There is indeed some malware showing up here that is most likely responsible for the audio alerts, but unfortunately also a rootkit. Before continuing with the cleaning process, read the following.BACKDOOR WARNING
------------------------------One or more of the identified infections is known to use a backdoor.
This allows hackers to remotely control your computer, steal critical system information
and download and execute files
I would advice you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.
Though the infection has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?When Should I Format, How Should I ReinstallWe can still clean this machine but I can't guarantee that it will be 100% secure afterwards. Let me know what you decide to do. If you decide to go through with the cleanup, please proceed with the following steps.We need to run a scan with Combofix:
- Please go to the download page for ComboFix by sUBs.
- Click the Download Now button pictured below and save the file to your desktop:
- Disable any anti-virus and/or firewall software you have installed.
instructions can be found here if needed
- Close all open windows including your web browser
as mentioned in the first post, you may want to print out all instructions before starting
- Double-click on the ComboFix icon on your desktop.
- Read the Disclaimer and click I Agree if you want to run the software, then you should see a window like the one below:
- DO NOT use your computer while ComboFix is running. There are a lot of things going on behind the scenes and a single mouse click can cause the program to stall.
However, if you see the prompt below, please click Yes to download the Microsoft Windows Recovery Console.
If an Internet connection is not available or you choose not to install the recovery console, ComboFix will run in Reduced Functionality mode
- Allow ComboFix to reboot the computer if necessary, it will run again after you log back in.
- When complete, a log file will be displayed, please copy and paste the contents of this file into your next post.
- More information about downloading and using ComboFix can be found here if needed.
"Now faith is the substance of things hoped for, the evidence of things not seen."
Follow BleepingComputer on: Facebook | Twitter | Google+ | lockerdome
Malware analyst @ Emsisoft