My computer screams...

Discussion in 'Malware Help (A Specialist Will Reply)' started by rubyscye, Feb 14, 2008.

  1. rubyscye

    rubyscye Private E-2

    Ok, this actually started about 3 months ago. I would be working on my computer doing any number of things and it would scream. Now I don't mean hardware noise, or my fan or anything like that. I mean that a .wav or some such would run and a woman's scream would play and be heard from my earphones or speakers. No players (winamp etc) have ever been running when this ocurred. I ran Avast virus scan and spybot seek and destroy, removed some threats and the scream would go away for a few days only to reappear again. I finally reformatted and re-installed windows XP on my computer 1 month ago.

    A little over two week ago, the screaming has returned. And with it came a new ding sound.

    There seems to be no real pattern to when the scream runs, or how often. Sometimes it will not play in an entire day, while other days I'll hear it several times, sometimes twice in a row. I have had different programs open when it occurs (including IE, Word, an online game, AIM, MSN, or nothing but solitaire). But it never seems to always happen with any one program. But I've never had it scream when my computer was just sitting at the desktop with no programs running in the foreground or background.

    The new ding noise is the same. It sounds like a regular windows noise (like when a program is done downloading), but it occurs at random intervals... and it has happened even if the computer is just sitting at the desktop with no programs running in the foreground or background. It will also occur while differing programs are running.

    I have read and followed the instructions in the READ & RUN ME FIRST Before Asking for Support thread. Attached are the files requested.

    Any help is appreciated and if any other information is needed I will endeavor to supply it quickly. Thanks!
     

    Attached Files:

  2. abri

    abri MajorGeek

    Hi rubyscye,
    Do you write horror stories? LOL I'm trying really hard not to laugh LOL (well, not too hard) :D

    Anyway ... I will try to be serious, because I think it could really creepy to have a computer that screams ...

    ... but then of course, ... no, no I won't go there. However, thank you for firing up my imagination!

    I'm looking at your logs and will see if I can find something out of the ordinary that might account for this odd behavior. This takes time, so please be patient.

    abri
     
  3. abri

    abri MajorGeek

    Hi Rubyscye,

    I don't see any obvious signs of malware in your logs. I have a couple of questions.

    The following two folders came onto your computer about the time the screaming started. What do you have in these folders?

    C:\Documents and Settings\Celos\My Documents\My Videos
    C:\WINDOWS\RegisteredPackages

    Did you put this add-on on your computer?

    Skype add-on (mastermind)

    Your computer is not in normal startup mode. Please go to Start / Run and type in msconfig and click on ok. In the window that opens up please put a check in the box next to normal startup. If rebooting is necessary, go ahead and do that.

    After you boot back up, go to the MGTools folder under C and look for the file GetLogs.bat. Double click on this file and allow it to run until you get the message to hit any key to close the window. A set of logs will be produced which you can find just above the superman icon directly under C. Please attach that zip file with your next post.

    Once your computer is in normal startup mode, I would like for you to observe whether the screaming occurs even though you don't open any programs. You mentioned that it does not when you just boot up to the desktop, but if you have startup items which aren't loading, then it's not an accurate picture of where the file might be coming from.

    Finally, I don't see a two-way firewall on your computer. Even if you're sitting behind a router, you need to be able to monitor what programs are trying to connect to the internet as well as from the internet. Please go to How to Protect Yourself from Malware and look for the list of free firewalls. Download and install one of these.


    abri
     
  4. rubyscye

    rubyscye Private E-2

    Hi, thanks for replies... and just on the aside, i DO write little stories on the side (nothing published or professional, just for friends and family) and a few have a horror-twist. ;) It IS funny, so laughing is completely ok with me, after the initial jump when it happens, i start laughing and all kinds of ideas pop in my head...and it is funny when it happens and my friends are nearby to hear it too....lol :D

    Ok back to the matter at hand, the two folders you mentioned. The My Videos is the folder that I guess is installed any time I re-install XP. I do not place things in this folder, usually I forget it's even there.
    Now as to whats inside it.. there's a file I didnt place there called Desktop.ini a configuration setting it says.

    In the C:Windows\RegisteredPackages...which again I don't recall ever placing that on my machine are a bunch of files (149files, 30folders) which looking at them seem to be associated with Microsoft and i believe it's Media Player.

    The skype thing...well I did install Skype, as to anything called mastermind, i dont RECALL it asking for add-ons, but that doesn't mean it didnt.

    Ok, i installed a firewall, the PCtools one, and ran the MGtool's .bat file. It is attached below. I am going to restart my computer and let it sit for a bit and see if my mystery screams make an appearance. Although, it hasnt made a peep while I was installing the firewall and running the .bat file (i had changed startup and restarted as first thing).

    Thanks again for you help, hopefully this will help me as i try to exorcise the souls of the damned from my computer and silence their screams :D
     

    Attached Files:

  5. abri

    abri MajorGeek

    Yes... but I was wondering if you should sell it to the circus for their freak show. lol

    I don't find any signs of malware in your logs. If it doesn't occur after your installation of the firewall, then I will suspect hacking. But for now, let's assume it's still there waiting to start screaming.

    Since this doesn't occur when you just load your computer and you have been running your computer not in normal startup mode but rather in either selective startup or diagnostic mode, that means some startup items have been turned off up to now that will appear in the startup sequence now that you've changed to normal startup mode. What I'd like for you to look at to begin with is whether or not this creature becomes activated when you do nothing but start up your computer in normal startup mode. Your startup will have a few more programs loading than it had before and one of them may contain this.

    After you've tried this to your satisfaction with just booting up and not running any other programs, to where either you hear the scream or not, then I would like for you to go to Start / Run and type in msconfig and change to diagnostic mode. Then make sure that both MSN Messenger and AIM are not loading at startup and go ahead and use your computer normally and see if it comes back again.

    Let me know how this goes.
    abri
     
  6. rubyscye

    rubyscye Private E-2

    oooo, selling to the circus might just be the way to go! lol onder how much i could make.... ;)

    Anyway lol, I will do as you say and try the computer in both normal and diagnostic mode with no odvious programs running. I do know that today it was in normal mode, i had a game running and the creature decided to let itself be known....this was after I had installed the new firewall from PCTools. So hopefully that means no hacking.

    In any case, I'll do a little testing in the two different start-up modes and see what happens. I'll definately be posting again in the next day or so with results! :)
     
  7. rubyscye

    rubyscye Private E-2

    Well, 4 days, 2 as normal startup and 2 at diagnostic startup and the screaming hasn't been heard yet. The weird little ding noise popped up once on normal startup, but also hasn't been back since.

    I dunno. Maybe it's gone. I've done another virus check through Avast which turned up nothing. So, I guess from here, I'll just be seeing if it comes back or hoping it's somehow gone for good.

    On a side note, my internet browsing has slowed. Although it too doesn't happen all the time, so I'm thinking it may not be related at all.

    In any case, thanks for the help. I guess if my computer decides again it wants to audition for the circus freak-shows, I'll be back here asking for more help :)
    Thanks again!
     
  8. abri

    abri MajorGeek

    Don't take less than a hundred grand! They'll make millions ya know!

    I don't know if you actually did anything like with msconfig to try finding the program it might be attached to, but it's possible that your firewall helped.

    Good luck with your computer. Maybe you'll get whale songs next.

    Oh, by the way, some months ago I was thinking it would be good if someone would invent a flash drive that would scream if it got thrown in the wash machine.

    abri
     
  9. rubyscye

    rubyscye Private E-2

    It's me again! Maybe you've got an idea with the flash drive screaming....I should become an inventor perhaps ;)
    Or call the circus, cause yea, it came back.

    I guess I was so happy it was gone I wasn't perpared when it came back and made it's presence known....by screaming twice in a row.

    Worse part was I had IE open (to here ironically, about to reply), MSN up with a chat window open talking to two friends, and AIM as well chatting with another. So now, I feel like i'm back to sqaure one.

    Is it safe to say it maybe one of those 3 programs? Over the last 2 days though, I've had all 3 running (seperately and together) and just now was the first it screamed since last week.

    Maybe I am going to just have to reformat and install these programs one at a time and give each a little while to see if the screaming returns....a real pain the butt process.

    Any other suggestions before I do such?
     
  10. abri

    abri MajorGeek

    Hi rubyscye!
    Welcome back!

    I don't think a reformat is going to help. What Chaslang suggested looking for is if one of the sounds was replaced in one of your messengers (by someone as a joke for instance). You might try using diagnostic startup mode and trying your computer for awhile without these two loading at startup and without running them. You can temporarily download a messenger like Trillian so you can still talk to people. If you go to http://www.majorgeeks.com/ you'll see messaging as one of the choices on the left side of the page. Click on that and scroll down until you come to Trillian. They're in alphabetical order.

    Also, are you using Firefox? If not, load that from the same webpage above, only instead of going to messaging, click on browers and Mozilla Firefox is at the top of the page.

    Also, does your firewall tell you what programs are trying to connect to the internet? Which programs have you given permission to to connect going out and coming in?

    abri
     
  11. rubyscye

    rubyscye Private E-2

    Hi, thanks for the quick reply.

    I will try as you say and switch to something like Trillian and Mozilla for awhile. See if that changes anything. I'll keep MSN and AIM off. With diagnostic startup though, I'll need to manually start-up my anti-virus and firewall won't i?

    Also, yes the firewall gives me a list of programs able to connect...two of which are AIM and MSN. I'm guessing putting them on a block list would be a good idea :)

    I've gone through the files for sound files in MSN and AIM and I haven't come up with anything that's been replaced or sounds like the scream.

    I'll run the computer at those specs and see if it defeats the screaming this time. Thanks once again :)
     
  12. abri

    abri MajorGeek

    Hi rubyscye,
    In diagnostic mode you can choose which programs should load at startup and which should not load. Check the ones you want to load and uncheck the ones you don't want to have load. There are a couple that have to load at startup. When you go to Start / Run and type in msconfig and hit okay, if you have Normal Startup checked and then look at the tabs at the top and select Startup, you'll see that all the items are checked. If you go back to the General tab and check Diagnostic Startup and then look at the Startup tab, you'll see that all the programs are unchecked. Simply check everything except the two messengers.
    abri
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds