Microsoft Security Alert Via Web Browser

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Fletch2011, Jun 17, 2018.

  1. Fletch2011

    Fletch2011 Private E-2

    My wife has been getting very frequent hits where her browser gets hijacked when she is browsing websites stating she has a Virus or other malware problem. The website address is not shown but claims to be from Microsoft and usually displays Microsoft Security Alert. There is a recorded message that tells her that her computer is infected and she has to call the toll free number to fix the problem.

    She and I were both running Firefox but she didn't like it and went to Edge, this "attack" has happened to her on both FF and Edge. I have told her not to click on anything when these kind of things appear and to close the web browser using the task manager. I thought it was because she like to read the stories from those add infested clickbait sites from Yahoo so I switched her home page to MSN.com and she still gets them.

    I found a article at bleeping computer that specifically dealt with the removal of this malware and followed all the steps but it keeps coming back.

    A friend suggested I come here and look as your team is the most knowledgeable in malware removal. I searched your forums and didn't see any obvious posts on this problem so I'm starting this one.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Since it is happening in multiple browsers, please follow the instructions at the top of this forum "Read and Run First instructions". Once finished, please attach the logs for us to review. If you both are having this issue, please start a different thread in this forum of the other computer.
     
  3. Fletch2011

    Fletch2011 Private E-2

    Thanks Tim, just her computer, I will get you those reports soon. (and just to clarify, attach using the upload a file button yes)
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes. :)
     
  5. Fletch2011

    Fletch2011 Private E-2

    Ok I ran all the test and here are the text files. The only one that found anything is RogueKiller, but since the instructions said not to remove selected they are still there. I'm assuming that's because you want to look and make sure I'm not deleting a good file?
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have RogueKiller remove this item:
    ¤¤¤ Registry : 3 ¤¤¤
    [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\0287651529114929mcinstcleanup (C:\WINDOWS\TEMP\028765~1.EXE -cleanup -nolog) -> Found

    You didn't let MGTools.exe to run to completion. Run the C:\MGtools\GetLogs.bat file by right clicking and run as admin. Let it finish.
     
  7. Fletch2011

    Fletch2011 Private E-2

    ok, thanks, I ran the one that was on the desktop and thought it was the right one.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It probably was the right one, but since you already ran it, the getlogs bat. is the right one now.
     
  9. Fletch2011

    Fletch2011 Private E-2

    Ok, I hope I got it right this time, and I had RK delete that file.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You again attached the GetUnKey.txt. If you let it run until it tells you it is finished, there will be a MGLogs.zip. That is what you need to attach.
     
  11. Fletch2011

    Fletch2011 Private E-2

    Sorry about that.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download Zemana Malware Removal to your desktop and run it please.

    It auto updates, and you click scan. After it's finished, click on the icon that looks like Cell phone strength bars. High-light the report (by date log was produced) and click on the "Open Report" icon. (looks like a folder). That notepad.txt can then be copied/pasted into another .txt doc and saved. Upload that, please.

    Then Reset Firefox to Defaults
     
  13. Fletch2011

    Fletch2011 Private E-2

    Ok will do, but she's currently using Edge.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Restore Default Settings in Microsoft Edge
    Launch Microsoft Edge and then click the More Actions menu then click Settings.

    reset edge 1
    Scroll down to Clear browsing data then click Choose what to clear.

    By default, Browsing History, Cookies, saved website data, and Cached data files are checked, but you can choose from additional data options in the list. The Show more collapsed menu reveals other options to select.

    To reset the entire browser, check all options, then click Clear.
     
  15. Fletch2011

    Fletch2011 Private E-2

    Zemana attached
     

    Attached Files:

  16. Fletch2011

    Fletch2011 Private E-2

    Browser Cleared
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    How are things running?
     
  18. Fletch2011

    Fletch2011 Private E-2

    So far no redirect or hijacking of the browser, but it still runs very slow. I took it apart already and used the canned air to clean it out plus I ran diagnostics on the memory (the windows one). At this point I'm wondering if her hard drive is failing. Since I just backed up all her documents and pictures if that happens no biggy.

    Thanks for all your help :)
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. If the slowness persists, I suggest you post in the software forum.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Re-enable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 or 10 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds