PC Desktop running slow possibly malware and virus

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by caspers, Jan 11, 2014.

  1. caspers

    caspers Private E-2

    Hi

    Nice to meet you all.

    My pc is running slower at the start up, some application show error (cannot run), internet explorer opening on its own, and there might be others. hahaha :D
    and so I try googling and find this forum.

    Please find the log attachment that I got from following malware instruction guide and help me fix the problems.

    Thanks in advance for the help.

    Note for the hitmanpro logs, I need to zip it because it's too large.


    View attachment TDSSKiller.3.0.0.19_11.01.2014_11.19.55_log.txt

    View attachment mbam-log-2014-01-11 (11-07-28).txt

    View attachment MGlogs.zip

    View attachment RKreport[0]_S_01112014_105905.txt

    View attachment HitmanPro_20140111_1156.zip
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    One main reason your PC is slow is you are out of free diskspace on drive C:
    Code:
    Size 99.90 GB (107,268,272,128 bytes) 
    Free Space 1,015.40 MB (1,064,726,528 bytes)
    And drive D is not much better:
    Same with drive L
    Another reason for slowness is multilple antivirus program which the READ & RUN ME warned you about:

    However a bigger problem is due to downloading cracks and patches you have infected almost every executable file on Drive C and Drive D with Win32.Virtob and or Virut. There is no reliable fix for this other than a full clean reinstall and if you keep any of these files ( backups etc ) and reuse them you will start the reinfection all over again. These infections could be stealing personal information. ( see: http://en.wikipedia.org/wiki/Virut )

    You could try running the below but I'm not sure it will be able to fix this and it could result in an unbootable PC.

    http://www.drwebhk.com/en/virus_removal/48646/Win32.Virtob.Gen.12.html

    Also the below could be attempted:

    http://free.avg.com/us-en/remove-win32-virut

    http://support.kaspersky.com/us/viruses/disinfection/2735#

    Still I would not be confident that your infection is 100% gone. All you need to do is keep just one of these infected files and as soon as you run it the first time, the total infection process will start over again and it will spread to every drive in this PC and to any network drives. If you put in a USB stick and move the stick into another PC, that PC will get infecte.
     
    Last edited: Jan 11, 2014
  3. caspers

    caspers Private E-2

    Hi,

    Firstly thank you the reply chaslang :).

    well so the main problems come from patch/crack usage. this should be expected as the risk come with using that.

    and just to clarify so the only way to fully fix this is by fully uninstalling all my drives C , D and L? The L drive is an external harddisk drive. and also There's some very important documents there. can i somehow differentiate between which file is infected or not?

    this virus is quite dangerous then. is there any solution for the future so that i can be safe from this? well not the obvious answer like not using crack/patch :p.

    and for the antivirus that's a miss because i taught that i only have kaspersky installed.

    thanks in advance :-D.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Any drive that is connected to this PC may be infected. The problem you have now is that you cannot really even trust your scanners because they may be infected too, but you could try running a few extensive scans on the external drive but DO NOT run executable that is stored on the external drive. Documents may not be infected because they are not necessarily considered executable files.

    You could try also checking to see if a full scan with Hitman Pro on that drive comes up with anything. The previous log did show that L:\SpellForce 2 - Shadow Wars\spellforce2.exe was infected. Not sure if anything else should have been found. Do you have anymore executable files on drive L? That does not mean just .exe files. See the descriptions for Virtob and Virut.


    You can also try the links I gave you.

    You answered your own question.


    Well actually AVG is still there but it only be their security toolbar. Direct from your logs you can see the below:
     
  5. caspers

    caspers Private E-2

    There's some more .exe files on L drive but most of them are installer. okay then, i will try your suggestion and advice with the virut.

    and about my log files, i mean with the hitmanpro, mb, and others. what should i do if i don't want to fully uninstall all my drives? should i just ignore them or maybe do like scanning and cleaning with hitmanpro, rougekiller, etc?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not you cannot ignore the infected files. You have to delete them or attempt to clean them but at stated earlier the only truly reliable fix for these kinds of infections ( especially when spread to an extent like on your PC ) is to delete partitions, format, and reinstall your Windows Operating System from scratch. And also as stated, keeping and reusing just one infected file will result in total reinfection. Remember this infection can be stealing personal information while you delay. It can be stealing passwords and financial type info. It will also spread to other PCs on your network or that you plug your removable media or you copy files to. Installer files that you downloaded are executables too and they will get infected.

    Are you saying that you do not want to remove the Virtub and Virut infections and just want to remove the other problems??????
     
    Last edited: Jan 11, 2014
  7. caspers

    caspers Private E-2

    Yea at the moment i am not going to reinstall all the drives yet. i am going to do so in the near future. so for now, what should i do to at least minimalize the damage for everyday use until i reinstall ?

    thank you chaslang for your assistance.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You really cannot minimize the damage. It will keep causing more and more damage the more you access files and folders on these drives. Also when you run programs it is spreading. You are also possibly having information stolen as stated earlier, so the very first thing you need to do is disconnect this PC from any network and do not give it access to the internet. Do not plug ay more USB type drives to it. If you wish to copy scanning programs to it then use a different uninfected PC and burn them to a CD to use to install in this infected PC. Then you could attempt to clean using some of the tools I pointed you too, but as I have stated several times already, this is not a reliable way to recover from these kinds of infections.

    I really cannnot emphasize this enough any more, you need to stop using this PC and you need to start fixing it. The best fix is to start over dumping all contents.

    Also as I stated earlier, you were almost out of free disk space on all drives. So this PC is likely to be very slow.
     
  9. caspers

    caspers Private E-2

    Hi chaslang

    sorry for this late reply.

    okay i get it then. that the only way is to do full uninstall and start anew :)

    I'll do so after sorting out some document to dropbox because i really have no other way to save the files, or maybe using DVD is an okay?

    anyway thanks for the help. i appreciate it very much :D

    see you in the future
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You just need to be careful what file types you save. When you say "document", exactly what file types do you mean?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds