Error while using MGTools

Discussion in 'Malware Help (A Specialist Will Reply)' started by Trillain, Jun 6, 2010.

  1. Trillain

    Trillain Private E-2

    I worked my way through your malware removal guide. Everything did what it was supposed to do until I got to MGTools. I did not write down the error, so I don't have it to add here. I did read that one of the possible fixes was to install the NET Framework, but I have that installed already.

    Thank you in advance for all your help
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    MGTools ran fine. What issues are you having?
     
  3. Trillain

    Trillain Private E-2

    I ran it again and took a screen shot of MGTools and the error message

    http://i73.photobucket.com/albums/i228/Trillain/th_mgtoolerror.jpg

    Did you see anything else in the logs that I might have missed? The reason why I decided to work my way through your Malware Removal Guide was because I had one of my email accounts hijacked yesterday.
     
  4. Trillain

    Trillain Private E-2

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ah, email issues, a horse of a different color! Here is a general guide to dealing with email infections:

    Malware detected in email databases has to be cleaned up by you. You have a few choices:

    1. delete the whole file which is not an option you normally want to use
    2. load the email folder that contains the infection and delete ALL unnecessary emails (hoping to remove the problem email) and then use the Mailbox Cleanup option to delete all old emails. Then compact the Outlook database to permanently remove data. See http://support.microsoft.com/kb/196990 If you do not cleanup and compact the databases, the deleted emails may still be leaving hidden information in the database that you just cannot see but a scanner may still pickup on it.
    3. create a new folder and move only emails you really need into the new folder and then delete the infected folder.
     
  6. Trillain

    Trillain Private E-2

    It wasn't an Outlook account though. It was an AOL one. One of the emails were still in my sent mail folder, so I deleted that. There was a second one that I know was sent, since a copy was sent to my second email account, but I do not have access to the original copy. Is there anything else I can do to make sure that everything is cleaned out of AOL and it doesn't happen again?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    One trick is to create a contact such as this:
    AAA@aaa.com

    This will often block mass mailing since it will not go anywhere. Other than that, you just need to be sure to delete any mail you think might be infected. As I said, that was a general guide. It would be up to you to create a new folder to move just legit emails into it and then delete all the rest. Worse case would be to remove all your contacts and create a new account. :(
     
  8. Trillain

    Trillain Private E-2

    Well thank you for all your help :) Yeah I am using my other email address while I try to decide what to do with the AOL one. If I need to close it and make something new, then so be it.

    But since I am here. When I ran those programs, I did find a few trojans and an adware file. Did I miss anything?
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No, your logs were clean other than what was already removed by SAS and MBAM.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds