OK GUYS, I AM CONFUSED LIKE A FAT KID WITH THE SALAD !!!
I have created Hitman Pro Kickstart USB on other computer. It copied 3 files on the USB drive
hitmanpro.exe
hitmanprox64.exe
kickstarter.exe
I booted from USB flash drive and I got 3 options, I went to first option (Bypass MBR record).
Then Windows started to diagnose my PC for startup problems and attempted to repair Startup problems (which actually doesn’t exists, I could boot to Windows normally every time).
At the end it showed up something like :
Windows cannot repair your startup problem (try advanced options or proceed to boot to Windows 8.1)…
Of course it couldn’t repair anything because there was nothing to repair
I was proceed to boot to Windows.
Then, it cross on my mind, let start Hitman Pro from that hitmanpro.exe on the usb drive.
AND IT STARTED!!!
I have installed HitmanPro on my computer and ran a scan, and of course Hitman Pro found a false positive in JDownloader folder called elevate32.exe (checked on VirusTotal, it is false positive, so I ignore it like I always do) and found one malformation in the registry
Hitman Pro Report LOG
Code:
HitmanPro 3.7.8.207
www.hitmanpro.com
Computer name . . . . : *****-PC
Windows . . . . . . . : 6.2.0.9200.X86/2 --------- dunno why is this version, Windows 8.1 should be 9.3.9600 ( maybe because usb was created on Windows XP, but it does not make sense, the scan was started on my Windows 8.1)
User name . . . . . . : *****-PC\*****
UAC . . . . . . . . . : Enabled
License . . . . . . . : Trial (30 days left)
Scan date . . . . . . : 2013-10-16 14:59:16
Scan mode . . . . . . : Normal
Scan duration . . . . : 3m 53s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : Yes
Threats . . . . . . . : 1
Traces . . . . . . . : 1
Objects scanned . . . : 687,729
Files scanned . . . . : 15,766
Remnants scanned . . : 138,406 files / 533,557 keys
Malware _____________________________________________________________________
C:\Users\*****\AppData\Local\JDownloader v2.0\tools\Windows\elevate\Elevate32.exe
Size . . . . . . . : 69,632 bytes
Age . . . . . . . : 45.8 days (2013-08-31 18:53:23)
Entropy . . . . . : 5.7
SHA-256 . . . . . : E708FE307DAB49A9FEB9F0CB845C3E13739F9F2BD9FE0B1C1A2AB749B5EFF45F
Product . . . . . : Elevate Application
Publisher . . . . : Johannes Passing
Description . . . : Elevate
Version . . . . . : 1.0.0.2894
Copyright . . . . : Copyright (C) 2007
> G Data . . . . . . : Application.Tool.SIB (Engine A)
> Ikarus . . . . . . : Application.Tool.SIB!IK
Fuzzy . . . . . . : 100.0
Malware remnants ____________________________________________________________
Boot Configuration Data (BCD) WinPE mode
HKLM\BCD00000000\Objects\{0ce4991b-e6b3-4b16-b23c-5e0d9250e5d9}\Elements\26000022\
So... What the hell is that malformation in the registry above? And what the hell just happened if anyone have a clue?