My PC started acting very strange a week or two ago. Occasionally strange voices come from the speakers. Sometimes they sound like ads, other times they seem random. They even come from the speakers while the PC is shutting down, after the user is logged off. Also, Avast! Free AV pops up red messages all the time saying 'Malicious URL Blocked'. The message always says the the process is C:\System32\svchost.exe. Also, CPU usage is up to 100% most of the time in Task Manager. Again, the culprit is always one of the several svchost processes running. A partial sample URL that is blocked is 'http://...check.php?tim=1373413030.2...'. I have Windows Home Server creating periodic backups, and the only thing I tried to fix the problem was to restore a backup from about a week ago. That didn't solve the problem

Here are the two logs.

Please help. Thanks, Harry


There may be a rootkit underfoot

Please download TDSSKiller.zip (http://support.kaspersky.com/downloads/utils/tdsskiller.zip)
Extract it to your desktop
Double click TDSSKiller.exe
Press Start Scan

Only if Malicious objects are found then ensure Cure is selected
Then click Continue > Reboot now

Copy and paste the log in your next reply

A copy of the log will be saved automatically to the root of the drive (typically C:\)

]Ken, I ran the scan and it found one serious threat. Then I rebooted and the PC ran the Microsoft Malware Removal program, then ran the TDSS Killer scan again. I had to zip the logs for the two scans and attach the zip file. They were too long to paste into the posting.

Thanks for your help. Harry

Good Morning Harry,

That was a serious threat. Have the sounds from the speakers stopped ?

Download ComboFix from one of these locations:

Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)

* IMPORTANT !!! Save ComboFix.exe to your Desktop

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
See this Link (http://www.bleepingcomputer.com/forums/topic114351.html) for programs that need to be disabled and instruction on how to disable them.
Remember to re-enable them when we're done.

Double click on ComboFix.exe & follow the prompts.

As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

The threat that I removed with TDSS Killer made the PC run much better. And the strange voices are no longer coming from the speakers. Thanks!

I ran Combo Fix. I first disabled Avast! but that wasn't enough to get it to run. I had to disable three Spybot services first. Combo Fix didn't install the Microsoft Recovery Console. That surprised me -- I didn't think that it was already installed.

Here's the log from Combo Fix.

Regards, Harry

Good Morning Harry,

You where infected with the TDSS Rootkit , what this rootkit did was infect the Master Boot Record on your hard drive so everytime you booted your computer up the infection became active, but looks likes its gone now :)

Most newer computers have a Recovery Console , when Combofix runs it first checks to make sure one is present and if not prompts you to install it.

Please download Malwarebytes Anti-Malware (http://www.malwarebytes.org/mbam-download.php) to your desktop.

Right-click and Run as Administrator mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform quick scan, then click Scan as shown below.


When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected.
When completed, a log will open in Notepad. Please save it to a convenient location and post the results.

I read about the TDSS Rootkit on the Internet. Scary stuff. Thanks for helping me remove it.

My PC is old. It started out with Windows XP, was upgraded to Windows Vista, then to Windows 7. It was hardly used until the Windows 7 upgrade.

I ran Malwarebytes Anti-Malware and it found no threats. Here's the log.

Malwarebytes Anti-Malware

Database version: v2013.07.19.03

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16635
Mary :: SEABISCUIT [administrator]

7/19/2013 4:17:11 AM
mbam-log-2013-07-19 (04-17-11).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra |

Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 313621
Time elapsed: 19 minute(s), 1 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)


Thanks again, Harry

Everything running ok ?

Everything is running just fine.

I'm going to go through the 'So how did I get infected in the first place?' thread and apply as many of the suggestions as I can (to all of my PCs, not just this one). Also, I'll make sure that people log on with administrator privileges only rarely.

Thanks for all the help you've given me. I might have never found the problem without your help.

:D: Harry :D:

Harry. Thats great. I am at work and on my phone. I will post some info for you a bit later

Hello Harry,

Been retired for about 3 months but my company wont let me go, they asked me to work all this week :lip:

Nice people so in reality I really don't mind. :)

Been a pleasure working with you and glad things are back to normal, here are instructions to update your Java (Very important ) you should check for new versions at least once a month and then uninstall any previous versions.

Update your Java to keep you more secure

Go to your Control Panel and click on the Java Icon ( looks like a little coffee cup ) click on About and you should have Version 7 Update 25, if not proceed with the instructions.

Go to the update Tab and update it
Important, during the upgrade UNCHECK ASK TOOL BAR. ( you do not need or want this )

Then go to your Add Remove Programs (WIN XP) or Programs and Features (Vista / Win 7) in the Control Panel and uninstall all previous versions.

You can verify the installation Here (http://www.java.com/en/download/help/testvm.xml)

Harry, let me take one final look to make sure nothing was missed

OTL by OldTimer

Download OTL (http://oldtimer.geekstogo.com/OTL.exe) to your desktop.
Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
When the window appears, underneath Output at the top change it to Minimal Output.
Click the "Scan All Users" checkbox.
Check the boxes beside LOP Check and Purity Check.
Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

Congrats on your retirement. :crowned: I'm old enough to retire, but don't plan to do so for another five years or so. And since they keep making you work, I'm glad you don't mind. :bigthumb:

I ran OTL and have attached the logs in a zip file. Then I checked Java and had the latest version. I uninstalled four old versions (all from Sun Microsystems).



Click START then RUN
Now type Combofix /uninstall in the runbox and click OK. Note the space between the X and the /, it needs to be there.


Open OTL and click on Clean Up and it will remove programs we used to clean your system along with there backups, any programs that where not removed you can just drag to the trash.

Malwarebytes is the free version and yours to keep and will not be removed

How did I get infected in the first place ?
Read these links and find out how to prevent getting infected again.
Tutorial for System Restore (http://www.bleepingcomputer.com/tutorials/tutorial56.html) <-- Do this first to prevent yourself from being reinfected.
WhattheTech (http://forums.whatthetech.com/index.php?showtopic=57817)
Grinler BleepingComputer (http://www.bleepingcomputer.com/forums/topic2520.html)
GeeksTo Go (http://www.geekstogo.com/forum/index.php?autocom=custom&page=How_did_I)
Dslreports (http://www.dslreports.com/faq/10002)

I thought I'd do all the things in the links you sent me, and then get back to you. But in all of those links there are so many things to do! I will develop a plan -- what to do initially to all of my PCs, what to do on a schedule for them, what to do differently for the Windows XP and Windows 7 PCs, and so on.

Thanks for getting my PC back in working order. I couldn't have done it without you. It's actually my wife's PC, and in her despair she wanted me to buy her a new computer. We were able to avoid that.

I did find problems with two of your links. The link to WhattheTech doesn't work. And the link to Dslreports redirecta me to the correct link. The others are all fine.

I have one more question. Should I run TDSS Killer on all of my PCs, maybe every week or so, or is there a reason why I shouldn't?

Once again, thanks.

Harry :D:

Hello Harry,

On my systems I have one Anti Virus program ( more than one is overkill and can cause problems ) I also have Spybot Search and Destroy and Malwarebytes. You should keep these updated and run regular scans maybe weekly.

We have many many tools and there run to remove a particular infection that there designed to remove. You where infected with a variant of the TDSS Rootkit and TDSSKiller was written to remove that infection, if your not infected with TDSS that running that tool will do no good, besides all our tools are updated on a regular basis and an old version would really not help, another downside is that as a helper on the forums I am notified about any potential problems with a tool and the tool is pulled, the average user is not so running a particular tool when its not needed can cause you other problems.

Another program you can run is a free online virus scanner, just have it run and you can post the results in the forum, dont have it remove anything as sometimes they pick up false positives.

This is one of the better ones, if you have the time run it and if it finds anything post the log

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan (http://eset.com/onlinescan)
Click the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetOnline.png button.
For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
Click on http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetSmartInstall.png to download the ESET Smart Installer. Save it to your desktop.
Double click on the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetSmartInstallDesktopIcon.png icon on your desktop.

Check http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetAcceptTerms.png
Click the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetStart.png button.
Accept any security warnings from your browser.
Check http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetScanArchives.png
Make sure that the option "Remove found threats" is Unchecked
Push the Start button.
ESET will then download updates for itself, install itself, and begin
scanning your computer. Please be patient as this can take some time.
When the scan completes, push http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetListThreats.png
Push http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetExport.png, and save the file to your desktop using a unique name, such as
ESETScan. Include the contents of this report in your next reply.
Push the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetBack.png button.
Push http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetFinish.png
Please make sure you include the following items in your next post:
The log that was produced after running ESET Online Scanner.

All those links worked for me , unsure why they wouldn't open for you

I ran the scan -- it ran for many, many hours! Here is the log.

C:\Users\hstumpf\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items\0F7B25C9-00011348.eml HTML/Phishing.gen trojan
C:\Users\hstumpf\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items\12EF47B7-000128B6.eml HTML/Phishing.gen trojan
C:\Users\hstumpf\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items\150948C0-000115B8.eml HTML/Phishing.gen trojan
C:\Users\hstumpf\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items\15432CFC-000112A3.eml HTML/Phishing.gen trojan
C:\Users\hstumpf\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items\240371CC-00012768.eml HTML/Phishing.gen trojan
C:\Users\hstumpf\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items\24CC4ACC-00011249.eml HTML/Phishing.gen trojan
C:\Users\hstumpf\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items\30664F79-00011314.eml HTML/Phishing.gen trojan
C:\Users\hstumpf\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items\3B4C2481-00012826.eml HTML/Phishing.gen trojan
C:\Users\hstumpf\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items\441E4550-0001285B.eml HTML/Phishing.gen trojan
C:\Users\hstumpf\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items\4ADC3400-000112ED.eml HTML/Phishing.gen trojan
C:\Users\hstumpf\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items\4BFF704C-0001155E.eml HTML/Phishing.gen trojan
C:\Users\hstumpf\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items\52EA650A-0001125D.eml HTML/Phishing.gen trojan
C:\Users\hstumpf\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items\539E7B44-000129F2.eml HTML/Phishing.gen trojan
C:\Users\hstumpf\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items\576B1F02-00011263.eml HTML/Phishing.gen trojan
C:\Users\hstumpf\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items\5B9F7083-000115F3.eml HTML/Phishing.gen trojan
C:\Users\hstumpf\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items\61FE1C3F-00012718.eml HTML/Phishing.gen trojan
C:\Users\hstumpf\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items\655269A0-000112E6.eml HTML/Phishing.gen trojan
C:\Users\hstumpf\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items\688A2E43-00011590.eml HTML/Phishing.gen trojan
C:\Users\hstumpf\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items\6F563B7C-0001161A.eml HTML/Phishing.gen trojan
C:\Users\hstumpf\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items\75266AA6-00011246.eml HTML/Phishing.gen trojan
C:\Users\hstumpf\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items\7A8521C9-000125D5.eml HTML/Phishing.gen trojan
C:\Users\hstumpf\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items\7B3A624E-0001162A.eml HTML/Phishing.gen trojan
C:\Users\hstumpf\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items\7C88076A-00011243.eml HTML/Phishing.gen trojan

Thanks again for your help.


Looks like some bad entries in your Windows Mail were removed.

All ok ?

Ken, all seems OK. But the entries weren't removed. You said to uncheck 'Remove found threats'. Should I run it again and remove them?


Ahh, hate to make you run that long scan again, it looks like what ESET found where deleted items in your mail.

Go here
C:\Users\hstumpf\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items <-- And see if you can delete all thats in there but not that folder itself

Let me know , we can try it another way if need be

Still with me ?

Yes, Ken, I'm back. Sorry I disappeared for a couple of days. I've done every thing you said, including the email messages that the last scan picked up.

The PC is working like a charm now. Thanks for saving it! You've been great to work with.

Is there anything else I should do?


Looks like your good to go Harry, been a pleasure :)

Open OTL and click on Clean Up and it will remove programs we used to clean your system along with there backups, any programs that where not removed you can just drag to the trash.

Malwarebytes is the free version and yours to keep and will not be removed

How did I get infected in the first place ?
Read these links and find out how to prevent getting infected again.
Tutorial for System Restore (http://www.bleepingcomputer.com/tutorials/tutorial56.html) <-- Do this first to prevent yourself from being reinfected.
WhattheTech (http://forums.whatthetech.com/index.php?showtopic=57817)
Grinler BleepingComputer (http://www.bleepingcomputer.com/forums/topic2520.html)
GeeksTo Go (http://www.geekstogo.com/forum/index.php?autocom=custom&page=How_did_I)
Dslreports (http://www.dslreports.com/faq/10002)

Safe Surfn

