Trojan virus detected - RRM1st performed

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by letsgojets, Nov 26, 2011.

  1. letsgojets

    letsgojets Private E-2

    Hi,

    My PC appears to have had a virus. I have gone through the Rean & Run Me 1st procedures and am unsure if there are any lingering issues that need cleaning. I have attached the logs from RRM1st and was hoping someone might have a look and give guidance.

    Thanks,
    JB
     

    Attached Files:

  2. letsgojets

    letsgojets Private E-2

    MGLogs.zip file attached...
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why do you say this? What problems were you having and what was detected that made you say this?
     
  4. letsgojets

    letsgojets Private E-2

    Hi,

    Thanks for the response.

    I was (and still am) experiencing extreme slowness with the pc and when I ran the SAS scan, it reported that I had a trojan virus.

    I ran through the RRM1st steps, but everything is still excrutiatingly slow. For example, trying to print a 1-page Word file to a inkjet, the printer will print a few lines and then stop as if its waiting to receive more data, then continue and stop, an so on.

    Maybe there's something else going on, but since SAS reported a trojan, I thought that malware might be the issue.

    JB
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All of these were false detections.


    This does not always occur due to malware, but let's run a couple of additional scans now that you have provided some information on what your problem is.

    Very unlikely to be related to malware. Not impossible....but very unlikely.


    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    • Be sure to attach your log from TDSSKiller
    Now please also download MBRCheck to your desktop.

    See the download links under this icon [​IMG]
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  6. letsgojets

    letsgojets Private E-2

    Hi,

    Thanks again for your response.

    Well, I am happy to hear those were false detections.

    I ran the two scans you have instructed. Attached are the logs from each.

    I appreciate your help with this.

    JB
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your 250GB My Book drive shows as having an unknown MBR. This does not mean that it is definitely infected. If you were not having any problems, we would normally ignore something like this, but since you are still having problems and this is the only sign of a potential problem, it may be a good idea to fix it. But two things mention first.
    • If we are going to attempt to fix the MBR, you really should back up the data you need from this drive first to your other harddisks. Since you seem to be a big space waster ( junk collector or movie collector), it may be a little chore to find the space.
    • But before trying to fix it and even before trying to back it up, what you could simply try is unplugging this USB drive for a few days and see how your PC works without it plugged in. If all is good, this drive may be your problem. If you still have problems with it unplugged, unplug all other removable drives to and if any change in behavior occurs.
     
  8. letsgojets

    letsgojets Private E-2

    Well, I disconnected that drive many days ago and ever since, the computer is running like a champ. So, that seems to me to be the problem.

    Thank you so much for mentioning this as a potential problem.

    You nailed it, I have a lot of media stored up. Movies are the bulk. Would there be any potential problem if I just extracted the data I want to keep from that drive and then just reformat it?

    Thanks,
    JB
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No!

    This will not work. You need to fix the MBR. So back up your data first. Then you need your Windows boot CD so that you can boot into the Recovery Console to fix the MBR.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds