-0603:2849 138.108.6.20:http ESTABLISHED
    TCP lt-0603:2855 www.meebo.com:http CLOSE_WAIT
    TCP lt-0603:2859 93.184.216.119:http ESTABLISHED
    TCP lt-0603:2861 93.184.216.119:http ESTABLISHED
    TCP lt-0603:2863 93.184.216.119:http ESTABLISHED
    TCP lt-0603:2869 93.184.216.119:http ESTABLISHED
    TCP lt-0603:2871 93.184.216.119:http ESTABLISHED
    TCP lt-0603:2873 93.184.216.119:http ESTABLISHED
    TCP lt-0603:2881 a23-3-68-136.deploy.akamaitechnologies.com:http
    ESTABLISHED
    TCP lt-0603:2891 216-18-215-4.hosted.static.webnx.com:http ESTAB
    LISHED

    C:\Documents and Settings\tfarrell.LT-0603>

  6. #6
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,066

    Default

    I believe your host file is missing a line. Those 007guard entries happen to be the first ones in Spybots host file. You can ignore it for now, we will come back to it. If you disable the feature in Spybot then you shoudnt see them.

    You said you killed ping.exe in task manager, does it return on reboot? Is a updated malwarebytes coming up clean after a scan. Is your ESET AV up to date?
    We will get download to use, its called combofix. There is a guide to read first, read through the guide then apply the directions on your own machine. Post the combofix log.

    Guide to using Combofix
    How Can I Reduce My Risk?

  7. #7
    Junior Member
    Join Date
    Dec 2011
    Posts
    21

    Default Ping.exe

    When I kill Ping.exe in taskMgr it comes back within 2 to 3 minutes. I will download combofix and send you the log. ESET does not prevent the ping.exe relaunching.

  8. #8
    Junior Member
    Join Date
    Dec 2011
    Posts
    21

    Default Ping.exe

    Hi shelf life,
    I ran combo fix and it created the txt file. However now I cannot attach to the Internet. My wifi shows it is connected but the stats show that no data is transmitting. Ipconfig will not run. I connected by cable to my router same result. In both normal and safe mode same result. My wireless connection status shows no data for address type, ip address , subnet mask and default gateway.
    Help!!!

  9. #9
    Junior Member
    Join Date
    Dec 2011
    Posts
    21

    Default Ping.exe

    Sent from my iPhone....

  10. #10
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,066

    Default

    Have you rebooted both the computer and router?
    How Can I Reduce My Risk?

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •