VIRTUAL TAKEOVER

12bfun

New Member
Thread author
Jan 5, 2013
5
working on attaching logs. otl ran smooth. asw log was stopped and errors and all programs shut down.
 

Attachments

  • Extras.Txt
    31.1 KB · Views: 170
  • OTL.Txt
    239.2 KB · Views: 116
  • aswMBR.txt
    1.2 KB · Views: 128

Fiery

Level 1
Jan 11, 2011
2,007
Hi and welcome to the forums!

I'm confused about your setup. So you have one win7 machine, one win8 machine that you turned into Linux and both are linked to a server? What do you mean by "Virtual machine established at preboot" and "networking hardware reformatted internally"?

Are both of your machines experiencing the symptoms? Do you remember exactly what the warning message was? Have you tried resetting the router to factory default?
 

12bfun

New Member
Thread author
Jan 5, 2013
5
Okay it's pretty complicated. I have a total of three separate computers involved here and two mobile phones. At the start, one ran win7homeprem. The other ran windows-ultim. and the last had win8pro installed leaving with a win7/8 choice at start up. the common link is my home network and router. NONE of my computers should be configuered as servers, I don't even media share between devices on my home or any other network. I've tried three different routers. my netgear log was being disabled so I replaced it with a wrt54g flashed with dd-wrt. A machines are exhibiting signs of creating a VM during boot before login. It's been a challenge to gain full admin control and once gained it can't be retained. The machines at times will display the same "themes" or slightly altered appearance. for example the start button on task bar changes from square to round logo. windows 8 theme appeared on my win7 machine once. SEE ATTACH screenshot of device mgr to explain internal reformatting---shoot how do I attach????
 

12bfun

New Member
Thread author
Jan 5, 2013
5
Okay it's pretty complicated. I have a total of three separate computers involved here and two mobile phones. At the start, one ran win7homeprem. The other ran windows-ultim. and the last had win8pro installed leaving with a win7/8 choice at start up. the common link is my home network and router. NONE of my computers should be configuered as servers, I don't even media share between devices on my home or any other network. I've tried three different routers. my netgear log was being disabled so I replaced it with a wrt54g flashed with dd-wrt. A machines are exhibiting signs of creating a VM during boot before login. It's been a challenge to gain full admin control and once gained it can't be retained. The machines at times will display the same "themes" or slightly altered appearance. for example the start button on task bar changes from square to round logo. windows 8 theme appeared on my win7 machine once. SEE ATTACH screenshot of device mgr to explain internal reformatting---shoot how do I attach????
 

Attachments

  • Screenshot (2).png
    Screenshot (2).png
    115.6 KB · Views: 117

12bfun

New Member
Thread author
Jan 5, 2013
5
So the hid keyboard keeps coming back, the microsoft kernel debug adapter isn't a usual part of my system and when I go to manage network adapt the list does not populate. and the two base devices that need troubleshooting pop-up when this VM malware is in effect.


So the hid keyboard keeps coming back, the microsoft kernel debug adapter isn't a usual part of my system and when I go to manage network adapt the list does not populate. and the two base devices that need troubleshooting pop-up when this VM malware is in effect.
 

Fiery

Level 1
Jan 11, 2011
2,007
The HID keyboard is a normal part of Windows 7. As for the microsoft kernel debug adapter, go to Start > type cmd in the search box. In the search results, right-click cmd and click Run as administrator

In the Command Prompt type: bcdedit /debug off then press enter

What "signs" are you seeing that is similar to a VM? And how do you know you are losing "full admin control"?
 

Fiery

Level 1
Jan 11, 2011
2,007
Have you tried my suggestion regarding resetting the router to factory default settings and the cmd command in my last post?

You can't have malware on a newly nuked HD. As for double posts, it's not your PC since
a) The posts are 3 minutes apart
b) You use a hr code to separate 2 paragraphs of the same text

And I still have no idea what type of symptoms you are having.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top