Attacked

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by TammyRDH, Jan 29, 2015.

  1. TammyRDH

    TammyRDH Private E-2

    I had a sudden malware attack while using IE in Windows 8. I didn't do anything besides closing the browser and then running SuperAntiSpyware, Norton 360. I attempted to run Malwarebytes. I initially couldn't run Malware bytes. But eventually I was able to run it by reloading it. It wouldn't even redownload. But somehow the original program suddenly started up. Then I ran "MBR Check" and got one error for an "Unknown MRB code" as a Standard or infect MBR. I didn't fix it. After a reboot, I can't see the Desktop app in the Windows Charms screen, or any of my other installed apps either. Possibly others, too. I just can't remember what was there. Strangely, I was able to access my desktop by clicking the upper right corner of the screen even though the image wasn't popping up. I followed the advice on your website and created logs which I will upload.
     

    Attached Files:

  2. TammyRDH

    TammyRDH Private E-2

    MGtools had a hang up in the processing and two bizarre pop ups appeared. One was during the "Running processeddll.exe to find loaded DLLs. The pop up title was "ProcessDLL.exe - Common Language Runtime Debugger Services" Click okay to terminate and CANCEL to debug the application. I did neither. I just clicked X and then MGtools continued to run. Then another pop up titled "ProcessDll.exe - No debugger found" It had some dialog including "cordbg.exe !a 0xa10". Click on Retry or Cancel. I just closed with the X.
     
  3. TammyRDH

    TammyRDH Private E-2

    I'm getting chronic pop up windows in IE now.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  5. TammyRDH

    TammyRDH Private E-2

    I ran Hitman Pro and deleted the 3 entries. I reset IE. I can't say yet about the pop ups in IE. But I still don't have my Windows tiles "Charms" back.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use it for a while and let me know if the popups return. You may have to post in the software forum for your other issue.
     
  7. TammyRDH

    TammyRDH Private E-2

    This is the entry on MBR check:

    PhysicalDrive0 Model Number: ST1000DM003-9YN162, Rev: HP16

    Size Device Name MBR Status
    --------------------------------------------
    931 GB \\.\PhysicalDrive0 Unknown MBR code
    SHA1: 639AC5CDF8A5CF3245975932C6A4215450A7B98F
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    MBR check often gets it wrong. Not something to be worried about.
     
  9. TammyRDH

    TammyRDH Private E-2

    Okay. Thanks. I put a post on the Software forum. Hopefully, this get resolved. I just reinstalled my operating system for the 2nd time because I didn't want Window 8.1 and it auto installed TWICE. I wasn't even finished reloading my programs when this happened.
    Any advice on what to do with the two shadow copies of the original operating systems and all my personal documents?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That is not a topic for the Malware forum. ;)

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  11. TammyRDH

    TammyRDH Private E-2

    Thank you for your help. I think we can close this thread now. If problems persist, I will open a new thread. I appreciate the support. :)
     
  12. TammyRDH

    TammyRDH Private E-2

    pop ups are back. :(
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are they only happening in IE or are they happening in other browsers? If so, which ones.
     
  14. TammyRDH

    TammyRDH Private E-2

    The pop ups are only IE. But everything else is acting wonky, too. I had just reinstalled my OS and was only partially finished reinstalling all of my programs. I don't have anything installed that can't be reinstalled. I am having issues with the new reinstallations of so many things as I progress, that I am going to wipe it out again and start fresh. Drastic, I know. But this dilemma is taking more time than a reinstall. Thanks for your help and I will be back to Major Geeks once I have started fresh to make sure the computer is properly protected.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know how you get along.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds