Results 1 to 14 of 14

Thread: Ping.exe virus can not be deleted

  1. #1
    YWD67's Avatar

    YOUR WATCH DOG 67

    Join Date
    Jan 2004
    Location
    Lost in time and space
    Posts
    3,330

    Ping.exe virus can not be deleted

    Last week I was looking at a video from Comedy Central. I had a virus that slammed through two security programs like a knife through hot butter. It disabled a shit load of window programs. It made my desk top invisible, redirected me to some shit site, and downloaded all kings of phonie Windows security Internet Security programs.

    It took four different virus programs to delete the crap security virus programs, (Spybot, Superantispyware, Norton, and Kaspersky).
    Even with that, there is a fucking program/reg/whatever that will not leave, or cleared out.

    When IE, Firefox, or any other program that accesses the net is used the virus comes back via the Ping.exe. All the above anti virus programs have as yet discovered what the hell keeps allowing this shit thing to activate.

    I have discovered one thing that may help someone with finding how to kill this cocksucker program.

    It seems to ride on the Scvhost program that deals with audio programs. I have found that when the Ping.exe shows up and killing it with the Taskmanger, it does nothing but delay it's return in about 75 seconds.
    If however you kill the scvhost that it rides on it does not return unless a program that requires an audio is used.

    If I turn my net ability off the ping still tries to access the net for about 45 seconds then stops. It tries again about every 75 seconds.
    Once it gets a net connection but there is no active use of the net, the damn program runs the computer useage to 100% and slows my system to a crawl.
    I am running XP Family Securtiy 3.

    This shit hole virus seems to be a big problem with many sites. I have all my virus programs up to date as of the 18.

    Thanks for any help.
    Last edited by YWD67; December 19th, 2011 at 11:34 AM.

  2. #2
    RACKnRAIL's Avatar

    今は知っているでしょ

    Join Date
    Apr 2003
    Location
    an island in the pacific
    Posts
    6,540
    Have you tried removing it from safemode?

    I've found combofix pretty good at removing tough viruses.

    http://majorgeeks.com/Combofix_d6402.html
    Last edited by RACKnRAIL; December 19th, 2011 at 11:44 AM. Reason: wording
    -----------®N®----------


    あなたをファック

  3. #3
    YWD67's Avatar

    YOUR WATCH DOG 67

    Join Date
    Jan 2004
    Location
    Lost in time and space
    Posts
    3,330
    Oh yeah! When I try to look for solving the prodgram on the net and using any wording of Ping.exe I get a fucking redirect as well.

    Will try the Conf program that you have suggested. I will get back with you hopefully soon.

  4. #4
    drtoker's Avatar

    Zeropaid VIP

    Join Date
    Feb 2007
    Posts
    1,296
    I use Hijackthis to identify all things that startup with the OS. The other handy thing, it will show you what loads when IE is started: toolbars, add ins, search redirects, any could contain the virus that keeps coming back. Of course this is more of a manual process, as the program doesn't identify only malicious items, so you kind of have to know what doesn't belong and tell the program to remove it.

    +1 for combofix, it has saved my butt before. I just hate that you can't really control it, just run it, and it does its thing.
    Join the Ron Paul Revolution
    Ron Paul 2012

  5. #5
    YWD67's Avatar

    YOUR WATCH DOG 67

    Join Date
    Jan 2004
    Location
    Lost in time and space
    Posts
    3,330
    Fuck an "A" Yes!! It took two runs of Combofix to do it. I used Hijackthis for sometime and the shit thing was so far into my system that it could not bring it out.

    It took me several days just to find away to access our site with out being redirectd to some shit site about food. I could do a net search for anything that did not contain the words Ping.
    Once I did all hell would break loose. Everytime the Ping.exe came on when I was hooked to the net it would download four to five different shit phonie Widnows Securtiy system alerts.

    Rack you now have the use of my wife and two sons, (plus one Pug and one Tabby cat) for any use that you wish.

    PM me for details for delivery. Offer is void in North America, South America and any nation ending in a vowel or consonant. (God damn US governemnt)

  6. #6
    mountain_rage's Avatar

    Zeropaids nipple

    Join Date
    Mar 2004
    Location
    purgatory
    Posts
    7,069
    Look up hirens boot disc on a torrent site and keep a copy handy at all times. If you get the right one it will come with a live linux, live mini windows xp, and every app you can possibly imagine needing to fix problems on your computer. Combo fix, Hijack this, Partition Magic, Acronis, Ghost, Kapersky, Malware bytes, spybot, etc.
    Last edited by mountain_rage; December 19th, 2011 at 04:40 PM.
    Anyone upset or offended by my post please follow the link and let your opinions be known.
    http://www.zeropaid.com/bbs/showthread.php?t=55492

  7. #7
    RACKnRAIL's Avatar

    今は知っているでしょ

    Join Date
    Apr 2003
    Location
    an island in the pacific
    Posts
    6,540
    Combofix has saved me a few times. Glad I could help.
    -----------®N®----------


    あなたをファック

  8. #8
    w31n3r's Avatar

    Stop 0x0000007B

    Join Date
    Sep 2007
    Location
    Huh?
    Posts
    1,345
    Quote Originally Posted by mountain_rage View Post
    If you get the right one it will come with a live linux, live mini windows xp, and every app you can possibly imagine needing to fix problems on your computer. Combo fix, Hijack this, Partition Magic, Acronis, Ghost, Kapersky, Malware bytes, spybot, etc.
    ...such as the miniPE 2010 ver by PlaNeD, you can get it off TPB. it's the geeks ultimate fixit toolbox.

    and yeah, combofix FTW

  9. #9

    Zeropaid Noob

    Join Date
    Dec 2011
    Posts
    1

    Ping.exe virus

    I have the ping.exe virus on my laptop. I have tried everything that I could think of to remove it. Thank you so much for the information on Combofix. I am going to give that a try.
    I found that to some extent I can avoid the redirects by right-clicking on the link I want to go to and selecting "Open in new tab". I don't know why that worked, but it did.

  10. #10
    YWD67's Avatar

    YOUR WATCH DOG 67

    Join Date
    Jan 2004
    Location
    Lost in time and space
    Posts
    3,330
    Quote Originally Posted by sistoy View Post
    I have the ping.exe virus on my laptop. I have tried everything that I could think of to remove it. Thank you so much for the information on Combofix. I am going to give that a try.
    I found that to some extent I can avoid the redirects by right-clicking on the link I want to go to and selecting "Open in new tab". I don't know why that worked, but it did.
    Please get back to us and let us know how it turned out. Since November this is one of the biggest and hardest to kill pieces of shit to hit the net for home systems in awhile.
    Last edited by YWD67; December 22nd, 2011 at 10:25 AM.

  11. #11
    YWD67's Avatar

    YOUR WATCH DOG 67

    Join Date
    Jan 2004
    Location
    Lost in time and space
    Posts
    3,330
    Quote Originally Posted by mountain_rage View Post
    Look up hirens boot disc on a torrent site and keep a copy handy at all times. If you get the right one it will come with a live linux, live mini windows xp, and every app you can possibly imagine needing to fix problems on your computer. Combo fix, Hijack this, Partition Magic, Acronis, Ghost, Kapersky, Malware bytes, spybot, etc.
    Thanks MR I did just that and saved it to a disk and my desktop hardrive as well. You were not shitting about it having eveything one would need to restore most problems.

  12. #12
    Krell's Avatar

    worthless dirtball

    Join Date
    Sep 2002
    Posts
    9,759
    I just now saw this, sorry for your frustrations.

    1) no matter what happens like this to someones PC, they should install Spybot and Spyware Blaster and use the HOST files that come with them immediately. Be sure to IMMUNIZE in both programs!!
    2) The Digiwiz Rescue CD is an all time favorite and the antivirus softwares there can be ran against EVERY drive and partition at once, so you can run 15 copies at once to tackle the virus if that's what it takes.
    3) There are any number of FREE antivirus sites that you can visit and do a complete scan online. This only requires a small browser install that can be removed later if you want.
    4) there are a number of registry fix programs that will also help clean up a registry that is tainted with malware entries, such as RegVac, or the "Windows 7 Manager > Cleaner > Registry Cleaner" which I find very effective.

    Have a peek at this > http://www.spywareremovalhelp.org/vi...ws-32-bit.html


    Good luck and Happy Holidays.

  13. #13
    Greylin's Avatar

    Well Ladifrickenda

    Join Date
    Dec 2002
    Location
    In a Van Down by the River
    Posts
    455
    I've had really good luck with Malwarebytes on lots of PC'sthat have been infected.

  14. #14

    ZeroPaid Regular

    Join Date
    Dec 2010
    Location
    Shelf
    Posts
    41
    Im paranoid enough to reinstall if I would get a virus. Good to always keep backups of important files. Being prepared to reinstall the system any day if needed and keeping daily backups makes it easier to cope with it when something happens.
    It sounds like a lot of work but its worth it in the longrun and can be automated with programs like cobian backup and similar. Defenitely better to do a clean reinstall then trying to clean up an infected system in my opinion.

Similar Threads

  1. questions about the TCP/IP and PING...
    By ltev2006 in forum General Computing
    Replies: 1
    Last Post: April 19th, 2007, 07:17 AM
  2. Cannot get Active mode working behind router (cannot ping)?
    By immcinto in forum Networks / Clients
    Replies: 1
    Last Post: February 9th, 2003, 01:08 PM
  3. Ping command and user's IP addresses
    By Lurka in forum Networks / Clients
    Replies: 2
    Last Post: September 28th, 2002, 02:21 PM
  4. Gnutella Protocol Ping and Pong
    By Power Penguin in forum Gnutella
    Replies: 5
    Last Post: August 24th, 2002, 06:52 PM
  5. Gnutella Protocol Ping and Pong
    By Will Rae in forum Gnutella
    Replies: 3
    Last Post: August 24th, 2002, 05:48 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •