Author Topic: [Resolved K] audio ads play & internet explorer is running in task manage  (Read 1510 times)

0 Members and 1 Guest are viewing this topic.

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6348
Excellent!! Ok continue as follows please :-

Step 1

Remove ESET Online Scanner

  • Click Start, type programs and features in the Search box, and then press ENTER.
  • Click to select the product to be uninstalled from the listing of installed products(ESET Online Scanner), and then click Uninstall/Change from the bar that displays the available tasks to remove ESET.
Only re-boot if prompted

Step 2

  • Download OTC by OldTimer and save it to your desktop. Alternative mirror
  • Double click icon to start the program.
    If you are using Vista or Windows 7, please right-click and choose run as administrator
  • Then Click the big button.
  • You will get a prompt saying "Begining Cleanup Process". Please select Yes.
  • Restart your computer when prompted.
  • This will remove tools we have used and itself.


Any tools/logs remaining on the Desktop can be deleted. Such as :-

RogueKiller plus logs/folders
SecurityChecks plus any logs
DDS plus any logs

Step 3

Go here http://www.filehippo.com/updatechecker/ run the FileHippo Update Checker, update all applications as suggested by the Update Checker. Ignore any Beta updates.
If Java or Adobe as updated please check under Start > Control Panel > Add/Remove Programs, ensure any old versions are removed.

Step 4

Download TFC  to your desktop, from either of the following links
Link 1
Link 2
  • Save any open work. TFC will close all open application windows.
  • Double-click TFC.exe to run the program. Vista or Windows 7 users right click and select “Run as Administartor”
  • If prompted, click "Yes" to reboot.
TFC will automatically close any open programs, including your Desktop. Let it run uninterrupted. It shouldn't take longer take a couple of minutes, and may only take a few seconds.  TFC may re-boot your system, if not Re-boot it yourself to  complete cleaning process <---- Very Important

Keep TFC it is an excellent utility to keep your system optimized, it empties all user temp folders, Java cache etc etc.  Always remember to re-boot after a run, even if not prompted

Let me know if those steps complete OK, also if any remaining issues or concerns.

Kevin







Offline gamer88

  • Bronze Member
  • Posts: 14
all the steps went fine and all my problems are gone, I want to thank you Kevin for helping me through all this.  :ty

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6348
OK, if no more issues here are some tips to reduce the potential for malware infection in the future:

Make proper use of your antivirus and firewall

Antivirus and Firewall programs are integral to your computer security. However, just having them installed isn't enough. The definitions of these programs are frequently updated to detect the latest malware, if you don't keep up with these updates then you'll be vulnerable to infection. Many antivirus and firewall programs have automatic update features, make use of those if you can. If your program doesn't, then get in the habit of routinely performing manual updates, because it's important.

You should keep your antivirus and firewall guard enabled at all times, NEVER turn them off unless there's a specific reason to do so. Also, regularly performing a full system scan with your antivirus program is a good idea to make sure you're system remains clean. Once a week should be adequate. You can set the scan to run during a time when you don't plan to use the computer and just leave it to complete on its own.

Install and use WinPatrol  This will inform you of any attempted unauthorized changes to your system.

WinPatrol features explained Here

Use a safer web browser

Internet Explorer is not the most secure tool for browsing the web. It has been known to be very susceptible to infection, and there are a few good free alternatives:
 
Firefox,

Opera, and

Chrome.
 
All of these are excellent faster, safer, more powerful and functional free alternatives to Internet Explorer. It's definitely worth the short period of adjustment to start using one of these. If you wish to continue using Internet Explorer, it would be a good idea to follow the tutorial HERE which will help you to make IE MUCH safer.

These browser add-ons will help to make your browser safer:

Web of Trust warns you about risky websites that try to scam visitors, deliver malware or send spam. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous ones:

Available for Firefox and Internet Explorer.

Green to go,
Yellow for caution, and
Red to stop.


Available for Firefox only. NoScript helps to block malicious scripts and in general gives you much better control over what types of things webpages can do to your computer while you're browsing.

These are just a couple of the most popular add-ons, if you're interested in more, take a look at THIS article.

Here a couple of links by two security experts that will give some excellent tips and advice.

So how did I get infected in the first place by Tony Klein

How to prevent Malware by Miekiemoes

Finally this link HERE will give a comprehensive upto date list of free Security programs. To include - Antivirus, Antispyware, Firewall, Antimalware, Online scanners and rescue CD`s.

Don`t forget, the best form of defense is common sense. If you don`t recognize it, don`t open it. If something looks to good to be true, then it aint.

Let me know when its OK to close out your thread..

Take care,

Kevin

Offline gamer88

  • Bronze Member
  • Posts: 14
thanks for the tips, they're very helpful. you may close this thread now.

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6348
Since this issue appears to be resolved the topic has been closed. Glad we could help.  :t 

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

The fixes and advice in this thread are for this System only. Do not apply the instructions from this thread to your own System. Please start a new thread describing your issue and someone will be along to assist you.

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6348
Hiya gamer88,

I`ve re-opened your thread as requested, if Windows updates are not working run the following:

Please download Farbar Service Scanner and run it on the computer with the issue.

Make sure the following options are checked:

  • Windows Firewall
  • System Restore
  • Security Center
  • Windows Update
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.

Kevin  :)1



Offline gamer88

  • Bronze Member
  • Posts: 14
thanks for doing this kevin and here's the log

Farbar Service Scanner Version: 22-06-2012 01
Ran by bud (administrator) on 23-06-2012 at 15:25:34
Running from "C:\Users\bud\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QRM75QF0"
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Security Center:
============

Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


File Check:
========
C:\Windows\system32\nsisvc.dll => MD5 is legit
C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit
C:\Windows\system32\dhcpcsvc.dll => MD5 is legit
C:\Windows\system32\Drivers\afd.sys
[2011-06-15 20:40] - [2011-04-21 06:58] - 0273408 ____A (Microsoft Corporation)

C:\Windows\system32\Drivers\tdx.sys => MD5 is legit
C:\Windows\system32\Drivers\tcpip.sys
[2012-05-10 14:26] - [2012-03-30 05:39] - 0914304 ____A (Microsoft Corporation) EE7E10BED85C312C1D5D30C435BDDA9F

C:\Windows\system32\dnsrslvr.dll => MD5 is legit
C:\Windows\system32\mpssvc.dll => MD5 is legit
C:\Windows\system32\bfe.dll => MD5 is legit
C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit
C:\Windows\system32\SDRSVC.dll => MD5 is legit
C:\Windows\system32\vssvc.exe => MD5 is legit
C:\Windows\system32\wscsvc.dll => MD5 is legit
C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\system32\wuaueng.dll => MD5 is legit
C:\Windows\system32\qmgr.dll => MD5 is legit
C:\Windows\system32\es.dll => MD5 is legit
C:\Windows\system32\cryptsvc.dll
[2012-06-12 15:40] - [2012-04-23 09:00] - 0133120 ____A (Microsoft Corporation) 75C6A297E364014840B48ECCD7525E30

C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit


**** End of log ****

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6348
Please visit
Virustotal
  • Click the Browse... button
  • Navigate to the file C:\Windows\system32\Drivers\afd.sys or just copy/paste it in.
  • Click the Scan it tab
  • If you get a message saying File has already been analyzed: click Reanalyze file now
  • Copy and paste the results back here please.
  • Repeat the above steps for the following files

C:\Windows\system32\Drivers\tcpip.sys
C:\Windows\system32\cryptsvc.dll


Kevin....

Offline gamer88

  • Bronze Member
  • Posts: 14
by results do you mean these?

SHA256: 62545b90c7dd3f73777e62cd8264e611a4d71b6956cabfd2d820d25f41f471fd
SHA1: f93d5768d534ae50b4a2f52c98fb14c3e9f77102
MD5: 3911b972b55fea0478476b2e777b29fa
File size: 267.0 KB ( 273408 bytes ) 
File name: C:\WINDOWS\System32\drivers\afd.sys
File type: Win32 EXE
Detection ratio: 0 / 39
Analysis date: 2012-06-24 06:45:14 UTC ( 1 minute ago )

SHA256: 091edbe02845e462cb2a30b02d51741f1e6b9cd4b4d2eb683be9fbd9bd27132a
SHA1: 831b449b8936781c252a46059e92770e0209c855
MD5: ee7e10bed85c312c1d5d30c435bdda9f
File size: 892.9 KB ( 914304 bytes ) 
File name: C:\WINDOWS\System32\drivers\tcpip.sys
File type: Win32 EXE
Detection ratio: 0 / 42
Analysis date: 2012-06-24 06:58:01 UTC ( 0 minutes ago )

SHA256: cd12f8dc46590b4e9d6629a75e5d21146f62188772cf29594b4d9a4e911d1088
SHA1: 2542dfc6a08004d9736356c64809b410ee377d81
MD5: 75c6a297e364014840b48eccd7525e30
File size: 130.0 KB ( 133120 bytes ) 
File name: C:\WINDOWS\System32\cryptsvc.dll
File type: Win32 DLL
Detection ratio: 0 / 38
Analysis date: 2012-06-24 07:01:04 UTC ( 1 minute ago ) 
 

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6348
That is what I wanted, the files are clean. OK do the following:

Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.

  • Now open Repair_Windows.exe
  • Go to Start Repairs tab.
  • Choose "Custom Mode" and press "Start".
  • Create a System Restore point if prompted.
  • In the Custom Mode window, select the following repair options:
  • Reset Registry Permissions
  • Register System Files
  • Repair WMI
  • Remove Policies Set By Infections
  • Repair Winsock & DNS Cache
  • Repair Proxy Settings
  • Repair Windows Updates
  • Click the Start button.


Be patient while the tool repairs the selected items.
If prompted reboot the computer for the changes to take affect, make sure other tasks in the program are not still running before re-booting..

Check updates after the re-boot..

Kevin..

Offline gamer88

  • Bronze Member
  • Posts: 14
I was able to successfully install updates for both Windows Update and Microsoft Security Essentials.

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6348
If no more issues you can delete Farbar Service Scanner and logs, also the Windows Repair tool. Are you OK to close now?

Kevin... :)1

Offline gamer88

  • Bronze Member
  • Posts: 14
I have no more issues, you may truly close this thread.

once again thank you kevin.

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6348
It was a pleasure to help, take care  :t

Since this issue appears to be resolved the topic has been closed. Glad we could help. 

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

The fixes and advice in this thread are for this System only. Do not apply the instructions from this thread to your own System. Please start a new thread describing your issue and someone will be along to assist you.