RougeKiller fails during prescan

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Buckleyterp, Nov 23, 2014.

  1. Buckleyterp

    Buckleyterp Private First Class

    Dear Benefactors,
    I have used your malware removal process years ago with total resolution of the problem.
    Now another laptop, a Dell Inspiron running 64-bit windows 7, is connected to our wireless router but three browsers fail to access any net addresses. Avast free antivirus on the affected computer regularly gives notice of infected files. An out-of-date Malwarebytes was resident on the computer and quarantined 426 files on first pass and another 35 on rescan. Still, connection with the internet was not possible and so Malwarebytes remains out-of-date. A second PC and a Mac have no trouble with using the router.
    It was at this point that it became necessary to visit Majorgeeks to go through he whole process again and get some competent help.
    I started with the browser redirect instructions and so ran through the cache emptying and other steps as directed, TDSSkiller and MBRCheck. No files were generated by TDSSK and nothing showed up during MBRC, so I began to perform the general malware cleaning protocol. Avast is the only security running, there is no firewall. Defogger showed no emulations and Ccleaner did its thing. I loaded all programs via SD card, locked when it is inserted into the infected computer.
    At Step 3, RogueKiller loaded and started but it has been stalled at 40% on the right sidebar 'checking processes' prescan for the past three hours. The program performed perfectly on the other PC.
    I am therefore hung at this point.
    Buckley
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just run RogueKiller in safe mode.
     
  3. Buckleyterp

    Buckleyterp Private First Class

    Continuing to follow directions...

    ...here are the logs. TDSS killer came up clean becuse it was run, as mentioned, before signing on to the Majorgeeks protocol, as did RogueKiller, but the logs are attached, as directed.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below programs. If you do not find them or they will not uninstall, just keep going.
    AVG Web TuneUp
    ClickForSale
    FlashCoUppon
    GetDiscountApp
    Java 7 Update 13
    Java(TM) 6 Update 17
    Optimizer Pro v3.2
    Search Protect
    Sendori
    SheopPerMaster
    Social Privacy DNS
    Social Privacy

    Also uninstall anything else from AVG and McAfee if you see any other items in your installed programs lists.



    Now install the current version of Sun Java from:
    Make sure that when you install the new version of Java that you uncheck the Install the Ask Toolbar junkware checkbox. Also if it asks if you want to install McAfee Security Scan Plus that you uncheck this too. You do not need to add these unncessary items and to your PC. Also just in case Oracle changes the Java installation in the future to possibly install other junk, uncheck all but just installing Java.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://mysearch.avg.com/?cid={4E087668-B992-4FB9-9D45-4A85EF814EF1}&mid=4836db035fbc47d18cc475f39d43eb11-aececa9502f49598e1e35dfc208a5629050c4da0&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-11-09%2014:37:32&v=4.0.0.19&pid=wtu&sg=&sap=hp
    O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - (no file)
    O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - (no file)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: AVG Web TuneUp - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Web TuneUp\4.0.0.19\AVG Web TuneUp.dll
    O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
    O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY
    O4 - HKLM\..\Run: [dnsshield] C:\Program Files (x86)\Social Privacy DNS\dnswatch.exe
    O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG Web TuneUp\vprot.exe"
    O4 - HKCU\..\Run: [Optimizer Pro] C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe
    O10 - Broken Internet access because of LSP provider 'c:\windows\system32\sendori.dll' missing
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (file missing)
    O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.10\ViProtocol.dll
    O20 - AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll c:\progra~2\optimi~1\optpro~1.dll



    After clicking Fix, exit HJT.



    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
     
    :Services
    Application Sendori
    AVGIDSAgent
    avgwd
    gupdate
    gupdatem
    gusvc
    McAfee SiteAdvisor Service
    McComponentHostService
    McMPFSvc
    Service Sendori
    sndappv2
    vToolbarUpdater18.1.10
     
     
    :Files
    C:\$AVG
    C:\found.000
    C:\found.001
    C:\found.002
    C:\msdia80.dll
    C:\SearchProtect
    C:\Program Files (x86)\Ask.com
    C:\Program Files (x86)\AVG
    C:\Program Files (x86)\Social Privacy  DNS
    C:\Program Files (x86)\AVG Web TuneUp
    C:\Program Files (x86)\Optimizer Pro
    C:\Program Files (x86)\SearchProtect
    C:\Program Files (x86)\Sendori
    C:\ProgramData\aa4cc793a0ca47d7
    C:\ProgramData\AVG Secure Search
    C:\ProgramData\AVG Security Toolbar
    C:\ProgramData\AVG Web TuneUp
    C:\ProgramData\AVG2013
    C:\ProgramData\ClickFForSSale
    C:\ProgramData\ClickForSale
    C:\ProgramData\deaali4Me
    C:\ProgramData\FlashCoUppon
    C:\ProgramData\GetDiscountApp
    C:\ProgramData\LowPricesApp
    C:\ProgramData\mbgpdogehjnckpgfalijkafihlomiogj
    C:\ProgramData\PnegTOPPTCOnvert
    C:\ProgramData\Sendori
    C:\ProgramData\SheopPerMaster
    C:\ProgramData\TicTaaCoUpon
    C:\Windows\tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job
    C:\Windows\tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job
    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4211984369-122285141-3675069962-1001Core1cec6d5dbe23bbb.job
    C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4211984369-122285141-3675069962-1001UA1cec6d5dcae4147.job
    C:\Windows\tasks\SmartPCFix Task.job
    C:\Windows\system32\tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv
    C:\Windows\system32\tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv
    C:\Windows\system32\tasks\D67H59L1
    C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore
    C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA
    C:\Windows\system32\tasks\GoogleUpdateTaskUserS-1-5-21-4211984369-122285141-3675069962-1001Core1cec6d5dbe23bbb
    C:\Windows\system32\tasks\GoogleUpdateTaskUserS-1-5-21-4211984369-122285141-3675069962-1001UA1cec6d5dcae4147
    C:\Windows\system32\tasks\Scheduled Update for Ask Toolbar
    C:\Windows\system32\tasks\SmartPCFix Task
    C:\Windows\TEMP\*.*
    C:\Users\Silanath Peungjesada\AppData\Local\Temp\*.*
     
     
    :Reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "Google Update"=-
    "Optimizer Pro"=-
    "swg"=-
     
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "ApnUpdater"=-
    "AVG_UI"=-
    "dnsshield"=-
    "vProt"=-
     
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\windows\currentVersion\Run]
    "ApnUpdater"=-
    "AVG_UI"=-
    "dnsshield"=-
    "vProt"=-
     
    [HKEY_USERS\S-1-5-21-4211984369-122285141-3675069962-1001\Software\Microsoft\Windows\CurrentVersion\run]
    "Google Update"=-
    "Optimizer Pro"=-
    "swg"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=""
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{47C64E8A-8014-4512-AD44-C1B17BB6023C}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{7386E50E-292E-4391-87AE-AC4A985F5934}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{8D5C4167-4592-4228-9CAE-D2753F0F2D7A}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
    "Tabs"="res://ieframe.dll/tabswelcome.htm"
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXT log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Nov 23, 2014
  5. Buckleyterp

    Buckleyterp Private First Class

    Wow! Thank you for the lightening fast response. I will get on it ASAP.
    BT
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Almost forgot to post the below. Just incase your internet access is still broken, do the below.

    Now download LSP - Fix

    Run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the sendori.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move sendori.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.
    If it is already in the Remove section, just click Finish.
     
  7. Buckleyterp

    Buckleyterp Private First Class

    Dear Chaslang, Kestrel13, et. al.,

    Firefox, Chrome and MIE9 are now fully functional, thanks to you. And thank you for the LSPfix postscript - that was very necessary.

    As you anticipated, certain programs, while they did show up, would not uninstall, notably AVG and all of the Java programs.
    Sun Java would not install (Error code 1601 corrupt registry file)

    May I now try to uninstall the suggested Java programs and install the latest program?

    One point of confusion: There was no MGtools\analyse.exe in the root directory, on the computer, or mentioned anywhere on the ‘net except for web pages where it is mentioned in Majorgeeks. I had run MGtools again, thinking that MGtools\analyse would show up, but no. So I ran HijackThis. The HijackThis results included most of the lines that you indicated to me except 6 lines, one of which was corrected by the LSPfix manuever.

    The affected computer has been used and abused by another family member for five years. Time for me to become the administrator and install privilege safeguards.

    Again, thank you.

    Buckley :wave
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Yes there is. And it is still there. If it did not exist you would not have been able to run all of the programs in MGtools to collect the logs.

    C: Is the driver letter
    \MGtools is the folder
    analyse.exe is the file ( program ) inside of the C:\MGtools folder

    Yes it did as stated above.

    Please delete the HijackThis.exe file you put in your C:\ folder now.


    The new logs show that you either ran MGtools.exe at the wrong time ( not at the end ) or that you did not fix everything as requested. I suspect your log is out of order. SO please run the below and please do not tell me that the C:\MGtools folder and GetLogs.bat do not exist because they do. I can see them in your logs.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
     
  9. Buckleyterp

    Buckleyterp Private First Class

    Now I get "The Windows Installer Service couldnot be Acessed". What forum thread do you want me to ask this in?
    (I tried starting it from services directory and unreged and rereged it using cmd, still no good.)
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When exactly do you get this? I did not ask you to install anything in my last message.

    You are not supposed to be doing anything except what we request per the READ & RUN ME instructions.
     
  11. Buckleyterp

    Buckleyterp Private First Class

    Please excuse my ignorance.
    Problem one is the computer fixing has left me cross-eyed and buggy.
    Problem two is that the Dell search is cr## and won't give me reliable or partial matches. The Dell search could not find MGtools on the disk. I knew where I put MGtools.exe, but lost sight of the other MG** files.
    Got it. Sorry you had to walk me through it.
    I deleted HJT.
    Attached is the zipfile you requested.
    Still cannot delete AVG2013 or Ask Toolbar updater and Windows Installer will not work. Internet access is normal now, though.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so let's work around the issues that do not allow you to uninstall AVG or ASK Toolbar.


    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Repair MSI (Windows Installer)
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished. If it does not then reboot it yourself.

    Now download and run the AVG 64 bit removal tool from the below link:

    http://www.majorgeeks.com/files/details/avg_remover.html


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7, or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!


    Anything left over now we will remove with more manual instructions. It may become necessary to uninstall Avast too. Your PC may have gotten into a bad state due to having multiple AV programs installed ( AVG, Avast and McAfee )
     
  13. Buckleyterp

    Buckleyterp Private First Class

    Again, my mistake.
    I thought that the malware had been vanquished and that we were finished with the project.
    Please let me know when it will be safe or even possible to configure the computer to minimize vulnerability.

    Buckley
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please complete the instructions in my last message.
     
  15. Buckleyterp

    Buckleyterp Private First Class

    I am working on your advice. The scans are, indeed, taking time, as you said they would. I am currently on step 5 of windows repair.
    B
     
  16. Buckleyterp

    Buckleyterp Private First Class

    How it is working?
    All 3 browsers still have normal function.
    The AVG shortcut disappeared from the desktop. That is a good sign.
    I noticed that when I right click on an application, I do not get a full menu with 'Run as Administrator' on it at first. When I right click a second time, then I do. It may just have something to do with the incredible latency of this machine (my wife's machine -- not my machine).
    As far as how other services behave - I don't know; I am still waiting for the opportunity to clean all of the trash off of this system.
    Thank you for your forbearance.

    B
     

    Attached Files:

  17. Buckleyterp

    Buckleyterp Private First Class

    Extra information.
    Malwarebytes is still resident on the drive from previous step.
    Last night it did its scheduled scan and gave me the attached report.
    No action was taken.
    B
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In your last logs when you ran GetLogs.bat you had all three browsers ( Firefox, Internet Explorer, and Chrome ) running? Why? This can cause a PC to slow down since they all use a lot of memory.

    There are still a few left overs from McAfee to remove. Let's see if we can finish getting rid of them and also get your Java Software updated too.

    Uninstall the below programs. If you do not find them or they will not uninstall, just keep going.
    Java 7 Update 13
    Java(TM) 6 Update 17 (64-bit)
    Java(TM) 6 Update 17
    Java(TM) 7 Update 5 (64-bit)
    TicTaaCoUpon


    Now install the current version of Sun Java from:
    Make sure that when you install the new version of Java that you uncheck the Install the Ask Toolbar junkware checkbox. Also if it asks if you want to install McAfee Security Scan Plus that you uncheck this too. You do not need to add these unncessary items and to your PC. Also just in case Oracle changes the Java installation in the future to possibly install other junk, uncheck all but just installing Java.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (file missing)
    O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (file missing)
    O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (file missing)


    After clicking Fix, exit HJT.


    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
     
    :Files
    C:\Users\Silanath Peungjesada\Desktop\avgremover.log
    C:\Users\Silanath Peungjesada\Desktop\avgremover_msilog.txt
    C:\Users\Silanath Peungjesada\Desktop\avg_remover_stf_x64_2015_5501.exe
    C:\Users\Silanath Peungjesada\Desktop\lspfix
    C:\Users\Silanath Peungjesada\Desktop\lspfix.zip
    
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}]
    
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064}"=-
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now download and save the below McAfee Removal Tool to your desktop and then run it.

    http://www.majorgeeks.com/files/details/mcafee_consumer_product_removal_tool.html

    Reboot after running the McAfee tool!




    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  19. Buckleyterp

    Buckleyterp Private First Class

    Thanks, chaslang.
    Everything seems to be cleaning up according to plan.
    Thanks for the tip about multiple browsers. It is my aim to restore some speed to this laptop. At the end of cleaning, if you could point me in the right direction toward acceleration do's and dont's, it would be appreciated.
    Buckley
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Things like this can be discussed in the Software Forum, but first thing two things I suggest are:
    1. Go thru all installed programs and uninstall anything that is not used or not needed.
    2. Take a look at startup processes and stop unnecessary programs from loading at startup.
    You're logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  21. Buckleyterp

    Buckleyterp Private First Class

    When I double click on enableUAC.reg the Notepad opens with the commands but there is no indication that any changes are running. Checking the
    Control Panel -> UAC it is still on 'never notify'. Of course I could change it manually, but that is not what you want me to do. And if I right click on enableUAC.reg, no Run as Administrator line is present. I had this problem with a .reg file two days ago - it wouldn't insert text into the registry - when I strayed from the majorgeeks protocol and tried to fix the nonfunctional Windows Installer by following a Microsoft help post. (I never did alter the registry in any way for this reason).

    How can we correct the inability to run .reg files?

    I am stopped here since I do not want to remove enableUAC.reg before solving or understanding this.

    Buckley
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay it sounds like your PC has lost the file association for .reg files. Let's try a simple quick fix and hope this is enough. Disable any protection software before continuing.

    I assume that you have not finished the rest of the final instructions and still have the C:\MGtools and contents available.

    Open Windows Explorer ( hold down the Windows Logo key and press the 'e' key at the same time ). Then Navigate to the C:\MGtools folder and locate the FixFA.bat file. If you only see FixFA and not FixFA.bat, you probably have already set file extensions to be hidden. Try right clicking on the FixFA.bat file and select Run As Administrator. If it does not run this way then just double click on it. If it appears to run then reboot your PC.
    After reboot, see if you can now run the enableUAC.reg registry patch by either right click and Run As Admin or by double clicking on it.
     
  23. Buckleyterp

    Buckleyterp Private First Class

    I was able to run fixFA.bat, at least the dos cmd window flashed open and closed quickly, but when I rebooted and right clicked on enableUAC.reg there was no 'Run as Administrator' command and when I double clicked on it there was just the appearance of Notepad and UAC is still 'never notify'.

    Buckley
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then it appears you may have issues within Windows itself. It does not look like this was due to the malware/junkware you had. Let's try another way to import the registry patch.


    Click Start, and type regedit into the search box.
    • You should see a regedit.exe and icon appear in the Programs area of the Start Menu.
    • Right click on regedit.exe and select Run As Administrator
    • Then in the Registry Editor menu click File and select Import.
    • Navigate to the C:\MGtools\enableUAC.reg file and double click it. Allow it to be added to the registry. Please observe whether you receive a success message.
    • If it imports successfully then immediately reboot your PC.
    After reboot, finish the rest of the Final Instructions and then at the end, double check your slider for UAC and set it correctly if it is not correctly set.
     
  25. Buckleyterp

    Buckleyterp Private First Class

    I received a success message: "..the values and keys....have been added to the registry..."

    I also received an error message when I rebooted - it held up the reboot. The window had the title: "WLTRAY.EXE - Application Error" and the text:
    "The exception unknown software exception (0x015000f) occurred in the application at location 0x771ddf0c."

    Okay I finished rebooting.

    B
     
  26. Buckleyterp

    Buckleyterp Private First Class

    Following your instructions to clean therapeutic programs and files off of desktop and to go through programs and get rid of superfluous ones.

    I tried to uninstall Ask Toolbar Updater and it wouldn't let me; it said that I didn't have sufficient administrative privileges to do it.

    With the exception of a few obvious shopping programs, I really do not know which programs to remove - they all make themselves sound indispensable.

    So I installed 'Should I Remove It'. This worked pretty well on my other PC to give me the confidence to remove 4 or 5 useless programs. I know it is not a great idea to base my decisions on what the majority of other users are doing - what do they know? - but it is better than nothing if I temper it with my own judgement.

    However - "Should I Remove IT' will not work on this problem PC. It installs and I ran the repair function from their installer. It failed to put a shortcut on this desktop. When I found it in the Program Files(x86)/Reason folder, I tried to run it twice (before and after running the repair) and both times the error message 'Should i Remove It' has stopped running' appeared several seconds after I ran it.

    This PC may be free of malware but it sure is whacked up.

    Buckley
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not related to anything we have been doing. This is for your Broadcom Wireless Manager ( came with your Dell PC ). If you continue to have problems with this you may need to reinstall the software / drivers for this. This would be a topic for the Software Forum.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not a topic for this forum.

    Yes I made that comment a few times.
     
  29. Buckleyterp

    Buckleyterp Private First Class

    Thanks a lot for everything, chaslang!

    I finished resetting the system restore.

    I will move over to software to clean up the other issues.

    You and your compadres are great!

    Buckley
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds