Annoying audio ads running in background and possible Trojan.Downloader.Delf.AKZ

Discussion in 'Malware Help (A Specialist Will Reply)' started by lavorlavor, Sep 19, 2012.

  1. lavorlavor

    lavorlavor Private E-2

    Hi there,
    so glad I found you guys and thanks in advance for any help you can give me. About a week ago I started to hear random audio in the background (clock ticking and then car alarm) a few times and it would stop. Then a few days later I had ongoing random audio ads running in the background even when I disconnected from the internet. I use avast free (up to date) and zonealarm (also up to date), XP SP3 with auto updates applied, Java up to date and Firefox (addons updated).

    Avast found nothing as did Mbam. PC Tools however found over 300 items and one which most worried me was - Trojan.Downloader.Delf.AKZ. I use my netbook for banking etc and am travelling at the moment. I did what you asked in your guide to posting so hope its what you want. Roguekiller found 2 things but the rest seemed ok to me. Attaching all logs (only attached last and biggest of tddskiller - let me know if you need the others) and hope you can help me. By the way the audio ads seemed to have stopped and everything else seems normal but I'm still worried I have some malware, Thanks again, Paul
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. However, you really need to clean out your temp folders.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  3. lavorlavor

    lavorlavor Private E-2

    Hi Tim,
    first of all I would like to thank you for taking the time to help me and so quickly!! (unlike another forum that has taken over a week to reply!!) I am much relieved and will tidy up all the programs used except for mbam which I had been using before all this started.

    Can I bother you to just doublecheck which temp files/folders I can delete or not? always a bit wary of just going ahead and deleting stuff. Full path please or just point me to a link explaining it.

    Will follow your tips to stay clean and would like to thank you guys (and you personally) again. MajorGeeks rocks!!

    Cheers,
    Paul
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  5. lavorlavor

    lavorlavor Private E-2

    will check it out and thanks again. all the best ..
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds