Odd .txt file showed up...

supersamio

New Member
Ok, so i got on the PC today, went to my c drive to look for something and i found this odd .txt file

It was called 'rapid.txt' and in it, had like, all the usernames and passwords of the sites i had logged into today... I didnt make this, so who/what did?

Im doing scans etc now, but any advice / info would be cool :(
 

My Computer

Seems like Google end up with some strange things like USDownloader, Rapidshare captchas tricks by using OCR and what not. Rapid.txt could be a result of a program used to find premium accounts?

Would the file be located here C:\WINDOWS\system32\ocr\Rapid.txt ?

Have no idea really. Probably a very good idea to scan if you are ????
 

My Computer

System One

  • CPU
    AMD X2 6000
    Motherboard
    Gigabyte GA-MA790FX-DS5
    Memory
    Corsair 4x1gb 6400C4
    Graphics Card(s)
    XFX 8800GTS XT 320mb, Generic Nvidia 6200 PCI 128mb
    Sound Card
    Onboard Realtek ALC889A
    Monitor(s) Displays
    24" Samsung 245b, 20" Dell 2007WFP, 19" Samsung 193P
    Hard Drives
    WD Raptor 74gb, Maxtor 300gb, WD Caviar 16SE 500gb
    PSU
    Corsair 520W
    Case
    Cooler Master Centurion 532
    Keyboard
    Logitech G15
    Mouse
    Logitech MX1100R
    Internet Speed
    20mb down, 1mb up
The file was found in C directory, literally just right there C/rapid.txt

Whats this about rapidshare captchas by the way? I do have a rapidshare premium account etc... So this might be it.
 

My Computer

I dont know, just my translation of bad Google searching.

Try "universal share downloader" or "C:\WINDOWS\system32\ocr\Rapid.txt"

You see a malware-removal process using Combofix here Forum > Dziwne rzeczy

Notice "C:\WINDOWS\system32\ocr\Rapid.txt" is among "deletions". You have a ocr folder under system32?

I would scan with Malwarebytes Anti-Malware, SuperAntispyware and even Spybot&Destroy. If you install S&D untick the resident stuff, teatimer and scriptblocking. Besides of course your AV - may be try an online scanner, like Microsofts or ESETs - anything else than what you have installed.

If nothing comes up I think you should contact a malware-removal forum - or post some more info here. Hijackthis, RSIT logs - the more the better.

Cryptload ring a bell? Check this google search http://www.google.dk/search?num=30&hl=en&client=firefox-a&rls=org.mozilla%3Aen-US%3Aofficial&hs=LFQ&q=cryptload+%22rapid.txt%22&btnG=Search
 
Last edited:

My Computer

System One

  • CPU
    AMD X2 6000
    Motherboard
    Gigabyte GA-MA790FX-DS5
    Memory
    Corsair 4x1gb 6400C4
    Graphics Card(s)
    XFX 8800GTS XT 320mb, Generic Nvidia 6200 PCI 128mb
    Sound Card
    Onboard Realtek ALC889A
    Monitor(s) Displays
    24" Samsung 245b, 20" Dell 2007WFP, 19" Samsung 193P
    Hard Drives
    WD Raptor 74gb, Maxtor 300gb, WD Caviar 16SE 500gb
    PSU
    Corsair 520W
    Case
    Cooler Master Centurion 532
    Keyboard
    Logitech G15
    Mouse
    Logitech MX1100R
    Internet Speed
    20mb down, 1mb up
Back
Top