So I have this audio ad malware that's taken up my computer. I recently had the Windows Recovery malware on my computer and was able to get rid of it (I think I got rid of it) by running RKill and MBAM. However, the audio ads won't stop. I have installed ERUNT and backed up my registry for Windows Vista.

My DDS log:

Please let me know what I can do. Thank you!

Sorry for the delay but when you double posted your post was kind of lost

Download aswMBR.exe (http://public.avast.com/~gmerek/aswMBR.exe) ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan

On completion of the scan click save log, save it to your desktop and post in your next reply

So I downloaded the aswMBR program onto my desktop. I ran the program and performed the scan. Then saved the log to my desktop as aswMBR.txt.

Here is the log file:

Lets do this

Please download TDSSKiller.zip (http://support.kaspersky.com/downloads/utils/tdsskiller.zip)
Extract it to your desktop
Double click TDSSKiller.exe
Press Start Scan

Only if Malicious objects are found then ensure Cure is selected
Then click Continue > Reboot now

Copy and paste the log in your next reply

A copy of the log will be saved automatically to the root of the drive (typically C:\)

So I downloaded the program from the link that you provided. I downloaded it to my desktop. Then I extracted the program onto my desktop and double-clicked on it. The "User Account Control" came up asking if I want to authorize this program to make changes to my computer. I clicked "Continue". After that, nothing happened.

Nothing looked different, and nothing changed. I tried this numerous times, extracting the file into different areas and turning off Windows Defender, but to no avail.

What do you think is my next step?

Thanks again for all the help. This is really awesome what you guys are doing.

Your running Vista, I should have pointed out that you need to right click on the program and select RUN AS ADMINISTRATOR

If it wont run then do this

Re-Run aswMBR

Click Scan

On completion of the scan

Click Fix


Save the log as before and post in your next reply

Upon completion of the aswMBR scan, "Fix" is not a highlighted option that I can choose. Only "FixMBR". Not sure what the difference is, but I don't want to press anything I'm not supposed to.

As far as running TDSSKiller using the "Run as Administrator" option, I had tried that earlier and just failed to mention it in my previous response.

I have saved a logfile to the desktop known as aswMBR2.txt:

What else do you think I should do?

Lets do this

Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)



* IMPORTANT !!! Save ComboFix.exe to your Desktop

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
See this Link (http://www.bleepingcomputer.com/forums/topic114351.html) for programs that need to be disabled and instruction on how to disable them.
Remember to re-enable them when we're done.

Double click on ComboFix.exe & follow the prompts.

As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

So I downloaded Combofix.exe. Saved it to my desktop as Combo-Fix. I tried to disable all and any Anti-Virus and Anti-Spyware programs, but a notice came stating that one of my programs, Spyware Doctor, was still running, so I uninstalled the program before proceeding.

ComboFix continued to scan and then recognized a rootkit and so prompted me to reboot the computer. As soon as the computer was up and running, ComboFix continued and subsequently produced this log:

I wasn't sure if you wanted me to zip the ComboFix txt file or not, but I did since that's what we've been doing with all other files. Internet was restored on my computer once ComboFix was finished.

What's the next step?

You can just copy and paste the reports into the thread, its easier for me to analyze.

I am looking at Markers in your log for both McAfee and Symantec AV, have you tried uninstalling them at one time ?

While I am looking over your Combofix log, run these scans and post the logs

Please download Malwarebytes from Here (http://www.malwarebytes.org/mbam-download.php) or Here (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html)

Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform quick scan, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected .
When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please

Please run this free online virus scanner from ESET (http://www.eset.com/onlinescan/)

Note: You will need to use Internet explorer for this scan
Tick the box next to YES, I accept the Terms of Use.
Click Start
When asked, allow the activex control to install
Click Start
Make sure that the option Remove found threats is ticked, and the option Scan unwanted applications is checked
Click Scan
Wait for the scan to finish
Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
Copy and paste that log as a reply to this topic

So I finished the MBAM and ESET scans following all the directions mentioned above. I have both logs, but the ESET log does not seem to show any evidence of the files quarantined and removed.

MBAM log:
Malwarebytes' Anti-Malware

Database version: 6668

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.19048

5/24/2011 9:12:08 PM
mbam-log-2011-05-24 (21-12-08).txt

Scan type: Quick scan
Objects scanned: 157097
Time elapsed: 6 minute(s), 2 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Users\alan enjetti\downloads\rkill.com (Trojan.BankerBot.Gen) -> Quarantined and deleted successfully.

ESET log:
ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK

Again, don't know why the ESET log is so empty. But this was the only file I found that was labeled log.txt under the ESET folder.

What's the next step?

Looks like ESET didnt find anything

How are things running now ?

So I'm positive ESET found some threats because I have a bunch of quarantined files in a folder marked quarantined. I also woke up this morning to find the ESET scan completed and 8 threats found. However, my computer rebooted shortly after. Still no log was found.

As far as symptoms, I have not observed any since the MBAM scan. So it seems like clear skies for now.

I had one more question. I wanted to uninstall my McAfee and Norton's and install a solid Antivirus and Anti-Malware Software with continuous scanning, but I did not know which one to go for. What do you recommend? Can I get updates for free or will I have to pay? Basically, how do I prevent this from happening again?

Thanks again for your help. I am really in your debt and am amazed that there is a kind of volunteer workforce that help people like this over the internet. It really is great.

Well , we had ESET set to not remove threats so dont know if there false positives or have to be removed.

When where done I will show you how to remove both McAfee and Norton and you may try giving Microsoft Security Essentials a shot

Run this other online scanner just to be sure

Please do a scan with Kaspersky Online Scanner (http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html) or from Here. (http://www.kaspersky.com/virusscanner)

Click on the Accept button and install any components it needs.
The program will install and then begin downloading the latest definition files.
After the files have been downloaded on the left side of the page in the Scan section select My Computer.
This will start the program and scan your system.
The scan will take a while, so be patient and let it run. (At times it may appear to stall)
Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.

Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.

Once the scan is complete, click on View scan report To obtain the report:
Click on: Save Report As
Next, in the Save as prompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select: Text file [*.txt]
Then, click: Save
Please post the Kaspersky Online Scanner Report in your reply.


So I tried running the Kaspersky Online Scanner from the first link you provided. However, I was unable to proceed through the "Database Update portion of the program. I received a prompt saying:

Update has failed The program could not be started. Please close the window of Kaspersky Online Scanner 7.0 and start the program again from the web site of Kaspersky Lab.

Successful updating of Kaspersky Online Scanner 7.0 and scanning of your computer requires uninterrupted Internet connection. Please make sure that the Internet connection is established. [ERROR: License has expired]

I went to Kaspersky Lab and did not find an online scanner comparable to one from the first link. All Anti-virus tools were programs that had to be downloaded for free trials.

As far as my internet connection, it has been consistent and uninterrupted, so I am not sure what to do regarding this Kaspersky Scan.

What do you think I should do next?

These on line virus scanners can be a problem to run sometimes, lets run this scan instead

OTL by OldTimer

Download OTL (http://oldtimer.geekstogo.com/OTL.exe) to your desktop.
Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
When the window appears, underneath Output at the top change it to Minimal Output.
Click the "Scan All Users" checkbox.
Check the boxes beside LOP Check and Purity Check.
Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

The OTL scan was successful and I ran it with all the necessary specifications you had mentioned above. Both txt files appeared soon after.

Here is the OTL.txt file:

I will include the Extras.txt file in the following post. Thanks!

Here's the extras.txt file that was produced by the OTL Scan:

So these are the files! What's the next step?

I am looking at markers in your log for both Symantec and McAfee, you cant have both, one needs to be uninstalled. You need to have just one AV, keep it updated and run regular scans. More than one is overkill and can severely hamper system perfomance, let me know what you want to do

Thanks again for all of your help. So, I was thinking about uninstalling both and either installing avast or AVG. Not both, obviously. I wanted your recommendation on the best anti-spyware or anti-virus software to download. I am happy with MBAM and have had it for awhile now, but I don't know if that's the only thing I should have or if I should download something more.

I'd prefer a program that doesn't interfere with the daily use of my computer and that won't make me close all my programs and reboot computer all the time. Free is also something that I'd prefer.

What is your take on all this?

Lets try this. First you have to completely remove McAfee and Symantec, if you have not done so already, remove via Programs and Features in the Control Panel. Then run there removal tool that will remove all traces of those programs from your system

Norton Removal Tool

Mcafee Removal Tool

Microsoft has a free program that I have heard good things about, give it a try and if you dont like it than uninstall it, its a free program


If you dont want to try it than I would pick Avast over AVG

Malwarebytes is the free version, you can upgrade to the Pro version very reasonably, the Pro version includes a protection moduale that will block and warn you if you stray into a bad site. I have it on 3 of my systems

Post back when your done and let me know how its going

Sorry for the late reply. So I removed McAfee and Norton's from my computer using Programs and Features and then downloading their respective removal tools and running them.

I decided to take your advice and go with Avast over AVG. I checked out Microsoft Essentials but I had more confidence in Avast from hearing about it from others. After downloading, I immediately updated the database. So far I am very happy with it, but I guess it really depends on whether I experience another malware situation or not and how it responds to it.

I tried to upgrade MBAM to the "Pro" version, but I think it costs and I'll have to wait until I can afford to pay for it before I get it. It'll definitely be something I will consider though.

Aside from that I don't have many other problems aside from the sluggishness of my computer. If you have any tips for that it would be greatly appreciated, but I've probably exhausted your help already. Thank you again for all your advice to help me and everyone else on the forum.

Please let me know if there is anything else that you need?

Not a problem with questions, thats why where here.

Combofix replaced a corrupted file that was infected and had to do with your computer booting up. Try this, drag TDSSKiller to the trash and lets get a new copy and run it, with what CF fixed it may run now

Please download TDSSKiller.zip (http://support.kaspersky.com/downloads/utils/tdsskiller.zip)
Extract it to your desktop
Double click TDSSKiller.exe
Press Start Scan

Only if Malicious objects are found then ensure Cure is selected
Then click Continue > Reboot now

Copy and paste the log in your next reply

A copy of the log will be saved automatically to the root of the drive (typically C:\)

If it still gives you problems try running it in safemode
To Enter Safemode

Go to Start> Shut off your Computer> Restart
As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
this will bring up a menu.
Use the Up and Down Arrow Keys to scroll up to Safemode
Then press the Enter Key on your Keyboard

Tutorial if you need it How to boot into Safemode (http://www.bleepingcomputer.com/tutorials/tutorial61.html)

