Possible hacker program installation

Gib

Level 3
Thread author
Verified
Well-known
May 23, 2014
113
The problems I'm experiencing... I want to start with the hacker problems first and foremost I listen to a radio show online at a specific time almost daily and the hacker is getting pretty annoyed, so when I go to click (while in the site) to activate radio program and chat room I'm taken back to the home page. What happened was the hacker created some sort of block so that I could not access! You will notice in the log/logs that I previously had virus zeroaccess. When I checked the developer's tool I found that I have acr error and if pages become dormant for a little while I would get a message saying that tabs need to recover. A lot of times if I agree to the message, the tabs will all move to the left side of the screen and become normalized, but for the most part I have had to close and reopen internet explorer. The other problem is similar and it causes me to close and reopen ie, I'm going through gcod.

I'm really not sure if I listed all the computer problems I'm having, but there may be others that I can think of offhand. BTW, I'm using a laptop computer.
 

Attachments

  • Addition.txt
    24.6 KB · Views: 125
  • FRST_23-05-2014_22-41-49.txt
    14.5 KB · Views: 86

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Hi,


First, go to Control Panel and uninstall following (skip lines that cannot be uninstalled):
- Adobe Reader X
- Ask Toolbar
- Java 7 Update 25
- McAfee
- Yahoo! Toolbar

Latest versions of Java and Adobe Reader available here --> http://www.java.com/en/ and here http://get.adobe.com/uk/reader/
Make sure to uncheck optional offers.



***** NEXT *****



Download attached fixlist.txt on the same location as FRST (otherwise the fix won't work)
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system

Open FRST, and click Fix. Attach me that report after it is finished.
 

Attachments

  • fixlist.txt
    1.1 KB · Views: 125

Gib

Level 3
Thread author
Verified
Well-known
May 23, 2014
113
Alright:)
As far as whether that takes care of the problem, I won't notice right off the bat, but I will be active on the computer to see for sure.
 

Attachments

  • Fixlog_24-05-2014_06-40-30.txt
    3 KB · Views: 64

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
How is computer now?

I would like one more check:


Download TDSSKiller and save it to your desktop

Execute TDSSKiller.exe by doubleclicking on it.
Confirm "End user Licence Agreement" and "KSN Statement" dialog box by clicking on Accept button.
  • Press Start Scan
  • If Suspicious object is detected, the default action will be Skip, click on Continue.
  • If Malicious objects are found, select Cure.

Once complete, a log will be produced at the root drive which is typically C:\ ,for example, C:\TDSSKiller.<version_date_time>log.txt


Please post the contents of that log in your next reply.
 

Gib

Level 3
Thread author
Verified
Well-known
May 23, 2014
113
Before your last post I was computer active. I'm going through computer slow down often, one of my tabs is on website restore error. I've noticed when tabs go to the left side of the screen they are loading and thats how I end up getting the website restore error. I also have a problem I forgot to mention, 'about blank' problem when I try to get to a desired page but that happens sometimes.
 

Attachments

  • TDSSKiller.3.0.0.35_24.05.2014_17.07.45_log.txt
    179.4 KB · Views: 83

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Please download zoek.zip or zoek.rar by smeenk (
Zoek_icon.png
) from here or here and save it to your Desktop.
Unpack the archive...
  • Close any open browsers
  • Temporarily disable your AntiVirus program. (If necessary)
    If you are unsure how to do this please read this or this Instruction.
  • Double click on zoek.exe to run the tool .
    Please wait while the tool does not start...
  • Copy the text present inside the code box below and paste it into the large window in the zoek tool:
    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system

    Code:
    createsrpoint;
    emptyfolderscheck;delete
    autoclean;
    emptyclsid;
    emptyalltemp;
    ipconfig /flushdns;b
  • Click on
    Run%20Script%20by%20zoek.png
    button.
    Please wait until a logreport will open (this can be after reboot)
  • Save notepad to your Desktop and attach here zoek-results.log
    Note: It will also create a log in the C:\ directory named "zoek-results.log"
 

Gib

Level 3
Thread author
Verified
Well-known
May 23, 2014
113
Idk if its zoek or anything like that, it seems the computer I have should be less airy sounding than it is now!
Here's the zoek results!
 

Attachments

  • zoek-results.log
    13.4 KB · Views: 70

Gib

Level 3
Thread author
Verified
Well-known
May 23, 2014
113
Only time will tell. My computer does sound better, more quieter right now.
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Ok, then we're done here unless you have any other problem.


For future protection I can recommend you:
- Adblock --> https://adblockplus.org/en/chrome
- Unchecky --> http://unchecky.com/



The following will implement some post-cleanup procedures:

=> Please download DelFix by Xplode to your Desktop.

Run the tool and check the following boxes below;
checkmark.png
Remove disinfection tools
checkmark.png
Create registry backup
checkmark.png
Purge System Restore

Click Run button and wait a few seconds for the programme completes his work.
At this point all the tools we used here should be gone. Tool will create an report for you (C:\DelFix.txt)

The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top