also @ TechSpot: Codemasters announces £125,000 special edition of GRID 2

Random audio clips and random pop-ups

Discussion in 'Virus and Malware Removal' started by AKFH, Jul 28, 2010.

  1. Broni Malware Annihilator Posts: 39,398   +177

  2. AKFH Newcomer, in training Posts: 106

    Not yet. But I don't think we (me and Bobbye) ever went over cleansing the Viruses. But no pop-ups or sounds has been produced, but it randomly happens unaccordingly and untimely. So I don't know whether they are gone or they're just not acting up.
  3. Broni Malware Annihilator Posts: 39,398   +177

    Let's recheck one more time.

    Update Malwarebytes, run "Quick scan" and post new log.

    Please download ComboFix from Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
      • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"
    **Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

    Make sure, you re-enable your security programs, when you're done with Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
  4. AKFH Newcomer, in training Posts: 106

    I don't have Malwarebytes
  5. Broni Malware Annihilator Posts: 39,398   +177

    Hmmm...OK...

    Download Malwarebytes' Anti-Malware (aka MBAM): http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform quick scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    Be sure to restart the computer.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  6. AKFH Newcomer, in training Posts: 106

    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 4397

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 7.0.5730.13

    06/08/2010 1:58:38 AM
    mbam-log-2010-08-06 (01-58-38).txt

    Scan type: Quick scan
    Objects scanned: 172460
    Time elapsed: 13 minute(s), 11 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
     
  7. Broni Malware Annihilator Posts: 39,398   +177

    Looks good :)
  8. AKFH Newcomer, in training Posts: 106

    I will do ComboFix tomorrow morning. I am EST time, Ontario Canada. I hope it isn't a problem. It's 2:01AM here and my mom wants me to go to bed now. She is really annoying. I apoligise for the sudden leave. I hope you forgive me, since I do know of Bobbye's sudden disappearance for Personal Affairs, you are very very busy, and may be frustrated due to many other people who need help. Forgive me for my dis-loyalty.

    Good night for now, Broni, and I thank you for taking up my case with haste right when Bobbye left. Thank you so much.

    ;Anthony
  9. AKFH Newcomer, in training Posts: 106

    Last time it looked like that, pop-ups where still going and audio was still up etc etc. So I never trusted Malwarebyes.

    Tomorrow, we can talk more.

    Thank you for the rapid reply! Apologies from me, Good night Broni :)



    EDIT: Not never trusted, all the other Anti-Viruses never caught anything either..... it was wierd. Explain tomorrow. THANK YOU!
  10. Broni Malware Annihilator Posts: 39,398   +177

    No problem :)
    See ya tomorrow :)
  11. AKFH Newcomer, in training Posts: 106

    Too long to post. Same reason (is more than 20000 characters) So I attached it.

    Attached Files:

  12. AKFH Newcomer, in training Posts: 106

    Yes so, I used to have around 3-4 anti-viruses and they detected NOTHING. Even when the Pop-ups and Audio sounds were active. It discovered nothing. Which is why I started to run them in Safe Mode (With Networking) [I did not try Safe Mode (with nothing)] It found 2 Back Door Trojans and it deleted it. I thought it would mean the end, but it did not. So after that, I really didn't trust my Anti-Viruses.

    Also, when after all of this is done, would you kindly link me up to a trusted Anti-Virus you use or would use for me to download?

    1 Paid and 1 Free? So I can decide. Thank you very much!
  13. Broni Malware Annihilator Posts: 39,398   +177

    Your computer was infected with a bootkit (fixed already), which was causing your main problems.
    Regular AV, or antimalware programs will NOT detect bootkits.
    That's why, we use a whole set of tools to make sure, your computer is clean.

    Also, there is no perfect security tool.
    The most important security tool is your brain and your computer habits.

    Now, do you have any antivirus program installed and current at this moment?

    Combofix reports:
    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

    With malware infections being as they are today, it's strongly recommended to have the Windows Recovery Console pre-installed on your machine before doing any malware removal.

    The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.


    Go to Microsoft's website => http://support.microsoft.com/kb/310994

    Select the download that's appropriate for your Operating System

    [IMG]


    Download the file & save it as it's originally named.


    ---------------------------------------------------------------------

    Transfer all files you just downloaded, to the desktop of the infected computer.

    --------------------------------------------------------------------


    Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

    [IMG]


    • Drag the setup package onto ComboFix.exe and drop it.

    • Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console.


      [IMG]


    • At the next prompt, click 'Yes' to run the full ComboFix scan.

    • When the tool is finished, it will produce a report for you.
    Please post the C:\ComboFix.txt.
  14. AKFH Newcomer, in training Posts: 106

    Recovery Console:
    I have tried that. Using SP2 to drag it in. Mine is a SP3, and you said it is the same as SP2. But it doesn't work. It keeps saying Boot enumoration error or some message along those lines I dragged it in 3 times.

    Anti-Viruses:
    Currently, besides Malwarebytes which you instructed me to re-install after Bobbye told me to un-install it. What would you suggest up toy our experience?
  15. Broni Malware Annihilator Posts: 39,398   +177

    OK. We'll leave recovery console for now.

    Malwarebytes is a program to keep. Currently, the best free antimalware tool, you can get.

    If you didn't use AVG Remover: http://www.avg.com/us-en/download-tools to uninstall AVG, please do it now, so we're are sure, there are no leftovers.
    If you did use it, you're fine.

    Download and install ONE of these:
    - Avast! free antivirus: http://www.avast.com/eng/download-avast-home.html
    - Avira free antivirus: http://www.free-av.com/en/download/1/avira_antivir_personal__free_antivirus.html

    When done, re-run OTL and give me fresh log.

    Also, disregarding any past issues, are there any current problems with your computer?
  16. AKFH Newcomer, in training Posts: 106

    No, i think it should be fine for now.

    Which would you prefer me to use? first download or second?
  17. AKFH Newcomer, in training Posts: 106

    And how do I get rid of all the cleaning tools
  18. AKFH Newcomer, in training Posts: 106

    Theree. OLT.

    Attached Files:

    • OTL.Txt
      File size:
      84.9 KB
      Views:
      1
  19. Broni Malware Annihilator Posts: 39,398   +177

    Good :)

    Both programs are pretty much equal. I use them both on different computers.

    We'll remove cleaning tools at certain point.

    Let me review your log.
  20. Broni Malware Annihilator Posts: 39,398   +177

    I don't see any AV program running.
    Install one and THEN post fresh OTL log.

    Also....

    Update your Java version here: http://www.java.com/en/download/installed.jsp

    Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

    Now, we need to remove old Java version and its remnants...

    Download JavaRa to your desktop and unzip it to its own folder
    • Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
    • Accept any prompts.