This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Randow audio file playing in the background [Closed]

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I shut down all programs and turned off MSE virus protection and ran combofix as per your instrutions. Attached is the txt file I got this time. The random audio file just ran for 10 seconds while I was typing this. Thanks

Attachments:

I rebooted in the safe mode with the exe TDSSKiller file on the desktop. I tried running it and nothing happened. I tried again running a administrator and nothing happed. I did wait just to see if it was running in the background but nothing showed up. Could it have run but I just didn't find the txt file? Thanks
Hi,

Let's come back to TDSSKiller later.
——–
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text

    present inside the code box below:
    ClearJavaCache::
    
    DDS::
    mStart Page = hxxp://start.funmoods.com/?f=1&a=fmtoby&chnl=fmtoby&cd=2XzutAtN2Y1L1QzutD0CyCtDyByCyE0Fzy0DyEtAtDyEyCyCtN0D0TzutBtDtCtBtDyCtDzy&cr=1000216271
    uInternet Settings,ProxyOverride = *.local
    Trusted Zone: comlu.com\lobospecial
    Trusted Zone: google.com\www
    Trusted Zone: internet
    Trusted Zone: mcafee.com
    Trusted Zone: statcounter.com
    Trusted Zone: statcounter.com\www
    
    Firefox::
    FF - ProfilePath - c:\users\RLE\AppData\Roaming\Mozilla\Firefox\Profiles\p15u0tz0.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&SearchSource=3&q={searchTerms}
    FF - prefs.js: browser.startup.homepage - hxxp://start.funmoods.com/?f=1&a=fmtoby&chnl=fmtoby&cd=2XzutAtN2Y1L1QzutD0CyCtDyByCyE0Fzy0DyEtAtDyEyCyCtN0D0TzutBtDtCtBtDyCtDzy&cr=1000216271
    FF - prefs.js: keyword.URL - hxxp://blekko.com/ws/?source={SourceID}&tbp=url&toolbarid=blekkotb_soc&u=USERGUID&q=
    FF - user.js: extensions.funmoods.hmpg - true
    FF - user.js: extensions.funmoods.hmpgUrl - hxxp://start.funmoods.com/?f=1&a=fmtoby&chnl=fmtoby&cd=2XzutAtN2Y1L1QzutD0CyCtDyByCyE0Fzy0DyEtAtDyEyCyCtN0D0TzutBtDtCtBtDyCtDzy&cr=1000216271
    FF - user.js: extensions.funmoods.dfltSrch - true
    FF - user.js: extensions.funmoods.srchPrvdr - Search
    FF - user.js: extensions.funmoods.dnsErr - true
    FF - user.js: extensions.funmoods_i.newTab - true
    FF - user.js: extensions.funmoods.newTabUrl - hxxp://start.funmoods.com/?f=2&a=fmtoby&chnl=fmtoby&cd=2XzutAtN2Y1L1QzutD0CyCtDyByCyE0Fzy0DyEtAtDyEyCyCtN0D0TzutBtDtCtBtDyCtDzy&cr=1000216271
    FF - user.js: extensions.funmoods.tlbrSrchUrl -
    FF - user.js: extensions.funmoods.id - 92f204660000000000000c60764f9d43
    FF - user.js: extensions.funmoods.instlDay - 15500
    FF - user.js: extensions.funmoods.vrsn - 1.5.23.22
    FF - user.js: extensions.funmoods.vrsni - 1.5.23.22
    FF - user.js: extensions.funmoods_i.vrsnTs - 1.5.23.2223:2:36
    FF - user.js: extensions.funmoods.prtnrId - funmoods
    FF - user.js: extensions.funmoods.prdct - funmoods
    FF - user.js: extensions.funmoods.aflt - fmtoby
    FF - user.js: extensions.funmoods_i.smplGrp - none
    FF - user.js: extensions.funmoods.tlbrId - base
    FF - user.js: extensions.funmoods.instlRef - fmtoby
    FF - user.js: extensions.funmoods.dfltLng -
    FF - user.js: extensions.funmoods.excTlbr - false
    FF - user.js: extensions.funmoods.autoRvrt - false
    FF - user.js: extensions.funmoods.envrmnt - production
    FF - user.js: extensions.funmoods.isdcmntcmplt - true
    FF - user.js: extensions.funmoods.mntrvrsn - 1.3.0
    FF - user.js: extentions.y2layers.installId - 23327821-86e4-4d83-8459-db6bbc3a7cb6
    FF - user.js: extentions.y2layers.defaultEnableAppsList - pagerage,buzzdock,bestvideodownloader,ezlooker,twittube,toprelatedtopics,interst
    itialads
    
    File::
    c:\program files (x86)\FSL\IconRestorer\IconRestorer.exe
    c:\program files (x86)\IObit\Advanced SystemCare 5\ASCService.exe
    
    Folder::
    c:\program files (x86)\Conduit
    
    Driver::
    AdvancedSystemCareService5
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your

    desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware

    real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded

    files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next

    reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
Malwarebytes

I see that you have Malwarebytes already on your computer. Please open Malwarebytes, update it and then run a Quick Scan. Save the log that is created for your next reply.
———-

Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats is NOT selected and the option Scan unwanted applications is selected.
  • Click Scan (This scan can take several hours, so please be patient)
  • If there are threats that are found, please press List of found threats and then in the next window that opens press Export to text file…
  • Copy and paste/or attach that log as a reply to this topic
**Note** If not threats are found there will not be a log created.
———-
I ran the ESET online scanner (downloaded the Active X file and did NOT select the remove threat option as per your good instructions.) It ran for over three hours and during that time it showed 9 infected files, but when finished, it did not give a report-just a place to purchase their product. I did not see a “list of found threats” or an option to export to a file. I guess I could have copied the names of the infected files before it finished but as far as I know they were not saved. It DID show some threats, one Trojan and a bunch of Ad files-what do you suggest? I can run it again and copy the file names before it is finished. I think it is still installed. Thanks much for your time. Note: The audio file ran two times during the three hours-I think -since I was not at the computer all that time, but my dog did bark only twice and I came running and caught the end of the audio. Cheers!
Ok….. Let's forgo ESET for now, but we will need to run that again to see what it is showing. For the time being try to run aswMBR.exe again…in Safe Mode if you can't get it to run in Normal.
Another problem. The aswMBR would not run normally (ran as administrator) so I rebooted in the safe mood (F8 after BIOS loaded), it loaded all of the files but I never did get the desktop (I did get the prompt to enter password). I had to turn off and then restart -got the warning that Windows did not shut down normally so I started it again and it worked fine. I tried to reboot in safe mode and again did not get the desktop. First time I have not been able to open in safe mode.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI