Solved What kind of Malware do I have?


Bunaby Jones

New member
Local time
4:09 AM
Posts
12
OS
Windows 11
Long story short I suddenly started having issues about 5 days ago when my keyboard was pressing buttons. I opened up notepad to see if my keys were sticking.

To my horror my usernames and passwords to many things started typing themselves out. Such as steam, google, Microsoft etc.

I naturally panicked and shut down my pc. I had the files I needed backed up already so I wiped my PC and downloaded Windows 11 from MS and reinstalled.

I immediately got Kaspersky which my family has used for a while and Changed all my passwords. Ram scans and found nothing on any drive.

Unfortunately it happened again with my passwords typing themselves out. There was no communication and it seemed automatic as if a bot was doing it. Then it started pasting out time stamps as if it was copied and pasted.

Now it was also reposting direct 1 to 1 text of things I googled and messages I sent in discord.

But anything typed on a different device such as my phone was not shown or anything.

I removed all drives and left only my m.2 and reinstalled once more. It did it again. This time I disconnect the internet, router and lan cables and disabled my Wi-Fi on the motherboard. It still typed stuff out without internet. So I think it’s an automatic bot.

I’ve done some research and I think this is a UEFI Bootkit/Rootkit.

I am unable to
Fix this so I took it to Geek Squad at BestBuy and am currently waiting to hear from them. But does it sound like a deep embedded bootkit or BIOS virus to you all?

I don’t have my desktop so I can’t be sure but the Windows Version is 22H2
 
Windows Build/Version
22H2

My Computer

System One

  • OS
    Windows 11

My Computer

System One

  • OS
    Windows 11 Home x64 Version 23H2 Build 22631.3447
I was surprised that you did not mention
Run Microsoft Defender Offline Scan - ElevenForumTutorials
since that is specifically designed to detect rootkits and which you can still use depsite your Russian software.

The last time I checked, Kaspersky's equivalent was
Anti-rootkit utility TDSSKiller


All the best,
Denis
I don’t have my PC it is currently at GeekSquad. I was more-so asking if the community thinks it’s a bootkit/rootkit.

But the information you have given me is very useful, so for that I thank you.
 

My Computer

System One

  • OS
    Windows 11
Doesn't have the characteristics of any virus or Rootkit i have ever worked on ! I would do an exorcism, sorry but couldn't help that !!
Lets see what the bad incompetent (charges to much) Geek squad has to say !
Also as @Try3 said run the TTDSKiller !
 

My Computer

System One

  • OS
    Windows11 23H2 (OS Build 22631.2428)
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP HP ENVY TE01
    CPU
    2.90 gigahertz Intel Core i7-10700
    Motherboard
    Board: HP 8767 A (SMVB)
    Memory
    16214 Megabytes Usable Installed Memor
    Hard Drives
    1511.52 Gigabytes Usable Hard Drive Capacity
    1418.15 Gigabytes Hard Drive Free Space
    Keyboard
    Logitech wireless
    Mouse
    M 185 wireless
    Internet Speed
    12 ms Jitter 8 ms Download 10.5 Mbps Upload 1.7
    Browser
    Edge & FF
    Antivirus
    Windows Defender

My Computers

System One System Two

  • OS
    11 Pro 23H2 OS build 22631.3374
    Computer type
    Laptop
    Manufacturer/Model
    Acer Swift SF114-34
    CPU
    Pentium Silver N6000 1.10GHz
    Memory
    4GB
    Screen Resolution
    1920 x 1080
    Hard Drives
    SSD
    Cooling
    fanless
    Internet Speed
    13Mbps
    Browser
    Brave, Edge or Firefox
    Antivirus
    Webroot Secure Anywhere
    Other Info
    System 3

    ASUS T100TA Transformer
    Processor Intel Atom Z3740 @ 1.33GHz
    Installed RAM 2.00 GB (1.89 GB usable)
    System type 32-bit operating system, x64-based processor

    Edition Windows 10 Home
    Version 22H2 build 19045.3570
  • Operating System
    Windows 11 Pro 23H2 22631.2506
    Computer type
    Laptop
    Manufacturer/Model
    HP Mini 210-1090NR PC (bought in late 2009!)
    CPU
    Atom N450 1.66GHz
    Memory
    2GB
I tried the MS rootkit scan by following Brink's instructions - nothing happened. When I tried the command prompt I got this response:

2023-04-10_105857.jpg

Something is wrong - but what is it and how can I fix it?
 

My Computer

System One

  • OS
    Win11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom build
    CPU
    Intel i5-12600K 3700 MHz
    Motherboard
    Asus B660-M
    Memory
    16 GB
    Graphics Card(s)
    none
    Sound Card
    none
    Monitor(s) Displays
    Primary: LG 4K; Secondary: Dell U2412M
    Screen Resolution
    Primary: 3860 x 2160; Secondary: 1200 x 1920
    Hard Drives
    C: Samsung NVme SSD970 256K
    E: 1 TB HDD
    F: 500K HDD
    W: Samsung SSD 840 128K
    Keyboard
    Logitech Lighted
    Mouse
    Kensington ExpertMouse trackball
    Internet Speed
    500/500
    Browser
    Brave
    Antivirus
    Windows Defender

My Computer

System One

  • OS
    Windows 11 Home x64 Version 23H2 Build 22631.3447
Something is wrong - but what is it and how can I fix it?

Birt,

I urge you to start a thread of your own or ask your question in that tutorial thread.
This is Bunaby Jones' thread.

All the best,
Denis
 

My Computer

System One

  • OS
    Windows 11 Home x64 Version 23H2 Build 22631.3447
Kaspersky? I just have a hard time trusting anything owned and operated by the Russians.
The Russian maffia controls so much of what goes on in that country!
 

My Computer

System One

  • OS
    Win-11/Pro/64, Optimum 11 V5, 23H2 22631.3374
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Made w/Gigabyte mobo/DX-10
    CPU
    AMD FX 6350 Six Core
    Motherboard
    Gigabyte, DX-10, GA-78LMT-USB3
    Memory
    Crucial, 16 GB
    Graphics Card(s)
    NVIDEA GeForce 210, 1GB DDR3 Ram.
    Sound Card
    Onboard
    Monitor(s) Displays
    24" Acer
    Screen Resolution
    1280x800
    Hard Drives
    Crucial SSD 500GB, SanDisk 126GB SSD, Toshiba 1TB HD
    PSU
    EVGA 500 W.
    Case
    Pac Man, Mid Tower
    Cooling
    AMD/OEM
    Keyboard
    101 key, Backlit/ Mechanical Switches/
    Mouse
    Logitech USB Wireless M310
    Internet Speed
    Hughes Net speed varies with the weather
    Browser
    Firefox 64x
    Antivirus
    Windows Defender, Super Anti Spyware
    Other Info
    Given to me as DEAD, and irreparable.
    Rebuilt with Gigabyte mobo, AMD cpu, 16GB ram and 500GB Crucial SSD.
Could you have visited any dodgy websites?
 

My Computers

System One System Two

  • OS
    11 Pro 23H2 OS build 22631.3374
    Computer type
    Laptop
    Manufacturer/Model
    Acer Swift SF114-34
    CPU
    Pentium Silver N6000 1.10GHz
    Memory
    4GB
    Screen Resolution
    1920 x 1080
    Hard Drives
    SSD
    Cooling
    fanless
    Internet Speed
    13Mbps
    Browser
    Brave, Edge or Firefox
    Antivirus
    Webroot Secure Anywhere
    Other Info
    System 3

    ASUS T100TA Transformer
    Processor Intel Atom Z3740 @ 1.33GHz
    Installed RAM 2.00 GB (1.89 GB usable)
    System type 32-bit operating system, x64-based processor

    Edition Windows 10 Home
    Version 22H2 build 19045.3570
  • Operating System
    Windows 11 Pro 23H2 22631.2506
    Computer type
    Laptop
    Manufacturer/Model
    HP Mini 210-1090NR PC (bought in late 2009!)
    CPU
    Atom N450 1.66GHz
    Memory
    2GB
Could you have visited any dodgy websites?
Well I was on a site streaming a series and I made the mistake of trying to download an episode. I cancelled within 30 seconds because it was gonna take forever.

These things started very shortly after this.
 

My Computer

System One

  • OS
    Windows 11
You need a better antimalware if you are visiting naughty websites!
 

My Computers

System One System Two

  • OS
    11 Pro 23H2 OS build 22631.3374
    Computer type
    Laptop
    Manufacturer/Model
    Acer Swift SF114-34
    CPU
    Pentium Silver N6000 1.10GHz
    Memory
    4GB
    Screen Resolution
    1920 x 1080
    Hard Drives
    SSD
    Cooling
    fanless
    Internet Speed
    13Mbps
    Browser
    Brave, Edge or Firefox
    Antivirus
    Webroot Secure Anywhere
    Other Info
    System 3

    ASUS T100TA Transformer
    Processor Intel Atom Z3740 @ 1.33GHz
    Installed RAM 2.00 GB (1.89 GB usable)
    System type 32-bit operating system, x64-based processor

    Edition Windows 10 Home
    Version 22H2 build 19045.3570
  • Operating System
    Windows 11 Pro 23H2 22631.2506
    Computer type
    Laptop
    Manufacturer/Model
    HP Mini 210-1090NR PC (bought in late 2009!)
    CPU
    Atom N450 1.66GHz
    Memory
    2GB
You need a better antimalware if you are visiting naughty websites!
It wasn’t porn. It was MoviesJoy and I was watching a series. Windows defender didn’t detect anything so I don’t think anything else would have. Unfortunately I didn’t know how volatile that site was and how unsafe. That’s on me.
 

My Computer

System One

  • OS
    Windows 11
@Bunaby Jones

You might want to try unhooking all the other drives (like you did), and unhooking the internet... then using some bootable partitioning software to "wipe" the drive you intend to re-install Windows on.

You can burn this to a CD or use RUFUS to put it on a USB stick.
It's the ISO for Minitools Partition Wizard 11...



Then, boot from the CD or USB stick and "wipe" the drive (write zeroes to it).
Then... install Windows on that drive, and see if the problem still exists.



IF the problem still exists, then it's probably the BIOS chip or possibly the router, that's infected.
[I don't know how you have all your devices hooked up, so I can't be sure about the router.]
 

My Computers

System One System Two

  • OS
    Win 11 Home ♦♦♦22631.3447 ♦♦♦♦♦♦♦23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® [May 2020]
    CPU
    AMD Ryzen 7 3700X
    Motherboard
    Asus Pro WS X570-ACE (BIOS 4702)
    Memory
    G.Skill (F4-3200C14D-16GTZKW)
    Graphics Card(s)
    EVGA RTX 2070 (08G-P4-2171-KR)
    Sound Card
    Realtek ALC1220P / ALC S1220A
    Monitor(s) Displays
    Dell U3011 30"
    Screen Resolution
    2560 x 1600
    Hard Drives
    2x Samsung 860 EVO 500GB,
    WD 4TB Black FZBX - SATA III,
    WD 8TB Black FZBX - SATA III,
    DRW-24B1ST CD/DVD Burner
    PSU
    PC Power & Cooling 750W Quad EPS12V
    Case
    Cooler Master ATCS 840 Tower
    Cooling
    CM Hyper 212 EVO (push/pull)
    Keyboard
    Ducky DK9008 Shine II Blue LED
    Mouse
    Logitech Optical M-100
    Internet Speed
    300/300
    Browser
    Firefox (latest)
    Antivirus
    Bitdefender Internet Security
    Other Info
    Speakers: Klipsch Pro Media 2.1
  • Operating System
    Windows XP Pro 32bit w/SP3
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® (not in use)
    CPU
    AMD Athlon 64 X2 5000+ (OC'd @ 3.2Ghz)
    Motherboard
    ASUS M2N32-SLI Deluxe Wireless Edition
    Memory
    TWIN2X2048-6400C4DHX (2 x 1GB, DDR2 800)
    Graphics card(s)
    EVGA 256-P2-N758-TR GeForce 8600GT SSC
    Sound Card
    Onboard
    Monitor(s) Displays
    ViewSonic G90FB Black 19" Professional (CRT)
    Screen Resolution
    up to 2048 x 1536
    Hard Drives
    WD 36GB 10,000rpm Raptor SATA
    Seagate 80GB 7200rpm SATA
    Lite-On LTR-52246S CD/RW
    Lite-On LH-18A1P CD/DVD Burner
    PSU
    PC Power & Cooling Silencer 750 Quad EPS12V
    Case
    Generic Beige case, 80mm fans
    Cooling
    ZALMAN 9500A 92mm CPU Cooler
    Mouse
    Logitech Optical M-BT96a
    Keyboard
    Logitech Classic Keybooard 200
    Internet Speed
    300/300
    Browser
    Firefox 3.x ??
    Antivirus
    Symantec (Norton)
    Other Info
    Still assembled, still runs. Haven't turned it on for 13 years?
@Bunaby Jones

You might want to try unhooking all the other drives (like you did), and unhooking the internet... then using some bootable partitioning software to "wipe" the drive you intend to re-install Windows on.

You can burn this to a CD or use RUFUS to put it on a USB stick.
It's the ISO for Minitools Partition Wizard 11...



Then, boot from the CD or USB stick and "wipe" the drive (write zeroes to it).
Then... install Windows on that drive, and see if the problem still exists.



IF the problem still exists, then it's probably the BIOS chip or possibly the router, that's infected.
[I don't know how you have all your devices hooked up, so I can't be sure about the router.]
I do not have my PC right now. It’s checked Into GeekSquad at Best Buy. My Desktop was LAN connected.
 

My Computer

System One

  • OS
    Windows 11
I do not have my PC right now. It’s checked Into GeekSquad at Best Buy. My Desktop was LAN connected.


They will probably do the same thing.
And as for router infections (I don't even use a router).
A while back I read about bad guys intercepting router packages, manually infecting them, the re-packaging them, so no one knew. If it still happens, I have no idea. I just pointed it out cause it's... possible.

Another way to get recurring infection is via infected USB stick or USB device.
You get everything cleaned... then stick the USB device back in... and you're infected again.




If all else fails... make a free account here, and let them clean the computer.
They're not fast, but they are the best...




It's not like a normal forum, where many people answer. You'll get something like a case worker.
One person who will take you from start to finish. It's all free.

Follow their directions exactly. Don't skip ahead, or try to 2nd guess them.
They've been doing this for 20 years that I know of... probably longer.
 
Last edited:

My Computers

System One System Two

  • OS
    Win 11 Home ♦♦♦22631.3447 ♦♦♦♦♦♦♦23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® [May 2020]
    CPU
    AMD Ryzen 7 3700X
    Motherboard
    Asus Pro WS X570-ACE (BIOS 4702)
    Memory
    G.Skill (F4-3200C14D-16GTZKW)
    Graphics Card(s)
    EVGA RTX 2070 (08G-P4-2171-KR)
    Sound Card
    Realtek ALC1220P / ALC S1220A
    Monitor(s) Displays
    Dell U3011 30"
    Screen Resolution
    2560 x 1600
    Hard Drives
    2x Samsung 860 EVO 500GB,
    WD 4TB Black FZBX - SATA III,
    WD 8TB Black FZBX - SATA III,
    DRW-24B1ST CD/DVD Burner
    PSU
    PC Power & Cooling 750W Quad EPS12V
    Case
    Cooler Master ATCS 840 Tower
    Cooling
    CM Hyper 212 EVO (push/pull)
    Keyboard
    Ducky DK9008 Shine II Blue LED
    Mouse
    Logitech Optical M-100
    Internet Speed
    300/300
    Browser
    Firefox (latest)
    Antivirus
    Bitdefender Internet Security
    Other Info
    Speakers: Klipsch Pro Media 2.1
  • Operating System
    Windows XP Pro 32bit w/SP3
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® (not in use)
    CPU
    AMD Athlon 64 X2 5000+ (OC'd @ 3.2Ghz)
    Motherboard
    ASUS M2N32-SLI Deluxe Wireless Edition
    Memory
    TWIN2X2048-6400C4DHX (2 x 1GB, DDR2 800)
    Graphics card(s)
    EVGA 256-P2-N758-TR GeForce 8600GT SSC
    Sound Card
    Onboard
    Monitor(s) Displays
    ViewSonic G90FB Black 19" Professional (CRT)
    Screen Resolution
    up to 2048 x 1536
    Hard Drives
    WD 36GB 10,000rpm Raptor SATA
    Seagate 80GB 7200rpm SATA
    Lite-On LTR-52246S CD/RW
    Lite-On LH-18A1P CD/DVD Burner
    PSU
    PC Power & Cooling Silencer 750 Quad EPS12V
    Case
    Generic Beige case, 80mm fans
    Cooling
    ZALMAN 9500A 92mm CPU Cooler
    Mouse
    Logitech Optical M-BT96a
    Keyboard
    Logitech Classic Keybooard 200
    Internet Speed
    300/300
    Browser
    Firefox 3.x ??
    Antivirus
    Symantec (Norton)
    Other Info
    Still assembled, still runs. Haven't turned it on for 13 years?
I can do the same job as they do at Bleepingcomputer & i have been doing it for 20 yrs. also !
!
 

My Computer

System One

  • OS
    Windows11 23H2 (OS Build 22631.2428)
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP HP ENVY TE01
    CPU
    2.90 gigahertz Intel Core i7-10700
    Motherboard
    Board: HP 8767 A (SMVB)
    Memory
    16214 Megabytes Usable Installed Memor
    Hard Drives
    1511.52 Gigabytes Usable Hard Drive Capacity
    1418.15 Gigabytes Hard Drive Free Space
    Keyboard
    Logitech wireless
    Mouse
    M 185 wireless
    Internet Speed
    12 ms Jitter 8 ms Download 10.5 Mbps Upload 1.7
    Browser
    Edge & FF
    Antivirus
    Windows Defender
I can do the same job as they do at Bleepingcomputer & i have been doing it for 20 yrs. also !
!
I shall remember that if ever the case I get one of these 'hidden' modern malware. 👍
 

My Computers

System One System Two

  • OS
    Win 11 Pro & 🐥.
    Computer type
    Laptop
    Manufacturer/Model
    ASUS VivoBook
    CPU
    AMD Ryzen 7 3700U with Radeon Vega Mobile Gfx
    Motherboard
    ASUSTeK COMPUTER INC. X509DA (FP5)
    Memory
    12GB
    Graphics Card(s)
    RX Vega 10 Graphics
    Monitor(s) Displays
    Generic PnP Monitor (1920x1080@60Hz)
    Screen Resolution
    1920x1080@60Hz
    Hard Drives
    Samsung SSD 970 EVO Plus 2TB NVMe 1.3
    Internet Speed
    25 Mbps
    Browser
    Edge
    Antivirus
    Defender
  • Operating System
    Windows 11
    Computer type
    Laptop
    Manufacturer/Model
    ACER NITRO
    CPU
    AMD Ryzen 7 5800H / 3.2 GHz
    Motherboard
    CZ Scala_CAS (FP6)
    Memory
    32 GB DDR4 SDRAM 3200 MHz
    Graphics card(s)
    NVIDIA GeForce RTX 3060 6 GB GDDR6 SDRAM
    Sound Card
    Realtek Audio. NVIDIA High Definition Audio
    Monitor(s) Displays
    15.6" LED backlight 1920 x 1080 (Full HD) 144 Hz
    Screen Resolution
    1920 x 1080 (Full HD)
    Hard Drives
    Samsung 970 Evo Plus 2TB NVMe M.2
    PSU
    180 Watt, 19.5 V
    Mouse
    Lenovo Bluetooth
    Internet Speed
    25 Mbps
    Browser
    Edge
    Antivirus
    Defender
I tried the MS rootkit scan by following Brink's instructions - nothing happened. When I tried the command prompt I got this response:

View attachment 57585

Something is wrong - but what is it and how can I fix it?
You have to uninstall any third party antivirus or antimalware first. I use Webroot and pausing it was not enough, I got the same error in Powershell as you. But Defender offline ran fine once I had uninstalled Webroot.
 

My Computers

System One System Two

  • OS
    11 Pro 23H2 OS build 22631.3374
    Computer type
    Laptop
    Manufacturer/Model
    Acer Swift SF114-34
    CPU
    Pentium Silver N6000 1.10GHz
    Memory
    4GB
    Screen Resolution
    1920 x 1080
    Hard Drives
    SSD
    Cooling
    fanless
    Internet Speed
    13Mbps
    Browser
    Brave, Edge or Firefox
    Antivirus
    Webroot Secure Anywhere
    Other Info
    System 3

    ASUS T100TA Transformer
    Processor Intel Atom Z3740 @ 1.33GHz
    Installed RAM 2.00 GB (1.89 GB usable)
    System type 32-bit operating system, x64-based processor

    Edition Windows 10 Home
    Version 22H2 build 19045.3570
  • Operating System
    Windows 11 Pro 23H2 22631.2506
    Computer type
    Laptop
    Manufacturer/Model
    HP Mini 210-1090NR PC (bought in late 2009!)
    CPU
    Atom N450 1.66GHz
    Memory
    2GB
Back
Top Bottom