Author Topic: I hear things that arn't there O.o  (Read 352 times)

0 Members and 1 Guest are viewing this topic.

Offline Ἆxule

  • *****
  • Posts: 1845
  • Gender: Male
  • Respect: +579
I hear things that arn't there O.o
« on: November 14, 2011, 10:01:42 PM »
It's quite odd, for awhile now I've been having these... noises, songs, advertisements, and whatever else, occasionally playing. There is nothing to close either. This is happening as I type.
There are also times when there are two or more playing at once.
And now, a webpage keeps opening up. The website is blinkx something.

What the hell is going on...

Offline Supertoaster

  • A completely superfluous bottle of cough syrup
  • ***
  • Cat LoverWindows User
    View More Badges!

  • Posts: 3711
  • Gender: Male
  • Only six bucks
  • Respect: +1236
Re: I hear things that arn't there O.o
« Reply #1 on: November 14, 2011, 10:15:51 PM »
Sounds like Adware, I'm unsure how to remove this.

Do a full virus scan and install Malawarebytes. Thats all I can contriubute

Offline Cable

  • ******
  • Posts: 2182
  • Gender: Male
  • hi
  • Respect: +1085

Offline Ἆxule

  • *****
  • Posts: 1845
  • Gender: Male
  • Respect: +579
Re: I hear things that arn't there O.o
« Reply #3 on: November 14, 2011, 11:34:59 PM »
So far I've only been able to get to the RKill thing. Whenever I try downloading or running it, the command prompt pops up once or twice and nothing happens after.

Offline Castle

  • ***
  • Posts: 166
  • Respect: +19
Re: I hear things that arn't there O.o
« Reply #4 on: November 15, 2011, 05:58:59 AM »
Gaming ghosts?  :trollface:

Offline Ἆxule

  • *****
  • Posts: 1845
  • Gender: Male
  • Respect: +579
Re: I hear things that arn't there O.o
« Reply #5 on: November 15, 2011, 08:58:55 AM »
Malwarebytes' Anti-Malware

Database version: 8165

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

11/15/2011 6:56:28 AM
mbam-log-2011-11-15 (06-56-28).txt

Scan type: Full scan (C:\|Q:\|)
Objects scanned: 601090
Time elapsed: 4 hour(s), 13 minute(s), 10 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 3
Registry Keys Infected: 5
Registry Values Infected: 4
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 16

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
c:\Users\Nate's\AppData\Local\servicesys32.dll (Trojan.SHarpro.Gen) -> Delete on reboot.
c:\programdata\mouseprofileupdate.dll (Trojan.SHarpro.PGen) -> Delete on reboot.
c:\Users\Nate's\AppData\Local\Google\googleupdate\Googleup.dll (Trojan.SHarpro.PGen) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{0EAB238E-497A-4884-AFA7-AAA599F601Fb} (Trojan.SHarpro.Gen) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0EAB238E-497A-4884-AFA7-AAA599F601FB} (Trojan.SHarpro.Gen) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{0EAB238E-497A-4884-AFA7-AAA599F601FB} (Trojan.SHarpro.Gen) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0EAB238E-497A-4884-AFA7-AAA599F601FB} (Trojan.SHarpro.Gen) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\.fsharproj (Trojan.BHO) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MouseProfileUpdate (Trojan.SHarpro.PGen) -> Value: MouseProfileUpdate -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Oberon Update (Trojan.SHarpro.PGen) -> Value: Oberon Update -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Trolltech Update (Trojan.SHarpro.PGen) -> Value: Trolltech Update -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\WinRAR Update (Trojan.SHarpro.PGen) -> Value: WinRAR Update -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Users\Nate's\AppData\Local\Temp\thpm3062737837039021031.tmp (Trojan.Exploit.Drop.THPM) -> Quarantined and deleted successfully.
c:\Users\Nate's\AppData\Local\Temp\thpm377124260971730934.tmp (Trojan.Exploit.Drop.THPM) -> Quarantined and deleted successfully.
c:\Users\Nate's\AppData\Local\Temp\nsc1DE0.tmp\msintl1a.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Nate's\AppData\Local\Temp\nsc1DE0.tmp\msintl1c.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Nate's\AppData\Local\Temp\nsc1DE0.tmp\msintl1e.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Nate's\AppData\Local\Temp\nshF251.tmp\tzdworf1.png (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Nate's\AppData\Local\Temp\nshF251.tmp\tzdworf2.png (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Nate's\AppData\Local\Temp\nshF251.tmp\tzdworf3.png (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Nate's\AppData\Local\Temp\nsn9993.tmp\001.jgg (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Nate's\AppData\Local\Temp\nsn9993.tmp\002.jgg (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Nate's\AppData\Local\Temp\nsn9993.tmp\003.jgg (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Nate's\AppData\Local\Temp\nsqBACC.tmp\errpoid2.xx (Trojan.Tracur.VGen) -> Quarantined and deleted successfully.
c:\Users\Nate's\local settings\application data\servicesys32.dll (Trojan.SHarpro.Gen) -> Quarantined and deleted successfully.
c:\Users\Nate's\AppData\Local\servicesys32.dll (Trojan.SHarpro.Gen) -> Quarantined and deleted successfully.
c:\programdata\mouseprofileupdate.dll (Trojan.SHarpro.PGen) -> Quarantined and deleted successfully.
c:\Users\Nate's\AppData\Local\Google\googleupdate\Googleup.dll (Trojan.SHarpro.PGen) -> Quarantined and deleted successfully.

Offline Deacon

  • The righteous rise, with burning eyes
  • ***
  • DonatorDWO Player
    View More Badges!

  • Posts: 4482
  • Gender: Male
  • of hatred and ill-will
  • Respect: +1788
Re: I hear things that arn't there O.o
« Reply #6 on: November 15, 2011, 10:27:18 AM »
holy shitfuck
enjoy dem trojans

Offline Ἆxule

  • *****
  • Posts: 1845
  • Gender: Male
  • Respect: +579
Re: I hear things that arn't there O.o
« Reply #7 on: November 15, 2011, 01:13:11 PM »
I'm not sure where they came from.
They should be gone now though.

Offline Loke

  • Click Click
  • *****
  • Windows UserCat Lover
    View More Badges!

  • Posts: 845
  • Gender: Male
  • Boom
  • Respect: +88
Re: I hear things that arn't there O.o
« Reply #8 on: November 15, 2011, 02:44:29 PM »

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MouseProfileUpdate (Trojan.SHarpro.PGen) -> Value: MouseProfileUpdate -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Oberon Update (Trojan.SHarpro.PGen) -> Value: Oberon Update -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Trolltech Update (Trojan.SHarpro.PGen) -> Value: Trolltech Update -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\WinRAR Update (Trojan.SHarpro.PGen) -> Value: WinRAR Update -> Quarantined and deleted successfully.

Just had to.
Allah's Snackbar is best food place.

Offline Hotgreensoldier

  • I think.. I think I won't see you again after all
  • *****
  • Posts: 1745
  • Gender: Male
  • But maybe..Maybe I'm fighting for different reason
  • Respect: +235
Re: I hear things that arn't there O.o
« Reply #9 on: November 15, 2011, 03:42:54 PM »

So everything is working naow?
<08:17:05> "RND Faggot": <17:16:21> "Nautilus": where
<17:16:24> "Nautilus": where u goin
<17:16:26> "[Valor]iPouncる": niggatown

Moo: general tishipants

Offline Ἆxule

  • *****
  • Posts: 1845
  • Gender: Male
  • Respect: +579
Re: I hear things that arn't there O.o
« Reply #10 on: November 15, 2011, 04:23:36 PM »

So everything is working naow?

Haven't had the time to find out.
Let it scan overnight, and had to leave for school early morning

Offline Dale Feles

  • Hoersface
  • ******
  • Posts: 2938
  • Gender: Male
  • Respect: +622
Re: I hear things that arn't there O.o
« Reply #11 on: November 16, 2011, 03:58:13 AM »
I'm pretty sure they will be gone thanks to Mbam. Remember to update it if you ever do a second scan. Versions that aren't correctly updated won't pick up all the viruses.

Thank you Marie for the sprite.

Offline Ἆxule

  • *****
  • Posts: 1845
  • Gender: Male
  • Respect: +579
Re: I hear things that arn't there O.o
« Reply #12 on: November 16, 2011, 10:25:42 PM »
fml so much right now.
I swear my computer hates me.

Everything was fine for awhile, but then out of nowhere the stupid sounds came back. And adding on to that, everytime I try to google something, it redirects me to something else.


I'm gonna do the damn scan again and hope it goes away for good.

Offline yoshi

  • as I said, pretty nice.
  • *****
  • Old Forum MemberWindows UserDog Lover
    View More Badges!

  • Posts: 1119
  • Respect: +377
Re: I hear things that arn't there O.o
« Reply #13 on: November 17, 2011, 03:15:59 AM »
Defrag your computer and show me the results.

Offline Cable

  • ******
  • Posts: 2182
  • Gender: Male
  • hi
  • Respect: +1085
Re: I hear things that arn't there O.o
« Reply #14 on: November 17, 2011, 03:54:23 AM »
Also, To make this clear:

I hear things that aren't there.