WiredWX Hobby Weather ToolsLog in

 


Browser runnng slow; Crashing

2 posters

descriptionBrowser runnng slow; Crashing - Page 2 EmptyRe: Browser runnng slow; Crashing

more_horiz
Thanks for the quick answer!

Cheetah Anti-Rogue v1.0.14
by DragonMaster Jay

Microsoft Windows XP [Version 5.1.2600]
Sun 01/03/2010 2:40:07.28


-- Known infection --

c:\windows\system32\drivers\fidbox.dat (Rtk.ParetoLogic)


If objects found, full virus scan or anti-malware scan necessary


EOF

descriptionBrowser runnng slow; Crashing - Page 2 EmptyRe: Browser runnng slow; Crashing

more_horiz
F/P in that log. Fixt. Big Grin

Please run a free online scan with the ESET Online Scanner
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic

descriptionBrowser runnng slow; Crashing - Page 2 EmptyRe: Browser runnng slow; Crashing

more_horiz
ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=e506dbd81783e5469a25aeef0946a375
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2010-01-04 09:40:41
# local_time=2010-01-04 01:40:41 (-0800, Pacific Standard Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=768 16777215 100 0 12906199 12906199 0 0
# compatibility_mode=5121 16776533 100 96 2991257 15426901 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=124255
# found=7
# cleaned=7
# scan_time=4267
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Data\TFR5.tmp Win32/Qhost trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Data\TFR8.tmp Win32/Qhost trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Data\TFRE.tmp Win32/Qhost trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\HelpAssistant\Local Settings\temp\44B.tmp a variant of Win32/Mebroot.DC trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\HelpAssistant\Local Settings\temp\44C.tmp a variant of Win32/Mebroot.DC trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\HelpAssistant\Local Settings\temp\44F.tmp a variant of Win32/Mebroot.DC trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\HelpAssistant\Local Settings\temp\tTwh.exe a variant of Win32/TrojanDownloader.Mebload.U trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

descriptionBrowser runnng slow; Crashing - Page 2 EmptyRe: Browser runnng slow; Crashing

more_horiz
Please download Stealth MBR Rootkit Detector by GMER from GMER.net, and save to your Desktop.
  • Double-click mbr.exe to start the program.
  • When done scanning, it will save a log on the Desktop called mbr.log.
  • Please post the contents of that log in your next reply.

descriptionBrowser runnng slow; Crashing - Page 2 EmptyRe: Browser runnng slow; Crashing

more_horiz
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
copy of MBR has been found in sector 0x0FFFAC44
malicious code @ sector 0x0FFFAC47 !
PE file found in sector at 0x0FFFAC5D !

descriptionBrowser runnng slow; Crashing - Page 2 EmptyRe: Browser runnng slow; Crashing

more_horiz
Please open Command Prompt (Start > Run and type CMD and press OK [Vista/7: Start search: CMD and press enter])
Enter the following in to the black box, pressing enter after each line:

Code:

cd desktop

mbr.exe -f

exit


Post a log (MBR.log).

descriptionBrowser runnng slow; Crashing - Page 2 EmptyRe: Browser runnng slow; Crashing

more_horiz
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
copy of MBR has been found in sector 0x0FFFAC44
malicious code @ sector 0x0FFFAC47 !
PE file found in sector at 0x0FFFAC5D !

descriptionBrowser runnng slow; Crashing - Page 2 EmptyRe: Browser runnng slow; Crashing

more_horiz
Please download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<--- ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.

  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked ... leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.

Post the contents of GMER.txt in your next reply.

descriptionBrowser runnng slow; Crashing - Page 2 EmptyRe: Browser runnng slow; Crashing

more_horiz
I didn't get asked for a scan, but my computer did restart once the program was started and after I saved the log. Is that all right?

MER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-01-05 03:18:09
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\pwtiykoc.sys


---- System - GMER 1.0.15 ----

Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xF56C978A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateKey [0xF56C9821]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xF56C9738]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xF56C974C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xF56C9835]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xF56C9861]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateKey [0xF56C98CF]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateValueKey [0xF56C98B9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xF56C97CA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xF56C98FB]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenKey [0xF56C980D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xF56C9710]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xF56C9724]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xF56C979E]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryKey [0xF56C9937]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xF56C98A3]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryValueKey [0xF56C988D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xF56C984B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xF56C9923]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xF56C990F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xF56C9776]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xF56C9762]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetValueKey [0xF56C9877]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xF56C97F9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xF56C98E5]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xF56C97E0]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xF56C97B4]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)

---- EOF - GMER 1.0.15 ----

descriptionBrowser runnng slow; Crashing - Page 2 EmptyRe: Browser runnng slow; Crashing

more_horiz
Please download the Kaspersky AVP Tool from Kaspersky-labs.com.
  • Save it to your desktop.
  • Please reboot to Safe Mode (tap the F8 key just before Windows starts to load and select the Safe Mode option from the menu).
  • Double click the setup file to run it.
  • Click Next to continue.
  • It will by default install it to your desktop folder.Click Next.
  • Hit ok at the prompt for scanning in Safe Mode.
  • It will then open a box There will be a tab that says Automatic scan.
  • Under Automatic scan make sure these are checked:

    • System Memory
    • Startup Objects
    • Disk Boot Sectors.
    • My Computer.
    • Also any other drives (Removable that you may have)

After that click on Security level then choose Customize then click on the tab that says Heuristic Analyzer then choose Enable Deep rootkit search then choose ok.
Then choose OK again then you are back to the main screen.

  • Then click on Scan at the to right hand Corner.
  • It will automatically Neutralize any objects found.
  • If some objects are left un-neutralized then click the button that says Neutralize all
  • If it says it cannot be Neutralized then chooose The delete option when prompted.
  • After that is done click on the reports button at the bottom and save it to file name it Kas.
  • Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.
Note: This tool will self uninstall when you close it so please save the log before closing it.

descriptionBrowser runnng slow; Crashing - Page 2 EmptyRe: Browser runnng slow; Crashing

more_horiz
Autoscan: completed 2 minutes ago (events: 152, objects: 586311, time: 13:23:52)
1/7/2010 1:03:50 AM Task started
1/7/2010 1:18:08 AM Detected: Trojan.Win32.FraudPack.rdo C:\Documents and Settings\HelpAssistant\Desktop\backups\backup-20100102-032005-692
1/7/2010 1:18:08 AM Untreated: Trojan.Win32.FraudPack.rdo C:\Documents and Settings\HelpAssistant\Desktop\backups\backup-20100102-032005-692 Postponed
1/7/2010 1:19:57 AM Detected: Packed.Win32.Krap.ai C:\Documents and Settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\51I205GF\install[2].exe
1/7/2010 1:19:57 AM Untreated: Packed.Win32.Krap.ai C:\Documents and Settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\51I205GF\install[2].exe Postponed
1/7/2010 1:20:04 AM Detected: Trojan.Win32.FraudPack.aeft C:\Documents and Settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\AYTZA7C9\install[2].exe
1/7/2010 1:20:04 AM Untreated: Trojan.Win32.FraudPack.aeft C:\Documents and Settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\AYTZA7C9\install[2].exe Postponed
1/7/2010 1:20:54 AM Detected: Packed.Win32.Krap.ai C:\Documents and Settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\ZDHWPBFH\install[3].exe
1/7/2010 1:20:54 AM Untreated: Packed.Win32.Krap.ai C:\Documents and Settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\ZDHWPBFH\install[3].exe Postponed
1/7/2010 1:33:23 AM Detected: Trojan.Win32.FraudPack.rdo C:\Documents and Settings\Owner\Desktop\backups\backup-20100102-032005-692
1/7/2010 1:33:23 AM Untreated: Trojan.Win32.FraudPack.rdo C:\Documents and Settings\Owner\Desktop\backups\backup-20100102-032005-692 Postponed
1/7/2010 1:41:44 AM Detected: HEUR:Trojan.Script.Iframer C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\FS11V3UZ\search[4].htm
1/7/2010 1:41:44 AM Untreated: HEUR:Trojan.Script.Iframer C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\FS11V3UZ\search[4].htm Postponed
1/7/2010 1:44:17 AM Detected: HEUR:Trojan.Script.Iframer C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\OC15LWMT\comicprofile[1].htm
1/7/2010 1:44:17 AM Untreated: HEUR:Trojan.Script.Iframer C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\OC15LWMT\comicprofile[1].htm Postponed
1/7/2010 3:12:46 AM Detected: Trojan.Win32.Vilsel.pom C:\Qoobox\Quarantine\C\WINDOWS\system32\xa.tmp.vir/PE_Patch.Molebox/Molebox
1/7/2010 3:12:46 AM Untreated: Trojan.Win32.Vilsel.pom C:\Qoobox\Quarantine\C\WINDOWS\system32\xa.tmp.vir/PE_Patch.Molebox/Molebox Postponed
1/7/2010 3:30:55 AM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008562.exe
1/7/2010 3:30:55 AM Untreated: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008562.exe Postponed
1/7/2010 3:30:55 AM Detected: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008568.exe
1/7/2010 3:30:55 AM Untreated: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008568.exe Postponed
1/7/2010 3:30:56 AM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008598.exe
1/7/2010 3:30:56 AM Untreated: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008598.exe Postponed
1/7/2010 3:31:20 AM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008839.exe
1/7/2010 3:31:20 AM Untreated: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008839.exe Postponed
1/7/2010 3:31:20 AM Detected: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008842.exe
1/7/2010 3:31:20 AM Untreated: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008842.exe Postponed
1/7/2010 3:31:21 AM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008864.exe
1/7/2010 3:31:21 AM Untreated: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008864.exe Postponed
1/7/2010 4:58:06 AM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010272.exe
1/7/2010 4:58:06 AM Untreated: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010272.exe Postponed
1/7/2010 4:58:06 AM Detected: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010275.exe
1/7/2010 4:58:06 AM Untreated: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010275.exe Postponed
1/7/2010 4:58:07 AM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010301.exe
1/7/2010 4:58:07 AM Untreated: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010301.exe Postponed
1/7/2010 4:58:28 AM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010867.exe
1/7/2010 4:58:28 AM Untreated: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010867.exe Postponed
1/7/2010 4:58:29 AM Detected: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010871.exe
1/7/2010 4:58:29 AM Untreated: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010871.exe Postponed
1/7/2010 4:58:29 AM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010898.exe
1/7/2010 4:58:29 AM Untreated: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010898.exe Postponed
1/7/2010 4:58:48 AM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0011453.exe
1/7/2010 4:58:48 AM Untreated: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0011453.exe Postponed
1/7/2010 4:58:48 AM Detected: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0011456.exe
1/7/2010 4:58:48 AM Untreated: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0011456.exe Postponed
1/7/2010 4:58:55 AM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0012454.exe
1/7/2010 4:58:55 AM Untreated: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0012454.exe Postponed
1/7/2010 4:58:55 AM Detected: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0012457.exe
1/7/2010 4:58:55 AM Untreated: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0012457.exe Postponed
1/7/2010 4:58:55 AM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0012479.exe
1/7/2010 4:58:55 AM Untreated: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0012479.exe Postponed
1/7/2010 6:12:16 AM Detected: Trojan.Win32.FraudPack.rdo C:\Documents and Settings\HelpAssistant\Desktop\backups\backup-20100102-032005-692
1/7/2010 6:12:16 AM Untreated: Trojan.Win32.FraudPack.rdo C:\Documents and Settings\HelpAssistant\Desktop\backups\backup-20100102-032005-692 Postponed
1/7/2010 6:14:08 AM Detected: Packed.Win32.Krap.ai C:\Documents and Settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\51I205GF\install[2].exe
1/7/2010 6:14:08 AM Untreated: Packed.Win32.Krap.ai C:\Documents and Settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\51I205GF\install[2].exe Postponed
1/7/2010 6:14:15 AM Detected: Trojan.Win32.FraudPack.aeft C:\Documents and Settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\AYTZA7C9\install[2].exe
1/7/2010 6:14:15 AM Untreated: Trojan.Win32.FraudPack.aeft C:\Documents and Settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\AYTZA7C9\install[2].exe Postponed
1/7/2010 6:15:05 AM Detected: Packed.Win32.Krap.ai C:\Documents and Settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\ZDHWPBFH\install[3].exe
1/7/2010 6:15:05 AM Untreated: Packed.Win32.Krap.ai C:\Documents and Settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\ZDHWPBFH\install[3].exe Postponed
1/7/2010 6:23:13 AM Detected: Trojan.Win32.FraudPack.rdo C:\Documents and Settings\Owner\Desktop\backups\backup-20100102-032005-692
1/7/2010 6:23:13 AM Untreated: Trojan.Win32.FraudPack.rdo C:\Documents and Settings\Owner\Desktop\backups\backup-20100102-032005-692 Postponed
1/7/2010 6:32:31 AM Detected: HEUR:Trojan.Script.Iframer C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\FS11V3UZ\search[4].htm
1/7/2010 6:32:31 AM Untreated: HEUR:Trojan.Script.Iframer C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\FS11V3UZ\search[4].htm Postponed
1/7/2010 6:35:16 AM Detected: HEUR:Trojan.Script.Iframer C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\OC15LWMT\comicprofile[1].htm
1/7/2010 6:35:16 AM Untreated: HEUR:Trojan.Script.Iframer C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\OC15LWMT\comicprofile[1].htm Postponed
1/7/2010 7:43:23 AM Detected: Trojan.Win32.Vilsel.pom C:\Qoobox\Quarantine\C\WINDOWS\system32\xa.tmp.vir/PE_Patch.Molebox/Molebox
1/7/2010 7:43:23 AM Untreated: Trojan.Win32.Vilsel.pom C:\Qoobox\Quarantine\C\WINDOWS\system32\xa.tmp.vir/PE_Patch.Molebox/Molebox Postponed
1/7/2010 7:54:13 AM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008562.exe
1/7/2010 7:54:13 AM Untreated: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008562.exe Postponed
1/7/2010 7:54:14 AM Detected: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008568.exe
1/7/2010 7:54:14 AM Untreated: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008568.exe Postponed
1/7/2010 7:54:15 AM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008598.exe
1/7/2010 7:54:15 AM Untreated: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008598.exe Postponed
1/7/2010 7:54:29 AM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008839.exe
1/7/2010 7:54:29 AM Untreated: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008839.exe Postponed
1/7/2010 7:54:29 AM Detected: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008842.exe
1/7/2010 7:54:29 AM Untreated: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008842.exe Postponed
1/7/2010 7:54:30 AM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008864.exe
1/7/2010 7:54:30 AM Untreated: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008864.exe Postponed
1/7/2010 7:55:56 AM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010272.exe
1/7/2010 7:55:56 AM Untreated: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010272.exe Postponed
1/7/2010 7:55:56 AM Detected: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010275.exe
1/7/2010 7:55:56 AM Untreated: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010275.exe Postponed
1/7/2010 7:55:57 AM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010301.exe
1/7/2010 7:55:57 AM Untreated: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010301.exe Postponed
1/7/2010 7:56:07 AM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010867.exe
1/7/2010 7:56:07 AM Untreated: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010867.exe Postponed
1/7/2010 7:56:07 AM Detected: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010871.exe
1/7/2010 7:56:07 AM Untreated: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010871.exe Postponed
1/7/2010 7:56:08 AM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010898.exe
1/7/2010 7:56:08 AM Untreated: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010898.exe Postponed
1/7/2010 7:56:18 AM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0011453.exe
1/7/2010 7:56:18 AM Untreated: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0011453.exe Postponed
1/7/2010 7:56:18 AM Detected: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0011456.exe
1/7/2010 7:56:18 AM Untreated: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0011456.exe Postponed
1/7/2010 7:56:22 AM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0012454.exe
1/7/2010 7:56:22 AM Untreated: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0012454.exe Postponed
1/7/2010 7:56:22 AM Detected: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0012457.exe
1/7/2010 7:56:22 AM Untreated: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0012457.exe Postponed
1/7/2010 7:56:22 AM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0012479.exe
1/7/2010 7:56:22 AM Untreated: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0012479.exe Postponed
1/7/2010 9:12:28 AM Detected: Trojan.Win32.FraudPack.rdo C:\Documents and Settings\HelpAssistant\Desktop\backups\backup-20100102-032005-692

1/7/2010 2:27:02 PM Detected: Packed.Win32.Krap.ai C:\Documents and Settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\51I205GF\install[2].exe

1/7/2010 2:27:10 PM Detected: Trojan.Win32.FraudPack.aeft C:\Documents and Settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\AYTZA7C9\install[2].exe

1/7/2010 2:27:12 PM Detected: Packed.Win32.Krap.ai C:\Documents and Settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\ZDHWPBFH\install[3].exe

1/7/2010 2:27:13 PM Detected: Trojan.Win32.FraudPack.rdo C:\Documents and Settings\Owner\Desktop\backups\backup-20100102-032005-692

1/7/2010 2:27:16 PM Detected: HEUR:Trojan.Script.Iframer C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\FS11V3UZ\search[4].htm

1/7/2010 2:27:19 PM Detected: HEUR:Trojan.Script.Iframer C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\OC15LWMT\comicprofile[1].htm

1/7/2010 2:27:23 PM Detected: Trojan.Win32.Vilsel.pom C:\Qoobox\Quarantine\C\WINDOWS\system32\xa.tmp.vir/PE_Patch.Molebox/Molebox

1/7/2010 2:27:26 PM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008562.exe

1/7/2010 2:27:29 PM Detected: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008568.exe

1/7/2010 2:27:31 PM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008598.exe

1/7/2010 2:27:32 PM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008839.exe

1/7/2010 2:27:35 PM Detected: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008842.exe

1/7/2010 2:27:36 PM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP8\A0008864.exe

1/7/2010 2:27:36 PM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010272.exe

1/7/2010 2:27:37 PM Detected: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010275.exe

1/7/2010 2:27:37 PM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010301.exe

1/7/2010 2:27:38 PM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010867.exe

1/7/2010 2:27:38 PM Detected: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010871.exe

1/7/2010 2:27:39 PM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0010898.exe

1/7/2010 2:27:40 PM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0011453.exe

1/7/2010 2:27:40 PM Detected: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0011456.exe

1/7/2010 2:27:41 PM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0012454.exe

1/7/2010 2:27:41 PM Detected: Trojan.Win32.FraudPack.aeft C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0012457.exe

1/7/2010 2:27:42 PM Detected: Packed.Win32.Krap.ai C:\System Volume Information\_restore{97065245-9E7F-4B0E-90CB-FD64272D7E1C}\RP9\A0012479.exe

1/7/2010 2:27:42 PM Task completed

descriptionBrowser runnng slow; Crashing - Page 2 EmptyRe: Browser runnng slow; Crashing

more_horiz
Please download the OTM.exe by OldTimer.

  • Save it to your Desktop.
  • Please double-click OTM.exe to run it.
  • Copy the commands with file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):


    C:\Documents and Settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\AYTZA7C9
    C:\Documents and Settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\ZDHWPBFH
    C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\FS11V3UZ
    C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\OC15LWMT


  • Return to OTM.exe, right click in the "Paste Instructions for Items to be Moved" window (under the light yellow bar) and choose Paste.

  • Click the red Moveit! button.
  • A fix log in Notepad will appear. Copy the contents of the fix log to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM.exe

If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

==

Please download TFC by OldTimer to your desktop
  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start
    button to begin the process. Depending on how often you clean temp
    files, execution time should be anywhere from a few seconds to a minute
    or two. Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.


==

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall

Browser runnng slow; Crashing - Page 2 Combofix_uninstall_image

(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.


==

Please post the OTM log in your next reply.

descriptionBrowser runnng slow; Crashing - Page 2 EmptyRe: Browser runnng slow; Crashing

more_horiz
I did what you said to do in the first half but after I clicked Moveit! I got this log with no question of rebooting. Do I do the rest of what you say or is something else wrong?

Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!

OTM by OldTimer - Version 3.1.4.0 log created on 01082010_022413

descriptionBrowser runnng slow; Crashing - Page 2 EmptyRe: Browser runnng slow; Crashing

more_horiz
We'll try a different method.

Please download ATF Cleaner by Atribune.

    Double-click ATF-Cleaner.exe to run the program.
    Under Main choose: Select All
    Click the Empty Selected button.
If you use Firefox browser
    Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, click No at the prompt.
If you use Opera browser
    Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, click No at the prompt.
Click Exit on the Main menu to close the program.

==

Now to get you off to a good start we will clean your restore points so that all the bad stuff is gone for good. Then if you need to restore at some stage you will be clean. There are several ways to reset your restore points, but this is my method:
  • Select Start > All Programs > Accessories > System tools > System Restore.
  • On the dialogue box that appears select Create a Restore Point
  • Click NEXT
  • Enter a name e.g. Clean
  • Click CREATE

You now have a clean restore point, to get rid of the bad ones:
  • Select Start > All Programs > Accessories > System tools > Disk Cleanup.
  • In the Drop down box that appears select your main drive e.g. C
  • Click OK
  • The System will do some calculation and the display a dialogue box with TABS
  • Select the More Options Tab.
  • At the bottom will be a system restore box with a CLEANUP button click this
  • Accept the Warning and select OK again, the program will close and you are done


==

Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

descriptionBrowser runnng slow; Crashing - Page 2 EmptyRe: Browser runnng slow; Crashing

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum