Technology Get the latest on technology, electronics and software…

WTF Is This and How Do I Kill It ....

Thread Tools
 
Old Jan 21, 2014 | 10:07 AM
  #1  
Bearcat94's Avatar
Thread Starter
AZ Community Team
 
Joined: May 2007
Posts: 32,488
Likes: 7,771
From: N35°03'16.75", W 080°51'0.9"
WTF Is This and How Do I Kill It ....




It's streaming random fucking audio ad's and it's seriously pissing me off .... .


No add-ons running to account for it; IE is closed/not running. TDSS Killer finds nothing; Malwarebytes finds nothing.

Started this morning for no known reason.

Only 'suspect' site I visited in the past several days was a news site .... Salon.com or Huffington or some similar ad infested news/magazine site.


Reply
Old Jan 21, 2014 | 10:09 AM
  #2  
Whiskers's Avatar
Go Giants
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Aug 2004
Posts: 70,003
Likes: 1,260
From: PA
its a virus, use tddskiller and npe and sas.....
Reply
Old Jan 21, 2014 | 10:11 AM
  #3  
Bearcat94's Avatar
Thread Starter
AZ Community Team
 
Joined: May 2007
Posts: 32,488
Likes: 7,771
From: N35°03'16.75", W 080°51'0.9"
TDDS Killer found nothing.


What are npe and sas?
Reply
Old Jan 21, 2014 | 10:12 AM
  #4  
Whiskers's Avatar
Go Giants
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Aug 2004
Posts: 70,003
Likes: 1,260
From: PA
Norton Power Eraser and Superantispyware (portable). NPE will need a reboot, run SAS in safe mode.
Reply
Old Jan 21, 2014 | 10:14 AM
  #5  
maharajamd's Avatar
Race Director
iTrader: (1)
 
Joined: Jan 2008
Posts: 13,382
Likes: 1,544
From: Columbus, OH
Reply
Old Jan 21, 2014 | 10:17 AM
  #6  
Bearcat94's Avatar
Thread Starter
AZ Community Team
 
Joined: May 2007
Posts: 32,488
Likes: 7,771
From: N35°03'16.75", W 080°51'0.9"
Originally Posted by Whiskers
Norton Power Eraser and Superantispyware (portable). NPE will need a reboot, run SAS in safe mode.

^^^

Helpful.



vvvv

Not helpful.

Originally Posted by maharajamd
Reply
Old Jan 21, 2014 | 10:19 AM
  #7  
stogie1020's Avatar
Needs more Lemon Pledge
 
Joined: Mar 2005
Posts: 52,768
Likes: 2,000
From: Phoenix, AZ
Unplug your speakers. You're welcome.







j/k, take warren's advice.
Reply
Old Jan 21, 2014 | 10:25 AM
  #8  
Yumcha's Avatar
Senior Moderator
20 Year Member
Photogenic
Community Builder
Liked
 
Joined: Dec 2001
Posts: 169,046
Likes: 23,823
Originally Posted by Bearcat94

Only 'suspect' site I visited in the past several days was a news site .... Salon.com or Huffington or some similar ad infested news/magazine site.


Sure sure...don't lie...we know you were surfing l33t pr0n.













Whiskers has some terrific steps to do. But, if you are really stuck, download HijackThis and post an image of the results (don't remove anything). One of us can take a peek to see what is up with your PC.

Otherwise, a refresh of your computer is not the worst thing to do. Just time-consuming.
Reply
Old Jan 21, 2014 | 10:35 AM
  #9  
#1 STUNNA's Avatar
Sanest Florida Man
Photogenic
Photoriffic
Shutterbug
Community Influencer
 
Joined: Aug 2007
Posts: 45,965
Likes: 11,758
From: Florida
I've only seen NPE work once for me, btw it gives a lot of false positives so don't go removing everything it finds.

I've had fantastic success with ESET Sirefef cleaner lately! Try that shit!

http://kb.eset.com/esetkb/index?page...nt&id=SOLN2895
Reply
Old Jan 21, 2014 | 10:36 AM
  #10  
03SSMTL-S's Avatar
Banned
 
Joined: Feb 2005
Posts: 13,252
Likes: 2,654
From: parts unknown
combofix.exe

http://www.bleepingcomputer.com/download/combofix/

wont work on Win 8
Reply
Old Jan 21, 2014 | 11:06 AM
  #11  
Whiskers's Avatar
Go Giants
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Aug 2004
Posts: 70,003
Likes: 1,260
From: PA
Originally Posted by 03SSMTL-S
overkill
Reply
Old Jan 21, 2014 | 11:44 AM
  #12  
97BlackAckCL's Avatar
Senior Moderator
Regional Coordinator
(Mid-Atlantic)
20 Year Member
Liked
Loved
Community Favorite
iTrader: (6)
 
Joined: Jan 2005
Posts: 92,733
Likes: 4,670
From: ShitsBurgh
Reply
Old Jan 21, 2014 | 12:22 PM
  #13  
Moog-Type-S's Avatar
The sizzle in the Steak
 
Joined: Nov 2001
Posts: 71,436
Likes: 1,877
From: Southern California
system restore

...and don't visit that pR0n site again.
Reply
Old Jan 21, 2014 | 01:44 PM
  #14  
#1 STUNNA's Avatar
Sanest Florida Man
Photogenic
Photoriffic
Shutterbug
Community Influencer
 
Joined: Aug 2007
Posts: 45,965
Likes: 11,758
From: Florida
^
Reply
Old Jan 21, 2014 | 01:51 PM
  #15  
97BlackAckCL's Avatar
Senior Moderator
Regional Coordinator
(Mid-Atlantic)
20 Year Member
Liked
Loved
Community Favorite
iTrader: (6)
 
Joined: Jan 2005
Posts: 92,733
Likes: 4,670
From: ShitsBurgh
Thanks Stunna!
Reply
Old Jan 21, 2014 | 04:08 PM
  #16  
nfnsquared's Avatar
Race Director
 
Joined: Dec 2003
Posts: 12,521
Likes: 1,824
From: MAGA country
Might be an variant of Happili...

Last I knew, both MBAM and MS Safety Scanner both detected it.

Check your %appdata% and %temp% folders for any .dll files. Delete them if they are there. Make note of the file name before deleting and then do a registry search for that file name.
Reply
Old Jan 21, 2014 | 05:15 PM
  #17  
stogie1020's Avatar
Needs more Lemon Pledge
 
Joined: Mar 2005
Posts: 52,768
Likes: 2,000
From: Phoenix, AZ
15 responses and no "get a mac"?
Reply
Old Jan 21, 2014 | 06:04 PM
  #18  
The Dougler's Avatar
Unofficial Goat
iTrader: (1)
 
Joined: Jul 2006
Posts: 15,744
Likes: 112
From: Toronto
Originally Posted by stogie1020
15 responses and no "get a mac"?
Post 5 is sort of saying it.
Reply
Old Jan 21, 2014 | 09:06 PM
  #19  
97BlackAckCL's Avatar
Senior Moderator
Regional Coordinator
(Mid-Atlantic)
20 Year Member
Liked
Loved
Community Favorite
iTrader: (6)
 
Joined: Jan 2005
Posts: 92,733
Likes: 4,670
From: ShitsBurgh
Originally Posted by stogie1020
15 responses and no "get a mac"?


Originally Posted by maharajamd
Reply
Old Jan 21, 2014 | 10:06 PM
  #20  
fuzzy02CLS's Avatar
Senior Moderator
iTrader: (2)
 
Joined: Jan 2003
Posts: 16,847
Likes: 223
From: South FL
Originally Posted by 03SSMTL-S
It works fine on 8. They may not support it but it works. I have cleaned a few 8 PC's recently.
Reply
Old Jan 22, 2014 | 07:55 AM
  #21  
maharajamd's Avatar
Race Director
iTrader: (1)
 
Joined: Jan 2008
Posts: 13,382
Likes: 1,544
From: Columbus, OH
Lol. You guys...
Reply
Old Jan 22, 2014 | 08:07 AM
  #22  
doopstr's Avatar
Team Owner
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Jan 2001
Posts: 25,967
Likes: 2,685
From: Jersey
Reply
Old Jan 22, 2014 | 08:57 AM
  #23  
03SSMTL-S's Avatar
Banned
 
Joined: Feb 2005
Posts: 13,252
Likes: 2,654
From: parts unknown
Originally Posted by fuzzy02CLS
It works fine on 8. They may not support it but it works. I have cleaned a few 8 PC's recently.
thanks, that good to know
Reply
Old Jan 22, 2014 | 08:57 AM
  #24  
Bearcat94's Avatar
Thread Starter
AZ Community Team
 
Joined: May 2007
Posts: 32,488
Likes: 7,771
From: N35°03'16.75", W 080°51'0.9"
Originally Posted by nfnsquared
Might be an variant of Happili...

Last I knew, both MBAM and MS Safety Scanner both detected it.

Check your %appdata% and %temp% folders for any .dll files. Delete them if they are there. Make note of the file name before deleting and then do a registry search for that file name.

What do the '%' mean .... I've got dozens of dll's in appdata. Which temp and/or appdata folders exactly?


TDSS Killer
Malwarebytes
SuperAntiSpyware
ComboFix

All fail .... nothing detected/deleted except a few ad tracking cookies.
Reply
Old Jan 22, 2014 | 09:09 AM
  #25  
03SSMTL-S's Avatar
Banned
 
Joined: Feb 2005
Posts: 13,252
Likes: 2,654
From: parts unknown
Originally Posted by Bearcat94
What do the '%' mean .... I've got dozens of dll's in appdata. Which temp and/or appdata folders exactly?


TDSS Killer
Malwarebytes
SuperAntiSpyware
ComboFix

All fail .... nothing detected/deleted except a few ad tracking cookies.
really, damn its a good one

try this

http://www.mcafee.com/us/downloads/f...s/getsusp.aspx

should give you a list of what is running and where it is located on the c:, so you can delete it
Reply
Old Jan 22, 2014 | 09:25 AM
  #26  
Whiskers's Avatar
Go Giants
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Aug 2004
Posts: 70,003
Likes: 1,260
From: PA
try hijackthis.
Reply
Old Jan 22, 2014 | 09:47 AM
  #27  
Yumcha's Avatar
Senior Moderator
20 Year Member
Photogenic
Community Builder
Liked
 
Joined: Dec 2001
Posts: 169,046
Likes: 23,823
Originally Posted by Whiskers
try hijackthis.
Yup...suggested that above. Post the results and we can see what does not belong.
Reply
Old Jan 22, 2014 | 10:45 AM
  #28  
#1 STUNNA's Avatar
Sanest Florida Man
Photogenic
Photoriffic
Shutterbug
Community Influencer
 
Joined: Aug 2007
Posts: 45,965
Likes: 11,758
From: Florida
Did you try this?

Originally Posted by #1 STUNNA
I've had fantastic success with ESET Sirefef cleaner lately! Try that shit!

http://kb.eset.com/esetkb/index?page...nt&id=SOLN2895
Reply
Old Jan 22, 2014 | 11:08 AM
  #29  
fuzzy02CLS's Avatar
Senior Moderator
iTrader: (2)
 
Joined: Jan 2003
Posts: 16,847
Likes: 223
From: South FL
Search for the AVG Boot CD. Download the image, burn to a CD & boot off it. It bypasses windows & runs a Linux shell scan. Updated it & select the threats you want it to detect. Will take a good hour. Delete any files it finds. Reboot.
Reply
Old Jan 22, 2014 | 11:29 AM
  #30  
Bearcat94's Avatar
Thread Starter
AZ Community Team
 
Joined: May 2007
Posts: 32,488
Likes: 7,771
From: N35°03'16.75", W 080°51'0.9"
Originally Posted by #1 STUNNA
Did you try this?
Not yet. I've downloaded enough 'crap' already. But it's on the list. I did, however, do a restore to last week .... not for the issue per se, but for the issues I created trying to eliminate this piece-of-shit malware.

And since the restore .... no issue .... .... .






Originally Posted by maharajamd

OK, I admit, it's funnier today .... .
Reply
Old Jan 22, 2014 | 11:32 AM
  #31  
maharajamd's Avatar
Race Director
iTrader: (1)
 
Joined: Jan 2008
Posts: 13,382
Likes: 1,544
From: Columbus, OH
Reply
Old Jan 22, 2014 | 02:40 PM
  #32  
Moog-Type-S's Avatar
The sizzle in the Steak
 
Joined: Nov 2001
Posts: 71,436
Likes: 1,877
From: Southern California
System restore?!?!

SHOCKING!

Clearly it altered the registry.

I'm not saying the malware is "gone", but it's not bothering you to the extent that it was.
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
jspangan
ILX
19
Aug 30, 2016 05:37 PM
95oRANGEcRUSH
Car Talk
35
Sep 25, 2015 12:50 PM
STL TL-S
3G TL Problems & Fixes
9
Sep 23, 2015 08:52 PM




All times are GMT -5. The time now is 01:05 AM.