Where does the phantom music come from

Page 4 of 6 FirstFirst ... 23456 LastLast

  1. Posts : 42
    Microsoft Windows 7 Professional 64-bit 7601 Multiprocessor Free Service Pack 1
    Thread Starter
       #31

    Bill,

    I have run the scanners suggested by Layback and used them to remove malware, except for nircmd.exe and install.rdf. Results are attached. No reply from VoiceTeach yet, but I think it was probably a false positive for nircmd.exe.

    Viv

    Scan_2014-3-7-12-30.txt
    AdwCleaner[S2].txt
    AdwCleaner[S1].txt
    AdwCleaner[R11].txt
    AdwCleaner[R10].txt
    AdwCleaner[R9].txt
      My Computer


  2. Posts : 42
    Microsoft Windows 7 Professional 64-bit 7601 Multiprocessor Free Service Pack 1
    Thread Starter
       #32

    Bill,

    Sorry, I forgot the Malwarebytes log. Thanks to all who have offered suggestions.

    Viv

    mbam-log-2014-03-07 (08-44-10).txt
      My Computer


  3. Posts : 6,458
    x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
       #33

    Thanks for posting the logs Viv,

    Mbam and AdwCleaner look clean. Two more just to make sure:

    Restart your machine in case there are any system operations pending

    Click here to download Old Timer-TFC.
    >> save the application to your Desktop.
    Old Timer-TFC is a standalone application, there is no install.

    Save your work and close all open windows.
    TFC will close ALL open programs including your browser!

    Old Timer-TFC resets Folder Options -> View -> Hidden files and folders to Don't show hidden...

    Right click TFC and select, Run as administrator from the alternate menu.

    Click the Start button to begin the cleaning up temporary files and folders.
    Do not work on other things while TFC is running - most applications use some sort of temporary files. Just let TFC run by itself on the machine until it completes.

    If TFC prompts you to restart, do so immediately.
    If TFC does NOT prompt you, then restart your machine immediately after TFC has completed.




    Run herdProtect one more time (see post# 15 - you don't have to download it again, just scan)

    Please post the log and if it's clean, I think you're done.
    Leave the thread open for a few days and when you feel that the issue is resolved, please mark the thread as solved.

    Thanks,

    Bill
    .
      My Computer


  4. Posts : 42
    Microsoft Windows 7 Professional 64-bit 7601 Multiprocessor Free Service Pack 1
    Thread Starter
       #34

    Bill,

    I have done as you suggest and attach the herdProtect results.

    Thanks again,

    Viv

    Scan_2014-3-8-22-50.txt
      My Computer


  5. Posts : 6,458
    x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
       #35

    Thanks,

    There are a few entries that concern me

    easyfundraising toolbar - conduit reference.
    Uninstall it in CPL - > Pgm & Feats
    and uninstall any tool bars - I thought this was already done - perhaps it was and the malware re-established itself.

    c:\program files (x86)\asus\axsp\1.00.19\pebiosinterface32.dll
    Anything asus on your machine?

    c:\users\viv\appdata\local\temp\install_hosts_anti-adware.exe
    Old Timer-TFC should have cleaned up every temp location.

    Download the Farbar Recovery Scan Tool (FRST) Click here
    1. Select the version that applies to your system: 32-bit OR 64-bit
      .
    2. Click the Save button
      Default save location is your Downloads folder
      If the SmartFilter bar is presented, click the Actions button and click Don't Run (saves FRST but does not run it)
      .
    3. Double-click FRST or FRST64 to launch the utility
      FRST is the 32-bit version / FRST64 is the 64-bit version
      1. Click the Yes button to confirm UAC
        .
      2. Click the Yes button on the Warranty disclaimer window.
        .
      3. Tick [a] all Whitelist checkboxes
        .
      4. Tick [a] Addition.txt in the Optional scan list
        .
    4. Click the Scan button to begin scanning.
      .
    5. FRST creates two logs when the scan has finished, they are located in the same folder where FRST was launched

      Exit out of Farbar


    I don't know this tool well enough to advise you past a scan.
    Do NOT experiment with FRST - the wrong line in the wrong place can rick your system.
    A simple scan is safe.

    I'll ask a member of the Security team to look at the output and they can determine what, if any, tool is needed next.

    Thanks
      My Computer


  6. Posts : 42
    Microsoft Windows 7 Professional 64-bit 7601 Multiprocessor Free Service Pack 1
    Thread Starter
       #36

    Slartybart said:
    easyfundraising toolbar - conduit reference.
    Uninstall it in CPL - > Pgm & Feats
    and uninstall any tool bars - I thought this was already done - perhaps it was and the malware re-established itself.
    I have now done this as I have realised that I do not use it.

    c:\program files (x86)\asus\axsp\1.00.19\pebiosinterface32.dll
    Anything asus on your machine?
    My MoBo.

    c:\users\viv\appdata\local\temp\install_hosts_anti-adware.exe

    Old Timer-TFC should have cleaned up every temp location.
    I have run Old Timer again but there are still 32Gb of files in c:\users\viv\appdata\local\temp\, including about 35 .tmp files, although the install_hosts_anti-adware.exe file is no longer there.


    Download the Farbar Recovery Scan Tool (FRST)
    I have done this, (just before running Old Timer for the second time), and the results are attached.

    Viv

    Addition.txt

    FRST.txt
      My Computer


  7. Posts : 6,458
    x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
       #37

    Ok, thank you. I've done a cursory look at FRST and there's not much that I saw, but I'll ask for a second opinion from the Sec team.

    I want to make sure your system is clean, the FRSt says your home page is easyfundraising.uk.org and I thought that should have been corrected by the reset. That and the 2nd run of herdProtect showing some remnants.

    ASUS: Oops... of course it's your Mobo

    The music is still gone - right?

    Thanks for all of your excellent feedback.


    I've collected all of your logs/screenshots and placed them here in chorological order
    1. Post# 16: herdProctect screenshots
    2. Post# 18: AdwCleaner[R7].txt
    3. Post# 20: AdwCleaner[R8].txt
    4. Post# 31:
      1. herdProtect log
      2. AdwCleaner [S1].txt
      3. AdwCleaner [S2].txt
      4. AdwCleaner[R9].txt
      5. AdwCleaner[R10].txt
      6. AdwCleaner[R11].txt
    5. Post# 32: Mbam log
    6. Post# 34: herdProtect log
      >> also ran Old timer-TFC at this point - no log
    7. Fabar logs from post# 36
      1. FRST.txt
      2. Addition.txt
    Hopefully this will save some time looking through the thread.


    Bill
    .
    Last edited by Slartybart; 11 Mar 2014 at 13:01.
      My Computer


  8. Posts : 8,608
    Windows 7 Ultimate 32bit SP1
       #38

    I have run Old Timer again but there are still 32Gb of files in c:\users\viv\appdata\local\temp\, including about 35 .tmp files, although the install_hosts_anti-adware.exe file is no longer there.
    It looks like these temp files are in "Quarantine".


    Download Combofix from any of the links below, and save it to your desktop.<--Important
    Link 1
    Link 2
    Link 3


    Click on this link Here to see a list of programs that should be disabled.
    The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    If your anti-virus or firewall complains, please allow this script to run as it is not malicious.
    Next: Disconnect from the internet. If you are on Cable or DSL, unplug your computer from the modem.
    Next: Please disable all onboard security programs (all running with back ground protection) as it may hinder the scanner from working.

    This includes Antivirus, Firewall, and any Spyware scanners that run in the background.
    • Double click combofix.exe and follow the prompts.
    • When finished, it will produce a log for you. Post that log.
    Note: Do not mouseclick combofix's window while its running. That may cause it to stall
    Please be patient while the scan runs, at times it may appear to stall.
    When finished and after reboot (in case it asks to reboot), it should open a log, combofix.txt.
    Post this log in your next reply.
    After rebooting ensure your Security applications have been re-enabled.

    In your next reply post:
    ComboFix.txt

    ***A guide and tutorial on "How to use Combofix" can be found here:
    ComboFix: A guide and tutorial on using ComboFix
      My Computer


  9. Posts : 42
    Microsoft Windows 7 Professional 64-bit 7601 Multiprocessor Free Service Pack 1
    Thread Starter
       #39

    Bill,

    I set the home pages of IE to the ones I want, as I use them regularly. There has been one occasion when I have heard the phantom noise, but I do not have my headphones on all of the time. It still seems likely that it is a web page which is doing this, although I have not been able to narrow it down yet.

    Jacee,

    The size of the c:\users\viv\appdata\local\temp\ file is now much reduced, 306Mb, most of which are tmp files from today.

    I ran combofix according to your instructions, rebooted even though I was not asked, and have attached the file you want to see.

    Viv

    ComboFix.txt
      My Computer


  10. Posts : 6,458
    x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
       #40

    Thanks for letting me know about the home page, Viv.

    You'll have to see what Jacee has to say about the ComboFix output, that's her forte'

    Bill
    .
      My Computer


 
Page 4 of 6 FirstFirst ... 23456 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 18:29.
Find Us