Situation that i couldn't solve for the last few months

Discussion in 'Malware Help (A Specialist Will Reply)' started by Trave160, Dec 9, 2013.

  1. Trave160

    Trave160 Private E-2

    My Computer has been ridiculously slow at times, BSOD also my windows would flash at startups. Even my mouse isn't working well as it should

    I used Roughkiller and GMER both in safe mode, was even using Hitmanpro at the same time

    RogueKiller V8.7.11 [Dec 3 2013] by Tigzy
    mail : tigzyRK<at>gmail<dot>com
    Feedback : http://www.adlice.com/forum/
    Website : http://www.adlice.com/softwares/roguekiller/
    Blog : http://tigzyrk.blogspot.com/

    Operating System : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
    Started in : Safe mode with network support
    User : AZE [Admin rights]
    Mode : Scan -- Date : 12/10/2013 08:42:44
    | ARK || FAK || MBR |

    ¤¤¤ Bad processes : 0 ¤¤¤

    ¤¤¤ Registry Entries : 2 ¤¤¤
    [DNS][PUM] HKLM\[...]\CCSet\[...]\{380966A7-8B08-4B33-B3D4-A2369520925D} : NameServer (8.8.8.8,203.76.96.5 [UNITED STATES (US) - BANGLADESH (BD)]) -> FOUND
    [DNS][PUM] HKLM\[...]\CS001\[...]\{380966A7-8B08-4B33-B3D4-A2369520925D} : NameServer (8.8.8.8,203.76.96.5 [UNITED STATES (US) - BANGLADESH (BD)]) -> FOUND

    ¤¤¤ Scheduled tasks : 0 ¤¤¤

    ¤¤¤ Startup Entries : 0 ¤¤¤

    ¤¤¤ Web browsers : 0 ¤¤¤

    ¤¤¤ Particular Files / Folders: ¤¤¤

    ¤¤¤ Driver : [NOT LOADED 0xc000035f] ¤¤¤

    ¤¤¤ External Hives: ¤¤¤

    ¤¤¤ Infection : ¤¤¤

    ¤¤¤ HOSTS File: ¤¤¤
    --> %SystemRoot%\System32\drivers\etc\hosts


    127.0.0.1 localhost


    ¤¤¤ MBR Check: ¤¤¤

    +++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) ST500DM005 HD502HJ ATA Device +++++
    --- User ---
    [MBR] 5be00982333cbc260f934d4d15fdcb89
    [BSP] 064634766eb48a7836c77334696f7e15 : Windows 7/8 MBR Code
    Partition table:
    0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 10001 Mo
    1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 20688896 | Size: 44901 Mo
    2 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 112647780 | Size: 421933 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    +++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ IDE) SAMSUNG HA320KJ ATA Device +++++
    --- User ---
    [MBR] 33550c25e0f3151e2370a86e23f90f70
    [BSP] 917fa29889a523b42391b0d315a9d2e5 : Empty MBR Code
    Partition table:
    0 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 262243 | Size: 249999 Mo
    1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 512262242 | Size: 55114 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    Finished : << RKreport[0]_S_12102013_084244.txt >>
    RKreport[0]_D_12102013_074958.txt;RKreport[0]_D_12102013_083535.txt;RKreport[0]_H_12102013_074957.txt
    RKreport[0]_H_12102013_083533.txt;RKreport[0]_S_12102013_074953.txt;RKreport[0]_S_12102013_083517.txt



    GMER 2.1.19163 - http://www.gmer.net
    Rootkit scan 2013-12-10 08:41:15
    Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-4 ST500DM005_HD502HJ rev.1AJ10001 465.76GB
    Running: u0jvqgxw.exe; Driver: C:\Users\AZE\AppData\Local\Temp\uwldrpow.sys


    ---- System - GMER 2.1 ----

    Code \??\C:\Windows\system32\drivers\hitmanpro37.sys ZwAllocateVirtualMemory [0x9948A562]
    Code \??\C:\Windows\system32\drivers\hitmanpro37.sys NtAllocateVirtualMemory

    ---- Kernel code sections - GMER 2.1 ----

    .text ntoskrnl.exe!ZwRollbackEnlistment + 1409 824459A5 1 Byte [06]
    .text ntoskrnl.exe!KiDispatchInterrupt + 5A2 82465512 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
    PAGE ntoskrnl.exe!NtAllocateVirtualMemory 82619FD5 5 Bytes JMP 9948A566 \??\C:\Windows\system32\drivers\hitmanpro37.sys

    ---- User code sections - GMER 2.1 ----

    .text D:\Windows.old\Users\AZE\Downloads\Programs\HitmanPro.exe[768] WS2_32.dll!GetAddrInfoW 76D54889 5 Bytes JMP 00224BF0 D:\Windows.old\Users\AZE\Downloads\Programs\HitmanPro.exe (HitmanPro 3.7/SurfRight B.V.)

    ---- Devices - GMER 2.1 ----

    Device \FileSystem\fastfat \FatCdrom 994EA130
    Device \FileSystem\fastfat \Fat 994EA130

    AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

    ---- Registry - GMER 2.1 ----

    Reg HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{380966A7-8B08-4B33-B3D4-A2369520925D}@NameServer 8.8.8.8,203.76.96.5
    Reg HKLM\SYSTEM\ControlSet002\services\Tcpip\Parameters\Interfaces\{380966A7-8B08-4B33-B3D4-A2369520925D}@NameServer 8.8.8.8,203.76.96.5
    Reg HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\RogueKiller.exe
    Reg HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\RogueKiller.exe@DumpFolder C:\Users\AZE\Desktop\RK_Quarantine?
    Reg HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\RogueKiller.exe@DumpCount 10
    Reg HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\RogueKiller.exe@DumpType 2
    Reg HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\RogueKiller.exe@CustomDumpFlags 0

    ---- EOF - GMER 2.1 ----
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please read the sticky/pinned threads and do not post inline logs. There are not problems in these logs. If you believe that you are having malware problems, please work thru the below and attach (See: HOW TO: Attach Items To Your Post )the requested logs:


    READ & RUN ME FIRST. Malware Removal Guide


    NOTE: You should never run multiple scans at the same time. Run one scan until it completes then begin the next!!
     
  3. Trave160

    Trave160 Private E-2

    Well ok i got your info thanks, but this is kinda of a special case. i think i have a Bios/MBR rootkit. I used bitdefender rescue cd and it got around 2100 I/O errors but wasn't able to move on with that cause i didn't get what it was until now
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have a BIOS infection, you will need to reflash your BIOS. Malware tools will not detect or fix an infection of the BIOS. I tend to doubt you have one since I have not seen a real BIOS infection for getting close to 10 yrs. I have seen BIOS corruption though.

    MBR infections would be detected by our process. Even what you attach thus far more than likely would have show it if one were present but there was no signs of one. Attaching all of the logs we request would give us additional info.
     
  5. Trave160

    Trave160 Private E-2

    Sad to say i already flashed my mobo, everything was running smoothly after few seconds into desktop till my computer kept freezing, browser window bar flashing again and few BSODs followed till it was back to its lousy state
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This sounds more like a problem with Windows, but we will not know for sure unless you follow the instructions already given for malware removal.
     
  7. Trave160

    Trave160 Private E-2

    I can't even do clean reinstalls cause it goes to being what it was somehow
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If your next post does not contain the logs requested, I will close this thread. We cannot help you if you will not help us help you.
     
  9. Trave160

    Trave160 Private E-2

    Ok but how do i start with that? :(
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Click Chaslan'gs blue coloured link in post number 2. (Read and Run me first procedures) Requested/posted 5 days ago now.
     
    Last edited by a moderator: Dec 14, 2013

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds