The attack of soundman.exe

Status
Not open for further replies.

Targon

Solid State Member
Messages
19
This is one that has been driving me crazy. I've been dealing with a computer that started with a LOT of spyware on it. That machine was so badly infested, I was pretty impressed that the machine would boot at all.

So, I start with an msconfig to keep a bunch of the stuff from starting. I know some will come back, but I needed the machine to be a bit more responsive.

Next, I went into regedit(after rebooting), and went through all the ...software\microsoft\windows\currentversion\run* entries and removed the junk I found that was bad. For those not familiar with this, it's a manual way to get to the startup stuff you can find in msconfig. The RunOnce and RunOnce variants are things that get run only once on Windows startup. These are how many pieces of spyware show up again in your startup tab, even after you've removed them.

So those were clean. The machine was fairly responsive, so I threw Ad-aware 6, CW Shredder, and HiJackThis onto the machine. Cleaning out the last of the junk, all looked pretty good. So I did a reboot to make sure the system stayed clean, and it was, except an entry in hijackthis that was indicating soundman.exe was back. So I removed it again, rebooted, and it came back.

So, I did some looking and found it was probably a part of the W32.Gaobot worm. So I went to the symantec site, downloaded the removal tool, and it found four files that it said were infected. Removed them, checked, all seemed clean. Ok, reboot, and soundman.exe is back AGAIN.

At this point, I've decided that I could use some help. Nothing on the web has come up with a solution to get rid of this thing. I've checked the hard drive and the soundman.exe file doesn't exist, so it may be a disguise for the true file, either that or there's something left over.

Since I know where the stuff that starts with windows is in the registry, does anyone know where the stuff that gets performed as you shut down is? I figure between the Run/RunOnce sections and that, clearing and keeping most spyware from returning SHOULD be a bit easier.

Any help would be appreciated.
 
Soundman.exe is part of realtek's audio software. What type of sound card do you have ?
 
soundman WAS a part of realtek's audio software, but the name has been hijacked by spyware companies. That's the problem I was running into.
 
Are you using RealTek's software? Do you need their Soundman.exe?

This may be oversimplified, but can't you rename the bad files, remove them, and then download the appropriate files for that software?

Or, is that what you have not been able to do?

Dave :D
 
The problem was that even after removing soundman.exe, it kept comming back. This is the trojan version, not the legit soundman.exe. That's the problem. The trojan in this case was able to re-add itself back into the registry, even when no process was running that would do it. Eventually I tracked it down to some spyware that would add this bad version of soundman.exe to the wininit.ini file, which in turn would re-add the registry values. Problem is solved, but it was a pain tracking this one down.
 
Give this a try, go to start then run, type in soundman.exe and see if it picks anything up. If it does you're in luck. You can delete just about anything from there

Good Luck!!
 
One thing I found when fighting this thing is that both Spybot and Ad-Aware will NOT check your wininit.ini file to make sure a piece of spyware isn't trying to come back after being removed. In this case, that's exactly what happened, I'd remove soundman.exe from the registry and from everywhere, the file would be gone from the hard drive, and it was gone in every sense of the word. BUT, it detected that it was being removed, so added itself to wininit.ini so that it would be re-installed on next reboot.
 
Status
Not open for further replies.
Back
Top Bottom