Hearing ads in the background after startup

Discussion in 'Malware Help (A Specialist Will Reply)' started by jono428, Aug 1, 2012.

  1. jono428

    jono428 Private E-2

    Hello.. after getting this laptop from Christmas I followed your advice for new computers and avoiding malware. But it looks like I got something anyway. Tried CCleaner and Malwarebytes but it is still happening. You guys are the best so I'm turning to you for help.

    After startup non stop random ads start playing in the background with nothing in the task manager. Running Windows 7 Premium 64-bit SP1

    Thank you for your help,
    Jono
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I want you to run TDSSKiller so refer to the below for how to do so. (DO NOT just quit after running TDSSKiller and MBRCheck, there is MUCH more to do, scroll further down and follow the Read and Run Me First Malware removal procedures link.)

    TDSSkiller - How to run


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.




    Now do not stop, please continue on with the below instructions too! :)

    v
    V
    V
    V
    READ & RUN ME FIRST. Malware Removal Guide
     
  3. jono428

    jono428 Private E-2

    It has been several hours since completing the list of tasks and I am not experiencing any of the previous symptoms.. . Here are the logs in case it helps

    Thank you so much for your help
     

    Attached Files:

  4. jono428

    jono428 Private E-2

    MBRCheck and
    TDSSkiller
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're in pretty good shape.

    Re-run TDSSKiller and have it fix this that you previously skipped.

    Re run again and attach the new log.



    If you did not deliberately set this proxy yourself then please include it in the HJT fix further below:
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    Run C:\MGTools\analyse.exe again and do a system scan only and save a log file. Attach it here for me to see.
     
  6. jono428

    jono428 Private E-2

    Thank you again.. . Completed the steps and here are the logs you requested.. .

    Your help is greatly appreciated.. Thank you
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    All is running well at this point I trust? :)
     
  8. jono428

    jono428 Private E-2

    Yes very much so.. Thank you again for your time
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  10. jono428

    jono428 Private E-2

    After finishing up the cleanup procedures I re-ran Malwarebytes and Spybot and they keep coming up with svchost.exe and Smitfraud-C.generic respectively after a few removals and restarts they keep coming up. Any suggestions?

    Thank you..
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Locations of these threats please? And exact file path.
     
  12. jono428

    jono428 Private E-2

    Malwarebytes found 2.. File and Memory Process both in C:\Windows\svchost.exe

    Spybot
    Smitfraud-C.generic: [SBI $5926A588] Executable C:\Windows\svchost.exe
    After choosing to 'Fix selected items' it says 'Zip file could not be opened' after clicking OK another message says 'This archive is not a valid Zip archive' then click OK and a message says '1 problems fixed'

    Avira
    Pops up once you click 'Fix selected items' and shows SmitfraudCgeneric.zip \\.\globalroot\systemroot\svchost.exe
    [WARNING] The file could not be opened!
    C:\ProgramData\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip
    [WARNING] The file is password protected

    Thank you. I hope this is what you were looking for.
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Malware Bytes and if it detects it again I'll organise a small fix.
     
  14. jono428

    jono428 Private E-2

    Yes still detecting after restart..
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Rerun Malwarebytes... all ok?
     
  16. jono428

    jono428 Private E-2

    No luck. . Should I run any of the previous programs again?
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    http://img827.imageshack.us/img827/1263/frst.gif For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    To enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    • Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
     
  18. jono428

    jono428 Private E-2

    Thank you.. Attached is the log. The computer has been having trouble waking from sleep.. It would go to Startup Repair and continue to scan seemingly forever. Until I finally just force shutdown and restart.
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK let's get to work again, this has been a stubborn one.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Now attempt to boot normally.

    -------------------------------

    • Now re-run RogueKiller - no fix just a scan and attach the log.
    • Re-run FRST - no fix, just a scan and attach the log.
    • Let me know how things are running at this point.
     

    Attached Files:

  20. jono428

    jono428 Private E-2

    Yes very stubborn.. Thank you again for the help. Here are the logs.

    After a reboot and a Malwarebytes scan it's still detecting the svchost.exe
     

    Attached Files:

  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Right, we are going to run Combofix.

    Please download Combofix to your desktop, make sure that you refer to these instructions prior to running the tool. Attach the log once you are done.
     
  22. jono428

    jono428 Private E-2

    I believe the combofix log says it deleted svchost.exe but after a reboot and a scan, Malwarebytes it is still detecting it.. This is the most stubborn file I've ever seen..
     

    Attached Files:

    • log.txt
      File size:
      21.2 KB
      Views:
      2
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please disable Spybot's TeaTimer.

    How to disable Spybot's TeaTimer

    Now Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following.

    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. See if you can save a log with it.

    Now run Combofix again and let me see the new log.
    Re scan with Malware Bytes to see if the pest is still there.

    Also try downloading TDSSKiller from scratch, overwrite old version, run new and attach results.
     
  24. jono428

    jono428 Private E-2

    Ran the first Rkill.exe and it detected and deleted a file .. I apologize I do not remember the name or file path. I saved the log but after running Rkill.com and Rkill.scr they both did not detect anything and replaced the log from the first kill.

    Rkill.pif was a dead link.

    Superantispyware only found cookies.

    Combofix deleted svchost.exe again BUT!!! this time after a Malwarebytes scan IT WASN'T DETECTED...

    TDSSKiller log attached

    Going to put the computer to sleep now and hopefully it wakes with no problems.. That will be the ultimate test... Thank you again for such dedicated help.. .
     

    Attached Files:

  25. jono428

    jono428 Private E-2

    SUCCESS!!! Awoke flawlessly.. .

    Thank you again for all your help.. The time and patience you spend with each individual to work out their problems deserves the praise of all the world wide web.. . THANK YOU!!!
     
  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Jono! Bit more to do.

    Re run TDSSKiller and have it fix this that you previously skipped.

    Re run again and attach new log to prove it's gone.
     
  27. jono428

    jono428 Private E-2

    Yup, It's gone...
     

    Attached Files:

  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What is Malware Bytes saying? Still good results? :)
     
  29. jono428

    jono428 Private E-2

    Clean results
     
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Excellent, you can follow those final steps again. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds