Windows 10: Virus / Malware, please help!

Discus and support Virus / Malware, please help! in AntiVirus, Firewalls and System Security to solve the problem; Hi, Ive got a virus that persists even after formats, I believe I caught it from my roomate and he recently got his identity stolen, so Im pretty... Discussion in 'AntiVirus, Firewalls and System Security' started by TheEnnd, Mar 21, 2020.

  1. TheEnnd Win User

    Virus / Malware, please help!


    Hi, Ive got a virus that persists even after formats, I believe I caught it from my roomate and he recently got his identity stolen, so Im pretty scared. We both seem to have it but his files are older, so Im guessing i got it from him over the local network somehow.
    I was using kapersky internet security and windows 10, upgrading from Home to to Pro when I noticed everything, my main concern is that im being roped into an evil twin situation or at least having my files stolen, or technicly shared against my will.
    Theres a few different things ive found out on my own, I have a background in web programming, I understand what shells are and limited cmd-line know-how like diskpart.


    My setup:

    Operating System

    Windows 10 Home 64-bit
    CPU
    Intel Core i5 7500 @ 3.40GHz 56 °C
    Kaby Lake 14nm Technology
    RAM
    4x8 32.0GB Dual-Channel G.Skillz @ 1066MHz 15-15-15-36
    Motherboard
    MSI Z170A KRAIT GAMING 3X MS-7A11 U3E1 33 °C
    Graphics
    GF276 1920x1080@60Hz
    LG FULL HD 1920x1080@60Hz
    2047MB NVIDIA GeForce GTX 1060 6GB EVGA 38 °C
    Storage
    119GB ADATA SP600 SATA SSD 30 °C
    1862GB Western Digital WD My Passport 2626 USB Device USB SATA SSD30 °C
    Optical Drives
    HL-DT-ST DVDRAM GH24NSB0
    Audio

    NVIDIA High Definition Audio



    Persistence;

    it persists by a variety of ways that each install each other, or install extensions to central windows services and processes to avoid detection. The main methods of infection are dlls and registries and svchost/ntoskernel-run services that all eventually removes your authority over everything on the computer and then shares out your files.


    Methods ive seen are;

    Binary coinstallers installed in locations where drivers are expectedprobably based of hardware like nvidia drivers. These coinstallers refer to PCI locations as devices with memory storage abilities of some kindmaybe they are virtualized objects in a shell? There also seems to be a set of drivers installed in an "EFI Shell" and my ethernet adapter settings, accessible from bios, go like this:

    Intel Gigabit 0.0 Uefi driver Adapter PBA FFFFFF-0FF. PCI ID ADDRESS MAC etc.
    Theres a bunch of VPN and Network Drive / Virtual Drive / Sharing / Remote Administration / Workgroup / Domain Administration - related services and confirgurations set up, so I installed bitdefender and requeted all connections through that adapter be refused, bought a wifi one and built its profile a little more carefully.

    However, my X: drive seems also affected, so I really just want someone to help me get a handle on whats happening and what I can do to log/Identify/Prevent/Wipe it.

    All my files are saved and backed up, I just need a cleaning procedure for my pc and my and my roomates, and if I should do anything with my cellphonesI have 2 androids before I go online and hunt out if anything has been opened in my name.

    Im using an administrator account, disabled all others and set up strict firewall rules.


    Ive installed Kapersky Ccleaner MalwareBytes ProcessHacker Bitdefender and none of them come up with anything please help!

    :)
     
    TheEnnd, Mar 21, 2020
    #1
  2. Ernie San Win User

    Is it a Virus or a Malware or something else?

    Hello Joes,

    There's a possibility that your device is infected with a malware causing why you're unable to delete the game on your laptop. In order for us to assist you better, we'd like to ask the following:

    • Aside from formatting the hard drive, what other troubleshooting steps have you tried so far?
    • Have you asked your friend where did he download the games?

    To identify if your computer is infected with a virus or malware, we recommend downloading and running
    Microsoft Safety Scanner. The scanner can easily detect if there's any virus found on your device. To do so, follow the steps on this
    link.

    We are looking forward to your reply.
     
    Ernie San, Mar 22, 2020
    #2
  3. Mel Tar Win User
    Rooted Malware, Virus, and Trojan Infection, Keylogger Trojan Malware

    Hi,

    Please click the link below and follow Stephen Boots' suggestion on how to remove Trojan virus on your computer:

    Let us know if you need further assistance.
     
    Mel Tar, Mar 22, 2020
    #3
  4. Le Boule Win User

    Virus / Malware, please help!

    Le Boule, Mar 22, 2020
    #4
Thema:

Virus / Malware, please help!

Loading...
  1. Virus / Malware, please help! - Similar Threads - Virus Malware please

  2. False Positive vbs/pordeezy.rb!lnk virus malware : Please Help

    in Windows 10 Gaming
    False Positive vbs/pordeezy.rb!lnk virus malware : Please Help: As I inserted a USB in my windows 11 PC, windows secuirty Windows Defender detected vbs/pordeezy.rb!lnk virus. Now I have checked with couple of Anti-Virus but no one is showing the virus, But Windows Security Windows Defender is still telling me that my PC is infected with...
  3. False Positive vbs/pordeezy.rb!lnk virus malware : Please Help

    in Windows 10 Software and Apps
    False Positive vbs/pordeezy.rb!lnk virus malware : Please Help: As I inserted a USB in my windows 11 PC, windows secuirty Windows Defender detected vbs/pordeezy.rb!lnk virus. Now I have checked with couple of Anti-Virus but no one is showing the virus, But Windows Security Windows Defender is still telling me that my PC is infected with...
  4. Need help with virus/malware removal

    in Windows 10 Gaming
    Need help with virus/malware removal: Seems I've picked up a virus/malware when visiting a webpage yesterday. Mcafee warned me but went anyway, bad decision. Ran several scans afterwards but Mcafee doesn't pick up anything. Windows 10 starts and runs slow and browsing is also slow. Any help is greatly...
  5. Need help with virus/malware removal

    in Windows 10 Software and Apps
    Need help with virus/malware removal: Seems I've picked up a virus/malware when visiting a webpage yesterday. Mcafee warned me but went anyway, bad decision. Ran several scans afterwards but Mcafee doesn't pick up anything. Windows 10 starts and runs slow and browsing is also slow. Any help is greatly...
  6. Need help with virus/malware removal

    in Windows 10 BSOD Crashes and Debugging
    Need help with virus/malware removal: Seems I've picked up a virus/malware when visiting a webpage yesterday. Mcafee warned me but went anyway, bad decision. Ran several scans afterwards but Mcafee doesn't pick up anything. Windows 10 starts and runs slow and browsing is also slow. Any help is greatly...
  7. Pls help malware virus

    in AntiVirus, Firewalls and System Security
    Pls help malware virus: Pls need help I downloaded file from internet and before I downloaded I checked with virustotal and it's says it safe so when I run the exe file my user control settings message popout and ask for restart to disable it, I tried to delete the folder but still I think my laptop...
  8. Virus or No? Help please :

    in Windows 10 BSOD Crashes and Debugging
    Virus or No? Help please :: Hello! This keeps popping up on my screen. I thought it was a virus but I ran a scan on McAfee and it said I was virus free. Help is appreciated! https://answers.microsoft.com/en-us/windows/forum/all/virus-or-no-help-please/43c81a66-9874-45b6-bd2f-74ba2636e29d
  9. Virus and Malware

    in AntiVirus, Firewalls and System Security
    Virus and Malware: My computer has been infected by a virus and encrypted all my drives. All my documents have a .peet extension and I can not open them. Any help on how on the decryption of the corrupted files?...
  10. Malware help please + cryptoprevent

    in AntiVirus, Firewalls and System Security
    Malware help please + cryptoprevent: So I have this in the log of cryptoprevent Event ID=866 Message of: Access to C:\Users\Zman\AppData\Local\atbizdu\cgcstpk.exe has been restricted by your Administrator by location with policy rule {B6AF3C37-6012-4DEC-87BB-5125E94F5BC5} placed on path...