Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

previous bootkit.. zeroaccess/max++..strange disconnect last night and missing logs


  • Please log in to reply
1 reply to this topic

#1 Aardopotamus

Aardopotamus

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:42 AM

Posted 18 January 2013 - 09:36 AM

Question: Am i still hacked?

Details:

I previously had a bootkit i believe to be max++ or some zeroaccess variant.. TDSS Killer came up with positive results.. in the beginning and i tried running aswMBR and one of those times it closed and caused a BSOD.. i tried many methods of removing it.. but every time i tried to get rid of it .. it came right back.. the giveaway was a folder called DRM with an alternate data stream containing arabic wording..so i decided to do a low level format on the drive and then reinstalled Windows 7 Ultimate x64 on January 1st 2013

Last night 1/17/2013 i decided to restore parts of my old firefox profile into my new firefox profile.. the files i restored were formhistory.sqlite and places.sqlite, and about an hour later i think it was.. firefox for no reason i can think of.. had high memory usage..at about the same time this happened.. my girlfriend who i was talking with on Skype lost her internet connection and i noticed my Skype connection was disconnecting and reconnecting as well. I then checked my Norton Internet Security History logs.. and strangely.. the history for Networks and Connections was completely empty.. all other logs were still there.. the girlfriend is still most definitely infected and will be visiting this forum soon.. but i'd like to make sure i am not infected again.. thank you

Possibly relevant.. i also restored my skype profile.. but that was on 1/1/2013

Edited by Aardopotamus, 18 January 2013 - 01:33 PM.


BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,058 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:03:42 AM

Posted 18 January 2013 - 04:20 PM

Hello best method is to get a deeper look. Please follow this Preparation Guide and post in a new topic.

Let me know if all went well.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users