No Sound and Annoying Ads

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Huthah, Jul 26, 2010.

  1. Huthah

    Huthah Private E-2

    I've been experiencing the same problems bht had in the topic "Invisible Ads and Wave Mute"; namely that my "wave" bar had been set to the bottom and that when I turned the wave volume back up, disembodied advertisements for Clorox and such things began playing. I've also been having pop-ups come up every now and then, in addition to having all of my programs being "alt-tabbed" to a nonexistent program; my full-screen games exit back to the desktop and I have to select them from the taskbar to get back to playing them.

    While I'm a looong way from being anything close to a computer expert, based on the diagnosis of bht's problems in the post mentioned above, I think there might be an infection in my Master Boot Record, but I'm not about to go altering anything in my computer without knowing what I'm doing.

    In case anyone's wondering, I already searched for malware with Norton 360, AVG, Malwarebytes, and while both Malwarebytes and AVG were able to find a single file each and delete them, the problem still persists.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...

    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.


    Now download the latest version of MGtools and save it to your root folder. Double click the .exe file and attach the C:\MGLogs.zip when it is finished running.
     
  3. Huthah

    Huthah Private E-2

    Okay, I downloaded the MBRCheck and attached the log. I've also placed the MGTools in my c: folder; that is my root folder right? I've attached the log from MGTools as well.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have all important data backed up? You really should do this before continuing since we will need to rewrite your MBR to fix this and while most times this can be done without any problem, these infections can react badly and that could result in a PC not being bootable. You really don't have much choice though since these infections are too dangerous to your security to leave on a PC.

    Also note if you have a Dell PC which uses a non-standard MBR ( or another manufacturer's who does similar to Dell) , fixing the mbr may prevent access the the Dell Restore Utility, which allows you to press a key on startup and revert your computer to a factory delivered state. There are a couple of known fixes for said condition, though the methods are somewhat advanced. If you are unwilling to take such a risk, you should not continue but you risk serious problems leaving this infection in place and thus your only other option would be to try using the Dell Restore Utility to return a factory ship state which will remove everything you additional you have put onto the PC.


    Now if you wish to continue and fix the malware - please do the following:

    * Run MBRCheck.exe
    * Wait until you see the following lines:
    o Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    o Options:
    [1] Dump the MBR of a physical disk to file.
    [2] Restore the MBR of a physical disk with a standard boot code.
    [3] Exit.
    Enter your choice:

    * Please push the 'Y' key and then press Enter
    * When the program asks you to Enter your choice: enter 2 to Restore the MBR and press the Enter key
    * Now the program will ask you to "Enter the physical disk number to fix (0-99, -1 to cancel):"
    o Enter 0 and press the Enter key.
    * The program will show Available MBR codes as below

    * You need to select your version of Windows from the list. For example, enter 0 or 1 for XP or enter 3 for Vista.....etc. and then press Enter.
    * The program will prompt for confirmation. Type 'YES' and hit Enter.
    * Left click on the title bar (where program name and path is written). From menu chose Edit -> Select All
    * You will see all the text in the window get highlighted.
    * Hit the Enter key on your keyboard to copy all of the text into the clipboard.
    * Paste that text into Notepad, save it to your desktop as MBRfix.txt
    * Restart your PC.
    * Attach the MBRfix.txt file to your next message..

    Now please re-run MBRCheck.exe and attach that log also.
     
  5. Huthah

    Huthah Private E-2

    We have one of those 80 GB usb drives at our house to place my data on, but we've been trying to get it to work; so I may need to wait a couple of days to get on that. Just curious though; is there a difference between [0] Default (Windows XP) and [1] Windows XP? If so then where on my computer should I look to determine which number I select?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Choose either 0 or 1. It shouldnt matter.
     
  7. Huthah

    Huthah Private E-2

    Apparently, to back up my data I'd have to get a lot of usb drives and hope that all of my data could be broken up amongst them. So, instead of going through that grueling process I went ahead and ran the MBR per your instructions; included is the log from that. As I started up my computer again, it went through a rather long process called "file check" I believe. It had three stages and verified things such as indexes and security...something (sorry, I was leaving it to do other chores from time to time so I only caught a few glimpses). It then booted up like normal and I opened up MBR and posted the log again. Just curious though, what if my computer hadn't booted up normally? Would I have to do a complete wipe?
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We have had only one or two systems that crashed when re-writing the MBR code. They could have been user errors. It's hard to determine, but you would have had to try a repair installation which would have required your OS cd.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    We will see if there is anything else that needs doing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds