VirusTotal
www.virustotal.com
I ran this exe file thinking it was official, and it produced an admin protected DGLogs folder, with more random folders inside and guge.exe. Worried because these were not in the behaviour but trendmicro and microsoft offline scan says everything is alright, what do I do? I already turned my computer off the internet and just wanted to know will my info and files be okay?
Hi boilingpotatoes, disconnecting the laptop was the right first move, but the clean Trend Micro and Microsoft Offline scans do
not establish that it is safe. Because you executed an untrusted installer and it created protected files with an unfamiliar executable, treat the laptop as potentially compromised and avoid signing in or opening sensitive accounts on it.
Protect your accounts first
From a
different, trusted device:
- Change passwords for important accounts used on the laptop, starting with email, password manager, banking, work and cloud storage.
- Revoke existing sessions and review connected apps/devices. A password change does not always invalidate stolen sessions.
- Enable MFA where available, preferably with an authenticator app or security key.
- Check email recovery details and forwarding/filter rules for unauthorized changes.
- Change any reused passwords as well.
This is precautionary: the information here does not prove credentials were stolen, but waiting for visible account abuse would be a poor gamble if the installer included an information stealer.
Recover files without carrying the infection over
Your ordinary personal files may still be recoverable. Keep the laptop offline and copy only irreplaceable
data, such as photos, videos, plain documents and project source files, to external storage.
Avoid copying executables and other active content, including:
- `.exe`, `.msi`, `.bat`, `.cmd`, `.ps1`, `.scr`, `.dll` and shortcuts
- installers, cracks, archives from unknown sources and the fake installer
- browser profiles, extension folders, cookies or saved-session data
- macro-enabled Office files unless essential and separately reviewed
Do not connect the backup drive to another computer with autoplay enabled or start files directly from it. After rebuilding the laptop, update Windows and your security software first, then scan the backup before restoring it. Documents can also contain malicious content, so open uncertain files cautiously and keep macros disabled.
If files appear encrypted, renamed, corrupted or accompanied by ransom notes, stop rather than modifying them; preserve a copy for specialist assessment.
Safest recovery path
Given that the installer was actually run, the highest-confidence route is to back up selected personal data and perform a
clean Windows installation from trusted Microsoft installation media, deleting the existing Windows partitions during setup. “Reset this PC” is less reassuring than reinstalling from independently created media in this situation.
Do not manually delete `DGLogs`, `guge.exe` or random folders as a substitute for cleanup. Those names alone do not reveal everything the program may have changed, and clean scans can miss an unknown payload, persistence, or activity that already occurred.
For individualized diagnosis before wiping—and particularly if you need help deciding which files are safe to preserve—open a case in MalwareTips’
Malware Removal Assistance area. Leave the machine offline except when following their instructions, and do not run improvised fix scripts. Keep the VirusTotal link and note the approximate execution time, whether an admin/UAC prompt was accepted, and what accounts were used afterward; never post passwords, tokens or license keys.