Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Rogue Killer detecting Hidden.ADS.


  • Please log in to reply
4 replies to this topic

#1 cadeteh

cadeteh

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:18 AM

Posted 08 October 2016 - 05:53 PM

HI, When I scan with rogue killer every time that I restart my computer the Hidden.ADS keeps appearing in the same place, then I proceeded to do a scan with Malwarebytes Anti-Malware,Panda Gold Protection,and nothing appeared. 

 

I dont know what to do.

:v

 

 

PD:Thanks In Advance.


RogueKiller V12.7.0.0 (x64) [Oct  3 2016] (Free) by Adlice Software
 
Sistema Operativo : Windows 10 (10.0.10586) 64 bits version
Iniciado en : Modo Normal
Usuario : cpu2 [Administrador]
Started from : C:\Users\cpu2\Downloads\RogueKillerX64.exe
Modo : Escanear -- Fecha : 10/08/2016 17:04:26 (Duration : 00:32:39)
 
¤¤¤ Procesos : 0 ¤¤¤
 
¤¤¤ Registro : 4 ¤¤¤
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-3705738826-2889361319-2203145478-1001\Software\Microsoft\Internet Explorer\Main | Search Bar : Preserve  -> Encontrado
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-3705738826-2889361319-2203145478-1001\Software\Microsoft\Internet Explorer\Main | Search Bar : Preserve  -> Encontrado
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 192.168.1.254 0.0.0.0 ([-][])  -> Encontrado
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{61dc74c9-5f6a-4ab1-8b0e-d39ad6e97b03} | DhcpNameServer : 192.168.1.254 0.0.0.0 ([-][])  -> Encontrado
 
¤¤¤ Tareas : 0 ¤¤¤
 
¤¤¤ Archivos : 1 ¤¤¤
[Hidden.ADS][Stream] C:\ProgramData:3BBB40F138830B1B -> Encontrado
 
¤¤¤ WMI : 0 ¤¤¤
 
¤¤¤ Archivo de hosts : 0 ¤¤¤
 
¤¤¤ Antirootkit : 0 (Driver: Cargado) ¤¤¤
 
¤¤¤ Navegadores Web : 0 ¤¤¤
 
¤¤¤ Chequeo MBR : ¤¤¤
+++++ PhysicalDrive0: Hitachi HUA722020ALA331 +++++
--- User ---
[MBR] 78dd788f6b21ef50a2963f428e33697d
[BSP] 96d31b2bd4e53e5f8ceaba6047c7579a : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 500 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 1026048 | Size: 1907227 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
 
+++++ PhysicalDrive1: Generic STORAGE DEVICE USB Device +++++
Error reading User MBR! ([15] El dispositivo no está listo. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Solicitud no compatible. )


BC AdBot (Login to Remove)

 


#2 Jo*

Jo*

  • Malware Response Team
  • 3,429 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:09:18 AM

Posted 02 November 2016 - 12:06 PM

It seems that your pc has a problem or could be infected with malware which is going to take some more work and a deeper look. No sense running a bunch of tools here.
Please follow this Preparation Guide. If have already done a step or you cannot complete a step, skip it and continue.
Pease include a link to this thread.

Let me know if all went well.

Graduate of the WTT Classroom
Cheers,
Jo
If I have been helping you, and I have not replied to your latest post in 36 hours please send me a PM.


#3 cadeteh

cadeteh
  • Topic Starter

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:18 AM

Posted 02 November 2016 - 03:22 PM

all went well :D,it was a file that I haved and used the same fixlist.txt of a previous problem that I haved. 

 

Thanks.

 

:D



#4 Jo*

Jo*

  • Malware Response Team
  • 3,429 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:09:18 AM

Posted 04 November 2016 - 03:53 AM

Ok, does this mean that your problem is solved?

Graduate of the WTT Classroom
Cheers,
Jo
If I have been helping you, and I have not replied to your latest post in 36 hours please send me a PM.


#5 cadeteh

cadeteh
  • Topic Starter

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:18 AM

Posted 04 November 2016 - 10:16 PM

yes :D

thanks. :D






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users