Volume gets muted and invisible ads?

Discussion in 'Malware Help (A Specialist Will Reply)' started by TPB, Jul 4, 2010.

  1. TPB

    TPB Private E-2

    I have seen a few other users noticing this problem. I'm completely clueless when it comes to computers, so i did my best following all of the malware removal instructions.

    Basically I use Google Chrome, and after downloading a file (music file) I've begun getting my volume muted and programs minimized, ads about 'Easy-off BAM' and Free Iphones appear. I am then left manually increasing the volume in order to hear anything again and closing the ads.

    I've attached all my logs and done all the scans etc. Nothing seems to be removing my problem. So if anyone could give me a helping hand, it would mean the world to me :)

    P.S If I'm missing ANYTHING, please let me know, i'll do my best to upload anything of use
     

    Attached Files:

  2. TPB

    TPB Private E-2

    Oh, here is the MGTools log thing.
     

    Attached Files:

  3. TPB

    TPB Private E-2

    I've run all the anti virus recommended, however the problem still persists.
     
  4. TPB

    TPB Private E-2

    I'd like to THANK TIMW for all the help. I believe the problem is now fixed :p

    I've attached the logs as well.
     

    Attached Files:

    Last edited: Jul 4, 2010
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Questions:

    a) What do you know about this running service and corresponding file?
    b) You used this script on 4th july
    Why did you run this script? Is this why you are thanking TimW because you followed advice from another thread and tried to do things on your own?

    c) Do you know anything about the below website?

    1. Did you install this knowingly?

    WinPcap 3.1 <-- if not then please uninstall it.

    2. Please uninstall this outdated version of java:

    • Java(TM) 6 Update 17

    3. SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      srsvc.dll
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt

    4. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    c:\documents and settings\Downloads\~WRL2219.tmp
    C:\Documents and Settings~WRL0732.tmp
    
    FileLook::
    c:\windows\system32\drivers\presafe.sys
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    5. Could you please get this: presafe.sys into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:

    log retrievable @ C:\collect.zip

    6. Please go to Jotti's malware scan

    (If more than one file needs scanned they must be done separately and logs posted for each one)
    • Copy the file path in the below Code box:
      Code:
      c:\windows\system32\drivers\presafe.sys
    • At the upload site, click the browse button.
    • Use Windows Explorer to navigate to the file(s) we need scanned and click "submit file"
    • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    • This will perform a scan across multiple different virus scanning engines.
    • Important: Wait for all of the scanning engines to complete.
    • Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.

    Then do the same for the below files and also let me know the results:

    Code:
    c:\windows\System32\srsvc.dll
    8. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    9. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also include the results from jotti, the systemlook log, the collect.zip and address any questions I may have asked.
     
  6. TPB

    TPB Private E-2

    Hey KEstrel

    Here are some of the logs you asked for.

    Answers to your questions:


    a) I am not sure about that, nor do i have any idea what that is :S
    b) Oh, TimW messaged me by email step by step instructions a few days ago, i could send you what he told me to do if you want.
    c) that website i have never seen before.
     

    Attached Files:

  7. TPB

    TPB Private E-2

    Sorry for double post, i forgot to attach another Log.

    Apologies :-o
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there, don't forget the collect.zip. :) Attach it if you have it and I will get back to you with a response in the morning. It's past 4am here and I am sleepy now.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I did???:confused
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I thought this sounded bizarre.

    @ OP... you only included the results for srsvc.dll from jotti, please also include the results from the second file we wanted scanned and don't forget that collect.zip. Are you still with us? :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds