MG TOOLS error type 4 question

Discussion in 'Malware Help (A Specialist Will Reply)' started by Pinnymom, Mar 24, 2008.

  1. Pinnymom

    Pinnymom Private E-2

    When doing the MGTOOLS step, I needed to disable McAfee and even though I right clicked on it and exited, it still came up through the process...will this mess things up?

    Also, I got this message

    Error Message Type 4

    If you receive a message similar to any of the below. It just means that you do not have the Microsoft .NET Framework software installed from Microsoft Update. You should install this as many .NET type applications require it. The processdll.exe program which is part of MGtools will not run without this software being installed. You don't have to install it but the output from processdll.exe can sometimes be critical in getting your malware removed.

    Quote:
    The application failed to initialize properly (0xc000007b). Click on OK to terminate the application.

    So----I terminated and want to know if I should install the Microsoft. NET Framework software and if so, where do I get it from? Also, should I rerun MGTOOLS after that?

    I notice an improvement in my computer already. Thanks to all who have helped so far. This is an educational and humbling experience.:)
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ignore McAfee and ignore the Error Message Type 4, just allow MGtools to run all the way thru to the end.

    Then if you are still having problems, attach all of the logs that were requested in the READ ME. Also make sure you describe your problems.
     
  3. Pinnymom

    Pinnymom Private E-2

    Is my computer better?

    My computer seems to be running better. How do I know if it is really OK? :confused Will someone still check the attached logs and let me know? It was running very slowly, hard to open any programs or print anything. It seemed to get a little better if I would shut down but within a short time the problems would re-occur. Is my computer clean now? Thanks again!:)
     

    Attached Files:

  4. Pinnymom

    Pinnymom Private E-2

    Is my computer better?

    One more thing...if all is well do I Toggle System Restore now? Thanks!:)
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Is my computer better?

    Don't worry! We will tell you when to do this.


    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to OESH
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run C:\MGtools\analyse.exe which is really HijackThis, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteOffice Source Engine Help into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old Sun Java versions as requested in the READ ME:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) SE Runtime Environment 6 Update 1

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
    O23 - Service: OESH (Office Source Engine Help) - Unknown owner - C:\Program.exe (file missing)
    After clicking Fix, exit HJT.

    Now reboot your PC.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working
     
  6. Pinnymom

    Pinnymom Private E-2

    Hello!
    I did all that was written in the last message. Things seem to be running well. Here is the log you wanted. Thanks so much for your time. I cannot tell you how I appreciate it. I would not be able to do this without you. :)
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. Uninstall COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN
      • Now type cf /u in the runbox and click OK.
      • Note: The space between the cf and the /U, it must be there.
    2. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    3. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    4. After doing the above, you should work thru the below link:
     
  8. Pinnymom

    Pinnymom Private E-2

    For some reason, I am unable to run cf...it is on my desktop as cf.exe. Is that not what I should have named it?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if the below works:
    1. Click START then RUN
    2. Now type or copy and paste the below into the run box to avoid mistakes:
      • C:\Documents and Settings\Administrator\Desktop\cf.exe /u
    3. Then click OK.
    4. Note: The space between the cf.exe and the /U, it must be there.
    Does that work?
     
  10. Pinnymom

    Pinnymom Private E-2

    No...it still says it cannot find it...I cut and pasted what you typed...C:\Documents and Settings\Administrator\Desktop\cf.exe /u Any ideas?:)
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that! I left out some necessary quotes! Use the below. The quotes are required.

    "C:\Documents and Settings\Administrator\Desktop\cf.exe" /u


    The below would also work since it is really the same thing:

    "%userprofile%\Desktop\cf" /u
     
  12. Pinnymom

    Pinnymom Private E-2

    Thank you so much! Everything seems to be running well. I cannot believe what I was able to undo with your help! Wow! My McAfee is outdated...should I update it?

    Thanks again! I am so happy that my computer is working again!
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Do you mean you just need to install the updates? Or do you mean your subscription has expired?

    For the first question, yes you always need to stay current.
    For the second, it you like McAfee and don't mind paying for it and don't mind how much it slows your system down, then go ahead and get a new subscription. Otherwise looking into the free tools in the How to protect yourself link
     
  14. Pinnymom

    Pinnymom Private E-2

    My McAfee has expired...

    Yes I love burning money and a slower computer...hee hee:)

    Of course I will use your free methods. Thank you so much!
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds