Bluescreens During Mgtool Scan

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by GuardianAngel671, Feb 12, 2017.

  1. GuardianAngel671

    GuardianAngel671 Private E-2

    It was suggested that I do a malware scan & have my comp checked. I was able to run 4 of the 5 programs. The last 1 -MGTools I keep having issues with. My comp keeps going bluescreen or crashing while it's trying to do it's scan.I tried 3 times & it's done this each time.So I'm not sure I want to risk a 4th. Now I have to figure out why it's bluescreening as that has me worried. My comp has been lagging a lot lately as well. I'll see if I can get the 4 logs that I did manage to get posted.If you can figure out how to do the other & not blue screen I'll retry it.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I suggest you begin by emptying your Recycle Bin. After that run Hitman Pro again and activate the 30 day trial license. Then use it to cleanup all the items it shows under Potential Unwanted Programs

    Reboot immediately after cleaning.

    After reboot, run a new scan with Hitman Pro and save a new log. Then attach this new log.

    Did you knowingly install and did you run Simplitec ?

    I would uninstall it. Registry cleaners are not recommended. Same for performance enhancing tools. Many of these cause more problems in the long run than they cure. They can be the cause of unexpected crashes, reboots, failures of some programs to run, failures of Windows Update.....etc.

    RogueKiller is showing a Proxy server address. Is this something you put in for some program you use? Possibly for a hack to illegal use of Microsoft Office using KMSEmulator ?
     
    Last edited: Feb 12, 2017
    Eldon likes this.
  3. GuardianAngel671

    GuardianAngel671 Private E-2

    Never heard of Simplitec-no idea what it is. Humm & proxy? not that I know of. I use a modem & router for wireless & that's it. I'll have ta see if something was added that I don't know of-could that be what is messing up my Office? It was working fine till a few days ago. My kids sometimes playgames on my comp besides doing schoolwork. Could the gamesites added something?

    ----

    I can't find Simplitec in my program list for uninstalls. Wonder if it has a dif name there? That proxy thing you mentioned-how do I check that or remove it if needed?
     
    Last edited: Feb 12, 2017
  4. GuardianAngel671

    GuardianAngel671 Private E-2

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    KMSEmulator is a hack for MS Office. Is your Office License legal?

    Please complete my previous instructions.
     
  6. GuardianAngel671

    GuardianAngel671 Private E-2

    As far as I know it is. It was a trail version I was trying out to decide if it was better for kids school work than open office. Open Offic4e didn't always show the pages correctly & they sometimes missed things in their homework. I'll do the above directions. I was working on hopefully getting rid of the program you mentioned.
     
  7. GuardianAngel671

    GuardianAngel671 Private E-2

    Ok I hit a glitch -I've never used the Hitman Pro before so I know that I never activated the trial period but it says it's expired? What should I do?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay someone must have installed it and activated it on this PC at some point in time longer than 30 days ago. We will have to perform some manual cleanup steps.

    Did you already empty the Recycle Bin as requested? If not, please do this now.


    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of the code box
    • Make sure that you scroll all the way to the bottom of the code box to get the whole fix!
    Code:
    :Processes
    explorer.exe
    
    :Files
    C:\ProgramData\simplitec
    C:\Users\Owner\AppData\LocalLow\SearchNewTab
    C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\iz715pi7.default\extensions\jid1-yZwVFzbsyfMrqQ@jetpack
    
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\WeatherBugSetup.exe]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4617889D-E8CB-4D06-9E7A-BECCE05030A7}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\DomaIQ10_RASAPI32]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\DomaIQ10_RASMANCS]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\ActiveX Compatibility\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{aad6e119-b8a2-4d59-a8f2-fc1a05c35225}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1B9604EE-B104-45C8-8551-5F63BA631E23}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MimarSinan\InstallAware\Ident.Cache\{1B9604EE-B104-45C8-8551-5F63BA631E23}]
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INNFD_1_10_0_14]
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INNFD_1_10_0_14]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INNFD_1_10_0_14]
    [-HKEY_USERS\S-1-5-21-4134042172-1387618530-866257113-1000\Software\IM]
    [-HKEY_USERS\S-1-5-21-4134042172-1387618530-866257113-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975}]
    [-HKEY_USERS\S-1-5-21-4134042172-1387618530-866257113-1000\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration{7F6AFBF1-E065-4627-A2FD-810366367D01}]
    [-HKEY_USERS\S-1-5-21-4134042172-1387618530-866257113-1000\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration{A1E28287-1A31-4B0F-8D05-AA8C465D3C5A}]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, Win7, 8 or 10, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXT log
    What malware related issues ( if any ) are your currently having?
     
  9. GuardianAngel671

    GuardianAngel671 Private E-2

    Here's the OTM log -now to do next step.
     

    Attached Files:

  10. GuardianAngel671

    GuardianAngel671 Private E-2

    At moment I'm not sure but before it was lagging & freezing up at times. I figured part of it was my slow internet though.
     
  11. GuardianAngel671

    GuardianAngel671 Private E-2

    Here's the JRT log.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay. Looks good now. There weren't really any major malware issues in your logs. Mostly just some junkware.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    3. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. After doing the above, you should work thru the below link:
     
  13. GuardianAngel671

    GuardianAngel671 Private E-2

    Remember I couldn't run the MGtools as it was crashing my comp & bluescreening it. So how do I do this part?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    My last instructions only wanted you to run C:\MGtools\MGclean.bat not the MGtools.exe program that you were running previously. If you don't have the C:\MGtools folder then you can just skip that step.
     
  15. GuardianAngel671

    GuardianAngel671 Private E-2

    Ok thanks. Sorry for delay in answering this. Some reason my email sent the post notice to the junk folder.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds