MGTools caused crash during Malware removal.

Discussion in 'Malware Help (A Specialist Will Reply)' started by lawsonium, Jun 5, 2010.

  1. lawsonium

    lawsonium Private E-2

    Dear Geeks,

    Firstly thank you for your clear and concise guide in the READ ME.

    I am trying to clear my mothers PC of some malware and I have followed the READ ME to the letter and all stages appear to have run fine (Please see attached logs).
    I also beleive they have cleared the malware that was causing her problems (especially the DNS re-route issue which was so obvious and very unpleasant).

    Unfortunetely the last stage 'MGtools' didn't work very well.
    I copied the .exe to the root drive (C:\) and ran as directed but it very quickly caused the 'dumping physical memory' blue screen error.
    I have NOT run MGtools.exe again and have NOT removed it.
    There IS a folder on my C: drive called /MGtools/ and it contains 50 objects consisting of various .bat .exe .reg and .txt etc. files.
    It seems to have managed to write the MGlogs.zip file on C: and that containt one text file (GetUnKey.txt - also attached).

    Have I uploaded everything you will need?

    Please could you kindly check my logs to see if all is ok and clear and if anyone knows why MGTools failed so spectacularly that would be much appreciated.
    I don't know if it is vital that I run MGTools but if so maybe you can help me sort that too.

    Very Kind Regards,

    Matt.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Not yet. In order for us to know whether you are really clean and free from the DNS infection, we need the requested log from ComboFix and we are going to need to get MGtools to run.

    Since it extracted things into the MGtools folder, please do the below.

    Shut down your protection software and then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below log ( do not attach anything from inside the MGtools folder unless requested ):
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. lawsonium

    lawsonium Private E-2

    Hi Chaslang,

    Thank you for your prompt reply.

    Sorry I missed the combofix log, please find it attached to this post.

    I have just successfully run C:\MGtools\GetLogs.bat as requsted and the MGlogs.zip is also attached.

    Thank you again, Matt.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 8
    J2SE Runtime Environment 5.0 Update 9
    Java(TM) 6 Update 17
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7
    Java(TM) SE Runtime Environment 6 Update 1

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now reboot your PC.
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. lawsonium

    lawsonium Private E-2

    Hi there,

    I have un-installed all the listed Java versions.
    I successfully updated the registry with your fix, then restarted.
    I rebooted the system and installed the new version of Java from your link.

    I then ran Ccleaner which freed up some space.

    Lastly I ran C:\MGtools\GetLogs.bat again and have attached MGlogs.zip to this post.

    Thank you,

    Matt.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  7. lawsonium

    lawsonium Private E-2

    Great news, thank you.

    There doesn't appear to be any more problems (keeping my fingers crossed). My mother is pleased to be back online too!

    I will work through the uninstall procedures next time I am there. I'll report back if I get any more problems.

    Thank you so much for your time,

    Matt
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds