Cannot Remove This Virus "safe Browser" - Mglogs.txt Enclosed

Discussion in 'Malware Help (A Specialist Will Reply)' started by lensman19067, Nov 25, 2015.

  1. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes those batch files are for Intel and are nothing to worry about.

    Let's run another fix with FRST.

    Download the attached fixlist.txt file found at the bottom of this message and save fixlist.txt on your Desktop. Make sure you save it as a txt file.

    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • Fixlog.txt
    • C:\MGlogs.zip
    How are things working?
     

    Attached Files:

  2. lensman19067

    lensman19067 Private E-2

    Hi chaslang,

    Everything done as per directions (I disabled the wireless driver and then re-enabled it after reboot, wow does that make Windows unhappy). The reboot went cleanly - no black screen and logging in twice.

    Other than the quarantined files, everything bad appears to be gone. No new Akick, Browser Data, Win Events, Safe Browsing, Safe_Browsing files/directories on the PC. There are a lot of leftover programs to kill that infection that I'll leave alone.

    There are curious (i.e. odd, unexpected) data gone (aside from browsers). None of the Angry Birds work any longer, they all say some program from Intel is needed but it's no longer available. My database of blood glucose readings is completely gone - it's as though the management program was freshly installed. I may have that backed up on Carbonite.

    It looks like you've succeeded! Thank you very much!

    dan davison
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Well we did not delete any of this. You can see everything we remove in the FRST and OTM quarantine folders on your hard disk. And you can see a list of the items removed in the newfiles.txt log in the C:\MGtools folder. See the contents of the C:\FRST and C:\_OTM folders there. Before we run final instructions to remove everything we put on your PC during the clean which would also remove these quarantine folders, you can look thru them for any signs of your missing data.
     
  4. lensman19067

    lensman19067 Private E-2

    Hi chaslang,

    Sorry if it sounded like I deleted them in this process, I just assumed the virus did the removal, and I haven't looked for those files until now. I should also mention that the virus deleted my iTunes library and playlists right at the beginning of the infection. I had the music backed up, but playlists are gone. Actually, I have them in the iTunes.itl file, they're just encoded somehow, so they're gone.

    The Angry Birds problem turns out to be a known problem since Intel closed its online store. If one loses those executables, everything from the Intel store stops working, and there's no workaround.

    I can deal with the endocrinologist's upcoming unhappiness. He'll get over it.

    I will take a quick look at the quarantine directories just in case something turns out to be there.

    thanks very much,
    dan
     
  5. lensman19067

    lensman19067 Private E-2

    Hi chaslang,

    Thanks again. The diabetes SQLite DB file is not in any of the quarantine directories. All is well, so we can proceed as you wish at your convenience.

    thanks,
    dan
    p.s. I've gone into heart failure (lots of edema, short of breath) for no obvious reason so it's *remotely* possible the cardiologist will whup me into the hospital tomorrow late afternoon or evening. I'll send a note if that is going to happen.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hope all goes well Dan!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    8. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • For Windows 8 and 8.1 system restore see this link: Win 8 System Restore - How to enable/disable
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  7. lensman19067

    lensman19067 Private E-2

    Hi chaslang,

    I did all of the above except the restore points, as I'm running Windows 10 and the directions were for 8,7, Vista, XP, or ME.

    Should I have done the system restore instructions even though I'm running Windows 10?

    I will be running Avast Pro, Malwarebytes Pro, Windows Firewall, and Hitman Pro.

    dan davison
    p.s. If I go outside and look east I can see the dome of the NJ State Capitol. I'm about a mile from the Delaware, on the PA side.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  9. lensman19067

    lensman19067 Private E-2

    Hi chaslang,

    Thanks for the update. I've restarted system updates. While I was at the clinic the machine updated windows 10 to a different version - Window 0 version 1511 OS build 10586.29 It took a long time to install, -a couple hours - but everything appears OK.
    Avast Antivirus Pro installed & activated
    Avast Internet Security installed, VPN turned on
    Malwarebytes Pro installed, updated
    Reinstalled FireFox and extensions for protection

    Thanks!
    dan​
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds