PC Privacy Tools - Removal issues

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by VoiD, Mar 14, 2009.

  1. VoiD

    VoiD Corporal

    have the above on a friends PC, it start just after you log into windows and scans the PC, after scanning it throws up a load of dialog boxes (1 for each issues, about 500 issues!) as its doing this the PC crashes then restarts.

    I cant get into windows at all to do any scans, not even in safemode as this program pops up everytime.

    I can stop the program as its running via task manager but then the PC wont load any further but i can still use task manager ok. i can access the registry editor via run but i cant seem to find an entry for the program process "PC.exe"

    thanks in advance guys :)
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I want to see if perhaps you can get anywhere by using Safe Mode with Command Prompt. But before trying to reboot in this mode, you first need to use another PC to download the below two files:
    1. Malwarebytes Anti-Malware
    2. MGtools.exe
    Copying the above two files to the problem PC.
    • Now copy the above two files to either a CD or flash drive.
    • Put this CD or flash drive into the problem PC and see if you can use Task Manager to copy the files to the root folder of the Windows boot drive which is normally drive C. If you don't have any idea how to do this from Task Manager, try the below methods (I'll give to methods in case the 1st does not work)
      • Method 1 to Copy Files
        1. Click File, New Task (Run...) and then click the Browse button.
        2. Use the Browse windows to navigate to the CD or flash drive.
        3. Select the MGtools.exe file by clicking on it once so that it is highlighted.
        4. Then press CTRL-C to copy the file.
        5. Then navigate back to the C drive by clicking the My Computer icon in the Browse window. Select the C drive by double clicking on it.
        6. Then press CTRL-P to copy the file to the C drive root folder.
        7. Repeat the for the mbam-setup.exe file.
      • Method 2 to Copy Files
        1. Click File, New Task (Run...) and enter cmd and click OK.
        2. If the above works a command prompt window will open
        3. In the command prompt window type cd C:\ and hit the enter key. This should change the prompt in the window to C:\>
        4. Now you need to know the drive letter of the CD drive or the flash drive that you will be copying from to do the below command. I'm going to assume the drive letter is E and put that in my example command. So enter the below commands followed by the enter key:
          • copy E:\MGtools.exe
          • copy E:\mbam-setup.exe
        5. If the above copy commands work, you should get a response of 1 file copied for each command.
    • Now reboot the PC by selecting the Shutdown tab in Task Manager and then select Restart to restart the PC.
    • and press the F8 key to get to the boot menu.
    • In the boot menu, select Safe Mode with Command Prompt
    • When the PC boots up, you should eventually get a command prompt Windows to open (assuming everything works OK).
    • In the command prompt window, enter the below commands (the commands are in black bold print. Other text are just comments or explanations).
      • cd C:\
      • mbam-setup.exe
        • this will attempt to install Malwarebytes. At the end of the installation procedure, just uncheck the option to update Malwarebytes but leave the option to Launch the program checked. This should automatically run the program.
        • If it installs and runs, select Perform quickscan
        • when it finishes running, make sure your fix everything it finds and then save a log.
        • Now continue on with the next commands below
      • mgtools.exe
        • wait for MGtools to finish running. When it finishes, the C:\MGlogs.zip file will exist. Now continue on to the next steps below
      • Now hit CTRL-ALT-DEL to bring up Task Manager and select the Shutdown tab and then select Restart to restart the PC. See if it will boot in normal mode now.
    • If you can log in now and get to a normal Desktop, attach the C:\MGlogs.zip file and the log from Malwarebytes.
    • The attempt to run SUPERAntiSpyware and ComboFix per the instructions in the READ & RUN ME and also attach these two logs.
     
    Last edited: Mar 16, 2009
  3. VoiD

    VoiD Corporal

    OK, managed to copy the files using method 1, then rebooted and installed Malwarebytes, it found and fixed a few things, then ran mgtools.exe ok.

    Rebooted into normal mode but the program started again!

    i did however manage to get the logs of the scans i ran using a USB disk and the run, browse window(Method 1). They are attached :)

    thanks for your help!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download this Malwarebytes' Anti-Malware Database and use the same Method 1 type procedure to get this update to MBAM on to the infected PC and run it to get updated. The run a new scan with MBAM and fix all that is found. Attach the new log

    Also you did not download the current version of MGtools. Please download from the link I gave you and use it to get a new log after updating and running the new MBAM scan.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure you attach the current log for MGtools. The date of your files shows the scans were run on Tue August 19, 2008 05:59:25 PM

    Is the clock on your PC wrong or did you just not run MGtools and you attached an old log file. Or the last option could be that MGtools really did not finish running and your log does not contain current files. This would explain why MGtools was out of date as stated in my last message. Did you notice any error message when you ran MGtools.exe? The last log is of no use to me in trying to determine your current status since it mostly contains old logs. The old MGlogs.zip file should have been deleted from your PC last time you finished removing malware.
     
  6. VoiD

    VoiD Corporal

    Sorry about that, I did download the new files you linked to, ran and finnished both, but for some reason it didnt update the files in the zip. I had an old copy left there from the last time i ran the READ & RUN ME, as i forgot to remove them, maybe you should add that to the removal guide?

    Anyways, i updated mbam and fixed all it found during the new scan then restarted when asked to and it fired up back into windows as normal.

    Since i can now start windows i'll go through the READ & RUN ME just to be sure i get everything as my friend needs his PC back ASAP.

    SOLVED! Thanks :)
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds