Virtumonde.sci Found - Computer SLOW

Discussion in 'Malware Help (A Specialist Will Reply)' started by pete226, Feb 22, 2013.

  1. pete226

    pete226 Private E-2

    Hey guys, I've been trying to figure this problem out for a long time and finally came across this website and it's awesome. This laptop has been running VERY slow. It starts running loud, the fan comes on and then that's it, everything moves slow, programs stop responding, internet is slow, response time to my typing is slow (like right now). I have an iMac that I use most of the time, but this HP laptop has photoshop on it, so I need this often.

    I've been running Spybot for a while now and just this week found Virtumonde.sci, but it didn't give me an option to remove it. It actually ended up slowing down the scan so bad that it didn't finish for about 48 hours. I did the malware scans as per your instructions and uncovered some files and potential malware that still needs to be removed, but first want to get your help.

    I disabled teatimer about a week ago, no difference. It's running slow right now and CPU Usage is fluctuating between 50 and 85 and Physical Memory is at 48%. CPU does shoot up to 100% on some days.

    I've attached the 5 logs. Please let me know if I need to provide anymore info in order to finalize the cleanup of this machine. Thank you in advance for all of your time and help.

    -Pete

    Machine Specs:
    HP G62 Notebook PC
    Intel(R) Core(TM) i3 CPU M330 @ 2.13 GHz
    RAM: 4GB (3.8GB useable)
    64-Bit OS - Windows 7 - Service Pack 1
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    May not be due to malware. Are you sure that you are not having overheating problems or hard disk problems?

    We have a few things to cleanup that may or may not help. We shall see.


    Are you referring to something that shows up at the bottem of the Spybot window while it is scanning? If so, those are not infections. Those are what it is currently scanning for. If you are referring to something it reports in the scan window after it finishes its scan then right click in the window and save a full log. Attach it here so we can see what it is finding.

    Rerun Hitman Pro and allow it to remove all the Malware remants attach to Firefox.
    Also allow it to remove the Potential Unwanted Programs. Then reboot.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Also tell me if there is any improvement to your performance.
     
  3. pete226

    pete226 Private E-2

    I don't know, could be overheating probs! Only thing I've read about this laptop is that a lot of people have battery problems and replacing them improves performance, but I typically always have it plugged in.

    Yes that was it. Oh man, good to hear. It didn't find Virtumonde then!

    I ran Hitman again and deleted all findings. I've also attached the JRT log. I'll run Spybot again now and if it finds anything I'll post it. Thank you very much.
     

    Attached Files:

    • JRT.txt
      File size:
      14 KB
      Views:
      1
  4. pete226

    pete226 Private E-2

    Spybot found 4 things, which I removed. Here's the log.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Cookies aren't problems as you will see in the link given in the last step below.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     
  6. pete226

    pete226 Private E-2

    Thank you again. All done. System is operating well so far today, I'll keep you posted if it starts acting up again.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds