Malware disabled Task Manager, Safe Mode, and wants us to buy AV!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by 45-70BFR, Aug 27, 2009.

  1. 45-70BFR

    45-70BFR Private E-2

    My wife's computer had a Trojan and other things that were messing it up. I thought I got them out but they seem to be back, or she got new ones that are similar. First one seemed to be from a program called "Protection Systems" that may have come from "My Web Search", which may have come with "Gamevance32". Protection Systems was trying to convince us we had many viruses and we should download their program (and pay to activate it) to clean these up. It used windows that looked remarkably like real Windows, but there was no mention of Microsoft or any copyright info at all. It also kept saying I had no AV software. Well, I used my Norton and Comcast Anti-Spyware, that I didn't have, to remove them. My Web Search was automatically blocking any attempt to change my default web search engine. Gamevance32 was making over 900K changes in my computer on each Startup (according to my Norton History). Something also disabled the Task Manager via Administrator, and also has disabled the Safe Mode Startup.
    Things were good for several days, but last night a new set started. A program called "Personal Anti-Virus" also trying to get us to buy it so it could clean out stuff it said we had. It had installed itself in the C:/Programs/ directory without Windows knowing about it. And added itself to the Startup list in MSCONFIG. I disabled the Startup and rebooted. Then I was able to delete the program. However, my Norton keeps telling me that Hacktool tries to run on each Startup, and tells me the file name, and Blocks or Removes it each time, but when I look in the File Manager where it says it is located, there is nothing there I can see. The file it names is not listed. I am the Administrator and all files are supposed to be visible. So obviously I have not found all of the problem children. My wife does a lot of downloads of simple games, you play for an hour and then it is done and you go find another one. If you really like one, you can download the full version and buy it. I think these might be coming in on one of these game suppliers, like Gamevance32. I'm thinking another one might be "IWon.com". Do you have any direct knowledge of these? In looking up the Safe Mode problem I came upon your forum for "Malware changed my Login's, Disabled AntiVirus & Windows Safe Mode. Please help!". Your response seemed to be what I may need also. I really don't want to re-format my C Drive. It would take three solid days to reload every program and document, if I can find all the original CD!
     
  2. 45-70BFR

    45-70BFR Private E-2

    This computer is now infected with Police Pro and nothing is allowed to work. None of the applications in the computer work except Police Pro, Internet Explorer, and Flock. All anti-virus, anti-spyware, downloaded fix programs (FindyKill) are blocked and will not run. Neither will the Run First stuff. No Regedit, no Msconfig, no Task Manager, no Safe Mode, etc.... So where can I go from here? I can download anything, but as soon as I click "Run", it is blocked. A window pops up from the toolbar saying this file is infected and cannot run. I am sending this from my computer. These seem to be popping up every three days.
     
    Last edited: Aug 30, 2009
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Did you actually try to run MGtools as requested? If almost always runs and helps to get us started.




    If you cannot run anything, not even MGtools in normal boot mode nor in safe boot and cannot give us any logs, then there is not much we can do for you except say the below:
     
  4. 45-70BFR

    45-70BFR Private E-2

    Thanks for responding Chaslang. Sorry, haven't tried MGTools yet. I didn't see the stuff about Read First until after I had already posted. May I suggest you folks use a verification email so new people have to read the email before they are allowed to post? Anyway, the last couple of days we have been preparing for vacation. We will be back 9/14 and I will start the Read First process on the 15th, documenting exactly what works and what doesn't. I have already printed about 60 pages of all the procedures. I have also asked the SAS people if that program can be downloaded to, installed on, and run from a write once CD, but I have had no response yet. I have a feeling I am going to wind up doing the suggestion you listed below. By the way, I forgot to mention this machine is a desktop running Windows XP Media Center Edition w/SP2. I have seen a lot of references to XP Home and XP Pro in various procedure listings (My new laptop is using XP Pro w/SP3). Would the procedures listed for XP Pro be basically the same as for XP Media Center?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We used to have one and that changed but the email sent to you when signing up does have the links to the procedures.

    No! It needs to be installed on the PC that you wish to use it on like most programs.

    All procedures are the basically the same for all versions of Windows XP unless specifically indicated in the procedure. Major exceptions are for 64 bit versions of Windows where many tools do not run at all.
     
  6. 45-70BFR

    45-70BFR Private E-2

    OK, I just started up the infected computer, but I didn't get far. I was going to try the MGTools and send you the log, but below is what happened. When I had been on this computer previously it had been locking up all applications from starting. I had Re-Started as Administrator and tried to run my Norton Internet Security 2008 (latest at the time bought) but it locked up after a few seconds of trying to bring up its History file. Scan would not run. I was able to open Internet Explorer and start my online Comcast.net Anti-Spyware and start a Full Scan. It immediately Quarantined 7 files and then froze. I was able to close it but when I re-opened it and tried to scan again it kept saying Scan was already running. I had Cancelled the Scan but it would not clear itself. At that point I tried to download and run SAS because it was listed before MGTools on the list of programs to download and Run. SAS downloaded successfully and appeared to install successfully, but when I tried to Run it, it failed with the Error window I had mentioned previously. I shut down the computer to await the time I could get all the instructions from Run First together and try it all. Today I started:

    *Started up as Administrator.
    *As several Error Windows were popping up, Police Pro Main Window appeared. As I started to disclaim "Aw, $%&*", it disappeared.
    *Error Windows continued to appear, total 34, all for .exe files.
    *Had to Click each OK button 3 times to clear each window. Clicked button, window popped off and popped back on. Repeat twice more before window did not return.
    *Most of Startup Toolbar icons appeared, including Norton. Opened Norton.
    *Got Error Window for Norton. Clicked it twice and then Norton opened anyway.
    *Opened Norton History. It opened with only two lines, neither Malware.
    *Tried Quick Scan, would not Run.
    *Tried Full Scan, would not Run.
    *Closed Norton.
    *Opened Internet Explorer to try Comcast.net Anti-Spyware and download MGTools. Got three Error windows but it opened anyway.
    *Ran Quick Scan on Anti-Spyware. It quarantined 46 files and completed its scan (I think when it quarantined the previous 7 files it disabled enough of Police Pro to be able to get the rest this time.)
    *I closed Anti-Spyware and went to Majorgeeks.com.
    *I was about to go to MGTools Download when Norton popped up a window that it had just quarantined tr(something).backdoor and that Norton needed to Restart the computer to finish fixing this problem.
    *I closed IE and clicked on OK for Norton to Restart.
    *During Restart, before Login Screen, I got two Error Windows. First one was titled "services.exe - Bad Image". Screen said "The application or DLL globalroot\systemroot\system32\kbiwkmlrrsotmo.dll is not a valid Windows image. Please check this against your installation diskette." It had an OK button. I clicked OK and the second window appeared saying exactly the same thing, except a different title. This one said "lsass.exe - Bad Image".
    *I clicked OK and it proceeded to the Login Screen. Clicked Administrator.
    *New window popped up with same message as last two, but a different title: "userinit.exe - Bad Image". Clicked OK.
    *Desktop Background picture appeared after about 15 seconds (longer than usual), but no icons or Toolbar.
    *Pressed Ctrl-Alt-Del. Same window appeared again with a 4th different title: "taskmgr.exe - Bad Image". Clicked OK and the Task Manager opened.
    Task Manager shows no Applications running, but shows 38 Processes running, including all four previously listed .exe files on the Error windows.
    *Tried the New Task button. It opened a Run Window with "msconfig" already showing. I clicked OK and Windows opened a new window asking me what program I wanted to use to open this .exe file. I then tried again with "explorer.exe", same result. Cancelled Run Window.
    *Clicked on Restart from Menu.
    *Restart repeated previous six steps except for New Task.
    *Restarted again. Restart now went to Login without Error screens.
    *Clicked Administrator. Went to Desktop Background picture without error, but still no icons or Toolbar.
    *Ctrl-Alt-Del opened Task Manager without any Error Screen. Still 0 Applications, but now has 39 Processes.
    *Restart from Menu. Repeats last 3 steps, but with 40 Processes.
    *Repeated Restarts show no further change except Processes vary from 39 to 41. Repeated 8 times.
    *Attempted Safe Mode Restart. Immediately after loading drivers, computer re-booted itself.
    *Shut down computer. Reporting here.

    Sorry I was not able to provide a log file. May I presume I will now need to create one of those bootable CDs you listed previously? I do not have the original Installation CD for Windows. This is a Gateway computer from 4 or 5 years ago and the Installation CD is actually a Partition of the Hard Drive. Drive D, for Recover purposes. They "Recommend" you make a Bootable CD when you first start up your new computer, but I was younger and dumber back then and never did. In looking at these 4 links you gave me, the Trinity Rescue Kit looks like the most comprehensive of the 4. Would any of these 4 be more apropo for my situation? I could do a Recover but all the Windows Settings would be cleared and I would have to re-install all the programs. It will save all documents, pictures, etc, but the programs, and their settings, will be gone.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Possibly but the one that will help the most is the UBCD4Win CD and it requires a Windows Boot CD to make it.

    You would not have been able to make a Windows Boot CD anyway. They were referring to something different then a full bootable CD for Windows which is what you need.

    All of these CDs have their pros and cons. None of them are perfect solutions for malware issues like you have. Even the scans you can run from them would most likley not detect and fix your problems anyway.

    From Task Manager can you still run Internet Explorer by entering iexplore.exe ?

    Also try running the below from Task Manager to see if you Desktop appears:

    C:\WINDOWS\ServicePackFiles\i386\explorer.exe

    If your Desktop does appear, then copy the above explorer.exe file into your C:\Windows folder. Then reboot and see if your Desktop still appears.

    From this point on, if we don't ask you to do it, don't do it. ;)
     
  8. 45-70BFR

    45-70BFR Private E-2

    The UBCD4Win is the one I used to create a Boot CD, with help from your brethrin in another thread. I was able to use it to clean out a couple hundred files and Registry items. I am still not able to boot up normally due to the Bad Image issue. I did have a slight problem with the Boot CD. Several of the programs in it would not work. I think this may be due to them not being complete. The CD was rated at 700MB and it had 733MB on it, so it may have been too small. I have remade a new one on DVD. It looks like it used about a quarter of it.

    I just tried your suggestions from above:

    iexplorer.exe would not Run from Task Manager. It gave a "Windows cannot find the selected file."

    C:\WINDOWS\ServicePackFiles\i386\explorer.exe would not Run either. A window opened requesting I select what program I wanted to use to open this file.

    Awaiting further instructions.
     
    Last edited: Sep 21, 2009
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try this.

    Download the below file to your Desktop. Once saved on your Desktop, Right click on it and select Install

    EXEfix

    Then see if can run EXE files.
     
  10. 45-70BFR

    45-70BFR Private E-2

    OK, how will I download this and install it on a CD so I can try it on the bad computer. I cannot download anything to that computer just yet, unless I can get a wireless connection thru the Boot CD?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is just a file that you need to save to the PC. You have to run it after you boot the PC having the problem. It is not designed to work if you have booted from UBCD4Win.

    Are you saying you have no way to read a USB drive or CD when you boot the problem PC from the hard disk.
     
  12. 45-70BFR

    45-70BFR Private E-2

    That is correct! All I get is the background picture of my Desktop. I can use Ctrl-Alt-Del to open the Task Manager, but there are no Applications running and only 40 (39 - 41) Processes running. I have not tried inserting a CD yet to see if it will Autorun. I tried using the Run window from the Task Manager to open the File Manager, but it failed with the same "Open With This" window that the C:\WINDOWS\ServicePackFiles\i386\explorer.exe had. This is the same response I got for msconfig.exe and any other .exe I tried. Would a list of the Processes that are running help? The computer I am using for this is currently running 66 Processes, so I don't know if 40 is too few or not.

    Does UBCD4Win have a dll repair program that I could use to fix the Bad Image dll file?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you open a command prompt window via Task Manager. Enter cmd into the run box and click OK.

    In many cases no since the infections do not always show in in Task Manager. Do you see anything that says pav.exe or mav.exe.


    No but you can use it to navigate your infected hard disk and tell me what the file sizes (in bytes) are for the below files.

    C:\Windows\system32\eventlog.dll
    C:\Windows\system32\netlogon.dll
    C:\Windows\system32\scecli.dll
     
  14. 45-70BFR

    45-70BFR Private E-2

    Had a surprise when I got back to the problem computer. I had left it on while I replied to you and when I returned to it, it had a Symantec window opened for its One Button Checkup Scan. Apparently it was still running in the background thru all the bootups I had attempted. It reported the following: Repaired 155 of 156 Registry Errors, 54 Program Integrity Errors, 102 Shortcut Errors, and Cleaned 1492 items in Norton Cleanup Scan.
    I Closed Symantec. Still no Desktop, just the Background Picture.
    Restarted the computer. Still no Desktop, just the Background Picture.

    This worked. As does the File Manager now (explorer.exe) and msconfig.exe.

    The only three letter names in the Processes are alg.exe & jqs.exe.

    C:\Windows\system32\eventlog.dll 55KB
    C:\Windows\system32\netlogon.dll 398KB
    C:\Windows\system32\scecli.dll 177KB

    All three were Last Modified on 04/13/2008. I was now able to use the File Manager to get these. I can probably now do EXEfix on a USB Stick. Do I still need it now the .exe seems to be working?

    I retried your previous suggestions now that Run is working:

    iexplorer.exe still cannot be found

    C:\WINDOWS\ServicePackFiles\i386\explorer.exe opens the File Manager. No Desktop Icons appear, nor does the Toolbar.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you run explorer.exe your Desktop is not appearing?

    Not problems.

    I need the file size in bytes not KB. Right click on the file and select Properties and you will see this info.

    File dates and times are meaningless because anyone, including the infection, can change them to anything they want. ;)

    Not necessary. See if C:\Program Files\Internet Explorer\iexplore.exe opens your browser. Make sure you copy and paste to get the spacing correct. Does it run? If yes, download MGtools.exe from the READ & RUN ME and try to run it.


    This is what we commonly call Windows Explorer or just Explorer. With this open, check to see if the C:\Windows\explorer.exe file exists.
     
  16. 45-70BFR

    45-70BFR Private E-2

    No. No icons, no Toolbar, only the Background Picture.

    ( SIZE/ SIZE ON DISK )
    C:\Windows\system32\eventlog.dll 56,320/ 57,344
    C:\Windows\system32\netlogon.dll 407,040/ 409,600
    C:\Windows\system32\scecli.dll 181,248/ 184.320


    Successful! Log file attached!

    It exists, as well as another file, same name, but no extension, and an icon of a folder with a spyglass.
     

    Attached Files:

    Last edited: Sep 21, 2009
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I'm seeing a bunch of problems. Let's see if we can get ComboFix to run which could help reduce manual steps. You must make sure you DOWNLOAD and save the files to your PC. You did not save MGtools.exe to your PC. You actually ran MGtools from your browser which is not a good idea since it will not always work properly like that. ComboFix will not work properly if you do that. So save the below file to your root folder

    combofix.exe

    Then double click on it to run it. If it works properly, it will scan your system and remove what it detects. The it will reboot the PC. After reboot it should run again to create the C:\combofix.txt log. Attach this log.
     
  18. 45-70BFR

    45-70BFR Private E-2

    Downloaded and currently running. It says Norton Internet Security is running and needs to be disabled. Do you know how I can disable it when I don't have a System Tray showing Its icon? It does not show on Task Manager either as an Application. I could stop its Processes if I knew which ones they were.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No not really since I would never use it. You would have to try locating it in C:\Program Files\Symantec to see if you can find what they use to access the program. A guess would be the below:

    C:\Program Files\Common Files\Symantec Shared\ccApp.exe

    You will not be able to disable all of it from Task Manager since some items are services and would automatically restart. All of the below processes are from Symantec. Some are not for the AV.

    ccSvcHst.exe
    symlcsvc.exe
    AluSchedulerSvc.exe
    NOPDB.EXE

    You should also disable the below from ComCast:
    ComcastAntiSpyService.exe


    See if you can just tell ComboFix to run anyway.
     
  20. 45-70BFR

    45-70BFR Private E-2

    OK, did all the stuff you suggested above. ComboFix seemed to run ok. It said Norton was still running. After restart it seems to be just sitting there. After 20 minutes I have gotten no further responses from ComboFix. I tried to disable ccSvcHst.exe again and this time it said I do not have permission to do that. Is this because ComboFix is still running in the background? Is this amount of time normal for it to finish?
     
    Last edited by a moderator: Sep 21, 2009
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No and No.

    Does combofix.exe show in the running process list?

    I will try to create a different fix by passing ComboFix for now. While I create this, I want you to get started on the below.

    What is all the below junk in the OWNER user account's root folder? These should not be here. Delete these files unless you know you need them for some reason. Whatever you are running that is doing this should not be using this folder to store this junk. Make sure you only delete what is indicate. Other files and folders should not be removed.
    Code:
    C:\Documents and Settings\OWNER\
    #'            Oct 26 2006        6258  #'
    )_            Jul 19 2007        3916  )_
    61            Dec 16 2005        4131  61
    _0cb3~1       Sep 30 2007        3916  ";A"
    @a            Sep 30 2007        3916  @A
    b'            Dec 16 2005        4131  B'
    clearl~1.win  Sep 28 2007           0  "Clear. Low 62F. Winds S at 5 to 10 mph"
    clears~1.win  Apr 28 2006           0  "Clear skies. Low near 55F. Winds SSW at 5 to 10 mph"
    c1            May  1 2006        6428  C1
    deskto~1.exe  Jun 13 2006           0  "DesktopDoctor1.5.1.exe"
    fewsho~1.wx   Feb 12 2007           0  "Few showers. Highs in the upper 60s and lows in the upper 85715.wx"
    f1            Sep 26 2006        6258  F1
    g’u           Mar 14 2006        4131  "G’u"
    h1            Dec 17 2005        4131  H1
    k«            Mar 18 2008        5206  "k«"
    log.txt       Aug  8 2008           0  "log.txt"
    luresult.txt  Nov  3 2005          75  "LuResult.txt"
    mainly~1.wx   Feb  4 2006           0  "Mainly sunny. Highs in the mid 70s and lows in the low 40s85715.wx"
    mainly~2.wx   Jan 16 2008           0  "Mainly sunny. Highs in the mid 60s and lows in the upper 385715.wx"
    m_            Jan 16 2007        6271  M_
    ný            Apr 26 2006        6428  "ný"
    n_            Jan 16 2008           0  N_
    partly~1.wx   Mar 18 2008           0  "Partly cloudy. Highs in the low 80s and lows in the low 5085715.wx"
    plugin~1.tra  Jul 27 2006         711  ".plugin141_02.trace"
    p1            May  1 2006           0  P1
    sunshi~1.hig  Oct 15 2006           0  "Sunshine. Highs in the low 80s and lows in the mid 50s"
    sunshi~2.hig  Mar 18 2008           0  "Sunshine. Highs in the low 80s and lows in the upper 40s"
    t1            Mar 30 2006           0  T1
    v3            Feb 11 2006           0  V3
    xú            Apr 28 2006           0  "Xú"
    ~_            Sep 28 2007        3916  ~_
    4bd8~1        Feb 12 2007           0  "?'"
    8bd8~1        Feb  2 2006        4131  "?,"
    ›_            Mar 18 2008           0  ›_
    œa            Sep  9 2007           0  œA
    5b7a~1        Aug 12 2007        3916  "æ"
    -ú            Feb 11 2006           0  -ú
    ø3            Apr 10 2006        6428  ø3
    '_            Sep  8 2007        3916  '_
    «¬            Jan 16 2007        6271  "«¬"
    6b1c~1        Feb  4 2006        4131  "A"
    €ú            Jan  6 2008           0  "€ú"
    8b8c~1        Aug 15 2006        6258  "E,"
    eú            Sep 30 2007        3916  Eú
    i¬            Sep 28 2007           0  I¬
    ™¨            Apr 28 2006           0  "”¨"
    8b8f~1        Feb  4 2006        4131  "o,"
    u'            Sep 26 2006        6258  U'
    8bfd~1        Mar 18 2008           0  "á,"
    `1            Oct 15 2006        6258  `1
    eba1~1        Jan 16 2007        6271  ",_"
    Ø3            Apr  4 2008        5206  Ø3
    %¬            Jan 19 2008           0  %¬
    Copy the bold text below to notepad. Save it as fixme.reg to anywhere you know you can locate it with Windows Explorer. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    In Task Manager's run box, enter appwiz.cpl and click OK. If this works, Add/Remove Progams should appear. See if you can uninstall all of the below:

    J2SE Runtime Environment 5.0 Update 1
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 9
    Java 2 Runtime Environment, SE v1.4.1_02
    Java 2 Runtime Environment, SE v1.4.2
    Java(TM) 6 Update 11
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7
    Java(TM) SE Runtime Environment 6 Update 1

    Let me know the results of the above!
     
  22. 45-70BFR

    45-70BFR Private E-2

    No. I'll be back later with the rest.
     
  23. 45-70BFR

    45-70BFR Private E-2

    When I got back to the computer last night it had a window for Norton Internet Security. It had finished a Full Scan. I restarted the computer again so it could finish its Cleanup. Nothing further appeared on the screen overnight. I proceeded with your procedures this morning.

     

    Attached Files:

    Last edited: Sep 22, 2009
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now we need to use ComboFix again
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  25. 45-70BFR

    45-70BFR Private E-2



    • Done!

      Done! Ran seperately for each userid.

      Done!

      Done! Everything seems to be OK so far.
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  27. 45-70BFR

    45-70BFR Private E-2

    All done! Thank you very much.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds