Audio advertisement Virus??

Discussion in 'Malware Help (A Specialist Will Reply)' started by dogmoat, Jun 22, 2012.

  1. dogmoat

    dogmoat Private E-2

    About a month ago we had a redirect virus that we deleted successfully. All was fine until about a bout a week ago when my computer started repeating an audio advertisement/propaganda track. Even when I turn off the internet, it continues playing. I ran a malwarebytes scan and the results state three different malicious items:
    1-- file trojan agent on windows\svchost.exe
    1-- memory process trojan agent on windows\svchost.exe
    1-- PUP.toolbardownloader
    Several instances I have tried to delete the malicious items with now success. They keep coming back.
    Any solutions on how to get rid of this would be appreciated.

    Thank you
     
  2. thisisu

    thisisu Malware Consultant

  3. dogmoat

    dogmoat Private E-2

    Tahnk you for your response. The TDSS Killer detected rootkit.boot.pihar.c on physicaldrive:\device\hardisk0\DRO. Scan is attached.
     

    Attached Files:

  4. thisisu

    thisisu Malware Consultant

    Hello,

    Now that Pihar.C appears to be gone, rescan with TDSSKiller and also delete the TDSS File System. Skip all other detections.

    Attach this log when finished.

    Then continue with thh Read and Run Me First.
     
  5. dogmoat

    dogmoat Private E-2

  6. thisisu

    thisisu Malware Consultant

    Hello,

    Can you retry attaching the the HitmanPro log?
    Are you still experiencing the repeating of an audio advertisement/propaganda track?
     
  7. dogmoat

    dogmoat Private E-2

    I am unable to attach the hitman log as it is in a .xml file.

    However, my computer is working just fine now. the virus is gone. :-D


    thank you-- Julie
     
  8. thisisu

    thisisu Malware Consultant

    You're welcome :)

    If you are not having any other malware related problems, it is time to do our final steps:
    • Any programs we had you download and/or install can be removed at this time.
    • If we had you download and run ComboFix, here is how to uninstall it:
      • Press and hold the Windows key http://i1106.photobucket.com/albums/h363/debojyotidas/Windows_Logo_key.gif and then press the letter R on your keyboard.
      • This opens the Run dialog box.
      • Copy and paste the below text inside the text-field:
        • "%userprofile%\desktop\ComboFix" /uninstall
      • Now press ENTER
      • ComboFix will extract its files one last time and you should receive a notification that ComboFix has been uninstalled shortly after.
    • You can re-enable your Disk Emulation software at this time via DeFogger.
    • If we had you create or download a registry patch or "fix" script, these can be deleted at this time.
    • Go into the C:\MGtools folder and run the MGclean.bat file to remove additional traces of our tools.
    • Now we will toggle System Restore to remove any infected system restore points.
    • Lastly, here is a guide to protect you from future infections: How to Protect yourself from malware!
    • Be safe :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds