Several Problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by camilete, Jan 31, 2008.

  1. camilete

    camilete Private E-2

    Hello, thanks in advance for the help. I already did the whole cleaning procedure and I attached the files requested.
    The problem I have is that I cannot turn off the computer, also it is very slow, also If i press ctrl, alt, Del, nothing happens. Spybot finds Munga_Bunga everytime but doesnt seem to get rid of it.
    I uninstalled the MSN I dont know If that produced a crash.
    help would be great appreciated
    regards,
     

    Attached Files:

  2. camilete

    camilete Private E-2

    There is one more thing, when I unplug the power cable the battery dies in 5 minutes...
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    More than likely not due to malware but we will fix potential problems including non-malware and see what happens. Most of your slow down issue is related to all the unnecessary software you are running. And McAfee may be a large factor too.

    Attach a log from Spyboy so we can see exactly what it is finding. Just right click in the scan window when it finishes the scan and save the log.

    Not malware. Post in the Hardware Forum. Sounds like you need a new battery.

    You saved ComboFix here:

    C:\Documents and Settings\cduque.PROEXPORTDOM\My Documents\cleaner\ComboFix.exe

    You must follow the instructions in the READ ME properly to avoid having problems. Please save ComboFix.exe to your Desktop now.

    Did you purchase XoftSpySE? If not then uninstall it now.

    You said you uninstalled MSN but I still see MSN Messenger in your log. Do you use MSN Messenger?

    Uninstall any software that you do not use. That includes uninstalling LiveUpdate 1.7 (Symantec Corporation) since you don't have Symantec installed anymore.

    Why do you always need the below running at startup?
    "Babylon Client"="C:\\Program Files\\Babylon\\Babylon.exe -AutoStart"

    What it the below for and do you use it?
    O4 - HKCU\..\Run: [DellTransferAgent] "C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe"

    Do you really need the below in your Trusted Zone?
    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 3
    Java 2 Runtime Environment, SE v1.4.2_03
    Java(TM) SE Development Kit 6 Update 1
    Java(TM) SE Runtime Environment 6 Update 1

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
    O4 - HKLM\..\RunServices: [java] Keygen.exe
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - Startup: conecta2.bat
    O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: (no name) - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now reboot your PC

    After reboot, run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  4. camilete

    camilete Private E-2

    First of all thank you for taking the time and helping me.
    after each instruction Im replying in BLACK

    Quote:
    Originally Posted by camilete
    The problem I have is that I cannot turn off the computer, also it is very slow, also If i press ctrl, alt, Del, nothing happens.

    More than likely not due to malware but we will fix potential problems including non-malware and see what happens. Most of your slow down issue is related to all the unnecessary software you are running. And McAfee may be a large factor too.

    still not working, CTRL, alt, del and nothing happens. if I go to start, shut down. it wont work, it wont restart shut down or anything

    Quote:
    Originally Posted by camilete
    Spybot finds Munga_Bunga everytime but doesnt seem to get rid of it.

    Attach a log from Spyboy so we can see exactly what it is finding. Just right click in the scan window when it finishes the scan and save the log.
    it dissapeared

    Quote:
    Originally Posted by camilete
    There is one more thing, when I unplug the power cable the battery dies in 5 minutes...

    Not malware. Post in the Hardware Forum. Sounds like you need a new battery.

    You saved ComboFix here:

    C:\Documents and Settings\cduque.PROEXPORTDOM\My Documents\cleaner\ComboFix.exe

    You must follow the instructions in the READ ME properly to avoid having problems. Please save ComboFix.exe to your Desktop now.
    done
    Did you purchase XoftSpySE? If not then uninstall it now.
    done
    You said you uninstalled MSN but I still see MSN Messenger in your log. Do you use MSN Messenger?
    i have messenger, I uninstalled the msn explorer, i think
    Uninstall any software that you do not use. That includes uninstalling LiveUpdate 1.7 (Symantec Corporation) since you don't have Symantec installed anymore.
    done
    Why do you always need the below running at startup?
    "Babylon Client"="C:\\Program Files\\Babylon\\Babylon.exe -AutoStart"
    no, deleted all babylon related findings
    What it the below for and do you use it?
    O4 - HKCU\..\Run: [DellTransferAgent] "C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe"
    no idea, couldn't delete it
    Do you really need the below in your Trusted Zone?

    Quote:
    O15 - Trusted Zone: http://www.proexport.com.co
    O15 - Trusted IP range: http://127.0.0.1
    O15 - ESC Trusted Zone: http://download.ccleaner.com
    O15 - ESC Trusted Zone: http://www.checkdns.net
    O15 - ESC Trusted Zone: http://www.google.com.co
    O15 - ESC Trusted Zone: http://www.imagine-msn.com
    O15 - ESC Trusted Zone: http://*.mailsrv
    O15 - ESC Trusted Zone: http://www.mcafee.com
    O15 - ESC Trusted Zone: http://www.mcafeesecurity.com
    O15 - ESC Trusted Zone: http://search.latam.msn.com
    O15 - ESC Trusted Zone: http://download.nai.com
    O15 - ESC Trusted Zone: http://sdownload.nai.com
    O15 - ESC Trusted Zone: http://speedownload.nai.com
    O15 - ESC Trusted Zone: http://register.passport.net
    O15 - ESC Trusted IP range: http://172.16.2.15

    I dont know. if it affects how can i change it, marking them in the HJT?
    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 3
    Java 2 Runtime Environment, SE v1.4.2_03
    Java(TM) SE Development Kit 6 Update 1
    Java(TM) SE Runtime Environment 6 Update 1
    done
    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
    done

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
    O4 - HKLM\..\RunServices: [java] Keygen.exe
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - Startup: conecta2.bat
    O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: (no name) - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Quote:
    REGEDIT4

    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a49a47a0-a33d-11dc-98cf-00123f813ab8}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
    done
    Now reboot your PC
    done
    After reboot, run Ccleaner!
    done
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    dont know which one is avenger
    Make sure you tell me how things are working now!

    at startup an error message would appear with some error but it was on CMD and it went away, anyways its not there anymore, so we started off great. now theproblem is mainly the turning off, should I post in the sftware forum? thanks again
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like you missed a few items I asked you to fix. We will cover them below along with a few more questions. Let's get everything in better working order and make sure you are only running things that you recognize and need. Then if you are still having problems, we will send you off to the Software Forum.

    Questions:
    1. Do you use Dell Support? Are you still under warantee to get free help? Do you think you will ever use it? If you said no then we should look into uninstall all the junk they put on your PC.
    2. Do you use a proxy server? I see the below in your log. Do you need these settings?
      • R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 172.16.1.10:80
      • R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = correo.proexport.com.co;<local>
    3. Do you use AOL, EarthLink, or QuickBooks Simple Start Special Edition? If not then uninstall the below which is just more junk Dell probably stuck you with:
      • AOLIcon
      • EarthLink setup files
      • QuickBooks Simple Start Special Edition
    4. Is the McAfee software something Dell stuck you with? Do you pay to keep the subscription up to date or has it expired? If you do not keep it up to date and it has expired then uninstall it now and then run this: McAfee Consumer Product Removal Tool
    5. Why do I always see C:\Program Files\uTorrent\uTorrent.exe running in your process list. Are you always downloading torrents??? You should not run this except when needed and it should not be running while you are doing malware cleaning. In fact some websites will not even help you fix your PC until ALL p2p or torrent downloaders are uninstalled completely.
    6. Do you use 3 different printers? Is this a business/office PC. I see services for:
      • Epson
      • HP
      • Lexmark
    Now let's remove some more unnecessary items from your PC.

    I'm going to assume you do not need to Trusted Zone entries and have you remove them with HijackThis. They are rarely reqired.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
    O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
    O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) - http://aolsvc.aol.com/onlinegames/free-trial-diner-dash-flo-on-the-go/ddfotg.1.0.0.33.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolsvc.aol.com/onlinegames/bejeweled2/popcaploader_v10.cab
    O15 - Trusted Zone: http://www.proexport.com.co
    O15 - Trusted IP range: http://127.0.0.1
    O15 - ESC Trusted Zone: http://download.ccleaner.com
    O15 - ESC Trusted Zone: http://www.checkdns.net
    O15 - ESC Trusted Zone: http://www.google.com.co
    O15 - ESC Trusted Zone: http://www.imagine-msn.com
    O15 - ESC Trusted Zone: http://*.mailsrv
    O15 - ESC Trusted Zone: http://www.mcafee.com
    O15 - ESC Trusted Zone: http://www.mcafeesecurity.com
    O15 - ESC Trusted Zone: http://search.latam.msn.com
    O15 - ESC Trusted Zone: http://download.nai.com
    O15 - ESC Trusted Zone: http://sdownload.nai.com
    O15 - ESC Trusted Zone: http://speedownload.nai.com
    O15 - ESC Trusted Zone: http://register.passport.net
    O15 - ESC Trusted IP range: http://172.16.2.15

    After clicking Fix, exit HJT.


    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\cduque.PROEXPORTDOM\Local Settings\Temp

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created.

    Make sure you tell me how things are working now!
     
  6. camilete

    camilete Private E-2

    Hello,
    Yes im using the company PC, here are the comments to each action, did them all..

    Questions:
    Do you use Dell Support? Are you still under warantee to get free help? Do you think you will ever use it? If you said no then we should look into uninstall all the junk they put on your PC. I Unistalled everything I found from dell
    Do you use a proxy server? I see the below in your log. Do you need these settings?
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 172.16.1.10:80
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = correo.proexport.com.co;<local>
    I suppose its from the company
    Do you use AOL, EarthLink, or QuickBooks Simple Start Special Edition? If not then uninstall the below which is just more junk Dell probably stuck you with:
    AOLIcon
    EarthLink setup files
    QuickBooks Simple Start Special Edition
    Unistalled
    Is the McAfee software something Dell stuck you with? Do you pay to keep the subscription up to date or has it expired? If you do not keep it up to date and it has expired then uninstall it now and then run this: McAfee Consumer Product Removal Tool
    it is the corporate edition ,got to have it
    Why do I always see C:\Program Files\uTorrent\uTorrent.exe running in your process list. Are you always downloading torrents??? You should not run this except when needed and it should not be running while you are doing malware cleaning. In fact some websites will not even help you fix your PC until ALL p2p or torrent downloaders are uninstalled completely.
    I use it ocassionally for music
    Do you use 3 different printers? Is this a business/office PC. I see services for:
    Epson
    HP
    Lexmark
    yes i use various printers
    Now let's remove some more unnecessary items from your PC.

    I'm going to assume you do not need to Trusted Zone entries and have you remove them with HijackThis. They are rarely reqired.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
    O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
    O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) - http://aolsvc.aol.com/onlinegames/fr...g.1.0.0.33.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolsvc.aol.com/onlinegames/be...loader_v10.cab
    O15 - Trusted Zone: http://www.proexport.com.co
    O15 - Trusted IP range: http://127.0.0.1
    O15 - ESC Trusted Zone: http://download.ccleaner.com
    O15 - ESC Trusted Zone: http://www.checkdns.net
    O15 - ESC Trusted Zone: http://www.google.com.co
    O15 - ESC Trusted Zone: http://www.imagine-msn.com
    O15 - ESC Trusted Zone: http://*.mailsrv
    O15 - ESC Trusted Zone: http://www.mcafee.com
    O15 - ESC Trusted Zone: http://www.mcafeesecurity.com
    O15 - ESC Trusted Zone: http://search.latam.msn.com
    O15 - ESC Trusted Zone: http://download.nai.com
    O15 - ESC Trusted Zone: http://sdownload.nai.com
    O15 - ESC Trusted Zone: http://speedownload.nai.com
    O15 - ESC Trusted Zone: http://register.passport.net
    O15 - ESC Trusted IP range: http://172.16.2.15

    After clicking Fix, exit HJT.
    Done, but i left some that might be from the office like mailsrv, and ip range, i dont really know how this works but I didnt touch them so i dont mess up my conf with the office server

    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\cduque.PROEXPORTDOM\Local Settings\Temp
    done
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    Double-click ATF-Cleaner.exe to run the program.
    Under Main choose: Select All
    Click the Empty Selected button.
    If you use Firefox browser
    Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.
    done
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to say how things are working now.

    What problems are you still having?
    Is CTRL-ALT-DEL still not working?
    If you right click the Task bar and select Task Manager, does it open?

    Note that since this is a company PC it is possible that various options may have been removed by the IT department.

    Your logs are clean!
     
  8. camilete

    camilete Private E-2

    Hello,
    the task manager opened with right click but not with ctrl alt del. and it still doesnt turn off when given the command. should I post on SOftware or hardware forums?
    Thank you
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Neither of these are probably malware issues however you can try doing the below for the CTRL-ALT-DEL issue.

    Goto this link: http://www.kellys-korner-xp.com/xp_tweaks.htm

    Scroll down to line 198 and then look in the right hand colum for the Enable or Disable Ctrl/Alt/Delete selection and click on it and download the cad.vbs file to your Desktop. The double click the cad.vbs file to run it. Some antivirus programs or antispyware programs will detect VBS scripts as a problem, just allow it to run. Did that cure this problem?

    You should contain with your remaining issues in the Software Forum but make sure you work thru the below.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds