Results from the READ ME FIRST XP Cleaning procedure

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by goofygrandma, Feb 1, 2010.

  1. goofygrandma

    goofygrandma Private E-2

    I cannot figure out how to attach the MGlog or Malware log, but I did the first few attachments. Check it out. I did all that cleaning because my PC was slow, and I kept getting hanging apps, "needed to close, send report" freezing, etc. Thanks for the really great tools to clean up with. They were amazing and free! :wine The puter does seem faster, the MGtools ran again when I opened it this AM. Thanks 4 help
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The same way you attached the other logs. Just put C:\MGlogs.zip into the box in the Manage Attachments form and click upload. We need this log to continue.

    The Malwarebytes log is in the below folder:

    C:\Documents and Settings\username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\

    Where username needs to be replaced by your actual user account name.
     
  3. goofygrandma

    goofygrandma Private E-2

    ok ty for the reply I appreciate it, hope this is it.
     

    Attached Files:

  4. goofygrandma

    goofygrandma Private E-2

    does everyone get to see my logs? Why isnt there more privacy for that? Do the files have anything that could harm my PC or take personal info? thx again for your help.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Only people who are members of Major Geeks like you.

    Because it is not required and impossible to easily do.

    No not really. How many people in the world would you guess have the same name for their user account as you? And even knowing that name, what does it tell anyone.

    Once you attach the last log, we can continue.


    What problems are you currently having?
     
  6. goofygrandma

    goofygrandma Private E-2

    Thanks Chad for your help. I did attach that file you requested & told me how to upload it...hope it is the one you need. It is posted under the one where I asked if the files were visible to the public.

    I have been having a lot of trouble with hanging, and those annoying "program is not responding and must close" then I have to do the old "ctrl, alt, delete" which takes awhile to unhang itself, then the "send this error report to Microsoft" box. That is the main problem.

    It seems to run faster since the clean up. However, the Adobe Reader, pdf file opening, is opening in giant size font and the colors are streaked, it is unreadable...not to mention hard to get rid of. I uninstalled the Adobe Acrobat and reinstalled it, no chg. I read the troubleshooting this malfunction on the Adobe site...also no help.

    If you can figure something out I would appreciate it A LOT!! Thx for your time and troubles.
     
  7. goofygrandma

    goofygrandma Private E-2

    I attached the MGLogs.zip I dont kno if I did it right.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No this is not MGlogs.zip it is exactly what you attached ..... sysinfo.txt.

    You need to attach the file that was requested which is c:\MGlogs.zip and nothing else.

    Problems with Adobe Reader should be posted in the Software Forum.

    The main reason for your PC being slow is probably due to the below which shows you do not have enough memory to properly run Windows XP.
    Code:
     Total Physical Memory 512.00 MB 
    Available Physical Memory 118.30 MB
    At a minimum, you must double your memory to 1 GB but 2 GB is highly recommended.
     
  9. goofygrandma

    goofygrandma Private E-2

    I agree I need more memory, thank you for finding that. I think I found the right MGlogs.zip
    I have a few other problems after you can find a solution to the problems found during the Cleaning Proc. thanks a bunch
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. We just have a little more to do.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: House of Many Games Toolbar - {6aa39034-952d-4854-90b4-e5498bda7b97} - C:\Program Files\House_of_Many_Games\tbHou1.dll
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: House of Many Games Toolbar - {6aa39034-952d-4854-90b4-e5498bda7b97} - C:\Program Files\House_of_Many_Games\tbHou1.dll
    O3 - Toolbar: House of Many Games Toolbar - {6aa39034-952d-4854-90b4-e5498bda7b97} - C:\Program Files\House_of_Many_Games\tbHou1.dll
    O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\\Program Files\\Common Files\\Symantec Shared\\ccSvcHst.exe (file missing)

    After clicking Fix, exit HJT.

    Uninstall the below software:
    Ask Toolbar
    House_of_Many_Games Toolbar

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. goofygrandma

    goofygrandma Private E-2

    hello again Chas, I got as far as the "uninstall the below software", but the AskToolbar refused to be uninstalled, said "AskBarDis\uninstall doesnt exist"
    I did uninstall the House of Many Games Toolbar. I did run the Ccleaner and hit the Run Cleaner button, it permanently removed what it found, it was a lot!! :eek hope that was a good thing to do!
    Ran into another problem, the "run MGtools\GetLogs.bat " I was unable to find it, can you help me with that? I did hit the MGtools.exe and it came up in the black screen, it did its thing, at the beginning/top the "getlogs.bat" was one of the many things listed, I just dont know where it is stored, and the RUN option couldnt find it, the SEARCH couldnt either, it even came up with "Windows has encountered a problem and must close, sorry if you were in the middle of something" :-D :confused, which happens quite often. Anyways, I will attach that MGlogs.zip after help given from you...again thanks a lot, we are getting somewhere!!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just keep going.

    It is right where stated C:\MGtools is the folder it is in and GetLogs.bat is the file. If you ran C:\MGtools\analyse.exe without a problem, why are you having a problem finding GetLogs.bat? Both analyse.exe and GetLogs.bat are located in the same location.

    Aren't you use Windows Explorer to navigate to the files?

    I did not say to run MGtools.exe but it you ran it and let it run all the way then a new MGlogs.zip file would be created anyway so just attach it.

    As stated above, it is in the C:\MGtools folder and you cannot just enter GetLogs.bat into the Run box from the Start button. It will not be found that way since it is not part of the Windows environment. However if you pasted C:\MGtools\GetLogs.bat into the Run box, it would run since that gives it the full path of where to find GetLogs.bat.
     
  13. goofygrandma

    goofygrandma Private E-2

    Here is the MGtools file you asked for. If it isnt right, I am pretty sure you will let me know, and yes I believe I am using Windows Explorer to navigate to the files, when I click on the "manage attachments" it takes me to the Browse which opens the "desktop, Documents" etc. Thats where I found the MGTools.exe and I attached it. thanks for your help
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No that is not Windows Explorer. Windows Explorer can be open many ways, like any of the below for example.
    • hold down the Windows Key on your keyboard and at the same time press 'e'
    • right click Start and select Explore
    • double click My Computer
    This brings up Windows Explorer which is the Windows file manager and it allows you to navigate thru files and folders and perform all kinds of operations on files and folders. Including giving you the ability to navigate to the C:\MGtools folder were you can double click on analyse.exe or GetLogs.bat to run them which is what previous steps were saying when they asked you to double click on them. Everyone who uses a PC should know how to open and use Windows Explorer.
    Your logs are clean but to finish removing the entry for Ask Toolbar, do the below.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
    Last edited: Feb 20, 2010
  15. goofygrandma

    goofygrandma Private E-2

    I got the message that it was successful, thanks a bunch for the instructions on how to open the Windows Explore...that was amazing. I finished the rest of your instructions also. I appreciate it so much. I will read and follow the "How to protect yourself fromMalware". If I have any other problems, I know where to find you Geeks! Thanks again.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
  17. goofygrandma

    goofygrandma Private E-2

    I have CCleaner, SuperAntiSpyware, & Malwarebytes AntiMalware, since the BIG cleaning. Should I routinely run them and hit the "fix all" or delete all they find? I did uninstall the "Hijackthis" like you said to do. Thanks again.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    See step 14 of this link I gave you: How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds