bizzare "Weather Report" virus - ID now?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by hempdidy, Apr 11, 2012.

  1. hempdidy

    hempdidy Private E-2

    Hi all,

    I've not worked my way through the sticky's yet on malware removal. After I do, I'll update this post.

    I was hoping if anyone can ID this problem: I was downloading a large torrent and when it was done, a generic "broadcast" of a few ambiguous weather reports starts coming out of my speakers. The reports come in succession for about 3 minutes and then stop. Every 20 minutes or so, the same "broadcast" starts coming out of my speakers again. There is no program running (that I can easily see) that would cause this and I have never installed any weather software.

    I've run CC Cleaner and Spybot Search and Destroy and AdAware and rebooted. The broadcasts are still coming. I will work my way through the sticky's tonight.

    I find this to be quite an odd thing to happen after downloading a torrent. When I download torrents, I run PC Tools Firewall Plus and Peerblocker.

    Has anyone heard of this "virus" before? Can anyone ID it?
     
  2. thisisu

    thisisu Malware Consultant

  3. hempdidy

    hempdidy Private E-2

    I ran TDSSkiller and nothing malicious was found. The report is attached. Please advise.
     

    Attached Files:

  4. thisisu

    thisisu Malware Consultant

  5. hempdidy

    hempdidy Private E-2

    Here is the Hijack This log (attached): please advise.
     

    Attached Files:

  6. hempdidy

    hempdidy Private E-2

    Here are the results of the Malwarebytes scan: Please advise.

    Malwarebytes' Anti-Malware 1.41
    Database version: 2775
     
    Last edited by a moderator: Apr 11, 2012
  7. thisisu

    thisisu Malware Consultant

    Read and follow these directions: READ & RUN ME FIRST Malware Removal Guide
     
  8. hempdidy

    hempdidy Private E-2

    Here is the UPDATED result of the malwarebye scan: Please advise.

    Malwarebytes Anti-Malware 1.61.0.1400
    www.malwarebytes.org

    Database version: v2012.04.11.07

    Windows XP Service Pack 3 x86 NTFS
    Internet Explorer 7.0.5730.13
    Owner :: POWERSLAVE2 [administrator]

    4/11/2012 8:52:57 PM
    mbam-log-2012-04-11 (20-52-57).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 181899
    Time elapsed: 3 minute(s), 13 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)
     
  9. hempdidy

    hempdidy Private E-2

    Sorry for the stutter step. Did you get my updated malwarebytes log?

    ATTACHED is my rootrepeal log. Is it helpful?
     

    Attached Files:

  10. hempdidy

    hempdidy Private E-2

    UPDATED correct version of malwarebytes log attached:
     

    Attached Files:

  11. thisisu

    thisisu Malware Consultant

    Keep on going through the instructions. I would prefer if you would attach the remaining logs in one post.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds