Avast WEBforum

Consumer Products => Avast Free Antivirus / Premium Security (legacy Pro Antivirus, Internet Security, Premier) => Topic started by: artscott on July 08, 2012, 05:20:12 PM

Title: Somewhere over the Rainbow Audio Virus?????
Post by: artscott on July 08, 2012, 05:20:12 PM
I just got an audio virus....do not know how or where as I have not downloaded anything or opened any emails that were not scanned........ it is a loop playing some version of "Somewhere over the rainbow" with a male voice and ukulele .... I am currently doing a complete system scann with avast and also with SUPER Anti Spyware ....

This thing is driving me nuts, as I cannot lsiten to anything but that stupid loop.

I do know it is not associated with any one of my 265 open FireFox tabs....i closed all the tabes and browser it was still playing........

Any one got any ideas on how to destroy this thing????
Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: essexboy on July 08, 2012, 05:25:11 PM
Yep ;D

Download aswMBR.exe (http://public.avast.com/~gmerek/aswMBR.exe) ( 4.8mb ) to your desktop.
 Double click the aswMBR.exe to run it  Click the "Scan" button to start scan 

(http://dl.dropbox.com/u/73555776/aswMBRscan.png)

On completion of the scan click save log, save it to your desktop and post in your next reply

(http://dl.dropbox.com/u/73555776/aswMBRlog.png)

THEN

Download OTL (http://oldtimer.geekstogo.com/OTL.exe)  to your Desktop
(https://dl.dropbox.com/u/73555776/OTL_Main_Tutorial.gif)
netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
services.*
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
CREATERESTOREPOINT

Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: artscott on July 09, 2012, 06:46:53 AM
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-08 23:30:50
-----------------------------
23:30:50.653    OS Version: Windows x64 6.1.7601 Service Pack 1
23:30:50.653    Number of processors: 2 586 0x170A
23:30:50.655    ComputerName: KRKONOSE  UserName:
23:31:03.479    Initialize success
23:31:09.468    AVAST engine defs: 12070801
23:31:15.176    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
23:31:15.190    Disk 0 Vendor: ST950042 0003 Size: 476940MB BusType: 3
23:31:15.196    Disk 1  \Device\Harddisk1\DR1 -> \Device\Ide\IAAStorageDevice-2
23:31:15.208    Disk 1 Vendor: WDC_WD50 01.0 Size: 476940MB BusType: 3
23:31:15.219    Disk 2  \Device\Harddisk2\SR0 -> \Device\SdBus-0
23:31:15.224    Disk 2 Vendor: (  Size: 1876MB BusType: 12
23:31:15.268    Disk 0 MBR read successfully
23:31:15.276    Disk 0 MBR scan
23:31:15.282    Disk 0 Windows 7 default MBR code
23:31:15.297    Disk 0 Partition 1 00     DE Dell Utility Dell 8.0       78 MB offset 63
23:31:15.322    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS         9642 MB offset 161792
23:31:15.352    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS       467218 MB offset 19908608
23:31:15.369    Disk 0 scanning C:\Windows\system32\drivers
23:31:40.108    Service scanning
23:32:16.045    Modules scanning
23:32:16.074    Disk 0 trace - called modules:
23:32:16.101    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys
23:32:16.109    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80057c3160]
23:32:16.117    3 CLASSPNP.SYS[fffff8800181743f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004ae7050]
23:32:18.406    AVAST engine scan C:\Windows
23:32:31.132    AVAST engine scan C:\Windows\system32
23:36:43.938    AVAST engine scan C:\Windows\system32\drivers
23:37:12.228    AVAST engine scan C:\Users\ART SCOTT FOTOGRAFIE
23:39:30.948    Disk 0 MBR has been saved successfully to "C:\Users\ART SCOTT FOTOGRAFIE\Documents\aswMBR log\MBR.dat"
23:39:31.150    The log file has been saved successfully to "C:\Users\ART SCOTT FOTOGRAFIE\Documents\aswMBR log\aswMBR.txt"

Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: artscott on July 09, 2012, 06:48:32 AM
Gettin a server busy on the OLT.exe.....
Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: SafeSurf on July 09, 2012, 08:54:40 AM
Please ATTACH your files.  Thank you.

Now I've got that song in my head! :P
Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: artscott on July 09, 2012, 02:11:36 PM
What files do you want me to attach??  And how.....I am not the smartest when it comes to this stuff....sorry.

Why did I not run the "FIX MBR"?

It is all quiet this morning....ran Avast overnight....Of course this thing could have a timer to only run late at night I guess...when I am trying to sleep and have a playlist of favorite music going...that is when I first noticed it...my music was garbled due tho this thing.......

Before i forget...thank you for trying to help....I am a dummy when it comes to this stuff.
Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: essexboy on July 09, 2012, 04:17:24 PM
Hi the main G2G site is down at the moment

Here is a secondary link http://majorgeeks.com/OTL_OldTimers_List-It_d7074.html

Do not fix MBR as Avast is not indicating that to be a problem area
Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: artscott on July 11, 2012, 05:22:01 PM

Do not fix MBR as Avast is not indicating that to be a problem area

ok....clicked on the OTL link above and it started running with out me ticking all the boxes and pasteing in the code for the custom box...since it does not have a stop button...I will try to rerun as spoon as it is done...Thanx for all the help so far.
Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: essexboy on July 11, 2012, 05:29:59 PM
OK G2G is back up now  ;D
Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: artscott on July 11, 2012, 05:57:24 PM
 I THANK YOU FOR THE GREAT HELP...GETTING READY TO RUN.
Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: artscott on July 11, 2012, 06:59:54 PM
rna OTL twice and I onoy get 1 note pad file to save...here it is:
Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: essexboy on July 11, 2012, 07:22:31 PM
OK that has shown me where to go.. This will be a busy fix

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
NEXT

Download the latest version of TDSSKiller from here (http://support.kaspersky.com/downloads/utils/tdsskiller.exe) and save it to your Desktop.
 
 
(http://dl.dropbox.com/u/73555776/TDSSEnd.JPG)
 
Please attach its contents on your next reply.

AND FINALLY

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1  (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here  (http://forums.whatthetech.com/How_Disable_your_Security_Programs_t96260.html&pid=494216#entry494216)
(http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png)

(http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png)

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.



Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: artscott on July 11, 2012, 10:33:24 PM
reading your instructions  you say:  "Run OTL
Under the Custom Scans/Fixes box at the bottom, paste in the following".   Am I supposed to paste in the same code as i did before or the whole of the blue box posted in your response above??   Sorry... I qm not the brightest lamp in the room...
Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: essexboy on July 11, 2012, 11:23:04 PM
Not a problem

Copy and paste just the part in the quote box in the last post as this is the fix
Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: artscott on July 12, 2012, 02:58:06 AM
fix report  and now off the download and run the TDSSKILLER....
Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: artscott on July 12, 2012, 03:21:31 AM
TDSS KILLER REPORT -
Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: artscott on July 13, 2012, 02:56:35 PM
Dobry den ...

I was listening too this little ditty as I posted the above TDSS report file....but I have not heard it since 7-12-2012 at 1PM Central Daylight time (US) .......

Dekuju.
Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: essexboy on July 13, 2012, 03:24:10 PM
Could you post the combofix log please and let me know of any remaining problems
Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: artscott on July 13, 2012, 03:57:24 PM
Was just getting into some David Koller music on Spotify ....and Damn it came back ..... or probably never gone....on my way to appointment i will try to find combpo fix log....when I ran TDSS it only showed one log posted above and the OTL only gave 1 notepad log  posted a few above also.... Sorry... but will look thru when I return in a few hours....

Dekuju!
Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: essexboy on July 13, 2012, 04:06:20 PM
It should be at C:\combofix txt...  If not could you re-run Combofix for me please

This is not an MBR infection so I think I will need to double check your BHO's
Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: artscott on July 13, 2012, 09:29:10 PM
I am such an idiot....I keep stopping at the end of each thing I had to run, not reading the whole dang post you made...my stupidity...here is the combofix log:
Mockrát děkuji!
Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: essexboy on July 13, 2012, 10:10:11 PM
Do you still have the music...  Does it start when you run any specific programme

Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: artscott on July 14, 2012, 01:49:16 AM
right now ... 6:41pm it is not playing......and as far as it coming on with particular program....no...it came on with some Spotify Music or my own wav files (all my CD's were converted to wav, not MP3 ... ... now I need HDD space and need to reconvert to MP3.....) of music or even when watching a DVD movie or if I was trying to do my Foreign Language lessons or on the net......

If it comes back I will let you know....i figure if it is gone for the next 72 hours then I am clean....ot it has some sort of built in calendar or clock... ... ... because when i first heard it it was constant 24hrs a day and that was when I realized that Avast was not showing on my tool bar, then when I got avast back on it was not connected to any account (weird casue I knew I had registered it and found my key code), then it became intermittent as I said previously, I thought it was gone as it had not shown up for over 24 hrs...then it was back as I was really getting in some David Korell ... So I am hoping it is gone for good....

Mockrát děkuji!
Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: essexboy on July 14, 2012, 01:20:09 PM
I wonder if there is a problem within spotify ?

Never used it myself so I could not be sure... But it does seem to be the one consistent area

Any way lets see how it goes

Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: artscott on July 15, 2012, 03:11:58 PM
Dobry den!!

So far all is quiet.......which is great....truly appreciate all the kind help.......I know it can be hard when helping someone like me .....that is computer technically challenged.

Mockrát děkuji!
Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: essexboy on July 15, 2012, 04:00:31 PM
Lets run for one more day to be sure, then if you are happy I will remove my tools ;D
Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: artscott on July 22, 2012, 05:20:47 PM
Well I was all excited...there had been no sign of that damn song ....was ready to give an all clear.....I have no idea where it is or came from or how it hides.....I went thru all of my email accounts and purged everything ..... I closed all 250 of my tabs in FireFox......I have no clue....this thing starts playing when I am in Photoshop or Lightroom......so I have no idea....I am aobut read to do a HDD format.

Thank You EVERYONE for all the help.....
Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: essexboy on July 22, 2012, 05:35:01 PM
So it just re-appeared ?  This does not really make sense... It's not part of a programme is it .. Photoshop, lightroom ?
Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: artscott on July 22, 2012, 09:38:07 PM
no it is not part of any of my programs....if it were it would be causing one heck of a buzz on those forums.....i agree it does not make sense.....well as I said Thanks for all of your help... as I said I guess I will just have to do a HDD format and start loading all software from ground up again....

THANX AGAIN.
Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: essexboy on July 22, 2012, 10:09:36 PM
OH well, I have just found another o these over at Geeks to Go.  So I will be playing with that one now to try and find a solution 
Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: artscott on July 23, 2012, 01:51:34 AM
This is really screwy ...... all I did since last post was to shut down my computer...a quick restart .... and brought all the same programs (spotify, Kindle, and Avast...) and the 250 FF tabs that I had open when I last posted....that restart was a little over a hr ago...all is quiet ................again.....sorta funny....and sorta not....have fun with the one over at Geeks to Go....
Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: mchain on July 23, 2012, 08:06:36 AM
Sometimes when something new/old comes up, the solution can be hard to pin down.  If I had what you have had, it would bother me.  At least for you, it is quiet for now.  As essexboy will be looking for a common link between here and Geeks to Go, once he finds it, you will be good to go.
Title: Re: Somewhere over the Rainbow Audio Virus?????
Post by: essexboy on July 23, 2012, 08:26:11 PM
Aye once the fella gets back to me  ;D