Can't download MGtools

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by onetimeuser, May 12, 2008.

  1. onetimeuser

    onetimeuser Private E-2

    Hello, I'm trying to download and use MGtools.exe as part of the recommended malware removal guide. I'm registered, but when I click the link it says I don't have access.

    I believe I have antispy spider on my computer. Any help is appreciated.

    Thanks,
    OTU
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Make sure that you have checked the box that says remember me when you log into Major Geeks!
     
  3. onetimeuser

    onetimeuser Private E-2

    I have that box selected when I log in. When I click the MGtools link, it takes me a login page (even though it's remembering me). I log in and it thanks me, but then takes me back to the same page.
     
  4. onetimeuser

    onetimeuser Private E-2

    Well, I've been able to get through the malware tutorial up to the MGtools point, so I've attached my logs for SAS, Combofix, and Malawarebytes.

    At this point, I still have the red background, and when I'm using IE Spybot notifies me of websites that are trying to be accessed. So, the process had cleaned a lot of stuff out.

    I really appreciate the tools and information offered by this forum and its people.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Normally when this happens the issue is caused by not checking that box. I suggest you log out and try again. Refresh your browser too. Also if necesary try downloading using another browser. Make sure that you are saving the file and not using Open or Run.
     
  6. onetimeuser

    onetimeuser Private E-2

    Thank you for your help. I'm on a Mac using Safari while my PC is infected. I would prefer not to install another browser. I've tried your other suggestions but they haven't allowed me to download the file. It's like clicking the link refuses to acknowledge my login - I just registered today, do I need to be validated somehow before I can download?

    Could you tell me in which category MGtools is classified? Perhaps I can just download it from the files section of the website.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since you are already posting messages, it means you are already validated. I suggest that you make sure that you are not using a popup blocker of any kind and also make sure your firewall (if any) is not blocking anything including cookies.

    You can only downloaded from the link in the procedure.
     
  8. onetimeuser

    onetimeuser Private E-2

    Downloaded Firefox and was able to get the file. I've attached it to this post, so all four of my files are in this thread. Please let me know if have any suggestions for clean-up.

    ETA: I did receive the fourth error when running MGtools - I suppose my computer does not use the .NET framework.

    Thanks,
    OTU
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is the below a setting that you configured?

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = file://c:/windows/homepage.html


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {0BB75BBA-1C92-401D-AD02-C91EEE83DD0B} - (no file)
    O2 - BHO: (no name) - {0E856D37-6579-4707-8F4D-5C2272A4794C} - (no file)
    O2 - BHO: (no name) - {0F027CB0-F53B-450A-B927-A18729456B04} - (no file)
    O2 - BHO: (no name) - {0F7631D2-4E66-44F4-99C9-111237A4E4EC} - D:\WINDOWS\System32\cbXPfEUM.dll (file missing)
    O2 - BHO: (no name) - {13B1902A-17F8-45FE-8BE4-09D25C61ECF6} - (no file)
    O2 - BHO: (no name) - {1BCC562C-0C02-4306-A1AA-E117EA298287} - (no file)
    O2 - BHO: (no name) - {1BCEACA3-2387-45A6-B895-53676FB40F16} - (no file)
    O2 - BHO: (no name) - {1C2091A9-580C-46DC-BC76-D52995EDADCA} - (no file)
    O2 - BHO: (no name) - {222DD1D5-255B-492F-9F8E-30B2B7744188} - (no file)
    O2 - BHO: (no name) - {27B041D2-DFCB-470F-AD81-D99F8951DE5F} - (no file)
    O2 - BHO: (no name) - {2BA706F7-50B1-4573-98F4-649C221B8D0C} - (no file)
    O2 - BHO: (no name) - {2BFB0B1F-72EF-4B67-ACE8-5EAE0224339D} - D:\WINDOWS\System32\khfgDvtQ.dll (file missing)
    O2 - BHO: (no name) - {2D661B27-096A-414C-86E3-09767F8210AA} - (no file)
    O2 - BHO: (no name) - {311B1E9D-6AF9-4010-AD5E-7463CA8C21D0} - (no file)
    O2 - BHO: (no name) - {3B97893D-9F88-41D6-92BC-100B73B0993A} - (no file)
    O2 - BHO: (no name) - {4CB754D6-620A-4C6E-A39C-7E352FCF661E} - D:\WINDOWS\System32\urqRkkji.dll (file missing)
    O2 - BHO: (no name) - {4D275B9E-915B-4F3C-A117-262BDDDB38FF} - (no file)
    O2 - BHO: (no name) - {52272148-7979-41FF-A39B-CFD7794F3E95} - (no file)
    O2 - BHO: (no name) - {58C6CD79-1BED-4B34-8303-8F66BB4CE616} - (no file)
    O2 - BHO: (no name) - {5A19E2FC-348A-404B-A872-5ED04AEB3B2B} - (no file)
    O2 - BHO: (no name) - {5DB261E0-FC68-4996-96F0-9D3E88C0BE3E} - (no file)
    O2 - BHO: (no name) - {662005AF-C7E5-4CAF-B340-487DEEF28363} - (no file)
    O2 - BHO: (no name) - {7AE77751-1C22-4BC2-B1FE-72F90A1C82DB} - (no file)
    O2 - BHO: (no name) - {7EAC1FA1-287A-456A-8956-A0B66377277C} - (no file)
    O2 - BHO: (no name) - {81F563D5-803B-4711-A2BD-A60D0FA66572} - (no file)
    O2 - BHO: (no name) - {891E2773-2117-49B8-844C-C1B2C61E62A3} - (no file)
    O2 - BHO: (no name) - {8A07CA88-FB44-4489-A558-87AB33628B80} - (no file)
    O2 - BHO: (no name) - {8A9C2C8C-7407-4971-ACF1-6A05CB8A535B} - (no file)
    O2 - BHO: (no name) - {8F8EF754-F436-4D3C-B686-CF973B1469C5} - (no file)
    O2 - BHO: (no name) - {97BD9FE6-25AD-4FF9-87F4-340373513CDF} - (no file)
    O2 - BHO: (no name) - {97E85A75-5D91-47DE-9952-1A49B05FB7A1} - D:\WINDOWS\System32\ssqOfFXP.dll (file missing)
    O2 - BHO: (no name) - {ACC4AC0F-3096-4BF1-86C9-F50D4714EAA0} - (no file)
    O2 - BHO: (no name) - {AD0D40A2-E0D0-45E9-A978-747F37698928} - (no file)
    O2 - BHO: (no name) - {B69CBCD7-2D62-4D28-BB57-FE538BF3EFAD} - (no file)
    O2 - BHO: (no name) - {BA9E9517-DEEE-4817-9B5F-B0057CAF19A0} - (no file)
    O2 - BHO: (no name) - {BD6EC16D-7F32-490A-9A96-DC9B5EEB6FCF} - (no file)
    O2 - BHO: (no name) - {CADD380F-0E8E-4BC8-9B01-EABEB22F400D} - (no file)
    O2 - BHO: (no name) - {DCD6E5E1-8525-43E1-9326-85709B1938FE} - (no file)
    O2 - BHO: (no name) - {DF075583-5E46-4BE0-A6C4-7FD8C775104F} - (no file)
    O2 - BHO: (no name) - {E4263073-942F-4DD1-A481-058BC5A3E061} - (no file)
    O2 - BHO: (no name) - {EF69BC81-62BE-4E3B-A42E-47D0CE7ADF65} - (no file)
    O2 - BHO: (no name) - {F1333740-DCCF-456A-9BDC-F27ADC0E118D} - (no file)
    O2 - BHO: (no name) - {F628C4B4-5F69-4D56-952D-D23ED6B0BE0A} - D:\WINDOWS\System32\opnlIXOG.dll (file missing)
    O2 - BHO: (no name) - {F648B9DC-C921-4346-A0F2-690ECE386DF2} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. onetimeuser

    onetimeuser Private E-2

    No, I did not configure it and I've seen it in some of the malware/virus windows and errors that have popped up.
     
  11. onetimeuser

    onetimeuser Private E-2

    I followed all of your instructions and the registry merge was successful. I've attached the combofix and mglogs to this message.

    I did not delete the entry you asked about in HijackThis, however.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It appears to be gone based on your new log.

    How are things working? Your logs are clean.
     
  13. onetimeuser

    onetimeuser Private E-2

    Things appear to be working properly. Thank you for your technical expertise. You saved me from Fdisking!

    Are there any post-clean-up tasks? For instance, my clock is still in 24hr format.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can fix your clock from Control Panel ->Regional and Language Options and then on the Regional Options tab click the Customize button then on the next form click the Time tab. Then change the Time format to what you want. It explains there what the lower case and upper case letters will do. Upper case H is giving you 24 hour clock settings.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    3. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. Go to add/remove programs and uninstall HijackThis.
    5. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    6. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work thru the below link:
     
  15. onetimeuser

    onetimeuser Private E-2

    Everything seems to be better. One oddity is that whenever I try to get to this site in IE, Spybot finds Avenue A, Inc or Better Internet trying to access something. Doesn't happen in Firefox.

    Thanks for all of your help!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I believe all you are referring to is cookies. See step 11 of the How to protect yourself from malware link I gave you.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds