This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Sysem freezing and going slower [Solved]

46 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I had the Ask & Record bar installed in Firefox and as you will see in the reports it was uninstalled

The ASK toolbar comes bundled with many third-party applications, is considered as Spyware and also comes with vulnerabilities. We usually recommend uninstalling it.

See the following links and decide yourself whether or not you want to useit.:

http://secunia.com/advisories/product/15810/
http://www.benedelman.org/spyware/ask-toolbars/

A quick Google search showed Cam Studio and Replay A/V are two alternatives to the Ask & Record Toolbar.

=================================

The AdwCleaner was closed as we lost the power in the middle

Why did you lose power?

=================================

Don’t worry about the Hosts file: when we clean up I’ll give you a suggestion regarding that.

Please can you run Rogue Killer- again.

Thanks

Satchfan
Hi Satchfan,
Thanks for the information about Ask bar, I didnt know that and after reading about it I won't go back to it, believe it or not its the only component of that kind (user bar or browser bundled tool) that I downloaded and installed on purpose, not with another installer as they use to come. Thanks for suggesting those tools too, I will install them once we are finished cleaning the machine.

The issue with the power was not local but in the whole area, and just for a short while, due to inclemency of the weather I think, I managed to shut down the computer before the remaining battery was totally empty, so I think maybe in that short time it managed to save the report, or perhaps it goes saving the report step by step I don't know.

I'm sorry I couldn't pass the RogueKiller scan yesterday, additionally I'm sorry it still says the machine is infected with Zero Access, I hope its not my fault as I think I have followed your guidelines so far. Here is the RogueKiller report RKreport[1]_S_11302012_02d1242:


RogueKiller V8.3.1 [Nov 26 2012] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows Vista (6.0.6000 ) 32 bits version
Started in : Normal mode
User : ASD-MASTER [Admin rights]
Mode : Scan – Date : 11/30/2012 12:42:09

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 5 ¤¤¤
[DNS] HKLM\[…]\ControlSet001\Services\Interfaces\{27E38242-552E-4801-8271-45AAE17EF99A} : NameServer (80.58.0.33,80.58.32.97) -> FOUND
[DNS] HKLM\[…]\ControlSet002\Services\Interfaces\{27E38242-552E-4801-8271-45AAE17EF99A} : NameServer (80.58.0.33,80.58.32.97) -> FOUND
[HJPOL] HKLM\[…]\System : DisableRegistryTools (0) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤
[ZeroAccess][FOLDER] U : C:\Windows\Installer\{f86398d5-3776-50de-51d3-06856123e733}\U –> FOUND
[ZeroAccess][FOLDER] L : C:\Windows\Installer\{f86398d5-3776-50de-51d3-06856123e733}\L –> FOUND

¤¤¤ Driver : [LOADED] ¤¤¤
IRP[IRP_MJ_CREATE] : \SystemRoot\system32\drivers\atapi.sys -> HOOKED ([MAJOR] Unknown @ 0x844591E8)
IRP[IRP_MJ_CLOSE] : \SystemRoot\system32\drivers\atapi.sys -> HOOKED ([MAJOR] Unknown @ 0x844591E8)
IRP[IRP_MJ_DEVICE_CONTROL] : \SystemRoot\system32\drivers\atapi.sys -> HOOKED ([MAJOR] Unknown @ 0x844591E8)
IRP[IRP_MJ_INTERNAL_DEVICE_CONTROL] : \SystemRoot\system32\drivers\atapi.sys -> HOOKED ([MAJOR] Unknown @ 0x844591E8)
IRP[IRP_MJ_POWER] : \SystemRoot\system32\drivers\atapi.sys -> HOOKED ([MAJOR] Unknown @ 0x844591E8)
IRP[IRP_MJ_SYSTEM_CONTROL] : \SystemRoot\system32\drivers\atapi.sys -> HOOKED ([MAJOR] Unknown @ 0x844591E8)
IRP[IRP_MJ_PNP] : \SystemRoot\system32\drivers\atapi.sys -> HOOKED ([MAJOR] Unknown @ 0x844591E8)

¤¤¤ Infection : ZeroAccess ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
–> C:\Windows\system32\drivers\etc\hosts

127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: FUJITSU MHY2200BH +++++
— User —
[MBR] b2d1d15aad92be8c7cec7741dd72ada3
[BSP] d87ab92584a1f67fd1a237ac11c00965 : Windows Vista MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 7543 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 15450112 | Size: 183237 Mo
User = LL1 … OK!
User = LL2 … OK!

+++++ PhysicalDrive3: WD Elements 1042 USB Device +++++
— User —
[MBR] ac87b68b8cb1cd72451ffbc8641912b7
[BSP] 21e3b9b7bc966cef2269498d52778a62 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 953866 Mo
User = LL1 … OK!
Error reading LL2 MBR!

+++++ PhysicalDrive4: LG External HDD USB Device +++++
— User —
[MBR] a0f440ce8ac6ca8ea791816e669f6743
[BSP] ea044f482a4aa9bfa0afb2c31031edd5 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 953867 Mo
User = LL1 … OK!
Error reading LL2 MBR!

Finished : << RKreport[1]_S_11302012_02d1242.txt >>
RKreport[1]_S_11302012_02d1242.txt
Thanks for the lengthy explanations.

Please do another scan with RogueKiller.

When it shows the results, check all the boxes next to the ZeroAccess detections then click on Delete. Post the log it produces.
I passed another scan and did as you said clicking on "Delete" with all incidences marked, here is the report.


RKreport[3]_D_11302012_02d2154.txt

RogueKiller V8.3.1 [Nov 26 2012] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows Vista (6.0.6000 ) 32 bits version
Started in : Normal mode
User : ASD-MASTER [Admin rights]
Mode : Remove – Date : 11/30/2012 21:54:25

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 5 ¤¤¤
[DNS] HKLM\[…]\ControlSet001\Services\Interfaces\{27E38242-552E-4801-8271-45AAE17EF99A} : NameServer (80.58.0.33,80.58.32.97) -> NOT REMOVED, USE DNSFIX
[DNS] HKLM\[…]\ControlSet002\Services\Interfaces\{27E38242-552E-4801-8271-45AAE17EF99A} : NameServer (80.58.0.33,80.58.32.97) -> NOT REMOVED, USE DNSFIX
[HJPOL] HKLM\[…]\System : DisableRegistryTools (0) -> DELETED
[HJ DESK] HKLM\[…]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

¤¤¤ Particular Files / Folders: ¤¤¤
[ZeroAccess][FOLDER] ROOT : C:\Windows\Installer\{f86398d5-3776-50de-51d3-06856123e733}\U –> REMOVED
[ZeroAccess][FOLDER] ROOT : C:\Windows\Installer\{f86398d5-3776-50de-51d3-06856123e733}\L –> REMOVED

¤¤¤ Driver : [LOADED] ¤¤¤
IRP[IRP_MJ_CREATE] : \SystemRoot\system32\drivers\atapi.sys -> HOOKED ([MAJOR] Unknown @ 0x844591E8)
IRP[IRP_MJ_CLOSE] : \SystemRoot\system32\drivers\atapi.sys -> HOOKED ([MAJOR] Unknown @ 0x844591E8)
IRP[IRP_MJ_DEVICE_CONTROL] : \SystemRoot\system32\drivers\atapi.sys -> HOOKED ([MAJOR] Unknown @ 0x844591E8)
IRP[IRP_MJ_INTERNAL_DEVICE_CONTROL] : \SystemRoot\system32\drivers\atapi.sys -> HOOKED ([MAJOR] Unknown @ 0x844591E8)
IRP[IRP_MJ_POWER] : \SystemRoot\system32\drivers\atapi.sys -> HOOKED ([MAJOR] Unknown @ 0x844591E8)
IRP[IRP_MJ_SYSTEM_CONTROL] : \SystemRoot\system32\drivers\atapi.sys -> HOOKED ([MAJOR] Unknown @ 0x844591E8)
IRP[IRP_MJ_PNP] : \SystemRoot\system32\drivers\atapi.sys -> HOOKED ([MAJOR] Unknown @ 0x844591E8)

¤¤¤ Infection : ZeroAccess ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
–> C:\Windows\system32\drivers\etc\hosts

127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: FUJITSU MHY2200BH +++++
— User —
[MBR] b2d1d15aad92be8c7cec7741dd72ada3
[BSP] d87ab92584a1f67fd1a237ac11c00965 : Windows Vista MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 7543 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 15450112 | Size: 183237 Mo
User = LL1 … OK!
User = LL2 … OK!

+++++ PhysicalDrive3: WD Elements 1042 USB Device +++++
— User —
[MBR] ac87b68b8cb1cd72451ffbc8641912b7
[BSP] 21e3b9b7bc966cef2269498d52778a62 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 953866 Mo
User = LL1 … OK!
Error reading LL2 MBR!

+++++ PhysicalDrive4: LG External HDD USB Device +++++
— User —
[MBR] a0f440ce8ac6ca8ea791816e669f6743
[BSP] ea044f482a4aa9bfa0afb2c31031edd5 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 953867 Mo
User = LL1 … OK!
Error reading LL2 MBR!

Finished : << RKreport[3]_D_11302012_02d2154.txt >>
RKreport[1]_S_11302012_02d1242.txt ; RKreport[2]_S_11302012_02d2153.txt ; RKreport[3]_D_11302012_02d2154.txt
Hi asdronin

You actually ticked more boxes than I asked but hopefully no harm done. ;)

A couple more scans should check that we’re all clear to tidy up.

Run Malwarebytes’ Anti-Malware

I noticed that you had MBAM on your system: if you no longer have it, you can download it from here:
  • start Malwarebytes-Anti-Malware and update it, (“Update” tab}
  • once it is updated, click on “Scanner” tab, select Perform quick scan, then click Scan.
  • when the scan is complete, click OK, then Show Results to view the results.
  • be sure that everything is checked, and click Remove Selected.
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

===================================================

Run ESET Online Scan

IMPORTANT Please make sure you uncheck the box next to Remove found threats. Eset will detect anything that looks even slightly suspicious, which could include legitimate program files. If you do not uncheck the box, Eset will automatically remove all suspicious files which could leave some of your software inoperable.

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.

ESET OnlineScan 1. Click the Eset online Scanner button.
2. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

• Click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
• Double click on the Eset installer icon on your desktop.

3. Check Yes, I accept the Terms of Use
4. Click the Start button.
5. Accept any security warnings from your browser.
6. Check Scan archives
7. Push the Start button.
8. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
9. When the scan completes, push List of found threats
10. Push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
Note - if ESET doesn't find any threats, no report will be created.
11. Push the back button.
12. Push Finish
If a log has been produced post it in your next reply.

Can you tell me if there are any outstanding problems.

Satchfan
Hi Satchfan, Sorry I couldn't post the results before, in fact I haven't completed the ESET Online scan yet, still running, but its has been scanning around +20 hours and still like 1/3 of the process is complete, so thats why Im posting only the MBAM result, because I dont want you to think I no longer worry or care about this or something, I really value and appreciate all your efforts in helping me clean the machine. As said I did the MBAM scan and no reboot was required, here is the log, however there is one fact that use to happen before you started helping me with MBAM, I was unable to perform a full scan, computer usually crashed with blue screen in the middle, I haven't tried again after all you have done, but I will try when you say so. The same way it happened before I forgot to change the language so it has parts in spanish, I know your knowledge of this kind of reports will let you see everything even in a different language, if anything is needed just let me know, here is MBAM log: Malwarebytes Anti-Malware 1.65.1.1000 www.malwarebytes.org Versión de la Base de Datos: v2012.12.01.11 Windows Vista x86 NTFS Internet Explorer 7.0.6000.16757 ASD-MASTER :: ASD [administrador] 02/12/2012 3:23:22 mbam-log-2012-12-02 (03-23-22).txt Tipos de Análisis: Análisis Rápido Opciones de análisis activado: Memoria | Inicio | Registro | Sistema de archivos | Heurística/Extra | Heurística/Shuriken | PUP | PUM Opciones de análisis desactivados: P2P Objetos examinados: 220663 Tiempo transcurrido: 28 minuto(s), 31 segundo(s) Procesos en Memoria Detectados: 0 (No se han detectado elementos maliciosos) Módulos de Memoria Detectados: 0 (No se han detectado elementos maliciosos) Claves del Registro Detectados: 0 (No se han detectado elementos maliciosos) Valores del Registro Detectados: 0 (No se han detectado elementos maliciosos) Elementos de Datos del Registro Detectados: 0 (No se han detectado elementos maliciosos) Carpetas Detectadas: 0 (No se han detectado elementos maliciosos) Archivos Detectados: 1 C:\Users\Public\Desktop\MP3 Downloader.lnk (Rogue.Link) -> En cuarentena y eliminado con éxito. fin) One last thing, the link it says was removed from the desktop doesn't correspond to any software or tool that I had as far as I know, I can say that in fact I haven't seen that link on the desktop before (I have many icons there), just knew about it when MBAM said it was removed, which in the end is good I think, but I guess could be as all the other things that I had crawling in the computer that mostly were not installed on purpose or downloaded at any point (appart from Ask bar when I was thinking it was clean of course).
Thanks for letting me know about the delay.

the link it says was removed from the desktop doesn't correspond to any software or tool that I had as far as I know

It probably came with one of your P2P programs.

I'll wait for the result of your scan. If it is not finishing, let me know.
Hi Satchfan, You are right, perhaps the link came with one of those programs, anyway I don't know why all the rest of programs that I had installed for preventing malicious links or malware in general never detected that or the rest of the infections you healed so far. The ESET scan was interrupted by another cut in power, I will post it due tomorrow if I have any luck or maybe more, I'm never sure as this scan took really a long while to just arrive at 80% or so when computer was switched off, sorry about the scan interruption it was totally out of my hand, I will post report once its ready but seeing the time it took I think more than 24 hours and again I'm really sorry about this delay.
Thanks for keeping me informed.

These power cuts must be very annoying but Eset shouldn’t be taking that long.

I would really like to see the results of an online scan to make sure that everything is as it should be.

Let’s try this one instead:

Panda Active Scan
  • please perform this scan using Internet Explorer.
  • this scan can take up to an hour or longer, please be patient.
  • it is recommended that you disable your onboard antivirus program and antispyware programs while performing scans to eliminate software conflicts and to speed up scan time.
  • DO NOT surf the net while your resident protection is disabled!
  • once the scan is finished remember to re-enable your resident antivirus protection along with whatever antispyware applications you use.
  • please perform an online scan with Panda Active Scan 2.0 by clicking here
  • click on the Scan Your PC button
  • click on the Scan now button and follow the instructions (you may have to install an active X component)
  • should you be required to register, click on Register.
  • choose the option you like most, but we recommend Free Active Scan 2.0 (requires registration)
  • click on Register
  • enter your e-mail address and create a password
  • select "I do not want to receive any type of information" (unless you want to receive such information).
  • click on Send
  • confirm your registration and continue by entering your user name and password, then click on Enter
  • select Full Scan, then Click on Scan Now
  • wait for the components to be loaded and installed. Don't close this window or go to another page while it is downloading
  • if the scan finds any malware it can disinfect, the Disinfect button will be enabled. Click on Disinfect
  • please ignore the offer to buy the program
  • click on the Export To button to export the log and save it to your desktop
  • please provide the contents of the log in your next reply.
If you are unable to get Panda to complete its scan, please open your AVG antivirus, update it and run a full system scan then let me know of anything was detected.

Thanks

Satchfan
Hi Satchfan, Yes its really annoying when power is cut and work is lost, but finally ESET scan was finished, here is the resut, I see there are some issues still related to IE but I wonder if they are perhaps innactive most of the time or just related to the moment IE is executed, I use IE not so much so thats why I wonder. Also one fact that I noticed is that frequently internet connection is lost, perhaps is due to the scans we are doing, I mean, for example, after ESET was finished I tried to acces the WTT to post the results but then there was no connection and not even rebooting the router restablished the connection, is that normal? I haven't done Panda scan yet, is that needed now that ESET was completed? I'm really willing to follow all your instructions but just thinking that Panda was a replacement for ESET rather than a different scan type. ESET results are here: C:\Program Files\RAR Password Cracker\rpc.exe a variant of Win32/TrojanDropper.Small.NMN trojan C:\Qoobox\Quarantine\C\Windows\System32\Mcx2Svd.dll.vir a variant of Win32/Delf.OGP trojan C:\TDSSKiller_Quarantine\23.11.2012_06.18.03\zasubsys0000\file0000\tsk0000.dta Win32/Sirefef.FE trojan C:\TDSSKiller_Quarantine\23.11.2012_06.18.03\zasubsys0000\zafs0000\tsk0002.dta Win32/Sirefef.FA trojan C:\TDSSKiller_Quarantine\23.11.2012_06.18.03\zasubsys0000\zafs0000\tsk0003.dta Win32/Sirefef.FL trojan C:\TDSSKiller_Quarantine\23.11.2012_06.18.03\zasubsys0000\zafs0000\tsk0005.dta a variant of Win32/Kryptik.AIRF trojan C:\TDSSKiller_Quarantine\23.11.2012_06.18.03\zasubsys0000\zafs0000\tsk0007.dta Win32/Sirefef.FA trojan C:\TDSSKiller_Quarantine\23.11.2012_06.18.03\zasubsys0000\zafs0000\tsk0008.dta Win32/Sirefef.FL trojan C:\Users\ASD-MASTER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\38bddadd-6f814783 Java/TrojanDownloader.Agent.NBU trojan C:\Users\ASD-MASTER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\7a052e27-2b7e6498 multiple threats C:\Users\ASD-MASTER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\1f842988-15f8e35d multiple threats C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1HVBW02Z\ferveton_biz[1].htm HTML/Iframe.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1SCQHRWL\banner_frame[1].htm HTML/ScrInject.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1UMCX32U\assured_units[1].htm HTML/Iframe.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1UMCX32U\flow1[1].htm HTML/Iframe.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1UMCX32U\flow2[1].htm HTML/Iframe.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1UMCX32U\flow7[1].htm HTML/Iframe.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\38Y1C0SE\mx_nan_a[1].htm HTML/Iframe.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5AA3ICFJ\flow3[1].htm HTML/Iframe.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5AA3ICFJ\world_tie-promised_why[1].htm HTML/Iframe.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\65300O4R\index[1].htm HTML/Iframe.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7G1MD4NE\mx_nan_a[1].htm HTML/Iframe.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7K3MF2GK\flow6[1].htm HTML/Iframe.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9XVLYES3\mx_nan_a[1].htm HTML/Iframe.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9XVLYES3\mx_nan_a[2].htm HTML/Iframe.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DA3WVFU3\mx_nan_a[1].htm HTML/Iframe.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EESMDCEZ\firstload_com[1].htm HTML/ScrInject.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EESMDCEZ\mx_nan_a[1].htm HTML/Iframe.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EESMDCEZ\mx_nan_a[2].htm HTML/Iframe.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G0DCMM5L\webmastermbb_org[1].htm HTML/IFrame.L trojan C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G38XFY4R\lesgirlsxxx_com[1].htm HTML/Iframe.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GQRAY2CN\flow4[1].htm HTML/Iframe.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GQRAY2CN\flow5[1].htm HTML/Iframe.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GTFZ94ZX\mx_nan_a[1].htm HTML/Iframe.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K2U9YRJZ\banner_frame[2].htm HTML/ScrInject.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K2U9YRJZ\mx_nan_a[1].htm HTML/Iframe.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LMNAR4NU\mx_nan_a[1].htm HTML/Iframe.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MM8QTA9M\mx_nan_a[1].htm HTML/Iframe.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NPOJVJCA\mx_nan_a[1].htm HTML/Iframe.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PHWPS199\mx_nan_a[1].htm HTML/Iframe.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TU8TUM17\firstload_com[1].htm HTML/ScrInject.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W8MZ7ZJ4\mueap[1].htm HTML/Iframe.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XVFUGYOW\565261d2ed643f275afe56e1c9d06330[1].htm HTML/Iframe.B.Gen virus C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XVFUGYOW\putts-college_cover[1].htm HTML/Iframe.B.Gen virus
We’ll run a program to check your Internet but if it shows nothing you may need to start a topic in out Browser forum which I’ll give a link to.

Most of what was found has either already been fixed, (in quarantined), or in temporary folders but when we fix the few remaining stragglers I would say everything is pretty good regarding malware.

Open ComboFix

Please do the following:
  • close any open browsers.
  • close/disable all anti virus and anti malware programs so that they do not interfere with the running of ComboFix.
  • open notepad and copy/paste the text in the codebox below into it:
File::
C:\Program Files\RAR Password Cracker\rpc.exe 
C:\TDSSKiller_Quarantine

Folder::
C:\Users\ASD-MASTER\AppData\LocalLow\Sun\Java\Deployment\cache\6.0
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe

When finished, it produces a log at C:\ComboFix.txt. Post the contents of Combofix.txt in your next reply.

================================================

Run Farbar Service Scanner

Please download Farbar Service Scanner and run it on the computer with the issue.
  • make sure the following options are checked:

    Internet Services
    Windows Firewallsfc
    System Restore
    Security Center
    Windows Update

  • press "Scan".
  • it will create a log (FSS.txt) in the same directory the tool is run.
  • please copy and paste the log to your reply.
Logs to include in the next post:

ComboFix.txt
FSS.txt


Thanks

Satchfan
Hi Satchfan, Sorry I couldn't post before, I lost the connection and this time it was permanent, a change in the configuration that took me time to detect and correct. The Combofix scan crashed 3 times, each time I run it I see the same issue, Catchme.3Xe crashes and then all is halted, I'm prompted to close or debug, I choose to close, then the action of Combofix continues but after 3 or 4 incidences of same crash, telling to close the Catchme.3xe after it crashes makes no change in the Combofix window, so well, I haven't performed the other scan as this one wasn't succesful, should I retry this or try the Farbar scan?
Yes I'm sure it was "3xe" and not "exe", I took special atention at that and the Combofix window too, so that I could tell you something helpful regarding the process crash. In fact this time Combofix wasn't running as the previous time we did the scan, this time it made the whole windows environment dissapear leaving only the default wallpaper and the Combofix blue console, it was odd somehow but I thought it could be normal, so it was wrong?
One fact that I noticed which is still present is that when I load a graphic program (for 3D design for example), even having just a internet browser loaded and nothing else, sometimes the graphic seem to turn black, and if I click the Windows "Start" button I see only some items names and icons, the rest are not visible, even in the desktop it seems like there is no memory for graphics and cant see the icons, after i close some programs or reboot the problem dissapear, what do you think about this?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI