Crypto infection?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mindgames, Jul 28, 2014.

  1. mindgames

    mindgames Private E-2

    Hi

    I've had some great help here before, and I'm hoping that one of you kind souls will be willing to help out again!

    I've noticed that since yesterday I have been having some pop-ups from Malware Bytes telling me that it has blocked access to and from certain websites - even though I have no programs open (that I know of) that are trying to connect to anything.

    A couple of the windowa that have popped up have mentioned "Microsoft/Crypto" which I have no knowledge of.

    Also I got a message saying that "steelwerx WhoAMI" is no longer running. Which I have never heard of.

    Obviously something is really wrong... Please could you look at the logs and see what's wrong?

    Thanks in advance!
     

    Attached Files:

  2. mindgames

    mindgames Private E-2

    i'm also posting a couple of protection logs from Malwarebytes.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I'm not seeing any malware in those logs.

    Have to be more specific about that.

    C:\ProgramData\Microsoft\crypto is a legit file path.

    Something like a randomly named file residing inside that folder is bad.
    That's probably due to the fact you ran MGTools ;)
     
  4. mindgames

    mindgames Private E-2

    Thanks for your reply.

    But something is definitely wrong. I'm sat here now, and Malwarebytes is - every few seconds - telling me that it's blocking websites.

    IP 222.186.19.18
    Port 6881
    Inbound
    Process: C:\Windows\explorer.exe

    It's pretty much permanently coming up now, with slight variations on the IP address:

    222.186.19.6
    222.186.19.7
    and so on.

    Would the Malwarebytes Protection logs help you - which document all the malicious websites that it blocks?

    I'm not sat here surfing by the way, trying to go these sites - it's just happening while I'm looking at the Major Geeks site!

    Thanks
     
  5. mindgames

    mindgames Private E-2

    and the Crypto alerts came up as "bad processes" in the Rogue Killer log.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run RogueKiller please and attach the new log.



    Please download SystemLook from the first link below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      rsa64.dll
      CryptoProvider.dll
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  7. mindgames

    mindgames Private E-2

    Thanks.

    Rogue Killer log attached. Looks like lots of stuff in there in the Registry section. :cry

    System Look log:

    SystemLook 30.07.11 by jpshortstuff
    Log created at 17:59 on 29/07/2014 by Mat
    Administrator - Elevation successful

    ========== filefind ==========

    Searching for "rsa64.dll"
    C:\ProgramData\Microsoft\Crypto\RSA64\rsa64.dll --a---- 2180096 bytes [17:11 27/07/2014] [17:11 27/07/2014] 524FF8879F3BD0CF80C7F7508160810B
    C:\Users\All Users\Microsoft\Crypto\RSA64\rsa64.dll --a---- 2180096 bytes [17:11 27/07/2014] [17:11 27/07/2014] 524FF8879F3BD0CF80C7F7508160810B

    Searching for "CryptoProvider.dll"
    C:\ProgramData\Microsoft\Crypto\RSA64\CryptoProvider.dll --a---- 2604032 bytes [17:11 27/07/2014] [17:11 27/07/2014] (Unable to calculate MD5)
    C:\Users\All Users\Microsoft\Crypto\RSA64\CryptoProvider.dll --a---- 2604032 bytes [17:11 27/07/2014] [17:11 27/07/2014] (Unable to calculate MD5)

    -= EOF =-
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.
    Code:
    :Files
    C:\ProgramData\Microsoft\Crypto\RSA64\rsa64.dll
    C:\Users\All Users\Microsoft\Crypto\RSA64\rsa64.dll 
    C:\ProgramData\Microsoft\Crypto\RSA64\CryptoProvider.dll 
    C:\Users\All Users\Microsoft\Crypto\RSA64\CryptoProvider.dll
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    Re run RogueKiller again and attach newest log please.
     
  9. mindgames

    mindgames Private E-2

    Thanks.

    Attaching requested logs.

    Still got the Malwarebytes "malicious website blocked" coming up every few seconds.
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run my instructions in post #6 to use SystemLook again. Attach the NEW log.
     
  11. mindgames

    mindgames Private E-2

    Thanks. I have to first let you know that after my last post, I rebooted the PC again - as after it ran OTM, I wasn't sure if it had actually rebooted or not. My desktop screen froze, and then Windows asked me to login again - but the PC never actually went off and came back on again. Now I've done it, the Malwarebytes warnings have stopped.

    Here's the SystemLook log as requested:

    SystemLook 30.07.11 by jpshortstuff
    Log created at 22:19 on 29/07/2014 by Mat
    Administrator - Elevation successful

    ========== filefind ==========

    Searching for "rsa64.dll"
    C:\ProgramData\Microsoft\Crypto\RSA64\rsa64.dll --a---- 2180096 bytes [20:09 29/07/2014] [20:09 29/07/2014] 524FF8879F3BD0CF80C7F7508160810B
    C:\Users\All Users\Microsoft\Crypto\RSA64\rsa64.dll --a---- 2180096 bytes [20:09 29/07/2014] [20:09 29/07/2014] 524FF8879F3BD0CF80C7F7508160810B
    C:\_OTM\MovedFiles\07292014_210747\C_ProgramData\Microsoft\Crypto\RSA64\rsa64.dll --a---- 2180096 bytes [17:11 27/07/2014] [17:11 27/07/2014] 524FF8879F3BD0CF80C7F7508160810B

    Searching for "CryptoProvider.dll"
    C:\_OTM\MovedFiles\07292014_210747\C_ProgramData\Microsoft\Crypto\RSA64\CryptoProvider.dll --a---- 2604032 bytes [17:11 27/07/2014] [17:11 27/07/2014] DCD4B87A97210D76D3B049BE7DB4C875

    -= EOF =-
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.



    Re run the SystemLook instructions once more, or navigate to where these files are/were and tell me if they are present or not.
     
  13. mindgames

    mindgames Private E-2

    Thanks.

    I ran Avenger, but the first time it ran, Avast popped up and said it was stopping the process and had deleted it. I rebooted, and got the Avenger txt file, but it said something about aborting the procedure.

    I turned off Avast and repeated everything, and it seemed to work ok, let me reboot, I saw the cleaner thing come up - but the Avenger.txt file hasn't updated, it's still the same one from the first aborted attempt.

    So i've run SystemLook and it says:

    SystemLook 30.07.11 by jpshortstuff
    Log created at 10:25 on 30/07/2014 by Mat
    Administrator - Elevation successful

    ========== filefind ==========

    Searching for "rsa64.dll"
    C:\ProgramData\Microsoft\Crypto\RSA64\rsa64.dll --a---- 2180096 bytes [20:09 29/07/2014] [20:09 29/07/2014] 524FF8879F3BD0CF80C7F7508160810B
    C:\Users\All Users\Microsoft\Crypto\RSA64\rsa64.dll --a---- 2180096 bytes [20:09 29/07/2014] [20:09 29/07/2014] 524FF8879F3BD0CF80C7F7508160810B
    C:\_OTM\MovedFiles\07292014_210747\C_ProgramData\Microsoft\Crypto\RSA64\rsa64.dll --a---- 2180096 bytes [17:11 27/07/2014] [17:11 27/07/2014] 524FF8879F3BD0CF80C7F7508160810B

    Searching for "CryptoProvider.dll"
    C:\_OTM\MovedFiles\07292014_210747\C_ProgramData\Microsoft\Crypto\RSA64\CryptoProvider.dll --a---- 2604032 bytes [17:11 27/07/2014] [17:11 27/07/2014] DCD4B87A97210D76D3B049BE7DB4C875

    -= EOF =-
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please download Combofix to your desktop. Please refer to these instructions prior to running.

    Attach the log once complete.
     
  15. mindgames

    mindgames Private E-2

    Thanks.

    I'm having a bit of trouble - Avast really doesn't seem to like it.

    It deletes it when I've downloaded it - if I disable Avast, I can download it and run it, but it deletes it as soon as it opens.

    Some kind of Win32 virus it suspects...

    What should I do? Disable Avast for the whole downloading and running process? Bit nervous to do that but will if required
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes please. Combofix is fine, Avast will naturally be suspicious of it.
     
  17. mindgames

    mindgames Private E-2

    ok thanks, have run it and attached the file.
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    jbyfh
    odsy
    sclg
    
    File::
    c:\windows\SysWow64\drivers\cgxgqw.sys
    c:\windows\SysWow64\drivers\segoa.sys
    c:\windows\SysWow64\drivers\lkcj.sys
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.


    Reboot.
    Have these files gone now?

    • C:\ProgramData\Microsoft\Crypto\RSA64\rsa64.dll
    • C:\Users\All Users\Microsoft\Crypto\RSA64\rsa64.dll
     
  19. mindgames

    mindgames Private E-2

    thanks, attached is the Combo Fix log.

    System look says:

    SystemLook 30.07.11 by jpshortstuff
    Log created at 23:27 on 30/07/2014 by Mat
    Administrator - Elevation successful

    ========== filefind ==========

    Searching for "rsa64.dll"
    C:\_OTM\MovedFiles\07292014_210747\C_ProgramData\Microsoft\Crypto\RSA64\rsa64.dll --a---- 2180096 bytes [17:11 27/07/2014] [17:11 27/07/2014] 524FF8879F3BD0CF80C7F7508160810B

    Searching for "CryptoProvider.dll"
    C:\_OTM\MovedFiles\07292014_210747\C_ProgramData\Microsoft\Crypto\RSA64\CryptoProvider.dll --a---- 2604032 bytes [17:11 27/07/2014] [17:11 27/07/2014] DCD4B87A97210D76D3B049BE7DB4C875

    -= EOF =-
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    These other files will not budge now...let's try again.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    C:\Windows\system32\drivers\cgxgqw.sys
    C:\Windows\system32\drivers\segoa.sys
    C:\Windows\system32\drivers\lkcj.sys
    c:\windows\SysWow64\drivers\cgxgqw.sys
    c:\windows\SysWow64\drivers\segoa.sys
    c:\windows\SysWow64\drivers\lkcj.sys
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.
     
  21. mindgames

    mindgames Private E-2

    Hi. Here's the ComboFix log.
     

    Attached Files:

  22. mindgames

    mindgames Private E-2

    System Look says:

    SystemLook 30.07.11 by jpshortstuff
    Log created at 10:14 on 31/07/2014 by Mat
    Administrator - Elevation successful

    ========== filefind ==========

    Searching for "rsa64.dll"
    C:\_OTM\MovedFiles\07292014_210747\C_ProgramData\Microsoft\Crypto\RSA64\rsa64.dll --a---- 2180096 bytes [17:11 27/07/2014] [17:11 27/07/2014] 524FF8879F3BD0CF80C7F7508160810B

    Searching for "CryptoProvider.dll"
    C:\_OTM\MovedFiles\07292014_210747\C_ProgramData\Microsoft\Crypto\RSA64\CryptoProvider.dll --a---- 2604032 bytes [17:11 27/07/2014] [17:11 27/07/2014] DCD4B87A97210D76D3B049BE7DB4C875

    -= EOF =-
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We are no longer looking for what we were previously with SystemLook.
    Since I had you run Combofix these bad files have been discovered.

    • c:\windows\SysWow64\drivers\cgxgqw.sys
    • c:\windows\SysWow64\drivers\segoa.sys
    • c:\windows\SysWow64\drivers\lkcj.sys

    I want to try using Combofix once more as I have just found some more bad registry related.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    File::
    c:\windows\SysWow64\drivers\cgxgqw.sys
    c:\windows\SysWow64\drivers\segoa.sys
    c:\windows\SysWow64\drivers\lkcj.sys
    
    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1CryptoProviderIcons]
    [-HKEY_CLASSES_ROOT\CLSID\{24808826-C2BF-4269-B3BA-89D1D5F431A4}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.
     
  24. mindgames

    mindgames Private E-2

    OK thanks. Here's the Combo Fix log.
     

    Attached Files:

  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am seeking advice regarding your thread. Let's try this:

    [​IMG] Please download BlitzBlank to your desktop.
    • Double-click BlitzBlank.exe to open (Vista/7 right-click and select Run as Administrator)
    • Press OK at the warning prompt.
    • Click the Script tab
    • Copy the text inside the code box below and paste it into the text-field.
    Code:
    [COLOR="DarkRed"]DeleteFile:[/COLOR]
    c:\windows\SysWow64\drivers\cgxgqw.sys
    c:\windows\SysWow64\drivers\segoa.sys
    c:\windows\SysWow64\drivers\lkcj.sys
    • Now click the Execute Now button.
    • The fix will require a reboot in order to complete successfully.
    • Upon reboot, locate C:\blitzblank.log and attach this log to your next message. (How to attach)


    Now run Combofix (Not the same way as before) just double click it to run it. Attach the log once done.
     
  26. mindgames

    mindgames Private E-2

    Thanks. Are these serious problems I have, then?

    I've run BlitzBlank and Combofix and am attaching the logs.

    Thank you.
     

    Attached Files:

  27. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The files have finally gone. How is the machine behaving? :)
     
  28. mindgames

    mindgames Private E-2

    Thank you!

    Funnily enough the machine is behaving a bit strangely. Things taking a longer time to open, things freezing etc. Doesn't seem quite right yet...
     
  29. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm, I don't think there is anything left for me to attack, but run this one more time:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    If I don't see anything in those logs malware wise then you will have to post about it in the software forum. ;)
     
  30. mindgames

    mindgames Private E-2

    Thanks - here it is.
     

    Attached Files:

  31. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    EDIT: post meant for another user. I'll review those logs now and see if anything remains. :)
     
  32. mindgames

    mindgames Private E-2

    Yes I do have the Windows 7 CD.

    What's actually wrong? sorry to be slow but I can't tell.
     
  33. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Read my edited post. :) My apologies.
     
  34. mindgames

    mindgames Private E-2

    no worries!
     
  35. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete this: C:\Windows\ahigzo.txt

    Run these:

    Please download AdwCleaner by Xplode and save to your Desktop.

    • Double click on AdwCleaner.exe to run the tool.
    • Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.


    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Run this also and attach the results.

    Using ESET's Online Scanner
     
  36. mindgames

    mindgames Private E-2

    Thanks, here you go.
     

    Attached Files:

  37. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not finding anything else malware related here. Are you ready for final steps? :) (You can always post in the software forum regarding any outstanding non malware related issues)
     
  38. mindgames

    mindgames Private E-2

    yes please! :)
     
  39. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key [​IMG] and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    8. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    9. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  40. mindgames

    mindgames Private E-2

    Thank you very much.

    I've done everything below - all seemed to work, except running the MGClean.bat file. I right clicked on it and chose "run as admin", but it didn't seem to do anything? A black window flashed up very briefly but too quickly for me to read what it said in it!
     
  41. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I would imagine the C:\MGTools folder has gone now though?
     
  42. mindgames

    mindgames Private E-2

    No, it's still there. With loads of stuff in it!
     
  43. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK just try double clicking the MGClean.bat file, and if it does not work just manually delete the MGTools folder.
     
  44. mindgames

    mindgames Private E-2

    Thanks, it's worked now.

    Thanks so much for all your patience and help.

    Cheers.
     
  45. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds