Computer Hope

Software => Computer viruses and spyware => Topic started by: Jaxxboss on July 10, 2008, 01:24:49 PM

Title: pages freeze/lock up, task mgr shows double the pages open.
Post by: Jaxxboss on July 10, 2008, 01:24:49 PM
recommended to come over here and post my logs.

amd 5000 x2
2gig ram.

Occasionaly a window I have open will freeze or lock up.  I will open task mgr and it will show 2 of the same pages as being open(and not responding) when its actually one page open(and not responding).

pages freeze or lock up every now and then with no thyme or reason.

Logs follows are:



[recovering disk space -- attachment deleted by admin]
Title: Re: pages freeze/lock up, task mgr shows double the pages open.
Post by: evilfantasy on July 10, 2008, 02:04:18 PM
Open Hijackthis and select Do a system scan only.

Place a check mark next to the following entries: (if there)

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)


Important: Close all windows except for Hijackthis and then click Fix checked.

Exit Hijackthis and run CCleaner.

----------

Use the  Kaspersky Online Scanner (http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html)

You must use Internet Explorer.
Title: Re: pages freeze/lock up, task mgr shows double the pages open.
Post by: Jaxxboss on July 11, 2008, 09:01:35 AM
Sorry it took so long.  The kscan keot getting bogged down at 20% on a rar file, eventualy I had to delete it.  It was a rar of a tv show.
anyway, here are the results.

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
 Friday, July 11, 2008
 Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
 Kaspersky Online Scanner 7 version: 7.0.25.0
 Program database last update: Friday, July 11, 2008 00:27:25
 Records in database: 937938
--------------------------------------------------------------------------------

Scan settings:
   Scan using the following database: extended
   Scan archives: yes
   Scan mail databases: yes

Scan area - My Computer:
   A:\
   C:\
   D:\
   E:\
   F:\
   G:\
   H:\
   I:\
   J:\
   K:\
   L:\

Scan statistics:
   Files scanned: 156460
   Threat name: 2
   Infected objects: 29
   Suspicious objects: 0
   Duration of the scan: 03:11:14


File name / Threat name / Threats count
C:\Documents and Settings\Ron.RON-630B944F5F1\Favorites\Application Data\Sun\Java\Deployment\cache\6.0\22\10453ed6-416465e5   Infected: Exploit.Java.Gimsh.b   1
C:\Documents and Settings\Ron.RON-630B944F5F1\Favorites\Application Data\Sun\Java\Deployment\cache\6.0\29\775d249d-33795efc   Infected: Exploit.Java.Gimsh.b   1
C:\Documents and Settings\Ron.RON-630B944F5F1\Favorites\Application Data\Sun\Java\Deployment\cache\6.0\34\63206922-34284ec7   Infected: Exploit.Java.Gimsh.b   1
C:\Documents and Settings\Ron.RON-630B944F5F1\Favorites\Application Data\Sun\Java\Deployment\cache\6.0\47\bd7ce2f-5e62bcd1   Infected: Exploit.Java.Gimsh.b   1
C:\Documents and Settings\Ron.RON-630B944F5F1\Favorites\Application Data\Sun\Java\Deployment\cache\6.0\49\49820371-47ef009c   Infected: Exploit.Java.Gimsh.b   1
C:\Documents and Settings\Ron.RON-630B944F5F1\Favorites\Application Data\Sun\Java\Deployment\cache\6.0\52\1c9644b4-7136818d   Infected: Exploit.Java.Gimsh.b   1
C:\Documents and Settings\Ron.RON-630B944F5F1\Favorites\Application Data\Sun\Java\Deployment\cache\6.0\52\66b0bd34-30dba1c0   Infected: Exploit.Java.Gimsh.b   1
C:\Documents and Settings\Ron.RON-630B944F5F1\Favorites\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-1181d259-5e64816c.zip   Infected: Exploit.Java.Gimsh.b   1
C:\Documents and Settings\Ron.RON-630B944F5F1\Favorites\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-1ab034e7-57ae9521.zip   Infected: Exploit.Java.Gimsh.b   1
C:\Documents and Settings\Ron.RON-630B944F5F1\Favorites\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-3ad601a5-45149665.zip   Infected: Exploit.Java.Gimsh.b   1
C:\Documents and Settings\Ron.RON-630B944F5F1\Favorites\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-5efd1945-11fe74e7.zip   Infected: Exploit.Java.Gimsh.b   1
C:\Documents and Settings\Ron.RON-630B944F5F1\Favorites\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-6b13a7e7-68d52672.zip   Infected: Exploit.Java.Gimsh.b   1
C:\Documents and Settings\Ron.RON-630B944F5F1\Favorites\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-6d3811e3-5d6dc0ab.zip   Infected: Exploit.Java.Gimsh.b   1
C:\Documents and Settings\Ron.RON-630B944F5F1\Favorites\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-b825669-75121a12.zip   Infected: Exploit.Java.Gimsh.b   1
C:\Program Files\DVDFab Platinum 4\unins000.exe   Infected: Trojan-Downloader.Win32.Agent.vuh   1
E:\Documents and Settings\RON\Favorites\Application Data\Sun\Java\Deployment\cache\6.0\22\10453ed6-416465e5   Infected: Exploit.Java.Gimsh.b   1
E:\Documents and Settings\RON\Favorites\Application Data\Sun\Java\Deployment\cache\6.0\29\775d249d-33795efc   Infected: Exploit.Java.Gimsh.b   1
E:\Documents and Settings\RON\Favorites\Application Data\Sun\Java\Deployment\cache\6.0\34\63206922-34284ec7   Infected: Exploit.Java.Gimsh.b   1
E:\Documents and Settings\RON\Favorites\Application Data\Sun\Java\Deployment\cache\6.0\47\bd7ce2f-5e62bcd1   Infected: Exploit.Java.Gimsh.b   1
E:\Documents and Settings\RON\Favorites\Application Data\Sun\Java\Deployment\cache\6.0\49\49820371-47ef009c   Infected: Exploit.Java.Gimsh.b   1
E:\Documents and Settings\RON\Favorites\Application Data\Sun\Java\Deployment\cache\6.0\52\1c9644b4-7136818d   Infected: Exploit.Java.Gimsh.b   1
E:\Documents and Settings\RON\Favorites\Application Data\Sun\Java\Deployment\cache\6.0\52\66b0bd34-30dba1c0   Infected: Exploit.Java.Gimsh.b   1
E:\Documents and Settings\RON\Favorites\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-1181d259-5e64816c.zip   Infected: Exploit.Java.Gimsh.b   1
E:\Documents and Settings\RON\Favorites\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-1ab034e7-57ae9521.zip   Infected: Exploit.Java.Gimsh.b   1
E:\Documents and Settings\RON\Favorites\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-3ad601a5-45149665.zip   Infected: Exploit.Java.Gimsh.b   1
E:\Documents and Settings\RON\Favorites\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-5efd1945-11fe74e7.zip   Infected: Exploit.Java.Gimsh.b   1
E:\Documents and Settings\RON\Favorites\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-6b13a7e7-68d52672.zip   Infected: Exploit.Java.Gimsh.b   1
E:\Documents and Settings\RON\Favorites\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-6d3811e3-5d6dc0ab.zip   Infected: Exploit.Java.Gimsh.b   1
E:\Documents and Settings\RON\Favorites\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-b825669-75121a12.zip   Infected: Exploit.Java.Gimsh.b   1

The selected area was scanned.
Title: Re: pages freeze/lock up, task mgr shows double the pages open.
Post by: evilfantasy on July 11, 2008, 10:57:50 AM
Clearing Java Cache

Go to Start > Control Panel and double-click the Java IconNote: This deletes ALL the Downloaded Applications and Applets from the CACHE.
.
----------

Download ATF Cleaner (http://www.atribune.org/ccount/click.php?id=1) by Atribune and save it to your Desktop.
Alternate Download link (http://www.majorgeeks.com/ATF_Cleaner_d4949.html)

Windows Vista users: ATF-Cleaner must be Run as an Administrator (http://vistasupport.mvps.org/run_as_administrator.htm)

Double click ATF-Cleaner.exe to run the program.
Check the boxes to the left of:

The rest are optional - if you want it to remove everything check Select All
Now click Empty Selected
When you get the Done Cleaning message, click OK

Firefox
users click Firefox on the menu bar

Click on Select All, then click Empty
        Note: If you want to keep your saved Passwords click No on the prompt.

Opera users click Opera on the menu bar

Click on Select All, then click Empty
        Note: If you want to keep your saved Passwords click No on the prompt

Important: Restart the computer before continuing.

----------

How is everything now?
Title: Re: pages freeze/lock up, task mgr shows double the pages open.
Post by: Jaxxboss on July 12, 2008, 10:55:20 AM
Well, same thing just happened again.  Well, twice this morning.  :-[
Title: Re: pages freeze/lock up, task mgr shows double the pages open.
Post by: evilfantasy on July 12, 2008, 11:33:15 AM
Download Combofix by sUBs from one of the below links.

Important! Combofix.exe MUST be saved to and ran from the Desktop.
Warning: Do not mouseclick Combofix's window while it is running. That may cause it to stall
If needed, see this  Combofix tutorial (http://www.bleepingcomputer.com/combofix/how-to-use-combofix) with screenshots that will detail more thoroughly the downloading and running of Combofix.

Combofix should never take more that 20 minutes including the reboot if malware is detected.

----------

Next post add
Combofix log
Title: Re: pages freeze/lock up, task mgr shows double the pages open.
Post by: Jaxxboss on July 12, 2008, 12:46:12 PM
had to post it this way as it was too big posting the full text.

[recovering disk space -- attachment deleted by admin]
Title: Re: pages freeze/lock up, task mgr shows double the pages open.
Post by: evilfantasy on July 12, 2008, 01:11:19 PM
Quote
Your log(s) show that you are using so called peer-to-peer (http://en.wikipedia.org/wiki/Peer-to-peer) or file-sharing (http://en.wikipedia.org/wiki/File_sharing) programs.

These programs allow to share files between users as the name(s) suggest. In today's world the cyber crime (http://en.wikipedia.org/wiki/Cyber_crime) has come to an enormous dimension and any means is used to infect personal computers to make use of their stored data or machine power for further propagation of the malware files.
A popular means is the use of file-sharing tools as a tremendous amount of prospective victims can be reached through it.

It is therefore possible to be infected by downloading manipulated files via peer-to-peer tools and thus suggested to be used with intense care.
Some further readings on this subject, along the included links, are as follows: File-Sharing, otherwise known as Peer To Peer (http://forums.spybot.info/showpost.php?p=1109&postcount=1) and Risks of File-Sharing Technology (http://www.us-cert.gov/cas/tips/ST05-007.html)

It is also important to note that sharing entertainment files and proprietary software (http://en.wikipedia.org/wiki/Proprietary_software)
infringes the copyright laws in many countries over the world and you are putting yourself at risk of being  indicted (http://en.wikipedia.org/wiki/Indictment) through organizations watching over the rights of the authors of such files (i.e. the RIAA (http://www.riaa.com/) for music files, or the MPAA (http://www.mpaa.org/) for movie files in the USA) or the authors of the files themselves.

----------

(http://i154.photobucket.com/albums/s258/evilfantasy69/combofixu-1.jpg)

.
----------

Download DrWeb CureIt (http://freedrweb.com/) & save it to your desktop.

Scan with DrWeb-CureIt as follows:[/COLOR][/list]
Title: Re: pages freeze/lock up, task mgr shows double the pages open.
Post by: Jaxxboss on July 12, 2008, 02:11:27 PM
Macafee detected this.  what do i do?

McAfee has blocked a potentially unwanted program (PUP) on your computer. If you do not recognize it, we recommend that you remove the program.

About this Potentially Unwanted Program
Name: RemAdm-ProcLaunch!171
Location: C:\327882R2FWJFW\psexec.cfexe

Spyware, adware, and other potentially unwanted programs can harm your computer, compromise its security, and damage valuable files

edit: this came up when I did the " Combofix /u ", which went ok.
Title: Re: pages freeze/lock up, task mgr shows double the pages open.
Post by: evilfantasy on July 12, 2008, 02:23:44 PM
psexec.cfexe is part of Combofix. That's why we suggest turning off your protection prior to running Combofix.

I didn't think it would be detected during the uninstall.
Title: Re: pages freeze/lock up, task mgr shows double the pages open.
Post by: Jaxxboss on July 12, 2008, 08:56:27 PM
troubleshooter.exe\data035;C:\Documents and Settings\RON\Desktop\1 DL\The.Ultimate.Troubleshooter.v.3.0\The.Ultimate.Troubleshooter.v.3.0\The.Ultimate.Tro;Modification of BackDoor.Generic.1219;;
troubleshooter.exe;C:\Documents and Settings\RON\Desktop\1 DL\The.Ultimate.Troubleshooter.v.3.0\The.Ultimate.Troubleshooter.v.3.0\The.Ultimate.Tro;Archive contains infected objects;Moved.;
WmrInstall_11.exe\data023;C:\Documents and Settings\RON\Desktop\1 DL\WM.Recorder.Ver.11.0(req)\WM.Recorder.Ver.11.0(req)\WM.Recorder.Ver.11.0(req)\WmrIns;Trojan.Proxy.1381;;
WmrInstall_11.exe;C:\Documents and Settings\RON\Desktop\1 DL\WM.Recorder.Ver.11.0(req)\WM.Recorder.Ver.11.0(req)\WM.Recorder.Ver.11.0(req);Archive contains infected objects;Moved.;
Mirror Magic Deluxe.exe\data003;C:\Documents and Settings\Ron.RON-630B944F5F1\Desktop\1DL\Mirror Magic Deluxe\Mirror Magic Deluxe.exe;Trojan.DownLoader.62561;;
Mirror Magic Deluxe.exe\data004;C:\Documents and Settings\Ron.RON-630B944F5F1\Desktop\1DL\Mirror Magic Deluxe\Mirror Magic Deluxe.exe;Trojan.Virtumod.based.11;;
mirror_magic_deluxe_setup.exe\data007;C:\Documents and Settings\Ron.RON-630B944F5F1\Desktop\1DL\Mirror Magic Deluxe\Mirror Magic Deluxe.exe\data005\mirror_magic_delu;Trojan.Virtumod.based.11;;
mirror_magic_deluxe_setup.exe;C:\Documents and Settings\Ron.RON-630B944F5F1\Desktop\1DL\Mirror Magic Deluxe\Mirror Magic Deluxe.exe\data005;Archive contains infected objects;;
data005;C:\Documents and Settings\Ron.RON-630B944F5F1\Desktop\1DL\Mirror Magic Deluxe\Mirror Magic Deluxe.exe;Archive contains infected objects;;
mirror_magic_deluxe_setup.exe\data007;C:\Documents and Settings\Ron.RON-630B944F5F1\Desktop\1DL\Mirror Magic Deluxe\Mirror Magic Deluxe.exe\data006\mirror_magic_delu;Trojan.Virtumod.based.11;;
mirror_magic_deluxe_setup.exe;C:\Documents and Settings\Ron.RON-630B944F5F1\Desktop\1DL\Mirror Magic Deluxe\Mirror Magic Deluxe.exe\data006;Archive contains infected objects;;
data006;C:\Documents and Settings\Ron.RON-630B944F5F1\Desktop\1DL\Mirror Magic Deluxe\Mirror Magic Deluxe.exe;Archive contains infected objects;;
Mirror Magic Deluxe.exe;C:\Documents and Settings\Ron.RON-630B944F5F1\Desktop\1DL\Mirror Magic Deluxe;Archive contains infected objects;Moved.;
data007\data001;C:\Documents and Settings\Ron.RON-630B944F5F1\Desktop\DVD STUFF\Executes\daemon4123-lite.exe\data007;Adware.Shopper;;
data007\data002;C:\Documents and Settings\Ron.RON-630B944F5F1\Desktop\DVD STUFF\Executes\daemon4123-lite.exe\data007;Adware.SaveNow.128;;
data007;C:\Documents and Settings\Ron.RON-630B944F5F1\Desktop\DVD STUFF\Executes\daemon4123-lite.exe;Archive contains infected objects;;
daemon4123-lite.exe;C:\Documents and Settings\Ron.RON-630B944F5F1\Desktop\DVD STUFF\Executes;Archive contains infected objects;Moved.;
data038\data008;C:\Documents and Settings\Ron.RON-630B944F5F1\Desktop\Seldom used short cuts\var execut proggys\DeadAim 4.5 + AIM\Install_AIM_5;Adware.Aws;;
data038;C:\Documents and Settings\Ron.RON-630B944F5F1\Desktop\Seldom used short cuts\var execut proggys\DeadAim 4.5 + AIM\Install_AIM_5;Archive contains infected objects;;
Install_AIM_5.5.3590.exe;C:\Documents and Settings\Ron.RON-630B944F5F1\Desktop\Seldom used short cuts\var execut proggys\DeadAim 4.5 + AIM;Archive contains infected objects;Moved.;
WxBug.EXE\data008;C:\Program Files\AIM\Sysfiles\WxBug.EXE;Adware.Aws;;
WxBug.EXE;C:\Program Files\AIM\Sysfiles;Archive contains infected objects;Moved.;
Tut_support.exe;C:\Program Files\AnswersThatWork\Troubleshooter;Modification of BackDoor.Generic.1219;Moved.;
MiniBugTransporter.dll;C:\Program Files\AWS\WeatherBug;Adware.Aws;;
A0052247.EXE\data008;C:\System Volume Information\_restore{D0A8D129-1F93-4002-84BF-8E59278885C1}\RP383\A0052247.EXE;Adware.Aws;;
A0052247.EXE;C:\System Volume Information\_restore{D0A8D129-1F93-4002-84BF-8E59278885C1}\RP383;Archive contains infected objects;Moved.;
troubleshooter.exe\data035;E:\Documents and Settings\RON\Desktop\1 DL\The.Ultimate.Troubleshooter.v.3.0\The.Ultimate.Troubleshooter.v.3.0\The.Ultimate.Tro;Modification of BackDoor.Generic.1219;;
troubleshooter.exe;E:\Documents and Settings\RON\Desktop\1 DL\The.Ultimate.Troubleshooter.v.3.0\The.Ultimate.Troubleshooter.v.3.0\The.Ultimate.Tro;Archive contains infected objects;Moved.;
WmrInstall_11.exe\data023;E:\Documents and Settings\RON\Desktop\1 DL\WM.Recorder.Ver.11.0(req)\WM.Recorder.Ver.11.0(req)\WM.Recorder.Ver.11.0(req)\WmrIns;Trojan.Proxy.1381;;
WmrInstall_11.exe;E:\Documents and Settings\RON\Desktop\1 DL\WM.Recorder.Ver.11.0(req)\WM.Recorder.Ver.11.0(req)\WM.Recorder.Ver.11.0(req);Archive contains infected objects;Moved.;
data038\data008;E:\Documents and Settings\RON\Desktop\Seldom used short cuts\var execut proggys\DeadAim 4.5 + AIM\Install_AIM_5.5.3590.exe\data;Adware.Aws;;
data038;E:\Documents and Settings\RON\Desktop\Seldom used short cuts\var execut proggys\DeadAim 4.5 + AIM\Install_AIM_5.5.3590.exe;Archive contains infected objects;;
Install_AIM_5.5.3590.exe;E:\Documents and Settings\RON\Desktop\Seldom used short cuts\var execut proggys\DeadAim 4.5 + AIM;Archive contains infected objects;Moved.;
data038\data008;E:\New Folder\Desktop\Seldom used short cuts\var execut proggys\DeadAim 4.5 + AIM\Install_AIM_5.5.3590.exe\data038;Adware.Aws;;
data038;E:\New Folder\Desktop\Seldom used short cuts\var execut proggys\DeadAim 4.5 + AIM\Install_AIM_5.5.3590.exe;Archive contains infected objects;;
Install_AIM_5.5.3590.exe;E:\New Folder\Desktop\Seldom used short cuts\var execut proggys\DeadAim 4.5 + AIM;Archive contains infected objects;Moved.;
Tut_support.exe;E:\Program Files\AnswersThatWork\Troubleshooter;Modification of BackDoor.Generic.1219;Moved.;
MiniBugTransporter.dll;E:\Program Files\AWS\WeatherBug;Adware.Aws;;
data038\data008;E:\saved *censored* from 21june\Seldom used short cuts\var execut proggys\DeadAim 4.5 + AIM\Install_AIM_5.5.3590.exe\data038;Adware.Aws;;
data038;E:\saved *censored* from 21june\Seldom used short cuts\var execut proggys\DeadAim 4.5 + AIM\Install_AIM_5.5.3590.exe;Archive contains infected objects;;
Install_AIM_5.5.3590.exe;E:\saved *censored* from 21june\Seldom used short cuts\var execut proggys\DeadAim 4.5 + AIM;Archive contains infected objects;Moved.;
Title: Re: pages freeze/lock up, task mgr shows double the pages open.
Post by: evilfantasy on July 12, 2008, 09:24:11 PM
This scanner works with Internet Explorer only
Go to the  BitDefender Online Scanner (http://www.bitdefender.com/scan8/ie.html)
Click I Agree to the license and then install the ActiveX control.
Please DO NOT change the Scanning Options.
That will make your logs huge and we don't need to see clean files.

Select Start Scan to begin.
This scan can take a while so please be patient and let it complete.

 Once Bitdefender completes the scan:
 Click-on the Detected Problems tab.
 Then select Click here to export the scan report

(http://i154.photobucket.com/albums/s258/evilfantasy69/Tutorials/bit.jpg)
 
 When the window comes up to save the report, change the Save as type: box to:
 Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click Save

(http://i154.photobucket.com/albums/s258/evilfantasy69/Tutorials/bit2.jpg)
 
 This will save a file named bdscan.txt. I would suggest saving it to the Desktop so you can easily find it. (take notice of where you save it so you can find it later)
 
 This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.
 
 If you do not follow these step, you will have an incorrect log or worse a log summary which is useless to us
 
 Post the bdscan.txt in the next post.

The log will be huge and must be added as an attachment.

See  HERE (http://www.computerhope.com/forum/index.php/topic,46313.msg316477.html#msg316477) fo rhow to attach logs.
Title: Re: pages freeze/lock up, task mgr shows double the pages open.
Post by: Jaxxboss on July 13, 2008, 09:34:17 AM
Heres the scan.  Sorry, but had thunderstorms last night.  Also, Although i had mcafee turned off, it still popped out a warning and blocked a proggy called  New Poly Win32 Infection.  Not sure if thats relevent or not and im not even sure ho mcafee caught it since it was turned off.

[recovering disk space -- attachment deleted by admin]
Title: Re: pages freeze/lock up, task mgr shows double the pages open.
Post by: evilfantasy on July 13, 2008, 11:53:38 AM
That log looked fine. Are you still having any problems?
Title: Re: pages freeze/lock up, task mgr shows double the pages open.
Post by: Jaxxboss on July 13, 2008, 12:03:41 PM
Well, so far so good I guess.  Ill do some heavy surfing today and keep my fingers crossed.  Thanks for your help and patience.  You rock dude!!
Title: Re: pages freeze/lock up, task mgr shows double the pages open.
Post by: evilfantasy on July 13, 2008, 12:05:37 PM
Final steps.

Set a New Restore Point to prevent possible reinfection from an old one
Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
You can find instructions on how to enable and re-enable system restore here:

Windows XP System Restore Guide (http://www.bleepingcomputer.com/forums/tutorial56.html) or Windows Vista System Restore Guide  (http://www.bleepingcomputer.com/tutorials/tutorial143.html)
.
----------

Use the  Secunia Software Inspector (http://secunia.com/software_inspector) to check for out of date software.
.
----------

Important: You Need to Update Windows and Internet Explorer regularly to protect your computer from the malware and other security threats that are on the Internet. Go to Microsoft Windows Update (http://windowsupdate.microsoft.com/) and get all critical updates.

If you are running any Microsoft Office version go to the Office Update (http://office.microsoft.com/search/redir.aspx?assetid=ES790020331033&CTT=96&Origin=CL100570421033) site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.

----------

Make sure all of your security programs are up to date and run scans with them regularly. Once or twice a week minimum.

Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

To prevent unknown applications from being installed on your computer install WinPatrol 2008 (http://www.winpatrol.com/winpatrol.html)
*  Using Winpatrol to protect your computer from malicious software (http://www.winpatrol.com/features.html)

I would suggest using SiteAdvisor (http://www.siteadvisor.com/). SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

 SpywareBlaster (http://www.javacoolsoftware.com/spywareblaster.html) - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
*  (http://www.bleepingcomputer.com/tutorials/tutorial49.html)Using SpywareBlaster to protect your computer from Spyware and Malware (http://www.bleepingcomputer.com/forums/tutorial49.html)
* If you don't know what ActiveX controls are, see here (http://www.webopedia.com/TERM/A/ActiveX_control.html)

Check out  Keeping Yourself Safe On The Web (http://evilspages.blogspot.com/2008/05/keeping-yourself-safe-on-web.html) for tips and free tools to help keep you safe in the future.

Also see  Slow Computer? It May Not Be Malware (http://evilspages.blogspot.com/2008/05/slow-computer-it-may-not-be-malware.html) for free cleaning/maintenance tools to help keep your computer running smooth.