Solved What kind of Malware do I have?


Bunaby Jones

New member
Local time
1:18 PM
Posts
12
OS
Windows 11
Long story short I suddenly started having issues about 5 days ago when my keyboard was pressing buttons. I opened up notepad to see if my keys were sticking.

To my horror my usernames and passwords to many things started typing themselves out. Such as steam, google, Microsoft etc.

I naturally panicked and shut down my pc. I had the files I needed backed up already so I wiped my PC and downloaded Windows 11 from MS and reinstalled.

I immediately got Kaspersky which my family has used for a while and Changed all my passwords. Ram scans and found nothing on any drive.

Unfortunately it happened again with my passwords typing themselves out. There was no communication and it seemed automatic as if a bot was doing it. Then it started pasting out time stamps as if it was copied and pasted.

Now it was also reposting direct 1 to 1 text of things I googled and messages I sent in discord.

But anything typed on a different device such as my phone was not shown or anything.

I removed all drives and left only my m.2 and reinstalled once more. It did it again. This time I disconnect the internet, router and lan cables and disabled my Wi-Fi on the motherboard. It still typed stuff out without internet. So I think it’s an automatic bot.

I’ve done some research and I think this is a UEFI Bootkit/Rootkit.

I am unable to
Fix this so I took it to Geek Squad at BestBuy and am currently waiting to hear from them. But does it sound like a deep embedded bootkit or BIOS virus to you all?

I don’t have my desktop so I can’t be sure but the Windows Version is 22H2
 
Windows Build/Version
22H2

My Computer My Computer

At a glance

Windows 11
OS
Windows 11

My Computer My Computer

At a glance

Windows 11 Home x64 Version 25H2 Build 26200....
OS
Windows 11 Home x64 Version 25H2 Build 26200.8037
I was surprised that you did not mention
Run Microsoft Defender Offline Scan - ElevenForumTutorials
since that is specifically designed to detect rootkits and which you can still use depsite your Russian software.

The last time I checked, Kaspersky's equivalent was
Anti-rootkit utility TDSSKiller


All the best,
Denis
I don’t have my PC it is currently at GeekSquad. I was more-so asking if the community thinks it’s a bootkit/rootkit.

But the information you have given me is very useful, so for that I thank you.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Doesn't have the characteristics of any virus or Rootkit i have ever worked on ! I would do an exorcism, sorry but couldn't help that !!
Lets see what the bad incompetent (charges to much) Geek squad has to say !
Also as @Try3 said run the TTDSKiller !
 

My Computer My Computer

At a glance

Windows11 23H2 (OS Build 22631.2428)2.90 gigahertz Intel Core i7-1070016214 Megabytes Usable Installed Memor
OS
Windows11 23H2 (OS Build 22631.2428)
Computer type
PC/Desktop
Manufacturer/Model
HP HP ENVY TE01
CPU
2.90 gigahertz Intel Core i7-10700
Motherboard
Board: HP 8767 A (SMVB)
Memory
16214 Megabytes Usable Installed Memor
Hard Drives
1511.52 Gigabytes Usable Hard Drive Capacity
1418.15 Gigabytes Hard Drive Free Space
Keyboard
Logitech wireless
Mouse
M 185 wireless
Internet Speed
12 ms Jitter 8 ms Download 10.5 Mbps Upload 1.7
Browser
Edge & FF
Antivirus
Windows Defender

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2 26200.8655AMD Ryzen 7 5825U with Radeon Graphics16GB
    OS
    Windows 11 Pro 25H2 26200.8655
    Computer type
    Laptop
    Manufacturer/Model
    Acemagic LX15PRO
    CPU
    AMD Ryzen 7 5825U with Radeon Graphics
    Memory
    16GB
    Screen Resolution
    1920 x 1080
    Hard Drives
    SSD 2TB
    Internet Speed
    30 Mbps
    Browser
    Brave
    Antivirus
    Webroot Secure Anywhere
    Other Info
    System 3

    Acer Swift SF114-34 laptop
    OS Windows 11 Pro 26200.8524
    CPU Pentium Silver N6000
    RAM 4GB
    SSD Samsung 970 EVO Plus SSD 2TB (an upgrade)
  • At a glance

    Windows 11 Pro 23H2 22631.2506Atom N450 1.66GHz2GB
    Operating System
    Windows 11 Pro 23H2 22631.2506
    Computer type
    Laptop
    Manufacturer/Model
    HP Mini 210-1090NR PC (bought in late 2009!)
    CPU
    Atom N450 1.66GHz
    Memory
    2GB
    Browser
    Brave
    Antivirus
    Webroot
I tried the MS rootkit scan by following Brink's instructions - nothing happened. When I tried the command prompt I got this response:

2023-04-10_105857.jpg

Something is wrong - but what is it and how can I fix it?
 

My Computer My Computer

At a glance

Win11 ProAMD Ryzen 5 5500U16 GBRadeon 2100
OS
Win11 Pro
Computer type
PC/Desktop
Manufacturer/Model
BeeLink SER Mini
CPU
AMD Ryzen 5 5500U
Motherboard
BeeLink SER
Memory
16 GB
Graphics Card(s)
Radeon 2100
Sound Card
none
Monitor(s) Displays
Primary: Phillips 4K; Secondary: LG 4K
Screen Resolution
Both 3860 x 2160
Hard Drives
C: NVme 500 GB Windows only
D: 128 GB NVme User data + Windows Temp via Junction Link
PSU
External
Case
Mini
Cooling
Internal fan
Keyboard
Logitech Wireless Lighted
Mouse
Kensington ExpertMouse wireless trackball
Internet Speed
500/500
Browser
Brave
Antivirus
Windows Defender

My Computer My Computer

At a glance

Windows 11 Home x64 Version 25H2 Build 26200....
OS
Windows 11 Home x64 Version 25H2 Build 26200.8037
Something is wrong - but what is it and how can I fix it?

Birt,

I urge you to start a thread of your own or ask your question in that tutorial thread.
This is Bunaby Jones' thread.

All the best,
Denis
 

My Computer My Computer

At a glance

Windows 11 Home x64 Version 25H2 Build 26200....
OS
Windows 11 Home x64 Version 25H2 Build 26200.8037
Kaspersky? I just have a hard time trusting anything owned and operated by the Russians.
The Russian maffia controls so much of what goes on in that country!
 
Could you have visited any dodgy websites?
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2 26200.8655AMD Ryzen 7 5825U with Radeon Graphics16GB
    OS
    Windows 11 Pro 25H2 26200.8655
    Computer type
    Laptop
    Manufacturer/Model
    Acemagic LX15PRO
    CPU
    AMD Ryzen 7 5825U with Radeon Graphics
    Memory
    16GB
    Screen Resolution
    1920 x 1080
    Hard Drives
    SSD 2TB
    Internet Speed
    30 Mbps
    Browser
    Brave
    Antivirus
    Webroot Secure Anywhere
    Other Info
    System 3

    Acer Swift SF114-34 laptop
    OS Windows 11 Pro 26200.8524
    CPU Pentium Silver N6000
    RAM 4GB
    SSD Samsung 970 EVO Plus SSD 2TB (an upgrade)
  • At a glance

    Windows 11 Pro 23H2 22631.2506Atom N450 1.66GHz2GB
    Operating System
    Windows 11 Pro 23H2 22631.2506
    Computer type
    Laptop
    Manufacturer/Model
    HP Mini 210-1090NR PC (bought in late 2009!)
    CPU
    Atom N450 1.66GHz
    Memory
    2GB
    Browser
    Brave
    Antivirus
    Webroot
Could you have visited any dodgy websites?
Well I was on a site streaming a series and I made the mistake of trying to download an episode. I cancelled within 30 seconds because it was gonna take forever.

These things started very shortly after this.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
You need a better antimalware if you are visiting naughty websites!
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2 26200.8655AMD Ryzen 7 5825U with Radeon Graphics16GB
    OS
    Windows 11 Pro 25H2 26200.8655
    Computer type
    Laptop
    Manufacturer/Model
    Acemagic LX15PRO
    CPU
    AMD Ryzen 7 5825U with Radeon Graphics
    Memory
    16GB
    Screen Resolution
    1920 x 1080
    Hard Drives
    SSD 2TB
    Internet Speed
    30 Mbps
    Browser
    Brave
    Antivirus
    Webroot Secure Anywhere
    Other Info
    System 3

    Acer Swift SF114-34 laptop
    OS Windows 11 Pro 26200.8524
    CPU Pentium Silver N6000
    RAM 4GB
    SSD Samsung 970 EVO Plus SSD 2TB (an upgrade)
  • At a glance

    Windows 11 Pro 23H2 22631.2506Atom N450 1.66GHz2GB
    Operating System
    Windows 11 Pro 23H2 22631.2506
    Computer type
    Laptop
    Manufacturer/Model
    HP Mini 210-1090NR PC (bought in late 2009!)
    CPU
    Atom N450 1.66GHz
    Memory
    2GB
    Browser
    Brave
    Antivirus
    Webroot
You need a better antimalware if you are visiting naughty websites!
It wasn’t porn. It was MoviesJoy and I was watching a series. Windows defender didn’t detect anything so I don’t think anything else would have. Unfortunately I didn’t know how volatile that site was and how unsafe. That’s on me.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
@Bunaby Jones

You might want to try unhooking all the other drives (like you did), and unhooking the internet... then using some bootable partitioning software to "wipe" the drive you intend to re-install Windows on.

You can burn this to a CD or use RUFUS to put it on a USB stick.
It's the ISO for Minitools Partition Wizard 11...



Then, boot from the CD or USB stick and "wipe" the drive (write zeroes to it).
Then... install Windows on that drive, and see if the problem still exists.



IF the problem still exists, then it's probably the BIOS chip or possibly the router, that's infected.
[I don't know how you have all your devices hooked up, so I can't be sure about the router.]
 

My Computers My Computers

  • At a glance

    Win 11 Home ♦♦♦26200.8655 ♦♦♦♦♦♦♦25H2AMD Ryzen 7 3700XG.Skill (F4-3200C14D-16GTZKW)EVGA RTX 2070 (08G-P4-2171-KR)
    OS
    Win 11 Home ♦♦♦26200.8655 ♦♦♦♦♦♦♦25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® [May 2020]
    CPU
    AMD Ryzen 7 3700X
    Motherboard
    Asus Pro WS X570-ACE (BIOS 5302)
    Memory
    G.Skill (F4-3200C14D-16GTZKW)
    Graphics Card(s)
    EVGA RTX 2070 (08G-P4-2171-KR)
    Sound Card
    Realtek ALC1220P / ALC S1220A
    Monitor(s) Displays
    Dell U3011 30"
    Screen Resolution
    2560 x 1600
    Hard Drives
    2x Samsung 860 EVO 500GB,
    WD 4TB Black FZBX - SATA III,
    WD 8TB Black FZBX - SATA III,
    DRW-24B1ST CD/DVD Burner
    PSU
    PC Power & Cooling 750W Quad EPS12V
    Case
    Cooler Master ATCS 840 Tower
    Cooling
    CM Hyper 212 EVO (push/pull)
    Keyboard
    Ducky DK9008 Shine II Blue LED
    Mouse
    Logitech Optical M-100
    Internet Speed
    300/300
    Browser
    Firefox (latest)
    Antivirus
    Bitdefender Total Security
    Other Info
    Speakers: Klipsch Pro Media 2.1
  • At a glance

    Windows XP Pro 32bit w/SP3AMD Athlon 64 X2 5000+ (OC'd @ 3.2Ghz)TWIN2X2048-6400C4DHX (2 x 1GB, DDR2 800)EVGA 256-P2-N758-TR GeForce 8600GT SSC
    Operating System
    Windows XP Pro 32bit w/SP3
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® (not in use)
    CPU
    AMD Athlon 64 X2 5000+ (OC'd @ 3.2Ghz)
    Motherboard
    ASUS M2N32-SLI Deluxe Wireless Edition
    Memory
    TWIN2X2048-6400C4DHX (2 x 1GB, DDR2 800)
    Graphics card(s)
    EVGA 256-P2-N758-TR GeForce 8600GT SSC
    Sound Card
    Onboard
    Monitor(s) Displays
    ViewSonic G90FB Black 19" Professional (CRT)
    Screen Resolution
    up to 2048 x 1536
    Hard Drives
    WD 36GB 10,000rpm Raptor SATA
    Seagate 80GB 7200rpm SATA
    Lite-On LTR-52246S CD/RW
    Lite-On LH-18A1P CD/DVD Burner
    PSU
    PC Power & Cooling Silencer 750 Quad EPS12V
    Case
    Generic Beige case, 80mm fans
    Cooling
    ZALMAN 9500A 92mm CPU Cooler
    Keyboard
    Logitech Classic Keybooard 200
    Mouse
    Logitech Optical M-BT96a
    Internet Speed
    300/300
    Browser
    Firefox 3.x ??
    Antivirus
    Symantec (Norton)
    Other Info
    Still assembled, still runs. Haven't turned it on for 15 years?
@Bunaby Jones

You might want to try unhooking all the other drives (like you did), and unhooking the internet... then using some bootable partitioning software to "wipe" the drive you intend to re-install Windows on.

You can burn this to a CD or use RUFUS to put it on a USB stick.
It's the ISO for Minitools Partition Wizard 11...



Then, boot from the CD or USB stick and "wipe" the drive (write zeroes to it).
Then... install Windows on that drive, and see if the problem still exists.



IF the problem still exists, then it's probably the BIOS chip or possibly the router, that's infected.
[I don't know how you have all your devices hooked up, so I can't be sure about the router.]
I do not have my PC right now. It’s checked Into GeekSquad at Best Buy. My Desktop was LAN connected.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
I do not have my PC right now. It’s checked Into GeekSquad at Best Buy. My Desktop was LAN connected.


They will probably do the same thing.
And as for router infections (I don't even use a router).
A while back I read about bad guys intercepting router packages, manually infecting them, the re-packaging them, so no one knew. If it still happens, I have no idea. I just pointed it out cause it's... possible.

Another way to get recurring infection is via infected USB stick or USB device.
You get everything cleaned... then stick the USB device back in... and you're infected again.




If all else fails... make a free account here, and let them clean the computer.
They're not fast, but they are the best...




It's not like a normal forum, where many people answer. You'll get something like a case worker.
One person who will take you from start to finish. It's all free.

Follow their directions exactly. Don't skip ahead, or try to 2nd guess them.
They've been doing this for 20 years that I know of... probably longer.
 
Last edited:

My Computers My Computers

  • At a glance

    Win 11 Home ♦♦♦26200.8655 ♦♦♦♦♦♦♦25H2AMD Ryzen 7 3700XG.Skill (F4-3200C14D-16GTZKW)EVGA RTX 2070 (08G-P4-2171-KR)
    OS
    Win 11 Home ♦♦♦26200.8655 ♦♦♦♦♦♦♦25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® [May 2020]
    CPU
    AMD Ryzen 7 3700X
    Motherboard
    Asus Pro WS X570-ACE (BIOS 5302)
    Memory
    G.Skill (F4-3200C14D-16GTZKW)
    Graphics Card(s)
    EVGA RTX 2070 (08G-P4-2171-KR)
    Sound Card
    Realtek ALC1220P / ALC S1220A
    Monitor(s) Displays
    Dell U3011 30"
    Screen Resolution
    2560 x 1600
    Hard Drives
    2x Samsung 860 EVO 500GB,
    WD 4TB Black FZBX - SATA III,
    WD 8TB Black FZBX - SATA III,
    DRW-24B1ST CD/DVD Burner
    PSU
    PC Power & Cooling 750W Quad EPS12V
    Case
    Cooler Master ATCS 840 Tower
    Cooling
    CM Hyper 212 EVO (push/pull)
    Keyboard
    Ducky DK9008 Shine II Blue LED
    Mouse
    Logitech Optical M-100
    Internet Speed
    300/300
    Browser
    Firefox (latest)
    Antivirus
    Bitdefender Total Security
    Other Info
    Speakers: Klipsch Pro Media 2.1
  • At a glance

    Windows XP Pro 32bit w/SP3AMD Athlon 64 X2 5000+ (OC'd @ 3.2Ghz)TWIN2X2048-6400C4DHX (2 x 1GB, DDR2 800)EVGA 256-P2-N758-TR GeForce 8600GT SSC
    Operating System
    Windows XP Pro 32bit w/SP3
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® (not in use)
    CPU
    AMD Athlon 64 X2 5000+ (OC'd @ 3.2Ghz)
    Motherboard
    ASUS M2N32-SLI Deluxe Wireless Edition
    Memory
    TWIN2X2048-6400C4DHX (2 x 1GB, DDR2 800)
    Graphics card(s)
    EVGA 256-P2-N758-TR GeForce 8600GT SSC
    Sound Card
    Onboard
    Monitor(s) Displays
    ViewSonic G90FB Black 19" Professional (CRT)
    Screen Resolution
    up to 2048 x 1536
    Hard Drives
    WD 36GB 10,000rpm Raptor SATA
    Seagate 80GB 7200rpm SATA
    Lite-On LTR-52246S CD/RW
    Lite-On LH-18A1P CD/DVD Burner
    PSU
    PC Power & Cooling Silencer 750 Quad EPS12V
    Case
    Generic Beige case, 80mm fans
    Cooling
    ZALMAN 9500A 92mm CPU Cooler
    Keyboard
    Logitech Classic Keybooard 200
    Mouse
    Logitech Optical M-BT96a
    Internet Speed
    300/300
    Browser
    Firefox 3.x ??
    Antivirus
    Symantec (Norton)
    Other Info
    Still assembled, still runs. Haven't turned it on for 15 years?
I can do the same job as they do at Bleepingcomputer & i have been doing it for 20 yrs. also !
!
 

My Computer My Computer

At a glance

Windows11 23H2 (OS Build 22631.2428)2.90 gigahertz Intel Core i7-1070016214 Megabytes Usable Installed Memor
OS
Windows11 23H2 (OS Build 22631.2428)
Computer type
PC/Desktop
Manufacturer/Model
HP HP ENVY TE01
CPU
2.90 gigahertz Intel Core i7-10700
Motherboard
Board: HP 8767 A (SMVB)
Memory
16214 Megabytes Usable Installed Memor
Hard Drives
1511.52 Gigabytes Usable Hard Drive Capacity
1418.15 Gigabytes Hard Drive Free Space
Keyboard
Logitech wireless
Mouse
M 185 wireless
Internet Speed
12 ms Jitter 8 ms Download 10.5 Mbps Upload 1.7
Browser
Edge & FF
Antivirus
Windows Defender
I can do the same job as they do at Bleepingcomputer & i have been doing it for 20 yrs. also !
!
I shall remember that if ever the case I get one of these 'hidden' modern malware. 👍
 

My Computers My Computers

  • At a glance

    Win 11 ProAMD Ryzen™ 7 7730U24GB Dual-Channel DDR4 @ 1596MHz (22-22-22-52)512MB ATI AMD Radeon Graphics (ASUStek Comput...
    OS
    Win 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    ASUS Vivobook
    CPU
    AMD Ryzen™ 7 7730U
    Motherboard
    M1605YA
    Memory
    24GB Dual-Channel DDR4 @ 1596MHz (22-22-22-52)
    Graphics Card(s)
    512MB ATI AMD Radeon Graphics (ASUStek Computer Inc)
    Monitor(s) Displays
    Generic PnP Monitor (1920x1200@60Hz) - P1 PLUS (1920x1080@59Hz)
    Screen Resolution
    1920 X 1200
    Hard Drives
    953GB Western Digital WD
    PSU
    45 Watts
    Mouse
    Lenovo Bluetooth.
    Internet Speed
    500 Mbps
    Browser
    Edge
    Antivirus
    Defender
  • At a glance

    Windows 11AMD Ryzen 7 5800H / 3.2 GHz32 GB DDR4 SDRAM 3200 MHzNVIDIA GeForce RTX 3060 6 GB GDDR6 SDRAM
    Operating System
    Windows 11
    Computer type
    Laptop
    Manufacturer/Model
    ACER NITRO
    CPU
    AMD Ryzen 7 5800H / 3.2 GHz
    Motherboard
    CZ Scala_CAS (FP6)
    Memory
    32 GB DDR4 SDRAM 3200 MHz
    Graphics card(s)
    NVIDIA GeForce RTX 3060 6 GB GDDR6 SDRAM
    Sound Card
    Realtek Audio. NVIDIA High Definition Audio
    Monitor(s) Displays
    15.6" LED backlight 1920 x 1080 (Full HD) 144 Hz
    Screen Resolution
    1920 x 1080 (Full HD)
    Hard Drives
    Samsung 970 Evo Plus 2TB NVMe M.2
    PSU
    180 Watt, 19.5 V
    Mouse
    Lenovo Bluetooth
    Internet Speed
    500 Mbps
    Browser
    Edge
    Antivirus
    Defender
I tried the MS rootkit scan by following Brink's instructions - nothing happened. When I tried the command prompt I got this response:

View attachment 57585

Something is wrong - but what is it and how can I fix it?
You have to uninstall any third party antivirus or antimalware first. I use Webroot and pausing it was not enough, I got the same error in Powershell as you. But Defender offline ran fine once I had uninstalled Webroot.
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 25H2 26200.8655AMD Ryzen 7 5825U with Radeon Graphics16GB
    OS
    Windows 11 Pro 25H2 26200.8655
    Computer type
    Laptop
    Manufacturer/Model
    Acemagic LX15PRO
    CPU
    AMD Ryzen 7 5825U with Radeon Graphics
    Memory
    16GB
    Screen Resolution
    1920 x 1080
    Hard Drives
    SSD 2TB
    Internet Speed
    30 Mbps
    Browser
    Brave
    Antivirus
    Webroot Secure Anywhere
    Other Info
    System 3

    Acer Swift SF114-34 laptop
    OS Windows 11 Pro 26200.8524
    CPU Pentium Silver N6000
    RAM 4GB
    SSD Samsung 970 EVO Plus SSD 2TB (an upgrade)
  • At a glance

    Windows 11 Pro 23H2 22631.2506Atom N450 1.66GHz2GB
    Operating System
    Windows 11 Pro 23H2 22631.2506
    Computer type
    Laptop
    Manufacturer/Model
    HP Mini 210-1090NR PC (bought in late 2009!)
    CPU
    Atom N450 1.66GHz
    Memory
    2GB
    Browser
    Brave
    Antivirus
    Webroot

Latest Support Threads

Back
Top Bottom