I have a virus. How do I remove it?

Discussion in 'Malware Help (A Specialist Will Reply)' started by FragPenguin, Oct 17, 2012.

  1. FragPenguin

    FragPenguin Private E-2

    I have followed the steps to identify and/or remove a virus, and I am posting the logs of the 5 programs. I hope someone can help me resolve this issue.
    My computer is constantly making the "busy" noise. Half of my physical memory is being used even when I'm not running any programs. I'm worried its the new Shenmue(?) virus that is going around. Please help. This started approximately 3 days ago.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not true! You are always running many programs unless your PC is turned off. Windows is always running all of its processes. Also anything else you load at startup is running and you at a minimum are loading the below:

    Code:
    O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
    O4 - HKLM\..\Run: [Super-Charger] C:\Program Files (x86)\MSI\Super-Charger\StartSuperCharger.exe
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
    O4 - HKLM\..\Run: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
    O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
    O4 - HKCU\..\Run: [Google Update] "C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe" /c
    O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Admin\AppData\Local\Akamai\netsession_win.exe"
    O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
    O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
    There are also many many more drivers/services running.

    You are not having malware problems other than the cracks and kegens you have been downloading which is the single largest cause of malware infections. Also you have some junk adware due to installing utorrent and Daemon Tools which have put Babylon and Funmoods on your PC. You can have Hitman remove all of this.

    Also you did not allow Malwarebytes to remove the below:
    C:\Users\Admin\Downloads\musicoasis_d132058.exe (PUP.BundleOffers.IIQ) -> No action taken.
     
    Last edited: Oct 20, 2012
  3. FragPenguin

    FragPenguin Private E-2

    Yes, I see that now. But it still does not explain why my computer is constantly "busy". It started when I used the cd crack "carrier.exe".


    Am I in any trouble on that front?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Any time you download cracks you can cause damage to your PC. Sometimes it may install malware and sometimes it just can just cause problems for the Windows Operating System.

    Uninstall all the hacked software and cracks and patches and see if it helps. If not try a system restore to a point where you did not have the problem. If you deleted all the old restore points than you are out of luck and may need a reinstall. There is nothing in your logs that indicates any problems with real malware or performance. No processes appear to be using excessive memory. I said real because you do have some junk related to Bablyon and Funmoods you installed but normally these just cause people issues with search engines and problems with what they see in their browsers. You can try the below to remove these, but I'm not sure they will fix your PC "busy" problem.


    Please download Junkware Removal Tool to your desktop.
    • Please save the work in your browsers before proceeding.
    • Double-click JRT.exe to run (Vista/7 right-click and select Run as Administrator)
    • The tool will open and start scanning your system.
    • Note that this will reset your home page to a default with google.
    • Please be patient as this can take a while to complete.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Please attach JRT.txt to your next message. (See: HOW TO: Attach Items To Your Post )
    Other than that, try not loading some items at startup and see what happens. We have seen Steam and Skype cause issues.

    Either way, your problem does not appear to be in the form of malware.
     
    Last edited: Oct 20, 2012

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds