Seeking Help For Mpc And Safefinder

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by canuck-pc, Jun 5, 2016.

  1. canuck-pc

    canuck-pc Private E-2

    Hi - would appreciate assistance and guidance.

    Similar experience to another message on this forum re a torrent that stated I couldn't view it until a codec update (June 04, 2016).

    • I actioned a program uninstall in safe mode for everything with a June 04 date, however SafeFinder will not uninstall and MPC Cleaner is not listed as a program but is elsewhere.
    • I tried to update Chrome and IE per instructions on other websites.
    • I attempted to delete anything MPC related from C: and message stated wasn't authorized.
    • I attempted a system recovery to May 31st but it didn't complete successfully.

    I ran the FRST64 (thank you for the detailed instructions provided in a different thread).
    Attached are two output txt files.

    Lenovo T400
    Windows 7
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    This PC is very badly infected. You really should have run our full cleaning process before using FRST. We will more than likely still have to run the full cleaning process and/or make a few iterations due to how much malware I see. However let's try to get started using FRST.

    Looking at your installed programs and see if you find any of the below. Uninstall them if found.

    SafeFinder
    Search module
    Setup
    WebOptimum


    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, Win7, 8 or 10, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Download the attached fixlist.txt file found at the bottom of this message and save fixlist.txt on your Desktop. Make sure you save it as a txt file.

    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)

    Then attach the below logs:
    • Fixlog.txt
    • JRT.txt
    Please attach the above two log first before you continue with the below.

    Also at this point, I want to double check your status by having you run another scan with FRSTand attach the new FRST.txt log.
     

    Attached Files:

  3. canuck-pc

    canuck-pc Private E-2

    Thanks for responding - yeah it's really f'd up. Before the reply I did go back and re-read and realized I didn't do all the steps but after I copied one of the recommended downloads (using 2nd laptop) the 2 drive options for USB on the infected laptop were no longer working.
    • In safe mode with networking I managed to install Avira.
    • I also bought Reimage Repair and let that process run overnight.
    Result: SafeFinder and MPC still visible
    • Attempting to uninstall program (SafeFinder would not go away prior two days) and again today.
    • Search Module uninstalled (message triggered that it was already uninstalled)
    • Did not see Setup or Web Optimum.

    Not sure how I can run JRT when my USB drivers are not usable. I'm in safe mode with networking so trying to see if I can find something in Lenovo website.

    EDIT - tried downloaded JRT and it stated it could not find a restore point so I abandoned - should I have kept going?
     
  4. canuck-pc

    canuck-pc Private E-2

    EDIT2 - I did start anyway - how worse could things possibly get...
     
  5. canuck-pc

    canuck-pc Private E-2

    Attaching 3 files (apologies if I did too many steps, I'm sure it must be frustrating when folks don't follow instructions)
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please only do what is requested and nothing else. Installing a protection program like this after the PC is already in bad shape can only serve to make cleanup more difficult. And it may not even be possible to get the antivirus program to run properly. Reimage Repair is something I do not recommend installing let alone running.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds