Pending winrscmde playing random audio

Discussion in 'Virus, Spyware and Malware Removal' started by Mythe7, Jul 17, 2012.


Thread Status:
Not open for further replies.
  1. Mythe7 Bronze Member

    Bronze
    Message Count:
    9
    Likes Received:
    0
    My System
    Loading...
    Last night my laptop restarted out of nowhere while I was browsing the internet. When it finished and I logged back on, the audio from 3 or 4 video ads began playing, even though no browser was open. I looked at the audio mixer and found that the sound was coming from something called "winrscmde.exe". I muted it, but other copies began showing up in the mixer and playing other ads with no discernible pattern. I checked the Task Manager to try to kill it, but there was no application or process with that name.



    I use McAfee Antivirus and had it run a full scan, but it found nothing, and I also searched my hard drive for winrscmde.exe and found nothing. My laptop has done the same thing of rebooting unexpectedly in the past, nearly since I got it around 2 months ago, so it's possible the problem dates back farther than last night, but this is the first time any obviously malicious symptoms had appeared (until now I had assumed the restarts were nothing of concern). So far nothing worse than the audio has occurred, but I want to get rid of this before it gets any worse.

    My computer runs Windows 7 64-bit. It's an Acer Apsire 5750G-6653, if that helps.

    Prework logs are attached below.

    Attached Files:

  2. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,885
    Likes Received:
    3,659
    My System
    Loading...
    Hi,

    Welcome to the site.

    Download Combofix from any of the links below, and save it to your desktop.

    Link 1
    Link 2
    Link 3

    When saving ComboFix rename it to PCHelpForum.exe to prevent it from being blocked by malware.


    Refer to this image:

    To prevent your anti-virus application interfering with ComboFix we need to disable it. See here for a tutorial regarding how to do so if you are unsure.
    • Close any open windows and double click PCHelpForum.exe to run it.

      You will see the following image:
    [IMG]

    Click I Agree to start the program.

    ComboFix will then extract the necessary files and you will see this:

    [IMG]

    As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. This will not occur in Windows Vista and 7

    It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

    If you did not have it installed, you will see the prompt below. Choose YES.

    [IMG]

    Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [IMG]

    Click on Yes, to continue scanning for malware.

    When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).

    Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so.

    Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.
  3. Mythe7 Bronze Member

    Bronze
    Message Count:
    9
    Likes Received:
    0
    My System
    Loading...
    So far everything looks good, the audio didn't play this time, which was my only symptom so far.

    Attached Files:

  4. Google Advertisement

  5. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,885
    Likes Received:
    3,659
    My System
    Loading...
    Ok. Give it a bit, see if it comes back
  6. Mythe7 Bronze Member

    Bronze
    Message Count:
    9
    Likes Received:
    0
    My System
    Loading...
    Nope, it's still happening. I've gotten it again over the past couple of days, and earlier when I started my computer instead of starting windows it opened some "System Repair" thing in a window scheme that looked like Windows 2000. When I clicked the cancel button it said "The current repair operation can't be cancelled", so I turned the computer off. As it booted again it gave me that "windows failed to shut down correctly" menu with "Launch System Repair (recommended)" (or whatever the wording was) and "Launch Windows Normally". I chose to launch windows normally. Most recently my computer just restarted on its own again, playing more ad audio and this time taking me to a suspicious website when I opened Firefox. A few minutes after it finished this last boot, McAfee gave me a notification saying it has removed a trojan called Generic.dx!b2qj and that no further action was required. I don't know if that was the one that's been causing my problems, or if it's bringing other viruses in, since McAfee's scan didn't find anything before. What should I do?
  7. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,885
    Likes Received:
    3,659
    My System
    Loading...
    Please download TDSSKiller from here and save it to your Desktop.

    • Doubleclick TDSSKiller.exe to run the tool
    • Choose Change Parameters and make sure all the options are checked
    • Click the Start Scan button
    • After the scan has finished, click the Close button
    • Click the Report button and attach the contents of it into your next reply
    Note:It will also create a log in the C:\ directory.
  8. Mythe7 Bronze Member

    Bronze
    Message Count:
    9
    Likes Received:
    0
    My System
    Loading...
    I ran it once and it said it found something that looked like malware, and to restart my computer, so I did. However, when I logged in and opened firefox it again redirected me to some suspicious pages. McAfee Also said it removed the same trojan again, so I ran TDSSKiller again; here are the logs from both

    Attached Files:

  9. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,885
    Likes Received:
    3,659
    My System
    Loading...
    Hi,

    Please re-run TDSSKiller and quarantine these:

    11:20:01.0529 6104\Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
    11:20:01.0529 6104\Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
  10. Mythe7 Bronze Member

    Bronze
    Message Count:
    9
    Likes Received:
    0
    My System
    Loading...
    Should I need a restart after this one? Also what's the other one, the GREGService thing?

    Attached Files:

  11. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,885
    Likes Received:
    3,659
    My System
    Loading...
    That's just a file without a digital signature. Nothing to worry about. How is the machine running?
  12. Mythe7 Bronze Member

    Bronze
    Message Count:
    9
    Likes Received:
    0
    My System
    Loading...
    So far nothing else has happened, looks like that did it! Thanks a lot to you and your staff, I think it's really great that you guys do this.
  13. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,885
    Likes Received:
    3,659
    My System
    Loading...
    To uninstall ComboFix


    • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
    • In the field, type in ComboFix /uninstall
    [IMG]

    (Note: Make sure there's a space between the word ComboFix and the forward-slash.)


    • Then, press Enter, or click OK.
    • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
    =========



    Please run OTL.exe.

    • Copy the commands with file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

      :Commands
      [emptytemp]
      [emptyflash]
      [clearallrestorepoints]
      [reboot]

      Return to OTL.exe, right click in the "Custom Scans/Fixes" window (under the light green bar) and choose Paste.
    • Click the red Run Fix button.
    • A fix log in Notepad will appear. Copy the contents of the fix log to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
    • Close OTL.exe
    If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

    ======

    Remove OTL:

    To remove all of the tools we used and the files and folders they created do the following:
    Double click OTL.exe.

    • Click the CleanUp button.
    • Select Yes when the "Begin cleanup Process?" prompt appears.
    • If you are prompted to Reboot during the cleanup, select Yes.
    • The tool will delete itself once it finishes.
    Note:If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
    =======

    Download Security Check by screen317 and save it to your Desktop.
    • Double-click Security Check.exe to start the application
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
    Note: if a security program requests permission from dig.exe to access the Internet, allow it to do so.
    =======

    There are many things you can do to keep this from happening again. You can think of a computer like a car. It requires basic maintenance to keep in tip top shape and ready to go. Would you drive your car 100,000 miles without changing the oil? The same principle applies here.

    For some helpful tips regarding why you were infected in the first place, what you can do to keep this from happening again, and routine basic maintenance you should be performing on your PC to keep it running, you may wish to review the following threads:

    So, you want to keep this from happening again?
    How Did I Get Infected?
    [IMG]

    In your next reply:

    Please confirm removal of the tools
    Post the SecurityCheck log
  14. Mythe7 Bronze Member

    Bronze
    Message Count:
    9
    Likes Received:
    0
    My System
    Loading...
    Hold on, before I remove the stuff, McAfee is now saying it keeps finding two "Issues", both called "Desktop.ini", that it can't delete. I don't think these are related to the original infection, but what should I do about them? Are they dangerous, and if so, can the same tools fix them?
  15. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,885
    Likes Received:
    3,659
    My System
    Loading...
    You can just delete them
  16. Mythe7 Bronze Member

    Bronze
    Message Count:
    9
    Likes Received:
    0
    My System
    Loading...
    I keep trying, but when I try to find them, the folders the report says they're in don't exist

winrscmde playing random audio

Thread Status:
Not open for further replies.