-
Ping.exe
Hi,
I would be grateful for any help you can offer. Ping.exe keeps starting up and is consuming system resources. Here is my DDS log
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.5.0_12
Run by tfarrell at 10:46:12 on 2011-12-07
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.821 [GMT -7:00]
.
AV: ESET NOD32 Antivirus 4.2 *Enabled/Outdated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
svchost.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\ColdFusion9\solr\solr.exe
C:\ColdFusion9\jnbridge\CFDotNetsvc.exe
C:\ColdFusion9\runtime\jre\bin\java.exe
C:\ColdFusion9\jnbridge\JNBDotNetSide.exe
C:\ColdFusion9\runtime\bin\jrunsvc.exe
C:\ColdFusion9\db\slserver54\bin\swagent.exe
C:\ColdFusion9\runtime\bin\jrun.exe
C:\ColdFusion9\db\slserver54\bin\swstrtr.exe
C:\ColdFusion9\db\slserver54\bin\swsoc.exe
C:\ColdFusion9\verity\k2\_nti40\bin\k2admin.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\ifxspmgt.exe
C:\WINDOWS\system32\IFXTCS.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
C:\Program Files\Novatel Wireless\Novacore\Server\NvtlSrvr.exe
C:\WINDOWS\system32\IfxPsdSv.exe
C:\WINDOWS\System32\svchost.exe -k Sqlses
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\ColdFusion9\verity\k2\_nti40\bin\k2server.exe
C:\ColdFusion9\verity\k2\_nti40\bin\k2index.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Evernote\Evernote\EvernoteClipper.exe
C:\Program Files\Microsoft Office 2010\Office14\ONENOTEM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
svchost.exe -m
C:\Program Files\Safari\Safari.exe
C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Safari\Safari.exe
C:\Program Files\Microsoft Office 2010\Office14\OUTLOOK.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\ping.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
.
============== Pseudo HJT Report ===============
.
mWindow Title =
uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: YTNavAssist.YTNavAssistPlugin Class: {81017ea9-9aa8-4a6a-9734-7af40e7d593f} - c:\progra~1\yahoo!\companion\installs\cpn0\YTNavAssist.dll
mURLSearchHooks: YTNavAssist.YTNavAssistPlugin Class: {81017ea9-9aa8-4a6a-9734-7af40e7d593f} - c:\progra~1\yahoo!\companion\installs\cpn0\YTNavAssist.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\npdivx32.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: DivX HiQ: {593ddec6-7468-4cdd-90e1-42dadaa222e9} - c:\program files\divx\divx plus web player\npdivx32.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_12\bin\ssv.dll
BHO: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7018.1622\swg.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\mi7967~1\office14\URLREDIR.DLL
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn0\YTSingleInstance.dll
TB: pdfforge Toolbar: {b922d405-6d13-4a2b-ae89-08a030da4402} - c:\program files\pdfforge toolbar\ie\4.3\pdfforgeToolbarIE.dll
TB: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [Cpqset] c:\program files\hpq\default settings\cpqset.exe
mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [FRYMXINS] "c:\program files\ati technologies\fire gl 3d studio max\atiimxgl"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [PTHOSTTR] c:\program files\hewlett-packard\hp protecttools security manager\PTHOSTTR.EXE /Start
mRun: [IFXSPMGT] c:\windows\system32\ifxspmgt.exe /NotifyLogon
mRun: [Recguard] c:\windows\sminst\Recguard.exe
mRun: [Reminder] c:\windows\creator\Remind_XP.exe
mRun: [Scheduler] c:\windows\sminst\Scheduler.exe
mRun: [BSDAppUpdater] c:\program files\common files\bsd\appupdater\BSDChecker.exe
mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
mRun: [Sprint SmartView] "c:\program files\sprint\sprint smartview\SprintSV.exe" -a
mRun: [RDVCHG] "c:\program files\sprint\sprint smartview\RDVCHG.exe"
mRun: [ConnectionCenter] "c:\program files\citrix\ica client\concentr.exe" /startup
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.5.0_12\bin\jusched.exe"
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [EEventManager] "c:\program files\epson software\event manager\EEventManager.exe"
mRun: [SynTPStart] c:\program files\synaptics\syntp\SynTPStart.exe
mRun: [BCSSync] "c:\program files\microsoft office 2010\office14\BCSSync.exe" /DelayServices
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [LWS] c:\program files\logitech\lws\webcam software\LWS.exe -hide
mRun: [Nikon Message Center 2] c:\program files\nikon\nikon message center 2\NkMC2.exe -s
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
mRunOnce: [SpybotDeletingA1528] command.com /c del "c:\program files\free offers from freeze.com\control.txt"
mRunOnce: [SpybotDeletingC333] cmd.exe /c del "c:\program files\free offers from freeze.com\control.txt"
mRunOnce: [SpybotDeletingA6697] command.com /c del "c:\program files\free offers from freeze.com\dolphinico.ico"
mRunOnce: [SpybotDeletingC3713] cmd.exe /c del "c:\program files\free offers from freeze.com\dolphinico.ico"
StartupFolder: c:\docume~1\tfarre~1.lt-\startm~1\programs\startup\everno~1.lnk - c:\program files\evernote\evernote\EvernoteClipper.exe
StartupFolder: c:\docume~1\tfarre~1.lt-\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office 2010\office14\ONENOTEM.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\servic~1.lnk - c:\program files\microsoft sql server\80\tools\binn\sqlmangr.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
mPolicies-explorer: DisableLocalMachineRunOnce = 1 (0x1)
mPolicies-explorer: DisableLocalMachineRun = 1 (0x1)
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://c:\program files\evernote\evernote\EvernoteIE.dll/204
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0012-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_12\bin\ssv.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office 2010\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office 2010\office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: mswsock.dll
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.6.0.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1297226283656
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1312306304906
DPF: {707ABFC2-1D27-4A10-A6E4-6BE6BDF9FB11} - hxxp://dscmtn4/vc/UltraMJCamX.ocx
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_12-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA} - hxxp://dscmtn4/vc/jinstall-1_5_0_12-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_12-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.2.1 75.75.75.75
TCP: Interfaces\{5179EC27-0321-4423-852A-713092ABFA0D} : DhcpNameServer = 192.168.2.1 75.75.75.75
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: Asynchronous - sqlesw32.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: sqlesw32 - sqlesw32.dll
Notify: Sqlseses - sqlesw32.dll
Notify: }{|·¦w71@ÚºÿÁ - sqlesw32.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2010-7-29 115008]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2010-8-3 95896]
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [2007-7-24 38816]
R2 CF9Solr;ColdFusion 9 Solr Service;c:\coldfusion9\solr\solr.exe -zglaxservice cf9solr --> c:\coldfusion9\solr\solr.exe -zglaxservice CF9Solr [?]
R2 ColdFusion 9 .NET Service;ColdFusion 9 .NET Service;c:\coldfusion9\jnbridge\CFDotNetsvc.exe [2011-5-10 77824]
R2 ColdFusion 9 Application Server;ColdFusion 9 Application Server;c:\coldfusion9\runtime\bin\jrunsvc.exe [2011-5-10 58880]
R2 ColdFusion 9 ODBC Agent;ColdFusion 9 ODBC Agent;c:\coldfusion9\db\slserver54\bin\swagent.exe "coldfusion 9 odbc agent" --> c:\coldfusion9\db\slserver54\bin\swagent.exe ColdFusion 9 ODBC Agent [?]
R2 ColdFusion 9 ODBC Server;ColdFusion 9 ODBC Server;c:\coldfusion9\db\slserver54\bin\swstrtr.exe "coldfusion 9 odbc server" --> c:\coldfusion9\db\slserver54\bin\swstrtr.exe ColdFusion 9 ODBC Server [?]
R2 ColdFusion 9 Search Server;ColdFusion 9 Search Server;c:\coldfusion9\verity\k2\_nti40\bin\k2admin.exe [2011-5-10 3677616]
R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2010-8-12 810144]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-6-13 366152]
R2 NvtlService;NovaCore SDK Service;c:\program files\novatel wireless\novacore\server\NvtlSrvr.exe [2010-1-11 82944]
R2 SqlCSS;SQL Server EXPRESS;c:\windows\system32\svchost.exe -k Sqlses [2006-2-28 14336]
R2 UMVPFSrv;UMVPFSrv;c:\program files\common files\logishrd\lvmvfm\UMVPFSrv.exe [2011-8-19 450848]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [2011-2-8 97280]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2007-7-24 41216]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-6-13 22216]
R3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S0 SMR210;Symantec SMR Utility Service 2.1.0;c:\windows\system32\drivers\smr210.sys --> c:\windows\system32\drivers\SMR210.SYS [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-2-14 136176]
S3 CompFilter;UVCCompositeFilter;c:\windows\system32\drivers\lvbusflt.sys [2011-8-19 22176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-2-14 136176]
S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\drivers\nwusbser2.sys [2010-12-15 174720]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2006-2-28 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-12-04 17:31:29 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-12-04 17:31:29 -------- d-----w- c:\documents and settings\all users\application data\Spybot - Search & Destroy
2011-12-03 23:57:53 -------- d-----w- c:\documents and settings\tfarrell.lt-0603\application data\Tific
2011-12-03 23:57:52 -------- d-----w- c:\documents and settings\tfarrell.lt-0603\local settings\application data\Symantec
2011-12-03 20:18:50 14744 ----a-w- c:\documents and settings\tfarrell.lt-0603\application data\microsoft\identitycrl\production\ppcrlconfig.dll
2011-12-03 20:17:34 -------- d-----w- c:\program files\MSECache
2011-12-03 19:53:05 -------- d-----w- c:\documents and settings\tfarrell.lt-0603\local settings\application data\NPE
2011-12-03 19:52:25 -------- d-----w- c:\program files\Norton Power Eraser
2011-12-03 19:15:22 -------- d-----w- c:\program files\SpyBot
2011-12-03 19:12:18 388096 ----a-r- c:\documents and settings\tfarrell.lt-0603\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-12-03 19:12:18 -------- d-----w- c:\program files\Trend Micro
2011-12-03 19:11:49 1402880 ----a-w- C:\HiJackThis.msi
2011-12-03 18:27:51 -------- d--h--w- c:\windows\PIF
2011-12-03 17:56:43 53248 ----a-w- c:\windows\system32\6to4v32.dll
2011-12-03 17:56:42 37888 ----a-w- c:\windows\system32\sqlesw32.dll
2011-12-03 17:56:42 156672 ----a-w- c:\windows\system32\sqlcsw32.dll
2011-12-03 10:11:22 116224 ----a-w- c:\windows\system32\5T740.com
2011-12-03 07:39:45 -------- d-----w- c:\documents and settings\all users\application data\IObit
2011-12-03 07:39:41 -------- d-----w- c:\program files\IObit
2011-12-02 17:13:53 116224 ----a-w- c:\windows\system32\5T740.com_
2011-12-01 21:08:35 751616 ----a-w- C:\roguekiller.exe
2011-12-01 21:02:33 -------- d-----w- C:\RK_Quarantine
2011-12-01 20:32:59 709968 ----a-w- c:\windows\is-BVQM3.exe
2011-11-30 23:38:39 -------- d-----w- c:\documents and settings\tfarrell.lt-0603\application data\pdfforge
2011-11-30 23:38:34 662288 ----a-w- c:\windows\system32\MSCOMCT2.OCX
2011-11-30 23:38:34 137000 ----a-w- c:\windows\system32\MSMAPI32.OCX
2011-11-30 23:38:34 116224 ----a-w- c:\windows\system32\pdfcmnnt.dll
2011-11-30 23:38:33 23552 ----a-w- c:\windows\system32\MSMPIDE.DLL
2011-11-29 21:27:08 -------- d-----w- c:\documents and settings\tfarrell.lt-0603\Bluetooth Software
2011-11-19 20:44:44 -------- d-----w- c:\program files\File Type Assistant
2011-11-19 20:40:18 -------- d-----w- C:\Torrent
2011-11-17 19:21:52 -------- d-----w- C:\Vail Resorts
2011-11-15 16:27:05 -------- d-----w- C:\e
2011-11-15 16:27:05 -------- d-----w- C:\Data
2011-11-15 00:15:29 -------- d-----w- c:\program files\iPod
2011-11-15 00:15:24 -------- d-----w- c:\program files\iTunes
2011-11-07 21:17:13 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll
2011-11-07 21:17:13 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
2011-11-07 21:17:13 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2011-11-07 21:17:13 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2011-11-07 21:17:13 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2011-11-07 21:17:13 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2011-11-07 21:17:13 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2011-11-07 21:03:43 -------- d-----w- c:\program files\Bonjour
.
==================== Find3M ====================
.
2011-11-12 22:12:18 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-24 21:29:02 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 21:29:02 69632 ----a-w- c:\windows\system32\QuickTime.qts
2011-09-27 19:21:33 106496 ----a-w- c:\windows\system32\ATL71.DLL
.
============= FINISH: 10:48:23.57 ===============
-
hi livinginmtn,
Your post is a few days old. If you still need help simply reply back.
-
Ping.exe
Hi, i have been travelling. Yes, I still need help. My situation is that i became infected with the 2012 Xp security virus. I downloaded spybot and hijack this. I was successful in removing the security virus but I bel;ieve that it was masking my real problem. I think i have a hijack virus. Some of my hotmail contacts have received spurious emails from that account. Now ping.exe is continually launching, gradually consuming memory and system resources until my laptop ginnds to a halt. Spybot seems to be blocking the access to the internet.
-
Ping.exe
The last statement may be misleading. Spybot is preventing the virus from access the internet. I have just removed ping.exe with taskmgr and it was over 400k in resources after being connected via wifi for 5 minutes.
Thanks for any help you can offer.
-
Ping.exe
This is what netstat show after 10 minutes of connection.
TCP lt-0603:30606 www.007guard.com:2449 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2455 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2459 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2461 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2463 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2467 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2473 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2477 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2479 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2481 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2483 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2485 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2487 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2491 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2493 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2501 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2503 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2509 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2511 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2513 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2515 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2519 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2521 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2524 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2526 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2530 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2532 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2536 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2538 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2542 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2544 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2546 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2548 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2550 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2552 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2554 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2556 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2558 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2560 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2562 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2564 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2566 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2568 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2570 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2572 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2574 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2576 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2578 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2580 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2586 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2588 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2590 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2592 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2594 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2596 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2598 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2606 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2608 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2610 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2612 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2614 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2616 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2618 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2624 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2626 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2628 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2630 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2634 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2638 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2642 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2644 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2646 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2648 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2654 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2656 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2660 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2662 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2664 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2666 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2668 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2670 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2672 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2678 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2680 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2682 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2684 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2688 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2690 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2692 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2694 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2696 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2698 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2700 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2706 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2712 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2714 FIN_WAIT_2
TCP lt-0603:30606 www.007guard.com:2716 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2718 FIN_WAIT_2
TCP lt-0603:30606 www.007guard.com:2720 FIN_WAIT_2
TCP lt-0603:30606 www.007guard.com:2726 FIN_WAIT_2
TCP lt-0603:30606 www.007guard.com:2728 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2730 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2732 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2734 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2736 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2738 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2742 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2744 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2758 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2760 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2766 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2772 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2774 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2776 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2778 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2780 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2782 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2784 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2786 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2788 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2790 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2792 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2798 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2802 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2804 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2808 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2810 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2812 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2814 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2816 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2818 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2820 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2822 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2824 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2826 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2828 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2830 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2832 FIN_WAIT_2
TCP lt-0603:30606 www.007guard.com:2834 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2836 FIN_WAIT_2
TCP lt-0603:30606 www.007guard.com:2838 FIN_WAIT_2
TCP lt-0603:30606 www.007guard.com:2846 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2848 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2850 TIME_WAIT
TCP lt-0603:30606 www.007guard.com:2854 FIN_WAIT_2
TCP lt-0603:30606 www.007guard.com:2858 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2860 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2862 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2868 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2870 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2872 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2880 ESTABLISHED
TCP lt-0603:30606 www.007guard.com:2890 ESTABLISHED
TCP lt-0603:2268 72.32.153.177:http LAST_ACK
TCP lt-0603:2319 211-111-162-69.static.reverse.lstn.net:http CLO
SE_WAIT
TCP lt-0603:2328 .:http TIME_WAIT
TCP lt-0603:2330 199.59.241.250:http TIME_WAIT
TCP lt-0603:2334 68.169.92.55:http TIME_WAIT
TCP lt-0603:2342 ec2-50-19-109-125.compute-1.amazonaws.com:http
ESTABLISHED
TCP lt-0603:2344 ec2-107-20-156-112.compute-1.amazonaws.com:http
ESTABLISHED
TCP lt-0603:2346 .:http TIME_WAIT
TCP lt-0603:2350 pz-in-f95.1e100.net:http ESTABLISHED
TCP lt-0603:2354 nuq04s06-in-f13.1e100.net:http ESTABLISHED
TCP lt-0603:2356 nuq04s06-in-f13.1e100.net:http ESTABLISHED
TCP lt-0603:2358 www-da1.adobe.com:http ESTABLISHED
TCP lt-0603:2360 a23-3-68-107.deploy.akamaitechnologies.com:http
ESTABLISHED
TCP lt-0603:2366 .:http TIME_WAIT
TCP lt-0603:2368 199.59.241.250:http TIME_WAIT
TCP lt-0603:2376 a96-17-239-139.deploy.akamaitechnologies.com:htt
ps ESTABLISHED
TCP lt-0603:2378 www-11-05-prn1.facebook.com:https ESTABLISHED
TCP lt-0603:2410 208.81.191.113:http ESTABLISHED
TCP lt-0603:2428 a23-3-68-107.deploy.akamaitechnologies.com:http
ESTABLISHED
TCP lt-0603:2450 a23-3-68-114.deploy.akamaitechnologies.com:http
ESTABLISHED
TCP lt-0603:2460 74.114.28.200:http ESTABLISHED
TCP lt-0603:2462 nuq04s07-in-f27.1e100.net:http ESTABLISHED
TCP lt-0603:2464 www-11-05-prn1.facebook.com:http ESTABLISHED
TCP lt-0603:2478 nuq04s07-in-f27.1e100.net:http ESTABLISHED
TCP lt-0603:2480 208.81.191.113:http ESTABLISHED
TCP lt-0603:2482 nuq04s06-in-f27.1e100.net:http ESTABLISHED
TCP lt-0603:2484 nuq04s06-in-f27.1e100.net:http ESTABLISHED
TCP lt-0603:2486 a96-17-227-24.deploy.akamaitechnologies.com:http
ESTABLISHED
TCP lt-0603:2492 ec2-184-73-247-213.compute-1.amazonaws.com:http
ESTABLISHED
TCP lt-0603:2494 a23-3-68-136.deploy.akamaitechnologies.com:http
ESTABLISHED
TCP lt-0603:2496 .:http TIME_WAIT
TCP lt-0603:2498 parkwebwin-v02.prod.mesa1.secureserver.net:http
CLOSING
TCP lt-0603:2504 66.150.149.23:http ESTABLISHED
TCP lt-0603:2510 66.150.149.23:http ESTABLISHED
TCP lt-0603:2512 98.129.232.76:http ESTABLISHED
TCP lt-0603:2514 ec2-184-73-170-119.compute-1.amazonaws.com:http
ESTABLISHED
TCP lt-0603:2516 a23-3-68-136.deploy.akamaitechnologies.com:http
ESTABLISHED
TCP lt-0603:2539 a23-3-68-114.deploy.akamaitechnologies.com:http
ESTABLISHED
TCP lt-0603:2551 a23-3-68-112.deploy.akamaitechnologies.com:http
ESTABLISHED
TCP lt-0603:2553 a23-3-68-112.deploy.akamaitechnologies.com:http
ESTABLISHED
TCP lt-0603:2565 ec2-107-22-189-186.compute-1.amazonaws.com:http
ESTABLISHED
TCP lt-0603:2567 a23-3-68-123.deploy.akamaitechnologies.com:http
ESTABLISHED
TCP lt-0603:2569 a23-3-68-123.deploy.akamaitechnologies.com:http
ESTABLISHED
TCP lt-0603:2575 ec2-107-22-189-186.compute-1.amazonaws.com:http
ESTABLISHED
TCP lt-0603:2587 a23-3-68-145.deploy.akamaitechnologies.com:http
ESTABLISHED
TCP lt-0603:2591 74.200.209.252:http ESTABLISHED
TCP lt-0603:2599 a23-3-68-146.deploy.akamaitechnologies.com:http
ESTABLISHED
TCP lt-0603:2607 a23-3-68-113.deploy.akamaitechnologies.com:http
ESTABLISHED
TCP lt-0603:2627 a23-3-68-145.deploy.akamaitechnologies.com:http
ESTABLISHED
TCP lt-0603:2637 .:http TIME_WAIT
TCP lt-0603:2641 213.174.148.3:http TIME_WAIT
TCP lt-0603:2655 ec2-50-19-225-159.compute-1.amazonaws.com:http
ESTABLISHED
TCP lt-0603:2665 76.74.136.93:http ESTABLISHED
TCP lt-0603:2673 76.74.136.96:http ESTABLISHED
TCP lt-0603:2679 a23-3-68-99.deploy.akamaitechnologies.com:http
ESTABLISHED
TCP lt-0603:2681 a23-3-68-145.deploy.akamaitechnologies.com:http
ESTABLISHED
TCP lt-0603:2683 a23-3-68-145.deploy.akamaitechnologies.com:http
ESTABLISHED
TCP lt-0603:2685 a23-3-68-99.deploy.akamaitechnologies.com:http
ESTABLISHED
TCP lt-0603:2689 a23-3-68-99.deploy.akamaitechnologies.com:http
ESTABLISHED
TCP lt-0603:2693 a23-3-68-145.deploy.akamaitechnologies.com:http
ESTABLISHED
TCP lt-0603:2695 a23-3-68-99.deploy.akamaitechnologies.com:http
ESTABLISHED
TCP lt-0603:2697 a23-3-68-130.deploy.akamaitechnologies.com:http
ESTABLISHED
TCP lt-0603:2699 a23-3-68-130.deploy.akamaitechnologies.com:http
ESTABLISHED
TCP lt-0603:2707 a23-3-68-115.deploy.akamaitechnologies.com:http
ESTABLISHED
TCP lt-0603:2713 a23-3-12-202.deploy.akamaitechnologies.com:http
ESTABLISHED
TCP lt-0603:2715 64.210.61.140:http CLOSE_WAIT
TCP lt-0603:2717 mpr2.ngd.vip.bf1.yahoo.com:http ESTABLISHED
TCP lt-0603:2719 64.210.61.140:http CLOSE_WAIT
TCP lt-0603:2723 64.210.61.136:http CLOSE_WAIT
TCP lt-0603:2727 64.210.61.136:http CLOSE_WAIT
TCP lt-0603:2729 mpr2.ngd.vip.bf1.yahoo.com:http ESTABLISHED
TCP lt-0603:2731 ec2-174-129-203-211.compute-1.amazonaws.com:http
ESTABLISHED
TCP lt-0603:2735 js-pd03.revsci.net:http ESTABLISHED
TCP lt-0603:2737 a23-3-68-138.deploy.akamaitechnologies.com:http
ESTABLISHED
TCP lt-0603:2739 a23-3-68-145.deploy.akamaitechnologies.com:http
ESTABLISHED
TCP lt-0603:2741 208.71.125.1:http TIME_WAIT
TCP lt-0603:2759 cust-69.194.143.60.switchnap.com:http ESTABLISH
ED
TCP lt-0603:2761 cust-69.194.143.60.switchnap.com:http ESTABLISH
ED
TCP lt-0603:2769 208.71.125.1:http TIME_WAIT
TCP lt-0603:2779 ec2-174-129-203-211.compute-1.amazonaws.com:http
ESTABLISHED
TCP lt-0603:2787 crispwireless.net:http ESTABLISHED
TCP lt-0603:2801 .:http TIME_WAIT
TCP lt-0603:2807 213.174.148.3:http TIME_WAIT
TCP lt-0603:2815 74.217.78.140:http ESTABLISHED
TCP lt-0603:2825 74.217.78.140:http ESTABLISHED
TCP lt-0603:2827 crispwireless.net:http ESTABLISHED
TCP lt-0603:2829 93.184.216.169:http ESTABLISHED
TCP lt-0603:2831 93.184.216.169:http ESTABLISHED
TCP lt-0603:2833 72.21.91.19:http CLOSE_WAIT
TCP lt-0603:2837 66.45.56.124:http CLOSE_WAIT
TCP lt-0603:2839 66.45.56.124:http CLOSE_WAIT
TCP lt-0603:2849 138.108.6.20:http ESTABLISHED
TCP lt-0603:2855 www.meebo.com:http CLOSE_WAIT
TCP lt-0603:2859 93.184.216.119:http ESTABLISHED
TCP lt-0603:2861 93.184.216.119:http ESTABLISHED
TCP lt-0603:2863 93.184.216.119:http ESTABLISHED
TCP lt-0603:2869 93.184.216.119:http ESTABLISHED
TCP lt-0603:2871 93.184.216.119:http ESTABLISHED
TCP lt-0603:2873 93.184.216.119:http ESTABLISHED
TCP lt-0603:2881 a23-3-68-136.deploy.akamaitechnologies.com:http
ESTABLISHED
TCP lt-0603:2891 216-18-215-4.hosted.static.webnx.com:http ESTAB
LISHED
C:\Documents and Settings\tfarrell.LT-0603>
-
I believe your host file is missing a line. Those 007guard entries happen to be the first ones in Spybots host file. You can ignore it for now, we will come back to it. If you disable the feature in Spybot then you shoudnt see them.
You said you killed ping.exe in task manager, does it return on reboot? Is a updated malwarebytes coming up clean after a scan. Is your ESET AV up to date?
We will get download to use, its called combofix. There is a guide to read first, read through the guide then apply the directions on your own machine. Post the combofix log.
Guide to using Combofix
-
Ping.exe
When I kill Ping.exe in taskMgr it comes back within 2 to 3 minutes. I will download combofix and send you the log. ESET does not prevent the ping.exe relaunching.
-
Ping.exe
Hi shelf life,
I ran combo fix and it created the txt file. However now I cannot attach to the Internet. My wifi shows it is connected but the stats show that no data is transmitting. Ipconfig will not run. I connected by cable to my router same result. In both normal and safe mode same result. My wireless connection status shows no data for address type, ip address , subnet mask and default gateway.
Help!!!
-
Ping.exe
-
Have you rebooted both the computer and router?
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules