Invisible Ads and Wave Mute

Discussion in 'Malware Help (A Specialist Will Reply)' started by bht, Jul 15, 2010.

  1. bht

    bht Private E-2

    Hi

    It looks like I am getting the same problems as a few others on here. I keep hearing invisible ads and my wave gets muted. It started hapening about a week ago.

    I've ran the tests but that didn't work so I have attached my logs.

    Hope you can help.

    Many Thanks

    BHT
     

    Attached Files:

  2. bht

    bht Private E-2

    and here is the MGTools log.

    Thanks
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Your infection is in your Master Boot Record (MBR). We need to see the below log before creating a fix.
    • Download bootkit_remover.rar
    • Click the underlined DOWNLOAD text to download the file and save it to your Desktop.
    • You then need to extract the remover.exe file from the RAR using a program capable of extracing RAR compressed files. If you don't have an extraction program, you can use 7-Zip
    • After extracing remover.exe to your Desktop, double click the remover.exe file to run the program.
    • Attach or post inline here, the output from remover.exe
    NOTE: The Command Prompt window text can be copied to the clip board by right clicking on the top bar of the window and using the Edit commands to Mark, Copy, and Paste.


    Also I need to ask some questions:
    1. Do you have any drives that has a non-windows installation on them
    2. Are all drives NTFS formatted
    3. Do you have any non-standard or special MBRs which can occur from companies like Dell or HP who frequently install additional partitions used for recovery partitions in lieu of giving CD/DVDs.
    4. Is any program like Grub ( see:http://www.gnu.org/software/grub/ ) being used
    5. Is drive-encryption being used?
    6. Are any drives external USB pen drives or external hard drives being used?
    7. VERY IMPORTANT: Do you have all important data backed up? You really should do this before continuing since we will need to rewrite your MBR to fix this and while most times this can be done without any problem, these infections can react badly and that could result in a PC not being bootable. You really don't have much choice though since these infections are too dangerous to your security to leave on a PC.
     
  4. bht

    bht Private E-2

    I have attached the bootkit log.

    To answer your questions -

    1 - No
    2- Drives C and D are- Drive E (back up) is FAT32
    3 - No
    4-No
    5-No
    6 -yes

    Thanks
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thus for example with remover.exe on the Desktop and assuming the physicaldrive0


    • Click Start, Run and copy and paste the below into the Run box and click OK.

    • Now reboot your PC and after reboot continue with the below instructions.
    • Run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. bht

    bht Private E-2

    Hi

    I ended up doing a full system restore (Not sure if that's what I was supposed to do?)

    I've attached the mglogszip file.

    Everything seems to be working fine now.Been listening to music and the volume has stayed constant and I'm not getting any invisible popups.

    Thanks for all your help :)
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it was not!

    A System Restore will not remove the infection from your Master Boot Record. So did you mean you did a System Restore or did you do a System Recovery which means you reimaged your system back to a factory recovery partition?
     
  8. bht

    bht Private E-2

    oops!!

    I did a system recovery, everything went back to the original factory settings.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's what I suspected since you implied the problem was gone.


    You should work thru the below now.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    8. After doing the above, you should work thru the below link:
     
  10. bht

    bht Private E-2

    done all that and all OK so thanks to you and Kestrel13 for all your help.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds