Aftermath, Hacktools/win32gen? Plus pre-existing blue-screen (probably not malware)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by johnxtampa, Dec 29, 2012.

  1. johnxtampa

    johnxtampa Private E-2

    I'm attaching all the pertinent logs for a problem computer I'm helping a friend with. These were all done in safe mode, because (see below) there's a blue-screening problem (I don't think malware related, this computer's done this from day one), so it's become tough to prevent shutdowns in regular mode.

    As it pertains to malware/suspected malware, the start menu shortcut icons disappeared, as did a few other things a week or so ago, including the user profile for Outlook 2010, but not all files or all shortcuts. Earlier, I had run the MS safety scanner, which implicated HackTool.

    As a sidenote, the computer had a history of sporadic blue screens, dating long before any signs of malware came along. SFC /ScanNow indicated about 20 or so files it couldn't repair, including one of the files marked as suspicious by HitMan. I have that log too, which I will upload as soon as asked. (I don't have the WIndows 7 DVD the computer came with, but by chance I have another Windows 7/AMD computer.. my plan is to take a copy of the files from the other computer and patch via sfc /offlinedir (I forget the actual switch at the moment, but I'll hold off on that pending the input I get here)

    Anyway, here are the files. Thanks in advance!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Aftermath, Hacktools/win32gen? Plus pre-existing blue-screen (probably not malwa

    Welcome to Major Geeks!

    What is reporting the Hacktools/win32gen infection and exactly where is it reporting it to be? Was it Microsoft Security Essentials or Windows Defender?

    Your logs ( especially from safe boot mode which are not as useful as normal mode ) are not showing any malware problems. And infections named like this are often misinforming or misleading. However this particular infection name from MS, may point to an illegal copy of Windows being used. Is this a legal licensed copy of Windows?

    I also see the below which is also illegal:

    "C:\Office 2010 Activation"

    epecially since the PC is using AutoKMS ( seen in the logs ) to bypass the legal activation of Office. This could even be another reason for the infection you have named. Is this also why you did not think the BSOD was malware related? Illegal copies of Windows and other software can cause all kinds of instabilities.
     
  3. johnxtampa

    johnxtampa Private E-2

    Re: Aftermath, Hacktools/win32gen? Plus pre-existing blue-screen (probably not malwa

    I had earlier scanned with the Microsoft Safety Scanner, which said Hacktools/win32gen, and had said it removed it. No sign of it since then, though. I was suspecting something was still wrong, because Security Essentials eventually ends up in "not updated" status, although the blue screens are coming more often in regular mode.

    I was suspecting the blue screens weren't malware related, just because of timing... The blue screens had been relatively infrequent, and only about a week ago was when the Outlook profile went away, and the start menu recently used shortcuts went away too.

    Let me try the scans in regular mode too. As far as the licensing issues, is it Office that's illegal, or the whole Windows, or both?
     
  4. johnxtampa

    johnxtampa Private E-2

    Re: Aftermath, Hacktools/win32gen? Plus pre-existing blue-screen (probably not malwa

    Update: I can only get Roguekiller and TDSSKiller to complete in normal mode. I blue screened before getting through MalwareBytes or HitmanPro, and didn't try MGTools yet. Here are the updated logs for RogueKiller, with a bit more info than from safe mode.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Aftermath, Hacktools/win32gen? Plus pre-existing blue-screen (probably not malwa

    That's what I'm asking you. I can tell that Office is definitely illegal. I cannot tell for sure with Windows itself.


    No malware found.
     
  6. johnxtampa

    johnxtampa Private E-2

    Re: Aftermath, Hacktools/win32gen? Plus pre-existing blue-screen (probably not malwa

    OK, thanks... It's a friends computer, who bought it from someone who sells/resells computers, so I don't know what to say about the rest of the computer. I did think it was odd that she had Windows 7 Ultimate... :(

    Anyway, I think I'll pass it back to them to let the reseller person take care of it. Thanks for the help!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  8. johnxtampa

    johnxtampa Private E-2

    Re: Aftermath, Hacktools/win32gen? Plus pre-existing blue-screen (probably not malwa

    Groan... After checking via the method in your link... Of course it's not legit... OK, thanks yet again!
     
    Last edited: Dec 31, 2012
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Aftermath, Hacktools/win32gen? Plus pre-existing blue-screen (probably not malwa

    You're welcome. And possibly the reason for having so many problems.;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds