Win10: Mpgear.dll Error At Startup

Discussion in 'Malware Help (A Specialist Will Reply)' started by SlipperyPete, Feb 5, 2024.

  1. SlipperyPete

    SlipperyPete Private E-2

    The computer seems to be running OK but a few weeks ago I got an error on startup that says:

    "The code execution cannot proceed because MpGear.dll was not found. Reinstalling the program may fix this problem."

    I initially started a thread in the software section noting the steps I've taken so far, but I was unable to get the problem fixed. That thread is here:

    https://forums.majorgeeks.com/threads/win10-mpgear-dll-missing-error-at-startup.325562

    And it was suggested that malware could be possible. Here's logs from ADWCleaner, Rogue Killer, Hitman Pro, Malwarebytes, and MGTools.

    Thanks!
     

    Attached Files:

  2. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings and welcome to the Major Geeks Malware Forum.

    While I review what you have posted please do this.

    ===================================================

    Farbar Recovery Scan Tool (FRST)

    --------------------
    • Download Farbar Recover Scan Tool for 64 bit systems and save(or copy and paste) the file onto your Desktop
    • Right click on the icon and select Run as administrator
    • Note: If you receive any warning about the download it is a false positive and you can ignore it. Click on More info to get the Run anyway option
    • Click Yes to the disclaimer
    • Click Scan and allow the program to run
    • Click OK on the Scan complete screen, then OK on the Addition.txt pop up screen
    • 2 Notepad documents should now be open on your desktop.
    • Please attempt to copy and paste each report in a separate reply. If unable to do so attach both reports.
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:

    • FRST.txt
    • Addition.txt
     
  3. SlipperyPete

    SlipperyPete Private E-2

    Here you go.
     

    Attached Files:

  4. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you for the information. This appears to be a system corruption issue.

    Shockwave Player is a security vulnerability so I would like to remove it.

    Please do this.

    ===================================================

    Uninstalling Programs Using Revo Uninstaller Free Portable

    --------------------

    • Download Revo Uninstaller Free Portable and save it to your Desktop
    • Right click on the folder and select Extract All..., then click Extract
    • Double click on the RevoUninstaller-Portable folder
    • Right click on RevoUPort and select Run as administrator
    • Click OK on the License Agreement
    • From the list of programs double click on the listed program(s), or anything similar, to remove it (if it exists)
    Code:
    Adobe Shockwave Player 12.3
    
    • If the program's uninstaller appears work through the steps to remove the program(s)
    • Be sure the Advanced option is selected then click Scan
    • For each window that may appear identifying leftover items click Select All, Delete, then confirm the deletion
    • Once done click Finish
    • Reboot your computer

    ===================================================

    Farbar Recovery Scan Tool - Run Fix Using Attached File

    --------------------
    • Download the attached file and save it in the same location as FRST.exe (example, Desktop, USB device) <<< Important
    • Right click on FRST and select Run as administrator
    • Click Fix and once completed your computer will reboot
    • The tool will create a log on the desktop called Fixlog.txt
    • Attach the file to your reply

    ===================================================

    Farbar Recovery Scan Tool SearchAll

    --------------------
    • Right click on FRST and select Run as administrator
    • Copy/paste the following in the Search: box
    Code:
    SearchAll: MpGear.dll
    
    • Click Search Files button
    • When completed click OK and a Search.txt document will open on your desktop
    • Attach the file to your reply
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Shockwave Player removed?
    • Attached Fixlog
    • Download link
    • Search.txt
     

    Attached Files:

    Last edited: Feb 6, 2024
  5. SlipperyPete

    SlipperyPete Private E-2

    Shockwave is removed.
     

    Attached Files:

  6. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you.

    Please do this.

    ===================================================

    Farbar Recovery Scan Tool Fix

    --------------------
    • Right click on the FRST64 icon and select Run as administrator
    • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
    • There is no need to paste the information anywhere, FRST64 will do it for you
    Code:
    Start::
    ExportKey: HKLM\SOFTWARE\Microsoft\ Windows Advanced Threat Protection
    Powershell: Set-ExecutionPolicy Unrestricted
    Powershell: Get-AppxPackage Microsoft.SecHealthUI -AllUsers | Reset-AppxPackage
    End::
    
    • Click Fix
    • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Fixlog
     
  7. SlipperyPete

    SlipperyPete Private E-2

    Here you go.

    Fix result of Farbar Recovery Scan Tool (x64) Version: 03.02.2024 01
    Ran by PC (07-02-2024 11:09:48) Run:2
    Running from C:\Users\PC\Desktop
    Loaded Profiles: PC & _ashbackuppb_ & MSSQL$MYMOVIES
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    Start::
    ExportKey: HKLM\SOFTWARE\Microsoft\ Windows Advanced Threat Protection
    Powershell: Set-ExecutionPolicy Unrestricted
    Powershell: Get-AppxPackage Microsoft.SecHealthUI -AllUsers | Reset-AppxPackage
    End::
    *****************

    ================== ExportKey: ===================

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ Windows Advanced Threat Protection]
    "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ Windows Advanced Threat Protection" => not found

    ========= Set-ExecutionPolicy Unrestricted =========

    Set-ExecutionPolicy : Windows PowerShell updated your execution policy successfully, but the setting is overridden by
    a policy defined at a more specific scope. Due to the override, your shell will retain its current effective
    execution policy of Bypass. Type "Get-ExecutionPolicy -List" to view your execution policy settings. For more
    information please see "Get-Help Set-ExecutionPolicy".
    At C:\FRST\tmp.ps1:1 char:1
    + Set-ExecutionPolicy Unrestricted
    + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo : PermissionDenied: :)) [Set-ExecutionPolicy], SecurityException
    + FullyQualifiedErrorId : ExecutionPolicyOverride,Microsoft.PowerShell.Commands.SetExecutionPolicyCommand

    ========= End of Powershell: =========


    ========= Get-AppxPackage Microsoft.SecHealthUI -AllUsers | Reset-AppxPackage =========

    Reset-AppxPackage : The term 'Reset-AppxPackage' is not recognized as the name of a cmdlet, function, script file, or
    operable program. Check the spelling of the name, or if a path was included, verify that the path is correct and try
    again.
    At C:\FRST\tmp.ps1:1 char:51
    + Get-AppxPackage Microsoft.SecHealthUI -AllUsers | Reset-AppxPackage
    + ~~~~~~~~~~~~~~~~~
    + CategoryInfo : ObjectNotFound: (Reset-AppxPackage:String) [], CommandNotFoundException
    + FullyQualifiedErrorId : CommandNotFoundException


    ========= End of Powershell: =========


    ==== End of Fixlog 11:10:00 ====
     

    Attached Files:

    Last edited by a moderator: Feb 7, 2024
  8. Oh My!

    Oh My! Malware Expert Staff Member

    That wasn't helpful, please do this.

    ===================================================

    Autoruns

    --------------------
    • Please download Autoruns and save it to your Desktop
    • Right click on the autoruns64 icon on your Desktop and select Run as administrator
    • Wait until the lower left hand corner of the window shows Ready
    • Hit the Ctrl + S key at the same time
    • Save the file onto your Desktop using the default File name:
    • Please zip and attach the file to your reply
    ===================================================

    Process Monitor Boot Log

    --------------------
    • Download Process Monitor and save it to your Desktop
    • Right click on Procmon and select Run as administrator
    • Agree to any permission requests
    • Hit Ctrl + E to stop capturing events
    • Hit Ctrl + X at the same time to clear the display
    • Click Options then Enable Boot Logging
    • Place a check mark in Generate thread profiling events
    • Click OK
    • Close Process Monitor
    • Close any open programs and shut down your computer
    • Start your computer and allow the boot up process to complete, including logging in if you use a password
    • Wait 15 minutes before doing anything further
    • Right click on Process Monitor and select Run as administrator
    • Click Yes on the next window that appears and save the boot-time activity log onto your desktop using the default name
    • Please zip and upload the file to GoFile or the file hosting site of your choice and send me a Personal Message with the download link
    ===================================================

    Things I would like to see in your next reply.
    • Attached autoruns zip file
    • Download link via Personal Message
     
  9. SlipperyPete

    SlipperyPete Private E-2

    I have the Autoruns log but I've run the Process Monitor instructions 3 times now and after shutting down, rebooting, and waiting the 15 minutes, nothing ever comes up about saving the boot activity log after I open the program again. Each time it starts just like it did the first time I opened it, without any prompts to do anything.

    I can manually click File and Save and it'll save a log, but I don't know if doing it that way gives you the info you're looking for.
     

    Attached Files:

  10. Oh My!

    Oh My! Malware Expert Staff Member

    Thanks for the extra effort. Let's see of we can manage without the Bootlog.

    Please do these things.

    ===================================================

    Farbar Recovery Scan Tool Fix

    --------------------
    • Right click on the FRST64 icon and select Run as administrator
    • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
    • There is no need to paste the information anywhere, FRST64 will do it for you
    Code:
    Start::
    File: C:\Users\PC\AppData\Roaming\pPNwqdKXV52U1X7\SenseCE.exe
    Folder: C:\Users\PC\AppData\Roaming\pPNwqdKXV52U1X7
    End::
    
    • Click Fix
    • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
    ===================================================

    Farbar Recovery Scan Tool Search

    --------------------
    • Launch FRST
    • Type the following in the Search: box
    Code:
    SenseCE.exe;MsSense.exe
    
    • Click Search Files button
    • When completed click OK and a Search.txt document will open on your desktop
    • Copy and paste the contents of that document your reply
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Fixlog
    • Search.txt
     
  11. SlipperyPete

    SlipperyPete Private E-2

    Fixlog:

    Fix result of Farbar Recovery Scan Tool (x64) Version: 03.02.2024 01
    Ran by PC (08-02-2024 09:43:15) Run:3
    Running from C:\Users\PC\Desktop
    Loaded Profiles: PC & _ashbackuppb_ & MSSQL$MYMOVIES
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    Start::
    File: C:\Users\PC\AppData\Roaming\pPNwqdKXV52U1X7\SenseCE.exe
    Folder: C:\Users\PC\AppData\Roaming\pPNwqdKXV52U1X7
    End::
    *****************


    ========================= File: C:\Users\PC\AppData\Roaming\pPNwqdKXV52U1X7\SenseCE.exe ========================

    C:\Users\PC\AppData\Roaming\pPNwqdKXV52U1X7\SenseCE.exe
    File not signed
    MD5: 8F0717916432E1E4F3313C8EBDE55210
    Creation and modification date: 2023-09-11 00:07 - 2023-09-08 18:48
    Size: 001719808
    Attributes: ----A
    Company Name: Microsoft Corporation
    Internal Name: SenseCE.exe
    Original Name: SenseCE.exe
    Product: Microsoft® Windows® Operating System
    Description: Windows Defender Advanced Threat Protection Sense CE module
    File Version: 10.8471.17763.4377 (WinBuild.160101.0800)
    Product Version: 10.8471.17763.4377
    Copyright: © Microsoft Corporation. All rights reserved.
    VirusTotal: https://www.virustotal.com/gui/file...e283b67408fc9ee187216a0ce80ee61bab-1699875540

    ====== End of File: ======


    ========================= Folder: C:\Users\PC\AppData\Roaming\pPNwqdKXV52U1X7 ========================

    2023-09-11 00:07 - 2023-09-08 18:48 - 000831307 ____A [CCA35CDA7FB238F7E48C3CF0234E48B1] () C:\Users\PC\AppData\Roaming\pPNwqdKXV52U1X7\premed.mkv
    2023-09-11 00:07 - 2023-09-08 18:48 - 001719808 ____A [8F0717916432E1E4F3313C8EBDE55210] (Microsoft Corporation) [File not signed] C:\Users\PC\AppData\Roaming\pPNwqdKXV52U1X7\SenseCE.exe

    ====== End of Folder: ======


    ==== End of Fixlog 09:43:16 ====

    Search:

    Farbar Recovery Scan Tool (x64) Version: 03.02.2024 01
    Ran by PC (08-02-2024 09:46:49)
    Running from C:\Users\PC\Desktop
    Boot Mode: Normal

    ================== Search Files: "SenseCE.exe;MsSense.exe" =============

    C:\Windows\WinSxS\amd64_windows-senseclient-service_31bf3856ad364e35_10.0.19041.3758_none_1cb356e9448fc18d\MsSense.exe
    [2023-12-15 05:35][2023-12-15 05:35] 000534472 _____ (Microsoft Corporation) BED9ADC0FED70B10BFAEB59853933AF6 [File is digitally signed]

    C:\Windows\WinSxS\amd64_windows-senseclient-service_31bf3856ad364e35_10.0.19041.3758_none_1cb356e9448fc18d\SenseCE.exe
    [2023-12-15 05:35][2023-12-15 05:35] 002031616 _____ (Microsoft Corporation) DFE6E26A8D3F6BCCE410E4F999FD3214 [File is digitally signed]

    C:\Windows\WinSxS\amd64_windows-senseclient-service_31bf3856ad364e35_10.0.19041.3758_none_1cb356e9448fc18d\r\MsSense.exe
    [2023-12-15 05:30][2023-12-03 13:19] 001472455 _____ () CB9D0D27294074675FF7C12E9417E750 [File not signed]

    C:\Windows\WinSxS\amd64_windows-senseclient-service_31bf3856ad364e35_10.0.19041.3758_none_1cb356e9448fc18d\r\SenseCE.exe
    [2023-12-15 05:31][2023-12-03 13:19] 000104053 _____ () 357EE6B532B44CB10066DFC5E22176C3 [File not signed]

    C:\Windows\WinSxS\amd64_windows-senseclient-service_31bf3856ad364e35_10.0.19041.3758_none_1cb356e9448fc18d\f\MsSense.exe
    [2023-12-15 05:30][2023-12-03 13:19] 000160353 _____ () 1377270EEAE0DEDDFEE93A0ABA6F03F0 [File not signed]

    C:\Windows\WinSxS\amd64_windows-senseclient-service_31bf3856ad364e35_10.0.19041.3758_none_1cb356e9448fc18d\f\SenseCE.exe
    [2023-12-15 05:31][2023-12-03 13:19] 000300619 _____ () 00A9F8FA86E631D3BA4594BF980B2EE9 [File not signed]

    C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3930.1.7\amd64_windows-senseclient-service_31bf3856ad364e35_10.0.19041.3758_none_1cb356e9448fc18d\r\mssense.exe
    [2024-01-11 19:01][2024-01-04 00:33] 001472455 ____N () CB9D0D27294074675FF7C12E9417E750 [File not signed]

    C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3930.1.7\amd64_windows-senseclient-service_31bf3856ad364e35_10.0.19041.3758_none_1cb356e9448fc18d\r\sensece.exe
    [2024-01-11 19:01][2024-01-04 00:33] 000104053 ____N () 357EE6B532B44CB10066DFC5E22176C3 [File not signed]

    C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3930.1.7\amd64_windows-senseclient-service_31bf3856ad364e35_10.0.19041.3758_none_1cb356e9448fc18d\f\mssense.exe
    [2024-01-11 19:01][2024-01-04 00:31] 000160353 ____N () 456CF26594052683D5559687BC723275 [File not signed]

    C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3930.1.7\amd64_windows-senseclient-service_31bf3856ad364e35_10.0.19041.3758_none_1cb356e9448fc18d\f\sensece.exe
    [2024-01-11 19:01][2024-01-04 00:31] 000300619 ____N () E12237AB16FA68199750B3727007A324 [File not signed]

    C:\Users\PC\AppData\Roaming\pPNwqdKXV52U1X7\SenseCE.exe
    [2023-09-11 00:07][2023-09-08 18:48] 001719808 _____ (Microsoft Corporation) 8F0717916432E1E4F3313C8EBDE55210 [File not signed]

    C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe
    [2023-12-15 05:35][2023-12-15 05:35] 000534472 _____ (Microsoft Corporation) BED9ADC0FED70B10BFAEB59853933AF6 [File is digitally signed]

    C:\Program Files\Windows Defender Advanced Threat Protection\Classification\SenseCE.exe
    [2023-12-15 05:35][2023-12-15 05:35] 002031616 _____ (Microsoft Corporation) DFE6E26A8D3F6BCCE410E4F999FD3214 [File is digitally signed]


    ====== End of Search ======
     
  12. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you.

    Please do this.

    ===================================================

    Farbar Recovery Scan Tool Fix

    --------------------
    • Right click on the FRST64 icon and select Run as administrator
    • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
    • There is no need to paste the information anywhere, FRST64 will do it for you
    Code:
    Start::
    SystemRestore: On
    CreateRestorePoint:
    CloseProcesses:
    Zip: C:\Users\PC\AppData\Roaming\pPNwqdKXV52U1X7\premed.mkv
    C:\Users\PC\AppData\Roaming\pPNwqdKXV52U1X7
    C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\browseui.lnk					
    End::
    
    • Click Fix
    • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply
    • The tool will create a zipped folder in the same location from where FRST was run with today's date, example: 07.30.2023_13.24.50.zip. Please upload the file to my BleepingComputer Channel here
    • Upon automatic reboot check for the MpGear.dll error
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Fixlog
    • Uploaded zip file
    • Error?
     
    Last edited: Feb 8, 2024
  13. SlipperyPete

    SlipperyPete Private E-2

    No error!

    Got the Fixlog but there was no zip file with it.

    Fixlog:

    Fix result of Farbar Recovery Scan Tool (x64) Version: 03.02.2024 01
    Ran by PC (08-02-2024 20:14:36) Run:4
    Running from C:\Users\PC\Desktop
    Loaded Profiles: PC & _ashbackuppb_ & MSSQL$MYMOVIES
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    Start::
    SystemRestore: On
    CreateRestorePoint:
    CloseProcesses:
    C:\Users\PC\AppData\Roaming\pPNwqdKXV52U1X7
    C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\browseui.lnk
    End::
    *****************

    SystemRestore: On => Error -> 9%
    Restore point was successfully created.
    Processes closed successfully.

    "C:\Users\PC\AppData\Roaming\pPNwqdKXV52U1X7" folder move:

    C:\Users\PC\AppData\Roaming\pPNwqdKXV52U1X7 => moved successfully
    C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\browseui.lnk => moved successfully


    The system needed a reboot.

    ==== End of Fixlog 20:14:54 ====
     
    Last edited: Feb 8, 2024
  14. Oh My!

    Oh My! Malware Expert Staff Member

    Great.

    Please do this.

    ===================================================

    Farbar Recovery Scan Tool Fix

    --------------------
    • Right click on the FRST64 icon and select Run as administrator
    • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
    • There is no need to paste the information anywhere, FRST64 will do it for you
    Code:
    Start::
    Zip: C:\FRST\Quarantine\C\Users\PC\AppData\Roaming\pPNwqdKXV52U1X7\premed.mkv.xBAD
    Reboot:
    End::
    
    • Click Fix
    • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
    • The tool will create a zipped folder in the same location from where FRST was run with today's date, example: 07.30.2023_13.24.50.zip. Upload it to the file hosting site of your choice and send me a Personal Message with the download link Do not post the link on this topic.
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Fixlog
    • Download link via PM
     
  15. SlipperyPete

    SlipperyPete Private E-2

    No zip file again.

    Fixlog:

    Fix result of Farbar Recovery Scan Tool (x64) Version: 03.02.2024 01
    Ran by PC (08-02-2024 22:16:57) Run:5
    Running from C:\Users\PC\Desktop
    Loaded Profiles: PC & _ashbackuppb_ & MSSQL$MYMOVIES
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    Start::
    Zip: C:\FRST\Quarantine\C\Users\PC\AppData\Roaming\pPNwqdKXV52U1X7\premed.mkv.xBAD
    Reboot:
    End::
    *****************

    ================== Zip: ===================
    "C:\FRST\Quarantine\C\Users\PC\AppData\Roaming\pPNwqdKXV52U1X7\premed.mkv.xBAD" => not found
    =========== Zip: End ===========


    The system needed a reboot.

    ==== End of Fixlog 22:16:58 ====
     
  16. Oh My!

    Oh My! Malware Expert Staff Member

    Can you manually look to see if that file exists?
     
  17. SlipperyPete

    SlipperyPete Private E-2

    There is no file ending in .mkv.xBAD. There is the one just ending in .mkv.
     
  18. Oh My!

    Oh My! Malware Expert Staff Member

    Hmmm. Can you zip that, upload it to a web hosting site then send me a PM with the download link?
     
  19. SlipperyPete

    SlipperyPete Private E-2

    Link sent.
     
  20. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you, I am evaluating it now.
     
  21. Oh My!

    Oh My! Malware Expert Staff Member

    Thanks for your patience.

    My testing concluded the premed.mkv was malicious. A few Virustotal vendors flagged it and ESET Online Scanner detected it as well on my computer.

    Let's run ESET. Please do this.

    ===================================================

    ESET Online Scanner

    --------------------

    Note: You can expect this process to take a long time, up to several hours or more.
    • Download ESET Free Online Scanner and save it to your Desktop
    • Right click on esetonlinescanner_enu.exe and select Run as administrator
    • NOTE: If the program immediately crashes rename esetonlinescanner_enu.exe to ESET.exe and attempt it again
    • Click Computer Scan
    • Click Full scan
    • Select Enable ESET to detect and quarantine potentially unwanted applications
    • Click Start scan
    • Once completed click View detailed results
    • Review the list of detected items for things you don't want to remove (sometimes Potentially Unwanted Applications)
    • If there entries you would like to keep click Restore cleaned files
    • Place a check mark in each entry you would like to restore then click Restore files then confirm the action
    • Click Finish
    • Save scan log and save it to your Desktop as ESETScan.txt
    • Click Continue then finally click Close
    • Copy and paste the ESETScan.txt file contents in your reply
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
    • ESET report
     
  22. SlipperyPete

    SlipperyPete Private E-2

    The scan moved onto unrelated drives that would have taken forever to finish, so I stopped it early. Will run it fully if needed though.

    2/9/2024 21:17:46 PM
    Files scanned: 1036696
    Detected files: 4
    Cleaned files: 4
    Total scan time 05:03:53
    Scan status: Stopped by user
    C:\FRST\Quarantine\C\Users\PC\AppData\Roaming\pPNwqdKXV52U1X7\premed.mkv probably a variant of Win32/TrojanDownloader.Rugmi.AAO trojan cleaned by deleting

    C:\MGtools\mgtproc.exe Win32/PrcView potentially unsafe application cleaned by deleting

    C:\Program Files\DAEMON Tools Lite\uninst.exe a variant of Win32/Yandex.K potentially unwanted application cleaned by deleting

    C:\MGtools.exe a variant of Generik.EYRBKTT trojan cleaned by deleting
     
  23. Oh My!

    Oh My! Malware Expert Staff Member

    No need.

    Things look good. Are there any remaining questions or concerns you might have before I post some tool/log clean up instructions and other information for you to consider going forward?
     
  24. SlipperyPete

    SlipperyPete Private E-2

    Nope, I'm good.
     
  25. Oh My!

    Oh My! Malware Expert Staff Member

    Very good.

    Here is our final step and some additional information to consider.

    ===================================================

    KpRm by Kernel-panik

    --------------
    • Download KpRm and save it to your Desktop (see here if you must use Chrome)
    • Note: If the file is detected as malware it is not and it is safe to download. The detection is a false positive.
    • Right click on the icon and select Run as administrator
    • Click Yes on the Disclaimer
    • Place a check mark in Delete Tools, Create Restore Point, and Delete in 7 days
    • Click Run
    • Click OK on All operations are completed
    • KpRm will delete itself from you Desktop and you can either save or remove the report that is generated
    • You are free to remove any other tools/reports still remaining
    ===================================================

    All Clean!

    --------------

    Your computer is now clean. Please consider this going forward.

    ===================================================

    Please take the time to read below on how to secure the machine and take the necessary steps to keep it clean.

    Thank you for placing your trust in Major Geeks. It was a pleasure serving you.
     
  26. SlipperyPete

    SlipperyPete Private E-2

    Thanks a ton for helping me get this solved. I greatly appreciate it.
     
  27. Oh My!

    Oh My! Malware Expert Staff Member

    Always my pleasure, my friend.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds