Jump to content

Weird infection


Recommended Posts

I have no idea what it is called, so please move to appropriate site. Computer seems to be working fine now after what I performed below,

but I have a feeling it is still there.

I had one firefox browser open and all of a sudden I noticed 5 firefox browsers open in my tray. So I attempted to delete the first one, and my entire screen was taken over. A message appeared on my screen saying Windows Defender had detected a xxxx.dll file and my computer was taken over. (My windows defender was turned off at that time.)

A message also said do not shut down your computer.

The message stated to call Microsoft and a ph: number was given. A box was open asking me if I wanted to "deny" or "accept"?, something like that. I clicked X over and over, then deny again and again, but the message just stayed there. I clicked accept over and over but no luck ridding of the take over.

I then did the following procedure.

1. I disconnected the computer from the internet.

2. Next I hit my power button, but only long enough for the computer to start to shut down. I did Not hold the power button long enough for the computer to actually power off.

3. I hit the power button just long enough for the screen to say that items needed to shut down, force or cancel.

4. I hit cancel and the computer immediately shown the normal desktop again as if nothing had happened.

5. I reconnected the computer to the internet.

6. I turned on my windows defender program and updated, but have not run it.

7. I ran Malware Antimalware but found no problems.

I have Not powered off the computer, and await further instructions.

 

Thank you for your time and any help.

pos

 

 

 

Link to post
Share on other sites

  • Root Admin

Hello @Positron

It sounds like it was just a fake html and javascript scare from the current user session.

Let's go ahead though and do some scans just o make sure.

 

Please run the following steps and post back the logs as an attachment when ready.
Temporarily disable your antivirus or other security software first. Make sure to turn it back on once the scans are completed.
Temporarily disable Microsoft SmartScreen to download software below if needed. Make sure to turn it back on once the scans are completed.
If you still have trouble downloading the software please click on Reveal Hidden Contents below for examples of how to allow the download.

 

Spoiler
 
 
 
 

 

Spoiler

 

When downloading with some browsers you may see a different style of screens that may block FRST from downloading. The program is safe and used hundreds of times a week by many users.

Example of Microsoft Edge blocking the download

image.png

image.png

image.png

 

 



STEP 01

  • If you already have Malwarebytes installed then open Malwarebytes and click on the Scan button. It will automatically check for updates and run a Threat Scan.
  • If you don't have Malwarebytes installed yet please download it from here and install it.
  • Once installed then open Malwarebytes and select Scan and let it run.
  • Once the scan is completed make sure you have it quarantine any detections it finds.
  • If no detections were found click on the Save results drop-down, then the Export to TXT  button, and save the file as a Text file to your desktop or other location you can find and attach that log on your next reply.
  • If there were detections then once the quarantine has completed click on the View report button, Then click the Export drop-down, then the Export to TXT  button, and save the file as a Text file to your desktop or other location you can find and attach that log on your next reply.
  • If the computer restarted to quarantine you can access the logs from the Detection History, then the History tab. Highlight the most recent scan and double-click to open it. Then click the Export drop-down, then the Export to TXT  button, and save the file as a Text file to your desktop or other location you can find and attach that log on your next reply.
  • If Malwarebytes won't run then please skip to the next step and let me know in your next reply that the scanner would not run.

STEP 02

Please download AdwCleaner by Malwarebytes and save the file to your Desktop.

  • Double-click to run the program
  • Accept the End User License Agreement.
  • Wait until the database is updated.
  • Click Scan Now.
  • When finished, if items are found please click Quarantine.
  • Your PC should reboot now if any items were found.
  • After reboot, a log file will be opened. Attach or Copy its content into your next reply.

RESTART THE COMPUTER Before running Step 3

STEP 03
Please download the Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatible with your system. You can check here if you're not sure if your computer is 32-bit or 64-bit

  • Double-click to run it. When the tool opens, click Yes to disclaimer.
  • Press the Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
  • The first time the tool is run, it also makes another log (Addition.txt). If you've, run the tool before you need to place a check mark here each time
  • Please attach the Additions.txt log to your reply as well.
  • On your next reply, you should be attaching frst.txt and additions.txt to your post, every time.

 

Thanks

Link to post
Share on other sites

  • Root Admin

I don't see any signs of an infection. The logs show that Malwarebytes did fault at least once and Windows Defender looks to have had some trouble updating at some point.

Please open Windows Defender and check for updates.

If you haven't done so already I'd recommend you get all the latest updates for Windows 7 (best to upgrade to Windows 10 as 11 is just around the corner too) but if you're going to remain on Windows 7 you should get the updates that are available.

 

Please let me know if there is anything else we can do to assist you

Cheers @Positron

 

 

Link to post
Share on other sites

Thanks Advanced. It was a little scary as it covered the entire screen, so I could not exit anything.

I would like to ask one more question if I may. If it had been a real threat, could I have formatted the hard drive and

then used my backup image to restore, or would remnants of the problem still be hiding somewhere, and require more work?

Thanks again Advanced.

pos

Link to post
Share on other sites

  • Root Admin

In the vast majority of cases a format will 100% remove any threat. However, from years ago there were some special rootkits that infected special areas of the hard drive. We've not seen those types in years now though. In those cases you would need to remove all partitions to make sure you removed the threat.

Cheers

 

Link to post
Share on other sites

  • Root Admin

Glad we could help.

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this topic with your request.

This applies only to the originator of this thread. Other members who need assistance please start your own topic in a new thread.

Please review the following for Tips to help protect from infection

Thank you

 

 

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.