I pressed the wrong button

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by edbo20, Nov 12, 2012.

  1. edbo20

    edbo20 Corporal

    I thought I was downloading software for a postal scale and I screwed up.

    Can you help with this office computer?

    I cannot connect to Internet Explorer, so I ran some logs of what I could by thumbdrive. I guess I can't run MGTools from a thumbdrive?

    Thank you for your help/
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes this was stated in the instructions. You need to save MGtools to the Windows Boot Driver and run it from there. So copy it from your thumb drive to drive C and then run it.

    You also need to tell us what you malware problem is. "I pressed the wrong button" is not helpful.
     
  3. edbo20

    edbo20 Corporal

    Sorry. Attached is MGlogs
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Shutdown ALL browsers and then uninstall the below programs:
    Ask Toolbar
    My Way Search Assistant
    Viewpoint Media Player

    Now reopen your browser to continue, then run the below.



    Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • JRT.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. edbo20

    edbo20 Corporal

    I was able to remove Viewpoint Media Player.

    I could not find My Way Search Assistant.

    When I tried to remove the Ask Toolbar I recieved a Fatal Error message and it would not complete the removal.

    Should I try to complete the rest, or should I wait for further instruction?

    Thank you for helping me.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Just continue on.
     
  7. edbo20

    edbo20 Corporal

    Attached are the logs. They seemed to run smoothly.

    I went back to try to remove the Ask Toolbar. I rec'd a msg that it could not be found, etc. then disappeared. It doesn't show up any more.

    I still can't find the My Way Search Asst. for some reason.

    I still cannot connect to Internet Explorer.

    Thanks
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They are both still there. We will remove the remaining things below.

    Shutdown McAfee before trying to do the below.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. edbo20

    edbo20 Corporal

    fixme.reg worked. I rec'd the success message.

    attached is mglogs

    still can't connect to internet explorer
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure exactly what you mean by this. Does this mean that Internet Explorer will not even run? Or does it mean that it will run but that you cannot connect to any websites with it? I see network connectivity based on your logs.

    What happens if you shutdown McAfee first ( make sure to shut all of it down including the firewall )?
     
  11. edbo20

    edbo20 Corporal

    Yes, Internet Explorer will not run. The window pops up then closes immediately.

    Unfortunately. I can not shut down the McAfee firewall, or I don't know how. I can shut everything else down but the firewall won't let me.
     
  12. edbo20

    edbo20 Corporal

    I was going to try and uninstall IE8 and went to the programs list. The Ask Toolbar was there. I clicked to remove it and it went away again.

    Didn't know if this helps?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does it do this in Safe Mode with Networking too?

    Can you try installing another browser like Firefox and see if it works? Obviously you will have to get it from another PC.

    I have to wonder about the below 2GB partition on your hard disk.

    Code:
    Partition 3    Unknown           2816 MB    72 GB
     
  14. edbo20

    edbo20 Corporal

    I'm sorry. I'm of minimal help with stuff.

    I uninstalled IE8 to see if that would do anything. It did not. Still will not open.

    I installed Firefox and it worked. I navigated, etc., but there is nothing on the desktop to start Firefox again.

    I can enter Firefox through the c drive by clicking firefox.exe, but it doesn't show in the Start Programs list.

    Also, it does not show in the add/remove programs.

    The Ask Toolbar still shows in the Add/Remove Programs list.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    May not be a malware issue. You have have to work this in the software forum, but try this >> http://support.microsoft.com/fixit/

    Did you install the full version or only the portable version ? Based on you saying it is not in Add/Remove Programs, it sounds like the portable version.

    Was not in the last logs you attached.


    Let's cleanup some more junk.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - (no file)
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
    O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
    O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_1_0 -reboot 1
    O4 - HKUS\S-1-5-18\..\RunOnce: [SSAWrapper] C:\WINDOWS\TEMP\sg_rd.bat (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\RunOnce: [SSAWrapper] C:\WINDOWS\TEMP\sg_rd.bat (User 'Default user')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exeatycoon.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.popcap.com/games/popcaploader_v6.cab

    After clicking Fix, exit HJT.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
     
  16. edbo20

    edbo20 Corporal

    Thanks for your help. I'll look into the software forum after I try the fixit for IE.

    Attached are the logs.

    Do you guys take donations? I can't see where you do? I've bought a couple of things through your website, but can't seem to find a donation screen.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay because my next suggestion since you went back to IE7 now would be to UNINSTALL McAfee and see what happens.

    There are no problems in your logs for us to fix.

    No we don't, but thanks for asking.

    And note that I see Mozilla Firefox 17.0 (x86 en-US) installed.
     
  18. edbo20

    edbo20 Corporal

    Is it possible we missed something?

    I cannot get SSAntispyware installed. Says there is an error in installation
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The only item of question that had remained was this that I mentioned
    Code:
    Partition 3    Unknown           2816 MB    72 GB
    However I doubt it has anything to do with SAS not installing. I would only suggest fixing/removing the above partition as a last resort if real malware problems were occurring. Sometimes removing these partitions winds up in the PC no longer booting.

    You may want to try what is mentioned here >> http://www.superantispyware.com/supportfaqdisplay.html?faq=48
     
  20. edbo20

    edbo20 Corporal

    I used the freeware Tweeking program and it apparently fixed the issue. Internet Explorer is now running.

    Thank you for your help.
     
    Last edited: Nov 24, 2012
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Glad to hear you have it fixed.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds