Help with virus removal (kind of a long story)

s7zero7

Reputable
May 29, 2014
21
0
4,510
MAJOR NEW UPDATE

After a system restore the problem persisted, but, after a scan my antivirus detected "Hacktool:MSIL/Gendows" on my computer.
Furthermore, does anyone know how to remove this? keep in mind my problem with downloading still persists as all of my downloads eventually fail.
 
Solution
Bottom line here is do a clean install of windows. Back up your data and do it right. The virus pointed to originally is a conduit for other malware. You are chasing the tail and need to cut off the head. If you were my client with this issue I would reinstall windows and rebuilt the system software. This is the only way you will be sure to have a clean system.

Keeno99

Distinguished
May 24, 2014
237
0
18,710

s7zero7

Reputable
May 29, 2014
21
0
4,510

The thing Is I cant download another one, as I stated, any download will suddenly go up to like 45 minutes and then blank out and freeze.
I'm considering a system restore

 

Dogsnake

Distinguished
Seems like this could be a real pain. I found this guide (http://malwaretips.com/blogs/virtool-win32-obfuscator-xz-removal/) and it implies a rather complicated infection. If you choose to follow it, I would download all the tools (6) that you don't already have so they are ready to install for each step. When you are done you can use the freeware version (http://www.revouninstaller.com/revo_uninstaller_free_download.html) to uninstall the tools as they are so many. Also once you have a clean system delete all you system restore points and set a new one that is clean. The virus parts are in your restore point files as well as your current version. Lastly this virus is a type of Trojan that gets into your system by your actions (questionable sites, bootleg software, etc.). Try being more attentive to what you open and look at.
 

s7zero7

Reputable
May 29, 2014
21
0
4,510


I cant download anything for one, so I wouldn't be able to get them programs.
I suspect I recieved the "virus" after downloading Call of Duty 2 the other day as my disk copy wouldn't work, however the game worked and it did for others so I don't know why I have this.

 

s7zero7

Reputable
May 29, 2014
21
0
4,510
For an update I managed to download RogueKiller and TDSS killer, but neither of them detected ANY malware/trojan, I'm not certain if Malwarebytes did remove the virus as my youtube videos and downloads still wont work.
 

s7zero7

Reputable
May 29, 2014
21
0
4,510


Again it didn't seem to detect anything, Im still convinced I do have a virus, absolutley no downloads will work, internet is shutting off every 5 minutes, PC is slow, Youtube wont work.

 

Dogsnake

Distinguished
Bottom line here is do a clean install of windows. Back up your data and do it right. The virus pointed to originally is a conduit for other malware. You are chasing the tail and need to cut off the head. If you were my client with this issue I would reinstall windows and rebuilt the system software. This is the only way you will be sure to have a clean system.
 
Solution

s7zero7

Reputable
May 29, 2014
21
0
4,510


Right, we're taking the PC to a friend soon/a few days who is very experienced with this stuff who can probably do something about it, thanks.
In the meantime, do you suggest I not use my PC incase of personal information being stolen?

 

Dogsnake

Distinguished
If you are concerned about info. theft disconnect from the internet. If you need to create documents, print, listen to music, work with phots or whatever it will all be good as long as you are stand alone not connected to the outside world.
 

s7zero7

Reputable
May 29, 2014
21
0
4,510


Now I was looking through task manager and saw something, "cltmngsvc.exe" and found out it was a virus...I did everything to remove it. from what I know it is completely removed.
But please, make me sound like a retard, are them green underlined words linking me to ads FROM toms hardware, or is it a virus..?
 

Keeno99

Distinguished
May 24, 2014
237
0
18,710
STEP1:

Press Ctrl+Alt+Del keys together and stop HackTool:Win64/Gendows virus processes in the Windows Task Manager.

STEP2:

Go to Folder Options from Control Panel. Under View tab, select Show hidden files and folders and uncheck Hide protected operating system files (Recommended), and then click OK. Remember to back up beforehand.

STEP3:

Press Windows+ R keys and search for regedit in Run. Delete associated files and registry entries related to HackTool:Win64/Gendows virus from your PC completely.

Run antivirus if you have one and then reboot. Hope this helps.