Windows 7 "Talking" Adware

tomato500

New member
Member
Local time
7:07 PM
Messages
17
Location
In your closet
So here I am with yet another PC problem.
My aunt gave me her Samsung laptop running windows 7 home edition. She said it had a virus that slowed her computer down. It also starts "talking" adverts. I turned it on, connected to my home Wi-Fi, and i heard it blabbing about Jack-in-the-Box specials. Tried running Avast full scan, but it's saying that there's some files it couldn't scan. Also, Avast is saying that it is blocking a malicious URL from various websites. Sorry if this is too little info, but I have never really had experience with virus removal.
Please help!
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom build
OS
Windows 7 Professional x64
CPU
AMD FX-4100 3.6 GHz
Motherboard
Asus M5A97 LE R2.0
Memory
8GB Corsair Vengance
Graphics Card(s)
EVGA GeForce GTX 650
Sound Card
Onboard
Monitor(s) Displays
Generic DVI Monitor
Screen Resolution
1440x900
Hard Drives
320GB Western Digital
PSU
ThermalTake 700W
Case
Enermax Ostrog
Cooling
AMD Stock Heatsink Fan
Keyboard
Logitech
Mouse
Logitech
Antivirus
Microsoft Security Essentials
Browser
Google Chrome
tomato500

Run the two programs below

s1lva1.png
AdwCleaner

Click here AdwCleaner

:ar: Click on Download Now button

:ar: Save to the Desktop

:ar: Right-click on AdwCleaner.exe and choose
mawket.jpg


:ar: Click on Delete and confirm the prompt.

axcoj5.jpg


:ar: Your computer will be rebooted automatically. A text file will open after the restart.

Upload the log : The log file is at C:\AdwCleaner[Sn].txt


Download Junkware Removal Toolkit

Click here Junkware Removal Tool to download

Drag the JRT.exe from the Downloads folder to your Desktop

Right click JRT.exe and choose
mawket.jpg


Once done upload the JRT.txt file
 

My Computer

Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
tomato500

Run the two programs below

s1lva1.png
AdwCleaner

Click here AdwCleaner

:ar: Click on Download Now button

:ar: Save to the Desktop

:ar: Right-click on AdwCleaner.exe and choose
mawket.jpg


:ar: Click on Delete and confirm the prompt.

axcoj5.jpg


:ar: Your computer will be rebooted automatically. A text file will open after the restart.

Upload the log : The log file is at C:\AdwCleaner[Sn].txt


Download Junkware Removal Toolkit

Click here Junkware Removal Tool to download

Drag the JRT.exe from the Downloads folder to your Desktop

Right click JRT.exe and choose
mawket.jpg


Once done upload the JRT.txt file

Ok here's the log files. It deleted a few files/registry keys associated with "StartNow toolbar".
 

Attachments

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom build
OS
Windows 7 Professional x64
CPU
AMD FX-4100 3.6 GHz
Motherboard
Asus M5A97 LE R2.0
Memory
8GB Corsair Vengance
Graphics Card(s)
EVGA GeForce GTX 650
Sound Card
Onboard
Monitor(s) Displays
Generic DVI Monitor
Screen Resolution
1440x900
Hard Drives
320GB Western Digital
PSU
ThermalTake 700W
Case
Enermax Ostrog
Cooling
AMD Stock Heatsink Fan
Keyboard
Logitech
Mouse
Logitech
Antivirus
Microsoft Security Essentials
Browser
Google Chrome
Can you boot into normal mode ? See if you hear the talking advertisements ?
 

My Computer

Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
Can you boot into normal mode ? See if you hear the talking advertisements ?

It's booting right now... it takes a while. I am using my other laptop to type this. It is configuring updates (taking a while). Yeah, it's talking about recipes? Oh, it just got a BSOD. It disappeared quickly, but it said something about "a clock interrupt was not received on a secondary processor within the allocated time interval". BlueScreenView shows that the same crash happened 2 days ago, when she said the PC got the virus. This is getting weird...
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom build
OS
Windows 7 Professional x64
CPU
AMD FX-4100 3.6 GHz
Motherboard
Asus M5A97 LE R2.0
Memory
8GB Corsair Vengance
Graphics Card(s)
EVGA GeForce GTX 650
Sound Card
Onboard
Monitor(s) Displays
Generic DVI Monitor
Screen Resolution
1440x900
Hard Drives
320GB Western Digital
PSU
ThermalTake 700W
Case
Enermax Ostrog
Cooling
AMD Stock Heatsink Fan
Keyboard
Logitech
Mouse
Logitech
Antivirus
Microsoft Security Essentials
Browser
Google Chrome
Do you have a USB Flash Drive ?
 

My Computer

Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom build
OS
Windows 7 Professional x64
CPU
AMD FX-4100 3.6 GHz
Motherboard
Asus M5A97 LE R2.0
Memory
8GB Corsair Vengance
Graphics Card(s)
EVGA GeForce GTX 650
Sound Card
Onboard
Monitor(s) Displays
Generic DVI Monitor
Screen Resolution
1440x900
Hard Drives
320GB Western Digital
PSU
ThermalTake 700W
Case
Enermax Ostrog
Cooling
AMD Stock Heatsink Fan
Keyboard
Logitech
Mouse
Logitech
Antivirus
Microsoft Security Essentials
Browser
Google Chrome
   Warning
You will need a USB FLASH DRIVE


   Tip
Download the Tool from a non infected PC


2j4a9si.png
Farbar Recovery Scan Tool

Choose one that goes with your OS bit version . Save the file to a USB Flash drive

32-bit Version OS :ar: Farbar Recovery Scan Tool

64-Bit Version OS :ar: Farbar Recovery Scan Tool x64


   Note
Click the :orb: button and right-click Computer .Select Properties . Look for System Type: which will say 32-bit Operating System or 64-bit Operating System


Plug the flash drive into the infected PC.

Enter System Recovery Options.

:ar: To enter System Recovery Options from the Advanced Boot Options:
Restart the computer.
As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
Use the arrow keys to select Repair Your Computer menu item.
Select US as the keyboard language settings, and then click Next.
Select the operating system you want to repair, and then click Next.
Select your user account an click Next.

:ar: To enter System Recovery Options by using Windows installation disc:
Insert the installation disc.
Restart your computer.
If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
Click Repair your computer.
Select US as the keyboard language settings, and then click Next.
Select the operating system you want to repair, and then click Next.
Select your user account and click Next.

:ar: On the System Recovery Options menu you will get the following options:

  • Startup Repair

  • System Restore

  • Windows Complete PC Restore

  • Windows Memory Diagnostic Tool

  • Command Prompt

Select Command Prompt

In the command window type X:\FRST.exe (for x64 bit version type X:\FRST64.exe) and press Enter

   Note
Replace letter X with the drive letter of your flash drive.


   Tip
Type the commands below to see what your letter is for the USB drive and press ENTER after each command


Code:
Diskpart
List volume
The tool will start to run.
When the tool opens click Yes to disclaimer.
Press Scan button.
FRST will let you know when the scan is complete and has written the FRST.txt to file
Please copy and paste both logs in your reply.(FRST.txt and Addition.txt)

   Note
FRST.txt and Addition.txt files will be inside the root of the USB Flash Drive
 

My Computer

Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
Ok, I ran the scan. For some reason there was no "Addition.txt"?
 

Attachments

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom build
OS
Windows 7 Professional x64
CPU
AMD FX-4100 3.6 GHz
Motherboard
Asus M5A97 LE R2.0
Memory
8GB Corsair Vengance
Graphics Card(s)
EVGA GeForce GTX 650
Sound Card
Onboard
Monitor(s) Displays
Generic DVI Monitor
Screen Resolution
1440x900
Hard Drives
320GB Western Digital
PSU
ThermalTake 700W
Case
Enermax Ostrog
Cooling
AMD Stock Heatsink Fan
Keyboard
Logitech
Mouse
Logitech
Antivirus
Microsoft Security Essentials
Browser
Google Chrome
Open Notepad . Inside Notepad paste the highlighted text inside notepad


start
HKU\UpdatusUser\...\RunOnce: [mctadmin] -
HKU\Melody\...\Run: [swg] - "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
C:\Windows\System32\mctadmin.exe
C:\Users\Melody\jqs.exe
end


Click on File ====> Save As

File Name : Fixlist.txt

Save as type : All Files

Location : USB flash drive

Click on the [Save] button .

Open the FRST tool again inside System Recovey and click on the [Fix] button . Once complete it will create a new log called Fixlog.txt . Upload the new log created in your reply . It should be inside the usb drive .
 

My Computer

Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
You're running 3 Antivirus Softwares


Remove Avast

Download Link ===> aswclear.exe
Save onto your desktop
Start Windows in Safe Mode
Open the uninstall utility right click on aswcleaner.exe and choose
mawket.jpg

If you installed avast! in a different folder than the default, browse for it. (Note: Be careful! The content of any folder you choose will be deleted!)
Click REMOVE
Restart your computer

Remove McAfee

Click here ====> How to uninstall or reinstall supported McAfee products using the Consumer Products Removal tool (MCPR)
 

My Computer

Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
I removed Avast and McAfee and ran the fix. Here's the results:
 

Attachments

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom build
OS
Windows 7 Professional x64
CPU
AMD FX-4100 3.6 GHz
Motherboard
Asus M5A97 LE R2.0
Memory
8GB Corsair Vengance
Graphics Card(s)
EVGA GeForce GTX 650
Sound Card
Onboard
Monitor(s) Displays
Generic DVI Monitor
Screen Resolution
1440x900
Hard Drives
320GB Western Digital
PSU
ThermalTake 700W
Case
Enermax Ostrog
Cooling
AMD Stock Heatsink Fan
Keyboard
Logitech
Mouse
Logitech
Antivirus
Microsoft Security Essentials
Browser
Google Chrome
Are you still getting the Talking advertisements ?
 

My Computer

Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom build
OS
Windows 7 Professional x64
CPU
AMD FX-4100 3.6 GHz
Motherboard
Asus M5A97 LE R2.0
Memory
8GB Corsair Vengance
Graphics Card(s)
EVGA GeForce GTX 650
Sound Card
Onboard
Monitor(s) Displays
Generic DVI Monitor
Screen Resolution
1440x900
Hard Drives
320GB Western Digital
PSU
ThermalTake 700W
Case
Enermax Ostrog
Cooling
AMD Stock Heatsink Fan
Keyboard
Logitech
Mouse
Logitech
Antivirus
Microsoft Security Essentials
Browser
Google Chrome
Lets see what this shows

RogueKiller for 32bit <==== Download Link

RogueKiller for 64bit <==== Download Link

:ar: Click on one of the links above that goes with your Windows 7 bit versions

:ar: Save to the Desktop.

:ar: Close all windows and browsers

:ar: Right click on
332trud.png
and choose
mawket.jpg


:ar: Press: SCAN

:ar: provide the RKreport.txt (Mode: Scan) in your reply.

You could go ahead and delete the FRST folder inside C:\ Drive
 

My Computer

Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
I ran RogueKiller. Here's the results, actually found a few:
 

Attachments

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom build
OS
Windows 7 Professional x64
CPU
AMD FX-4100 3.6 GHz
Motherboard
Asus M5A97 LE R2.0
Memory
8GB Corsair Vengance
Graphics Card(s)
EVGA GeForce GTX 650
Sound Card
Onboard
Monitor(s) Displays
Generic DVI Monitor
Screen Resolution
1440x900
Hard Drives
320GB Western Digital
PSU
ThermalTake 700W
Case
Enermax Ostrog
Cooling
AMD Stock Heatsink Fan
Keyboard
Logitech
Mouse
Logitech
Antivirus
Microsoft Security Essentials
Browser
Google Chrome
Run the tool again and click on the [Delete] button .
 

My Computer

Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
Back
Top