Hello, I was just watching netflix and noticed a sound playing very quietly in the background. So, I closed everything I had open and there is the sound of a random local radio station playing out of the speakers. I am sure this is some kind of virus but I am not sure how to get rid of it everything I have tried has not stopped the sound. I also have recently has adds popping up on my internet browser no matter what site I am on.
Radio Station Playing in Background/Random popup adds [Closed]
8 min read
Hello Everstar, welcome to WhatTheTech's Malware Removal forum!
My username is LiquidTension, but you can call me Adam. I will be assisting you with your malware-related problems.
If you would allow me to call you by your first name I would prefer that. ![]()
======================================================
Please read through the points below to ensure this process moves as quickly and efficiently as possible.
- Please ensure you read through my instructions thoroughly, and carry out each step in the order specified.
- Please do not post logs using the CODE, QUOTE or ATTACHMENT format. Logs should be posted directly in plain text. If you receive an error whilst posting, please break the log in half and use multiple posts.
- Please do not run any tools or take any steps other than those I provide for you. Independent efforts may make matters worse, and will affect my ability in ascertaining the current situation and providing the best set of instructions for you.
- Please backup important files before proceeding with my instructions. Malware removal can be unpredictable.
- If you come across any issues whilst following my instructions, please stop and inform me of the issue in as much detail as possible. Please do not hesitate to ask before proceeding.
- Topics are locked if no response is made after 4 days. Please inform me if you require additional time to complete my instructions.
- Ensure you are following this topic. Click [external image: etYzdbu.png] at the top of the page.
======================================================
Please run the following diagnostic scans so I can ascertain the state of your computer.
STEP 1
[external image: xlK5Hdb.png] Farbar Recovery Scan Tool (FRST) Scan
- Please download Farbar Recovery Scan Tool (x32) or Farbar Recovery Scan Tool (x64) and save the file to your Desktop.
- Note: Download and run the version compatible with your system (32 or 64-bit). Download both if you're unsure; only one will run.
- Right-Click FRST.exe / FRST64.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
- Click Yes to the disclaimer.
- Ensure the Addition.txt box is checked.
- Click the Scan button and let the programme run.
- Upon completion, click OK, then OK on the Addition.txt pop up screen.
- Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy the contents of both logs and paste in your next reply.
STEP 2
[external image: YARWD1t.png.pagespeed.ce.nvhmVeYDe3.png] TDSSKiller Scan
- Please download TDSSKiller and save the file to your Desktop.
- Right-Click TDSSKiller.exe and select [external image: xAVOiBNU.jpg.pagespeed.ic.H5HC6LkiJX.jpg] Run as administrator to run the programme.
- Click Change parameters. Place a checkmark next to Detect TDLFS file system and Verify file digital signatures.
- Click Start Scan. Do not use the computer during the scan.
- If objects are found, change the action to skip.
- Click Continue and close the window.
- A log will be created and saved to the root directory (usually C:\). Attach the file in your next reply.
======================================================
STEP 3
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.
- FRST.txt
- Addition.txt
- TDSSKiller log (attached)
Hi, thanks for the reply and the help. You can call me Nathan. I have done what you said and posted below what you have asked for.
TDSSKiller.3.0.0.41_16.11.2014_17.45.02_log.txt
Addition:
Hi Nathan,
Please consider the following warning, and work your way through the instructions below.
[external image: goGMWSt.gif]Multiple Anti-Virus Software Installed
——————————
It is inadvisable to have more than one Anti-Virus installed on your computer at the same time. Doing so may:Please remove all but one Anti-Virus from your computer.
- Cause conflicts, negatively impacting the effectiveness of each Anti-Virus installed.
- Trigger false-positives.
- Trigger false-negatives, where neither programme detects malware.
- Cause system instability/performance issues. Your system may lock up or slow down due to both software attempting to access the same file at the same time.
- Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time.
- Type appwiz.cpl and click OK.
- Search for and uninstall all but one of the programmes listed below by right-clicking and clicking Uninstall.
- AVG AntiVirus Free Edition 2014
- Microsoft Security Essentials
- Follow the prompts, and reboot your computer once uninstalled.
STEP 1
[external image: 6JO0hXH.png] Revo Uninstaller
- Please download and install Revo Uninstaller Free.
- Double-click Revo Uninstaller to run the programme.
- From the list of programmes, locate the following, or anything similar and carry out the steps below one at a time.
- Ask Toolbar
- Ask Toolbar Updater
- AVG Web TuneUp
- Lock Poker (if you did not install yourself)
- ValueApps
- Double-click the programme.
- When prompted if you want to uninstall click Yes.
- Ensure the Moderate option is selected and click Next.
- The programme uninstaller will run. If prompted again click Yes.
- Work your way through the uninstaller, ensuring you read each page thoroughly.
- Note: Ensure you decline offers of additional software if applicable.
- Once the built-in uninstaller is finished click Next.
- Once the programme has searched for leftovers click Next.
- Check items in bold only in the list and click Delete. You may have to expand folders by clicking the "+" mark.
- When prompted click Yes, followed by Next.
- Click Select all, followed by Delete.
- When prompted click Yes, followed by Next.
- Once done click Finish.
STEP 2
[external image: BY4dvz9.png] AdwCleaner
- Please download AdwCleaner and save the file to your Desktop.
- Right-Click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
- Follow the prompts.
- Click Scan.
- Upon completion, click Report. A log (AdwCleaner[R0].txt) will open. Briefly check the log for anything you know to be legitimate.
- Ensure anything you know to be legitimate does not have a checkmark, and click Clean.
- Follow the prompts and allow your computer to reboot.
- After rebooting, a log (AdwCleaner[S0].txt) will open. Copy the contents of the log and paste in your next reply.
– File and registry key backups are made for anything removed using this tool. Should a legitimate entry be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the entry. Please do not overly concern yourself with the contents of AdwCleaner[R0].txt.
STEP 3
[external image: E3feWj5.png] Junkware Removal Tool (JRT)
- Please download Junkware Removal Tool and save the file to your Desktop.
- Note: If you unchecked any items in AdwCleaner, please backup the associated folders/files before running JRT.
- Temporarily disable your anti-virus software. For instructions, please refer to the following link.
- Right-Click JRT.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
- Follow the prompts and allow the scan to run uninterrupted.
- Upon completion, a log (JRT.txt) will open on your desktop.
- Re-enable your anti-virus software.
- Copy the contents of JRT.txt and paste in your next reply.
STEP 4
[external image: xlK5Hdb.png] Farbar Recovery Scan Tool (FRST) Scan
- Right-Click FRST64.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
- Click Yes to the disclaimer.
- Ensure the Addition.txt box is checked.
- Click the Scan button and let the programme run.
- Upon completion, click OK, then OK on the Addition.txt pop up screen.
- Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy the contents of both logs and paste in your next reply.
======================================================
STEP 5
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.
- Which Anti-Virus did you uninstall?
- Did the programmes uninstall OK?
- AdwCleaner[S0].txt
- JRT.txt
- FRST.txt
- Addition.txt
Hello Nathan,
Do you still require assistance?
Sorry I have been busy with University classes/ Work. Could you leave this topic open and I will post back today after work?
Sorry for the Inconvenience,
Nathan.
No problem, that's quite alright. ![]()
1. I uninstalled AVG anti-virus
2. I could not remove ask toolbar
3.
Hello Nathan,
Please provide an update on your computer after completing the steps below.
STEP 1
[external image: xlK5Hdb.png] Farbar Recovery Scan Tool (FRST) Script
- Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type Notepad and click OK.
- Copy the entire contents of the codebox below and paste into the Notepad document.
start HKLM-x32\…\Run: [] => [X] SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search SearchScopes: HKU\S-1-5-21-232412378-3118420049-1387226345-1000 -> DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69} URL = SearchScopes: HKU\S-1-5-21-232412378-3118420049-1387226345-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = CHR StartupUrls: Default -> "hxxp://www.msn.com/?pc=UP97&ocid=UP97DHP", "hxxp://mysearch.avg.com?cid={7B279313-C709-41AF-A472-7CD76BA06AC5}&mid=f7fd2eb02e1447d2ad7cd157753fc03e-b602d594afd2b0b327e07a06f36ca6a7e42546d0&lang=en&ds=AVG&coid=avgtbavg&pr=fr&d=2014-06-20 21:22:45&v=3.0.0.2&pid=wtu&sg=&sap=hp" CHR HKLM-x32\…\Chrome\Extension: [cfgmipjabpfjdgflgbjjpgekdejokfci] - C:\Users\Owner\AppData\Local\CRE\cfgmipjabpfjdgflgbjjpgekdejokfci.crx [] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] C:\Users\Owner\RA2-QM-Resolution-patch.exe C:\Users\Owner\AppData\Local\Temp\DseShExt-x64.dll C:\Users\Owner\AppData\Local\Temp\DseShExt-x86.dll C:\Users\Owner\AppData\Local\Temp\SDShelEx-win32.dll C:\Users\Owner\AppData\Local\Temp\SDShelEx-x64.dll C:\Users\Owner\AppData\Local\Temp\SkypeSetup.exe File: C:\Windows\System32\drivers\tcpip.sys CMD: ipconfig /flushdns CMD: netsh winsock reset all CMD: netsh int ipv4 reset CMD: netsh int ipv6 reset EmptyTemp: end - Click File, Save As and type fixlist.txt as the File Name.
- Important: The file must be saved in the same location as FRST64.exe.
NOTICE: This script is intended for use on this particular machine. Do not use this script on any other machine; doing so may cause damage to your Operating System.
- Right-Click FRST64.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
- Click Fix.
- A log (Fixlog.txt) will open on your desktop. Copy the contents of the log and paste in your next reply.
STEP 2
[external image: mlEX1wH.png] RogueKiller
- Please download RogueKiller (x64) and save the file to your Desktop.
- Close any running programmes.
- Right-Click RogueKiller.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
- Allow the Prescan to complete. Upon completion, a window will open. Click Accept.
- A browser window may open. Close the browser window.
- Click [external image: jpgUwzp.png]. Upon completion, click [external image: phPvmc6.png].
- Close the programme. Do not fix anything!
- A log (RKreport.txt) will be open. Copy the contents of the log and paste in your next reply.
======================================================
STEP 3
[external image: xpfNZP4A.png.pagespeed.ic.bp5cRl1pJg.jpg] Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.
- Fixlog.txt
- RKreport.txt
Well before I post the logs I'd just like to say thank you very much for your help, even though I have no idea whats going on I know its helping cause the dang radio station has stopped haha!
However one concern, for part 2 of your last post: After "prescan" I was to scan again, and it told me the scan was finished in under 3 seconds….So i hope my log is correct.
1.
my rougekiler worked this time, I believe I had this website open during my first attempt and messed it up. Here is the log.
That log looks good. ![]()
Lets check for malware remnants.
STEP 1
[external image: GfiJrQ9.png] Malwarebytes Anti-Malware (MBAM)
- Please download the Malwarebytes Anti-Malware setup file to your Desktop.
- Open mbam-setup.x.x.xxxx.exe (x represents the version #) and follow the prompts to install the programme.
- Open Malwarebytes Anti-Malware and click Update Now.
- Once updated, click the Settings tab, followed by Detection and Protection and tick Scan for rootkits.
- Click the Scan tab, ensure Threat Scan is checked and click Scan Now.
- Note: You may see the following message, "Could not load DDA driver". Click Yes, allow your PC to reboot and continue afterwards.
- If threats are detected, click the Apply Actions button. You will now be prompted to reboot. Click Yes.
- Upon completion of the scan (or after the reboot), click the History tab.
- Click Application Logs and double-click the Scan Log.
- Click Copy to Clipboard and paste the log in your next reply.
STEP 2
[external image: GzlsbnV.png] ESET Online Scan
Note: This scan may take a long time to complete. Please do not browse the Internet whilst your Anti-Virus is disabled.
- Please download ESET Online Scan and save the file to your Desktop.
- Temporarily disable your anti-virus software. For instructions, please refer to the following link.
- Double-click esetsmartinstaller_enu.exe to run the programme.
- Agree to the EULA by placing a checkmark next to Yes, I accept the Terms of Use. Then click Start.
- Agree to the Terms of Use once more and click Start. Allow components to download.
- Place a checkmark next to Enable detection of potentially unwanted applications.
- Click Hide advanced settings. Place a checkmark next to:
- Scan archives
- Scan for potentially unsafe applications
- Enable Anti-Stealth technology
- Ensure Remove found threats is unchecked.
- Click Start.
- Wait for the scan to finish. Please be patient as this can take some time.
- Upon completion, click [external image: esetListThreats.png]. If no threats were found, skip the next two bullet points.
- Click [external image: esetExport.png] and save the file to your Desktop, naming it something such as "MyEsetScan".
- Push the Back button.
- Place a checkmark next to [external image: xKN1w2nv.png.pagespeed.ic.JWqIaEgZi7.png] and click [external image: SzOC1p0.png.pagespeed.ce.OWDP45O6oG.png].
- Re-enable your anti-virus software.
- Copy the contents of the log and paste in your next reply.
======================================================
STEP 3
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.
- MBAM Scan log
- ESET Online Scan log
Hi Nathan,
Just checking in to see how you're getting on?
If you need help please start a new thread.
New members follow the instructions here http://forums.whatthetech.com/you_Infected_t106388.html and start a new topic
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI