Google redirection hijack & other malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by BobLewiston, Jun 1, 2011.

  1. BobLewiston

    BobLewiston Private E-2

    My friend Bob's computer had the following symptoms:

    1. A . This would only happen in Firefox, but not in IE.

    2. Add / Remove Programs would simply refuse to run.

    3. In Avast Antirirus, whenever an attempt was made to update either the engine and virus definitions or the program itself, an error message would appear saying that Avast was unable to access the server. I know the problem was not the server, since I didn't have this problem on my computer.This problem didn't disappear even when I reinstalled Avast Antivirus.

    4. Programs got launched simply by positioning the cursor over their desktop icons, rather than actually double clicking on the icons. I'm not sure if that's a malware problem or just a Windows configuration problem, but it sure is obnoxious.

    I took all the steps recommended in the Fixing Google Redirection/Hijacking Problems guide and in the Major Geeks' Malware Removal Guide, and the first two problems disappeared, but not the problem with Avast, or the program launch problem. Also, now that Add / Remove Programs works, I can see an installed program called "aaa", which I suspect is malware, and which I can't uninstall.

    I'm sending the logs from GooredFix, TDSSkiller, SUPERAntiSPyware, Malwarebytes Anti-Malware, Combofix, Root Repeal and MGtools.
     

    Attached Files:

  2. BobLewiston

    BobLewiston Private E-2

    And here are the rest of the logs. Thanks a lot for any help you can give.
     

    Attached Files:

  3. BobLewiston

    BobLewiston Private E-2

    Update: I just downloaded the latest version of Avast FreeAntivirus (6.0.1125.0) and installed that, but I still can't connect to the server to update the engine and virus definitions.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am reviewing your logs and will get back to you with a response later on.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Important Notice: A new version of SUPERAntiSpyware is available.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log later.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    C:\Documents and Settings\Bob Heil\Local Settings\Application Data\rwm24r6hc455p7p67o
    C:\Documents and Settings\All Users\Application Data\rwm24r6hc455p7p67o
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    The version of MGTools you are using is outdated too! Note, using outdated software can cause big issues, not with MGTools but with Combofix especially. Never keep old copies lying around, always be current.

    Now go to this MGTools and download the new version of MGtools.exe. Overwrite your previous MGtools.exe file with this one.

    Run the new C:\MGTools.exe and attach the C:\Mglogs.zip
     
  6. BobLewiston

    BobLewiston Private E-2

    Somehow, I managed to screw up point #1. The point was the Google was being redirected.

    Anyway, here are the logs. The first Combofix log was from before I dragged CFscript.txt over Combofix.exe, and the second one is from afterwards.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do redirects persist at this point or not?
     
  8. BobLewiston

    BobLewiston Private E-2

    The Google redirection and Add / Remove Programs problems appear to be resolved, except that I can't remove program "aaa", which I believe is Trojan Downloader Agent AAA. Avast Antivirus still can't connect to the server to update itself, and the mouse-over problem persists.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm the only software beginning with a shown in your logs is as follows:

    Adobe Flash Player 10 Plugin
    Adobe Reader 8.2.6
    AiO_Scan
    AiOSoftware

    Can you show me with a screenshot?

    Are you able to uninstall it using the below program?

    Try Revo Uninstaller.

    Choose the option on the bottom of the list (#4). Be very careful while deleting the bolded registry items ONLY!! This software will create a system restore point for you as well prior to uninstalling a software program.

    Does Revo even see the program?
     
  10. BobLewiston

    BobLewiston Private E-2

    Here are the screenshots:

    As you can see, Add or Remove Programs sees "aaa" but can't remove it completely, and the same for Revo Uninstaller.

    Is the cursor-over problem just a Windows configuration issue? Because it's indescribably obnoxious. If it IS just a Windows configuration issue, is it possible that Miscrosoft simply has sh*t for brains?
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try removing Java(TM) 6 Update 25 with Revo, reboot and now tell me if the aaa entry still appears.
     
  12. BobLewiston

    BobLewiston Private E-2

    OK, I removed Java 6 Build 25, and "aaa" was still visible in Add or Remove Programs, as well as in Revo Uninstaller, but Add or Remove Programs was then able to completely remove "aaa", and now "aaa" isn't visible in either Add or Remove Programs or Revo Uninstaller, so I guess "aaa" was part of Java. So should I reinstall Java 6 Build 25?

    And Avast Antivirus still can't connect to the server.

    And WOW, would I like to get rid of this cursor-over problem. To my mind, my friend's computer is hell to work on with this problem, and he can't stand it either.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    There's a newer version out now. 6.26, and yes, install it. :)

    Uninstall PCTools Firewall > reboot > are you now able to update Avast? I am not seeing any signs of malware which could be blocking this...

    Not sure I will be able to help with this one. Not exactly my territory. Have you tried another mouse?
     
  14. BobLewiston

    BobLewiston Private E-2

    >Uninstall PCTools Firewall > reboot > are you now able to update Avast? I am not seeing any signs of malware which could be blocking this...

    I uninstalled PCTools Firewall Plus and rebooted, but avast still couldn't connect to the server, so I uninstalled and reinstalled avast, but it still couldn't connect to the server, so I rebooted, and when the desktop came up, a whole bunch of program icons were missing, and the computer doesn't work at all now, not even the mouse cursor, and I can't turn the computer off, so I guess I'll have to figure out how to remove the battery (it's a laptop). That's where we're at right now.
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Why can't you turn it off? Just hold the power button in. Does that not work? :confused
     
  16. BobLewiston

    BobLewiston Private E-2

    It turns out it does work - it's just that, for some reason, you've got to hold the button in for, like, 20 seconds, rather than 10. Dunno why.

    But then, for exactly 2 attempts, these problems still persisted: not all the icons appeared on the desktop, and the mouse still didn't work. But then, on the third, attempt, it worked. Again, dunno why.

    And avast still can't connect to the server.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  18. BobLewiston

    BobLewiston Private E-2

    I got a success message for the regedit.

    I've attached MGlogs.zip.
     

    Attached Files:

  19. BobLewiston

    BobLewiston Private E-2

    OK, I was too busy before, but now I've once again tried to get Avast to connect to the server, and it still won't do it.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What version of Avast do you have installed?

    I would suggest uninstalling and then rebooting. Then cleanup manually all files and folders related to Avast. Regsitry keys for Avast may need cleaning too; however, just try running this too: Avast! Uninstall Utility

    Then do a fresh download and install from the below link:

    Avast! Free Edition
     
  21. BobLewiston

    BobLewiston Private E-2

    OK, I did that, but it didn't work. I know there's nothing wrong with Avast's server, because I can connect to it on my own computer.

    So you can't see ANYTHING in the logs that would account for this...?
     
  22. BobLewiston

    BobLewiston Private E-2

    Oh yeah, both before and after following these recent instructions, my friend was running the version of avast! Antivirus that I downloaded from Major Geeks. Major Geeks says that version is 6.0.1125, but the properties of the file actually downloaded says it's version 6.0.1000.0.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! It does not appear to be due to malware. You may have an issue on your end with a firewall, a browser or proxy setting, or possibly a router or cable/dsl modem causing and issue with the connection.
    • Have you tried bypassing your router?
    • Also have you tried doing an update in safe mode?
    • Have you tried logging into a different user account to see if it can be updated when using a different user account?
    If this continues to fail, I suggest uninstalling it and running a registry cleaner ( like CCleaner ) and remove all items related to Avast ( only remove items related to Avast as much of what registry cleaners report are incorrectly stated to be errors when they are not ). I would then suggest that you use a different antivirus like Avira or Microsoft Security Essentials.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! The link I gave you states that is is 6.0.1000

    There is also a another link to a Beta version: Avast! Free Edition BETA 6.0.1035 ( link is >> Avast! Free Edition BETA )
     
  25. BobLewiston

    BobLewiston Private E-2

    >You may have an issue on your end with a firewall, ...

    No, I don't think so, because I actually uninstalled PC Tools Firewall Plus while trying to troubleshoot this. Unless... could this be a problem with Windows' own firewall? Incidentally, since uninstalling PC Tools didn't allow avast! to update, I should reinstall PC Tools, correct?

    >...a browser (setting)...

    This seems unlikely to me, since:
    1. no browser is involved in updating avast!,
    2. this happens whether Firefox or IE8 is being used (or both or neither), and
    3. my friend (whose computer I'm attempting to disinfect), now tells me that avast! has been unable to update for far longer than this most recent malware problem of his showed itself, and he didn't have any other problems in all that time, including with updating any other program.

    But maybe I'm wrong. If you can suggest any browser setting that I should look at, I'll do so.

    >...or proxy setting, ...

    Could be, I guess. See my response below to your question about trying to update in Safe Mode.

    >...or possibly a router or cable/dsl modem causing and issue with the connection.

    I don't think so, since I have his computer at my house and it's therefore on the same wireless router and cable modem as my computer, and I'm not having any problem updating any programs on my own computer.

    >Have you tried bypassing your router?

    No, for the reason I've given above, but if you think I should try this anyway, I will, but I'll do this only if you tell me to, because then I'll have to do it wired, which would be a bit of a hassle.

    >Also have you tried doing an update in safe mode?

    Yes, I tried booting up in Safe Mode, logging on as Administrator, and updating avast!, but it didn't work. I didn't get any error message, but when attempting to update the engine and virus definitions, it stalls out when attempting to initialize, and when attempting to update the program itself, absolutely nothing happens when I click the button. Maybe that shouldn't be a surprise though, because in Safe Mode I couldn't update my friend's antimalware programs (Malwarebytes' Anti-Malware and SUPERAntiSpyware) either, although I can in Normal Mode.

    >Have you tried logging into a different user account to see if it can be updated when using a different user account?

    I've tried it as:
    1. Bob Heil (my friend's name) - this is an administrator level user account; I tried this in both Safe Mode and in Normal Mode
    2. Administrator - I tried this in Safe Mode; my friend has Windows XP Home Edition, so it's not possible to log on as Administrator in Normal Mode

    Should I create some other user account to log on under?

    Incidentally, to my surprise, my friend just told me that he upgraded his SUPERAntiSpyware from the free version to the paid version, which I believe runs all the time in the background, rather than just on command, so I though maybe it might have been blocking avast! from updating, so I tried exiting SUPERAntiSpyware and trying again to update avast!, but that didn't work either, either in Safe Mode or in Normal Mode.

    Again incidentally, I can find no way whatsoever to exit avast! when it's running, other than to uninstall it or turn off the computer (or presumably, to log off). Do you know if there is any “normal” way to exit avast! without resorting to such measures?

    >>Major Geeks says that version is 6.0.1125, but the properties of the file actually downloaded says it's version 6.0.1000.0.

    >No! The link I gave you states that is is 6.0.1000

    I must respectfully disagree. Please see the attached screen shot "Major Geeks' Avast 6.0.1125 download".

    And now there is a new development. Upon booting up in Normal Mode, I'm getting an avast! warning of a possible unsafe app (please see attached screen shot "avast unsafe app warning"). This seems odd, since it's talking about Hewlett Packard printer software. And in fact, when I click OK, I get a subsequent message that HP's software needs to be reinstalled (please see attached screen shot "HP software uninstalled"). Nonetheless, four HP apps still show in Add or Remove Programs and Revo Uninstaller, and although I don’t have my friend’s type of printer, attempting to print does output to the printer queue for his printer profile, so I don’t know what to make of these messages.

    Incidentally: as I mentioned in an earlier post in this thread, upon uninstalling Java 6 Build 25, the mystery app "aaa" vanished from the list of installed apps, and now, upon installing Java 6 Build 26, it has NOT returned to the list of installed apps, whether viewed in Add or Remove Programs or in Revo Uninstaller. If memory serves, I believe it was right about at the time I uninstalled Java 6 Build 25 that the Google redirection problem was resolved. I don't know why it occurred to Kestrel13! to recommend uninstalling Java 6 Build 25, but as I recall, "aaa" did have a Java icon in Add or Remove Programs (and I believe also in Revo Uninstaller). At any rate, "aaa" has apparently not returned, and I wouldn't know if it's a legitimate part of Java or not. Perhaps I was correct in my guess that it was Downloader Agent AAA, and had somehow piggy-backed onto Java. But for all I know, maybe that's a stupid guess.

    Sorry for the ridiculously long message, but that’s the story at the moment.
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sometimes programs like this do not uninstall properly. Rerun ComboFix and then after it finishes rerun MGtools and attach new logs.

    Potentially yes.

    No. Not yet.

    Many software programs actually make use of browsers to aid in their downloads.

    They don't have to be running. Update programs, can make use of them without them running. Whether Avast uses the browser in the background or not is unknown.



    Then it is more likely not a malware problem which was why I suggested uninstalling and then manually cleaning ALL signs of Avast from the file system and registry. Are you sure that you did this correctly. If you did, then you have two options:
    1. Post for help on Avast's website.
    2. Use a different antivirus as I previously suggested.
    3. I know I said two ;), but you could reinstall the OS to potentially correct problems within the registry that may be causing this.
    Are you also using Avast on your PC ? Are you using a wired connection or wireless and how is your friends laptop connected? Is it connected the exact same way? None of this may really matter, I leaning more towards a registry or file system issue.

    Actually you can use the Administrator account in normal boot mode but you have to make a tweak to the registry to make it show. Or you have to delete all other admin accounts and then it would show by defaults.

    It would be worth a try to create a new admin user account and then reboot and login into it. DO NOT use a switch to another user account. Logout completely and reboot. Then use the new account. If this account does not work then it may be a Windows file system issue or a registry entry that is in a common area used by all user accounts.

    It would not block Avast and by the way the version being used is way out of date. Your log showed version 4.35.1000 and the current version is Version: 4.54.0.1000

    A I have not used the newer versions of Avast, but I don't remember anyone having problems shutting it down.

    Interesting I was getting the below which is what you were getting on the download.

    AvastDL.jpg

    However I figured out why I was getting this. I had some settings on my PC related to when we were working on changes to the servers used by MGs and this was causing some old pages to be shown because the old server address was being access. I fix that now and see the same version as you. I will download it and see what versions shows on the file.

    Likely just a false detection.

    Because the icon showed as a Java icon.

    It think it was just a corrupted entry from Sun Java.
     
    Last edited: Jun 12, 2011
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I downloaded it twice. Once from the link that shows the Author's Site and once from MG link. The author link is downloading the correct version. The one from MGs is downloading the old version. Again this is likely due to the recent changes in our servers. I will get it fixed.
     
  28. BobLewiston

    BobLewiston Private E-2

    I'll digest all this a little later today when I get a chance. For the moment, let me just SINCERELY thank you for being willing to work on such things essentially as a public service.

    >...and by the way the version being used is way out of date. Your log showed version 4.35.1000 and the current version is Version: 4.54.0.1000

    Yes, of course, it's way out of date because it can't update itself.

    >Because the icon showed as a Java icon.

    I had forgotten I sent him a screen shot that would enable him to see the icon. My bad.

    >Okay I downloaded it twice. Once from the link that shows the Author's Site and once from MG link. The author link is downloading the correct version. The one from MGs is downloading the old version. Again this is likely due to the recent changes in our servers. I will get it fixed.

    OK, good to know. I'll redownload it from the author's website. To tell you the truth, the reason I downloaded it from Major Geeks in that I trust you guys even more than the software authors in terms of the software being malware free.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Not sure that is your problem. The two databases used are reasonably up to date. The real problem is in a design deficiency of SUPERAntiSpyware. Unlike most other programs, when you run the internal update program of SUPERAntiSpyware, it only updates the databases!!! It does not update the main program itself. To get the program to update, you have to uninstall the old version and then install the new version. So to get version 4.54.0.1000 you have to uninstall what you have, then download and install the current version. Then you would run the internal update, to get the databases back to the current versions.

    All fixed now.
     
  30. BobLewiston

    BobLewiston Private E-2

    >>Incidentally, to my surprise, my friend just told me that he upgraded his SUPERAntiSpyware from the free version to the paid version

    >It would not block Avast and by the way the version being used is way out of date. Your log showed version 4.35.1000 and the current version is Version: 4.54.0.1000

    >>Yes, of course, it's way out of date because it can't update itself.

    Sorry, for some reason I thought you meant avast! was way out of date (which it is), not SUPERAntiSpyware. I've just updated SUPERAntiSpyware and its databases, both on my friend's computer and on my own.

    Incidentally, when trying to download the newest version of SUPERAntiSpyware, I first tried downloading from the author's website. This opened a new window, but it was just the same webpage I had already been on to select where I wanted to download from (namely, http://www.majorgeeks.com/SUPERAntiSpyware_d5116.html). Then I tried to download from Major Geeks', and that worked fine.
     
  31. BobLewiston

    BobLewiston Private E-2

    >I suggest uninstalling (avast!) and running a registry cleaner ( like CCleaner ) and remove all items related to Avast...

    >>my friend (whose computer I'm attempting to disinfect), now tells me that avast! has been unable to update for far longer than this most recent malware problem of his showed itself

    >Then it is more likely not a malware problem which was why I suggested uninstalling and then manually cleaning ALL signs of Avast from the file system and registry. Are you sure that you did this correctly.

    OK, I just now uninstalled avast! via CCleaner. Sorry, I didn’t realize you were actually telling me to do that, I thought it was just suggested as a possible course of action.

    >Rerun ComboFix and then after it finishes rerun MGtools and attach new logs.

    OK, here they are.

    >Are you also using Avast on your PC ?

    Yes.

    >Are you using a wired connection or wireless and how is your friends laptop connected? Is it connected the exact same way?

    Both my computer and my friend's computer are both connected via my wireless router.

    >Or you have to delete all other admin accounts and then it would show by defaults.

    >It would be worth a try to create a new admin user account and then reboot and login into it. DO NOT use a switch to another user account. Logout completely and reboot. Then use the new account. If this account does not work then it may be a Windows file system issue or a registry entry that is in a common area used by all user accounts.

    I see that for some reason (no doubt because Microsoft made it the default option), my friend set up his user account with administrative level privileges, rather than limited privileges, which isn't a good idea for surfing the web, and he's not savvy enough to need to use an account with administrative level privileges anyway, so I just limited his account's privileges. However, Windows XP Home Edition wouldn't allow me to do this without first creating another administrative level user account, so that's what I did, so I never saw the default Administrator user account, but of course that doesn't really matter.

    >>Incidentally, to my surprise, my friend just told me that he upgraded his SUPERAntiSpyware from the free version to the paid version,

    >It would not block Avast and by the way the version being used is way out of date. Your log showed version 4.35.1000 and the current version is Version: 4.54.0.1000

    It just occurred to me: since I updated my friend's SUPERAntiSpyware to version 4.54.0.1000 (from the Major Geeks website), does this version number apply to both the free and lifetime subscription versions? Because the newly installed version says it's version 4.54.0.1000 and that it's the Professional version.

    >>...I can find no way whatsoever to exit avast! when it's running, other than to uninstall it or turn off the computer (or presumably, to log off). Do you know if there is any “normal” way to exit avast! without resorting to such measures?

    > I have not used the newer versions of Avast, but I don't remember anyone having problems shutting it down.

    I don't mean that the means provided to shut down avast! aren't working, I mean that no means to shut down avast! are provided in the program, as bizarre as that may sound, at least that I can find.

    >>And now there is a new development. Upon booting up in Normal Mode, I'm getting an avast! warning of a possible unsafe app (please see attached screen shot "avast unsafe app warning").

    >Likely just a false detection.

    Can I stop these warnings?

    By the way, do you know how I can solve my friend's cursor-over problem? (See my first post in this thread.) As I commented to Kestrel13!, I find this indescribably obnoxious. Incidentally, my friend didn't give me his mouse, so I'm using the laptop's "onboard" mouse-type control below the keyboard. Would this problem go away if I used a mouse?
     

    Attached Files:

  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No I was not saying uninstall Avast using CCleaner. I said to uninstall Avast and then use CCleaner's registry cleaning option ( the Isssues button ) to scan the registry and the find all the items related to Avast and remove them. If that is what you meant you did and it still has problem, you need to do what I previously said as this is not malware problem. What I said was
    It does appear that PC Tool Firewall was properly removed.


    The current versions of free and paid are always the same. They just have different features enabled.

    Some scanners have the ability to put things on an ignore list. Obviously needed due to issues with false detections. I don't know what the current feature list is for Avast. Also you should report false detections to help get them fixed. Does not seem to matter much since you have a larger issue that the program will not update.

    I suggest starting a thread for this in the Software Forum as this is more likely a Windows issue.



    Since you do not appear to be having any more malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  33. BobLewiston

    BobLewiston Private E-2

    Thanks again to chaslang & Kestrel13! for all their help!
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome from both of us. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds