Author Topic: Audio advertisements occuring whether there are programs running or not....  (Read 4455 times)

0 Members and 1 Guest are viewing this topic.

GodlyChepsky

  • Guest
Hello, I have been getting audio advertisements in the background while I am using my computer. They are invisible ads that vary from time to time. Also, my avast or any antivirus software I have will not/can't scan my PC. The only exception to this is Malwarebytes, which is the only program I can use right now to scan my PC. Any suggestions or help is appreciated!

I have an attachment that shows my Malwarebytes log, which I just got today.

jeffce

  • Guest

Hi and welcome!

Please visit the site located here.  Follow the directions
for running OTL, aswMBR.exe and Malwarebytes and then attach the logs that are created to your next reply.  :)

GodlyChepsky

  • Guest
Thank you for the quick reply!

Here are the logs you asked for.

jeffce

  • Guest
Hi,

**WARNING**Unfortunately one or more of the infections I have identified are Backdoor Trojans, IRCBots or other Malware capable of stealing very important information. You need to stop using all Internet Banking sites, change passwords to all sites with sensitive information from a clean computer and phone your bank to inform them that you may be a victim of identify theft. More often than not, we advise users that a full reinstallation of their Operating System is the only way to ensure that their computer will ever be 100% clean again.

Unfortunately I have found what is known as the ZeroAccess rootkit on your system. It is an especially nasty infection that can take quite some time to clean as well as may have damaged your system files itself. As a warning, during the cleaning (if you choose to do so) you may lose internet access with this computer and in the end we may need to reinstall the operating system anyway depending on the extent of the infection.

If you would like to format and reinstall your Operating System please let me know and we can assist you with that.

If you would like to continue with the cleaning, please continue with the following instructions and I will be more than happy to help.  :)
----------

Please download and run ERUNT (Emergency Recovery Utility NT).  This program allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.  **Remember if you are using Windows Vista as your operating system right-click the executable and Run as Administrator.
----------

If you are running Malwarebytes 1.6 or better, please disable it for the duration of this run.

To disable Malwarebytes
  • Open the scanner and select the Protection tab
  • Remove the tick from "Start Protection Module with Windows" as seen below


Once complete continue with the instructions...
----------

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

Code: [Select]
:Services

:Files
C:\windows\Installer\{3b99f81f-31d5-dbab-1bcf-87d0107a285a}
C:\Users\Heinrick\AppData\Local\{3b99f81f-31d5-dbab-1bcf-87d0107a285a}

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
----------

Download Combofix from the link below, and save it to your desktop. 
Link

**Note:  It is important that it is saved directly to your desktop**
 If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.


--------------------------------------------------------------------

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

--------------------------------------------------------------------

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
    When finished, it will produce a report for you. 
  • Please post the C:\ComboFix.txt for further review.
----------

Please attach the logs made by OTL and ComboFix. 

GodlyChepsky

  • Guest
If I reinstall my operating system, will it completely wipe out any of the malware mentioned in your post?

If I do continue with the cleaning, will it also completely wipe out the malware?

jeffce

  • Guest
If you were to decide to completely wipe your system, you will remove the malware that is there. 

If you decide to continue cleaning,  I can not give you any absolute guarantees that it will be completely gone due to the backdoor capabilities of this infection; however, we are able to cure about 75% of the cases involved with this infection.

GodlyChepsky

  • Guest
Then, I would like to format and re-install my OS, please.  ;)

jeffce

  • Guest
Ok.....

Get your Windows installation disk ready as we will need this... Now be sure to save all pictures, music and personal files you want to keep to a CD. 

Then you can go to the site here >> http://howtoformatacomputer.com/format-windows-7  and this will guide you through step-by-step.  :)

GodlyChepsky

  • Guest
Thank you so much for your help! I am using a chromebook as of right now, while I am reinstalling windows on the affected computer.

I just want to know how I can prevent this from happening again because it is such a hassle for me since I am in college. Any advice on antivirus softwares to use would be appreciated.   ;D

One more thing, do you know the source of the malware that infected my PC? Thanks in advance!  ;)

EDIT: Can I use DataSafe Local Backup to format and clean up the malware?

-GodlyChepsky
« Last Edit: July 12, 2012, 11:05:42 PM by GodlyChepsky »

jeffce

  • Guest
Quote
Thank you so much for your help!
You are more than welcome!  :)
----------

Quote
I just want to know how I can prevent this from happening again because it is such a hassle for me since I am in college. Any advice on antivirus softwares to use would be appreciated.
The absolute best way to help prevent an infection like this is to practice safe internet usage.  The infection you got is bad but not unbeatable; however, I would have done the same thing you are right now by formatting my computer and starting over.  As for any antivirus software, I would recommend Avast hands down.  It seems to be having extremely early detection rates compared to other software (that is just my opinion though).  I would also use Malwarebytes like you used before on a weekly basis as well as have a firewall that you use.
----------

Quote
One more thing, do you know the source of the malware that infected my PC?
That is really hard for me to say with any certainty.  You could have gotten it a month ago and it was sitting dormant for a while so it is just difficult to tell you....sorry.
----------

I would just use the Windows disk to perform a complete format.  Be sure to save files, pics, music and personal files (that you created) before you format your system though.  Any type of software that you had on your system you will need to download fresh.