Help, MGtools does not run on my PC

Discussion in 'Malware Help (A Specialist Will Reply)' started by smallcarnivore, Feb 2, 2010.

  1. smallcarnivore

    smallcarnivore Private E-2

    Hi,
    I used your "READ AND RUN ME FIRST. Malware Removal Guide" to download, install and run your malware software because my PC's been infected. (My brother recommended I come here to Major Geeks).

    The one tool that did not run was MGtools :confused. I saved it to my C:/ drive and not to the desktop. Any help, feedback, suggestions would be greatly appreciated.

    Here are my attached logs:
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    You did not save it in your root folder of drive C. You saved it here: c:\program files\MGtools.exe


    Either move it to the correct location ( C:\MGtools.exe ) or delete the incorrectly saved one and redownload to the correct location. Then try to run it. If you have any problem running it and getting a log then answer the below questions:
    • What exactly happens when you run it?
    • Was the C:\MGtools folder created?
      • If yes, look for the C:\MGtools\GetLogs.bat file and double click on it and see if this runs and produces a log.
    By the way, what malware problems are you actually having?
     
  3. smallcarnivore

    smallcarnivore Private E-2

    Hello ChasLang:wave

    ChasLang wrote:
    You did not save it in your root folder of drive C. You saved it here: c:\program files\MGtools.exe

    Either move it to the correct location ( C:\MGtools.exe ) or delete the incorrectly saved one and redownload to the correct location. Then try to run it. If you have any problem running it and getting a log then answer the below questions:
    What exactly happens when you run it?
    Was the C:\MGtools folder created?
    If yes, look for the C:\MGtools\GetLogs.bat file and double click on it and see if this runs and produces a log.
    By the way, what malware problems are you actually having?

    SmallCarnivore wrote:
    I don't know how you figured it out that I didn't originally save it to C:\. I moved it to there before I posted to you from my C:\Program files. It didn't run from C:\MGtools.exe either (where I also ran it from before 1st posting).

    ChasLang's Questions Small Carn's Answers:
    1) What exactly happens when you run it?
    It did nothing.
    2) Was the C:\MGtools folder created?
    Yes
    3) If yes, see if it runs from C:\MGtools\GetLogs.bat.
    It did run. At least I think so - I have a MGlogs.zip.
    4) By the way, what malware problems are you actually having?
    I had Virus: Win32/virut.a. at least this is what popped up when I went to sign in to my Flickr account in a pseudo IE window that told me my computer was infected and that this pseudo wanted to scan my Audio CD drive (there's nothing there). I knew this was not right and shut down my computer pronto. Since then, pseudo IE windows have been popping up and I fearfully assume I've been infected.

    Thank you so much for your response and help.

    Here's my zip log.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Because ComboFix shows the below
    Code:
    2010-02-01 23:43 . 2010-02-01 23:44 2387269 ----a-w- c:\program files\MGtools.exe
    Your logs are not showing any infections not even a Virut infection. But just to be safe, you may want to update your antivirus program and then run a full scan of all files.
     
  5. smallcarnivore

    smallcarnivore Private E-2

    Re: Help, MGtools does not run on my PC (new Java Virtaul Machine error)

    Dear Chaslang,

    It is really good news my logs do not show a virus! Although, I realize you and MajorGeeks are volunteers, the help you give to us commoners is way beyond professional and something I am not used to in this crazy tech world. Thank you so much for your help.

    NEW PROBLEM: After going step-by-step, down the line with your malware removal "READ & RUN ME FIRST", I got all the way to

    "Windows XP Cleaning Procedure"
    "Step 5 Keeping your computer safe and secure"
    "Step 8 Uninstall Microsoft Java

    Well, this was my mistake, I think.... The Program list on my Control Panel did not show I even had Virtual Machine but I thought I would go through the uninstall to make sure there were no lasting remnants using MajorGeeks "Step 8 Uninstall Microsoft Java". I do have the latest Java Sun 1.6.18.

    Now, I get an error message at startup on my desktop saying: "Unable to start the application--The Java Virtual Machine cannot be loaded. Class not registered." - very annoying -

    Everything seems to load and work fine, except, now, I also get this pop-up from Opera browser's Error Console all the time. - also very annoying - I do not wish to create new problems for myself, especially since my logs showed no viruses,:-o

    Have you heard of these problems? And, can you help? Thank you for everything.

    Sincerely, smallcarnivore.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Help, MGtools does not run on my PC (new Java Virtaul Machine error)

    You're welcome.

    Yes it was. ;)

    WHY? You did not have an old version of Windows as noted and you did not have it installed and you had the proper version of Sun Java already installed and running.

    Not sure exactly what you may have removed but try reinstalling Sun Java.

    What popup?
     
  7. smallcarnivore

    smallcarnivore Private E-2

    The pop ups are gone because I uninstalled Opera.

    I reinstalled Java and I'm still getting the Error message at startup: "Unable to start the application--the Java Virtual Machine cannot be loaded. Class not registered".

    Just after the error message pops up, the SAS (which is where a Trojan of unknown origin was found and is logged) logo pops up and then disappears. Maybe this is the app my error message is talking about? I can't figure it out. Do you have another idea on how to get rid of this error message?

    Also, can I now uninstall all the software I downloaded from MajorGeeks? Every time I do a Search in Windows Explorer, my computer scans literally thousands of files now. Thanks.

    small carnivore.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the below.

    Download the below to your Desktop:

    msjavax86.exe

    1. Run the above by double clicking on it.
    2. Answer Yes to the License Agreement question and when it finishes installing, re-boot your PC.
    3. After reboot, do you still have a problem?
     
  9. smallcarnivore

    smallcarnivore Private E-2

    Hi Chaslang,
    I installed the msjavax86.exe to my desktop and ran it. The error message is still there after rebooting.

    After running it, a new popup said "This setup will only upgrade over an existing version of the MVM.

    sc
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then it may just be due to one of the programs you are loading at startup having something missing that it requires. You will have to experiment with your Startups using MSconfig ( this is what it was designed for..... debugging!! ). Disable various items like the below from starting up and see if you can narrow in on which one/ones cause the message. It could be the HP software.

    But here are the items I see in your HijackThis log that run at startup. The ones in bold are the first ones I would check.


    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
    O4 - HKLM\..\Run: [PCCClient.exe] "C:\Program Files\PC-cillin 2002\PCCClient.exe"
    O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
    O4 - HKLM\..\Run: [IPInSightLAN 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l
    O4 - HKLM\..\Run: [IPInSightMonitor 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
    O4 - HKLM\..\Run: [SansaDispatch] C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe
    O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
    O4 - HKLM\..\Run: [hpinstantsupport] "C:\Program Files\Hewlett-Packard\hpis\bin\matcliwrapper.exe" "C:\Program Files\Hewlett-Packard\hpis\" -boot
    O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
    O4 - HKCU\..\Run: [Yahoo! Pager] 1
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
    O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
     
  11. smallcarnivore

    smallcarnivore Private E-2

    Hi Chaslang,

    I'll try everything you suggest. But, how do I startup using MSconfig? Do I just go to my BIOS screen and select it there?

    Thanks so much,

    sc
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click Start, Run, and enter msconfig into the Run box and click OK. This runs MSconfig ( the System Configuration utility ). Then use it as I suggested to experiment with disabling/enabling various Startup process to see it you can locate the ones responsible for the error message.
     
    Last edited: Feb 26, 2010
  13. smallcarnivore

    smallcarnivore Private E-2

    Re: Help, MGtools does not run on my PC/startup error message

    Hi Chaslang,

    You said: "It could be the HP software."

    Good news, I followed your suggestions in 'msconfig' and disabled 'hp' stuff and so far so good. No annoying error message at startup. Now, I have to figure out how to enable my HP printer properly again.

    Would you recommend just uninstalling and re-installing? You know, I read all about how hp software was the cause of this problem on the web but, wasn't sure this cause applied to me.

    I still have a lot more questions, but, I figure, one thing at a time. Thank you so much. I'm glad I didn't have to go through disabling many things before I found the culprit.

    smallcarnivore
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Help, MGtools does not run on my PC/startup error message

    You could try that with a reboot after the uninstall. But since this is not a malware problem, you need to continue in the Software Forum.

    If they are non-malware, please post in the appropriate forum.


    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. After doing the above, you should work thru the below link:
     
  15. smallcarnivore

    smallcarnivore Private E-2

    Re: Help, MGtools does not run on my PC/startup error message

    Dear Chaslang, I'm almost done with the malware stuff, please bear with me just a wee bit more.


    [*]We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection.[*]

    Please help clear this one up for me. You recommend keeping SAS and MAM, but, at the end of your post, you suggest to get an additional anti-virus software program?:


    [*]After doing the above, you should work thru the below link: How to Protect yourself from malware! [*]

    I thought the terms "anti-malware" and "anti-virus" mean the same thing and do the same things. But, aren't we supposed to only use one anti-malware/anti-virus program?


    [*]If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.[*]

    Where do I find the registry patches? Or, are these the files I put into my text log?

    One last thing. You said my pc have any issues with malware. But, SAS quarantined an unknown trojan and MAM quarantined a Hijack. I hope these mean nothing.

    Well, that's just about it.

    Sincerely and thank you,

    smallcarnivore
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Help, MGtools does not run on my PC/startup error message

    SAS and MBAM are not antivirus programs. They are antispyware programs. And no we don't say get additional programs, we say make sure you are following the guidelines mentioned by each of the steps in the How to protect yourself from malware link.

    Not true. However more and more protection packages are now embedding both antivirus and antispyware protection into the software making them combined programs. Thus software like Avira, Avast, and AVG now include both forms of protection although they may be a little weak on the antispyware side.

    Internet Security Suites may combine things like AV, AS, firewall, email scanner, spam blocking, rootkit detection.....etc. In almost all cases they are over kill and tend to bog PCs down especially if you are not using a current, state of the art, high performance PC with lots of memory.


    The rules are:
    1. one antivirus program
    2. one antispyware program that is providing realtime protection (SAS and MBAM are not doing this unless purchased)
    3. one real software firewall and it should not be the Windows firewall since it is a very poor performer
    The key words were: If we had you download

    You did not download any of these.

    What MBAM found was not an infection. It was just something you changed from the Windows default.

    What SAS found was most likely just from this "SBC Yahoo! Applications" Other programs have had similar false detections in the past. See the below example:

    http://www.dslreports.com/forum/r20681962-Avast-detecting-CWINDOWSBrowserexe-as-trojan-FP
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds