last night i got a couple dozen popups telling me there was a "delayed read error" or something. Then a popup telling my my hard drive was broke- asked me to scan and fix. before this I was receiving messages about "googleupdate.exe" or something like that. Whatever infected me logged me off and restarted the computer.
1. I unplugged the network cable and I immediately came here (using another computer) and downloaded iExplore.exe to "stop the processes".
2. Popups disappeared, scan and fix dialog disappeared.
3. Next, I ran tdsskiller it reported it found one thing (Locked File (Service: sptd) default action presented to me was "skip" per the TDSSKiller instructions I hit "continue" keeping "Skip" selected.
4. I installed malwarebytes from a flash drive. because i was unplugged from the network i couldnt update the database
5. when I restarted the same behavior (popups, scan and fix) but no logoff and no mention of googleupdate
6. ran unhide
6. Repeated steps 1-3 ran Malwarebytes again. This time only reported Registry entries.
7. I removed them.
8. Restarted. Same behavior.
9. BECAUSE I DID NOT READ INSTRUCTIONS CAREFULLY I then installed and ran ComboFix but did not do anything other than let it generate a log.
10. Realized that I should update my Malwarebytes and so plugged in the network cable again.
11. updated Malwarebytes.
12. Noticed that I now no longer get the popups or system scan message
13. However, in my notification tray I have a little flag with an X that says: "Solve PC Issues: 1 important message 6 total messages" when I mouse over.
14. If I right-click the task bar and select Properties > Notification Area > Customize Button In the list of Icons there is a file called "Action Center" (the little flag with the X) vMttfGqwlJXmmgo.exe with a USB icon next to it (that looks like malware) and three instances of "proxycheck.exe".
While things seem to be running fine, I'm convinced that by running ComboFix, I half-fixed something. I have since downloaded DDS and created a log. I also have all the logs generated through the above process.
What do you think? Am I doomed?
Thank you for reading this!
If anyone knows how I might go about fixing this, I of course am grateful.