Suspect Ramnit-AK Computer being filled with trz files.

So one day i came back to my computer
Things were turning into trz****.TMP files
So i decided to do a ESET Online Scan
And it came up with

A variant of Win32/Packed.VMProtect.ABD trojan
A variant of Win32/Packed.VMProtect.ABD trojan

Also is Win32/SpeedBit.c

A virus or just computer slowing rubish applications.

And last thing i have OTL installed and i did a full scan.
Results in attachments.

Also my browser at one stage was opening new tabs for no reason.
(i might of accidentally did it myself)

I wont be able to get back to you on the ESET Online scan until tomorrow as its stuck on 41% because its scanning my minecraft files with like 10,000 files so ya.

EDIT: I opened task manager and found like 10 scvhost.exe open, I heard that’s to do with
Ramnit so i am very concerned.

Anyway any help would be loved.

Essexboy has moved from OTL to FARBAR now…

see instructions here https://forum.avast.com/index.php?topic=53253.0
attach Malwarebytes / Farbar Recovery Scan Tool / aswMBR logs

Hi :slight_smile:

Let’s hope that it’s not Ramnit. Ramnit means a death sentence for your system…

https://sites.google.com/site/cannedfixes/home/hosted-images-tools/DrWebCureIt.png
Scan with Dr.Web CureIt

Please visit this page: Dr.Web CureIt!
You will find there a download site and instructions how to run a free scan with Dr.Web.

Some notes from me:

https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
The file will come totally randomly named (like h34cva7) - that’s normal; however it will have this icon:
https://sites.google.com/site/cannedfixes/home/hosted-images-tools/DrWebCureIt.png

https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
It may take a while to finish, depending of your capacities and system specs, be patient

https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
Don’t fix anything on your own using Dr.Web - this type of scans often produces false positives; I will tell you what to remove and how to do it after inspecting provided results

Upon completion, please click Open Report and paste it here for my analysis.

Yeah, death sentence if it is Ramnit.

It’s the real Mccoy, not some flimsy piece of trash adware. http://www.f-secure.com/v-descs/virus_w32_ramnit_n.shtml