Questions About Read Me First

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by whitequeen96, Oct 29, 2017.

  1. whitequeen96

    whitequeen96 Private First Class

    OK, I'm a dummy! But when I download the AdwCleaner on Microsoft 10:
    1. How do I save it to my desktop?
    2. When I right click on it Run, nothing happens. How do I get it to Run as Administrator?
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If it is in your downloads, just left click and hold while you slide it to your desktop. You then just click it to run. Or you can right click the download and choose "send to" to the desktop.
     
  3. whitequeen96

    whitequeen96 Private First Class

    Thank you! I did this, then moved on to the 2nd page of instructions. I've been downloading everything through Internet Explorer. I downloaded everything as told except for MGTools. I don't know how to "download this file to the root folder of the drive where you have installed Windows " so I just parked it on my desktop for now.
    I always use Firefox until this problem started (made downloading a mess), so will what I'm doing here on I.E. work to clean my computer and I can then go back to Firefox?
    This is as far as I've gotten for now.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It's OK to download MGTools to the desktop. And there is no problem using I.E. Just continue and run the scans. Once done, attach the requested logs.
     
  5. whitequeen96

    whitequeen96 Private First Class

    Thank you again. I'm about to run Rogue Killer on Windows 10. It has something that asks me if I want to download(?) the 32 or 64 bit (both at one time) version "Recommended for Technicians" when I install it. Should I say YES? I get Page Not Found when I go to the Rogue Killer Tutorial.
     
    Last edited: Oct 31, 2017
  6. whitequeen96

    whitequeen96 Private First Class

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Right click the start button and click on file explorer. On the left will be This PC. Right click it and it will tell you if you have a 32 or 64 bit system. I am pretty sure you are running 64. So that will be the one to download.
     
  8. whitequeen96

    whitequeen96 Private First Class

    Thank you again for your patience and help! As you can see, I'm doing this over several days (have special needs son who constantly needs me), so I'm finally ready to run MG Tools. I'm using Firefox (I was using MicroSoft Edge before, not Int. Explorer) and my options are different from what is described in "Using MGtools" on here. I have "Privacy and Security" along the left side; when I click on that, I get
    Phishing Protection:
    Block dangerous and deceptive content;
    block dangerous content
    warn you about unwanted and uncommon software
    What should I uncheck? Everything else in the Security section is about Certificates and Offline Web stuff.
    And will I be safe to do this and then run stuff later, or should I run it immediately?
    In the meantime, I keep getting "Access Denied." I also get "Do you want to allow this to make changes to your computer?" and it keeps reappearing over and over and freezes my computer until I pull up TaskMaster and close that function.
     
    Last edited: Nov 1, 2017
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Close out your browser. Right click MGTools and choose "Run as Administrator". Wait for it to finish. It will tell you when it is done. Then run the other requested scans and attach the logs.
     
  10. whitequeen96

    whitequeen96 Private First Class

    OK, it started running. It's stopped now, although it says "Running analyse.exe. But another window has popped up. It wants me to Accept or Do Not Accept. Do I need to accept this to continue running MGTools? Here it is:

    GNU General Public License
    Version 2, June 1991

    Copyright (C) 1989, 1991 Free Software Foundation, Inc.,
    51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
    Everyone is permitted to copy and distribute verbatim copies
    of this license document, but changing it is not allowed.
    Preamble
    The licenses for most software are designed to take away your
    freedom to share and change it. By contrast, the GNU General Public
    License is intended to guarantee your freedom to share and change free
    software--to make sure the software is free for all its users. This
    General Public License applies to most of the Free Software
    Foundation's software and to any other program whose authors commit to
    using it. (Some other Free Software Foundation software is covered by
    the GNU Lesser General Public License instead.) You can apply it to
    your programs, too.
    When we speak of free software, we are referring to freedom, not
    price. Our General Public Licenses are designed to make sure that you
    have the freedom to distribute copies of free software (and charge for
    this service if you wish), that you receive source code or can get it
    if you want it, that you can change the software or use pieces of it
    in new free programs; and that you know you can do these things.
    To protect your rights, we need to make restrictions that forbid
    anyone to deny you these rights or to ask you to surrender the rights.
    These restrictions translate to certain responsibilities for you if you
    distribute copies of the software, or if you modify it.
     
  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    re: https://forums.majorgeeks.com/threads/using-mgtools.137630/
     
    TimW likes this.
  12. whitequeen96

    whitequeen96 Private First Class

    OK, I think I've done everything I need to. :) I'm going to attach the logs here; hope I get this right!
    I thought you might enjoy the screenshot I included (PC Infected.png) showing the stuff that came up from "WindowsWarns.ml. It froze my computer so that the only thing I could do was unplug it. I'm pretty sure I wasn't really supposed to click on it or call anyone at that number, so I didn't. Was I right? :confused:
    Once again, thank you a million times for your help. I want to contribute to this site (money, as I have no knowledge), so please point me in the right direction.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good job. Let's get to work.

    Rerun ADWCleaner and have it remove these items:
    PUP.Optional.ByteFence, C:\Users\Louise\AppData\Roaming\Microsoft\Windows\Start Menu\ByteFence
    PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
    PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
    PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
    PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
    PUP.Optional.Reimage, [Key] - HKLM\SOFTWARE\Reimage
    PUP.Optional.ByteFence, [Key] - HKU\.DEFAULT\Software\ByteFence
    PUP.Optional.ByteFence, [Key] - HKU\S-1-5-18\Software\ByteFence
    PUP.Optional.ByteFence, [Key] - HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Reason\ReasonByteFence

    Next have Hitman remove everything that it found.

    Now rerun RogueKiller and have it remove these items:
    ¤¤¤ Registry : 9 ¤¤¤
    [PUP.Gen1] (X64) HKEY_LOCAL_MACHINE\Software\Reimage -> Found
    [PUP.ByteFence|PUP.Gen1] (X64) HKEY_USERS\.DEFAULT\Software\ByteFence -> Found
    [PUP.ByteFence|PUP.Gen1] (X86) HKEY_USERS\.DEFAULT\Software\ByteFence -> Found
    [PUP.ByteFence|PUP.Gen1] (X64) HKEY_USERS\S-1-5-18\Software\ByteFence -> Found
    [PUP.ByteFence|PUP.Gen1] (X86) HKEY_USERS\S-1-5-18\Software\ByteFence -> Found
    [PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! SearchSet -> Found
    [PUP.Gen0] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> Found

    ¤¤¤ Tasks : 3 ¤¤¤
    [VT.not-a-virus:HEUR:AdWare.Win32.Generic] %WINDIR%\Tasks\{53E8E042-AA95-F2DB-5635-4AF40918C081}.job -- C:\Users\Louise\AppData\Roaming\{441C72A7-614E-1FD1-0A78-3803D6AAC53D}\ProductUpdate.exe (/Check) -> Found
    [Hj.Shortcut] \{4CA592E1-8F24-4C86-AF8B-0D693A7F4C6B} -- "c:\program files (x86)\mozilla firefox\firefox.exe" (https://ui.skype.com/ui/0/7.32.0.103/en/abandoninstall?source=lightinstaller&page=tsMain) -> Found
    [VT.not-a-virus:HEUR:AdWare.Win32.Generic] \{53E8E042-AA95-F2DB-5635-4AF40918C081} -- C:\Users\Louise\AppData\Roaming\{441C72A7-614E-1FD1-0A78-3803D6AAC53D}\ProductUpdate.exe (/Check) -> Found

    ¤¤¤ Files : 5 ¤¤¤
    [PUP.Gen3][File] C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml -> Found

    Now I want you to reboot and install an Anti-Virus program! I personally prefer 360 Total Security which you can find HERE.

    Now rerun RogueKiller and Hitman and attach the new logs.
     
  14. whitequeen96

    whitequeen96 Private First Class

    On ADWcleaner, I just went to EDIT and the DELETED everything, except I couldn't find:
    PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
    Is that how to "remove" the items? And what about this missing item, above? I just deleted these from the white report, but I'm still left with the small white box
    Malwarebytes
    AdwCleaner
    Waiting an action ....... 32 elements
    Then a list of 5 "Pup Optional" things that don't exactly match what you wanted me to remove, yet are all checked. What should I do now?

    And for Hitman, do I just pull up the report, select all the stuff under Malware, then click Edit/delet? And should I do this to the stuff below, Potential Unwanted Programs?
     
    Last edited: Nov 2, 2017
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If it's not found, don't worry about it. Remove all the PUP's. As for Hitman, once done just hit next and it should create a restore point and then remove all it found. Again, after removal, reboot and rescan with RogueKiller, Hitman and ADWCleaner and attach the new logs.
     
  16. whitequeen96

    whitequeen96 Private First Class

    This is my first chance to return. I'm scared to look at banking/credit card statements on-line so I'm extremely grateful to you! Maybe I'll finish today!
    When you say "Remove all the PUP's", I no longer see boxes with checkmarks in front of the 5 items I mentioned, yet all have "Key" in front of them. They are:
    PUP.Optional.AdvancedSystemCare, [Key] - HKLM\SOFTWARE\IOBIT\ASC
    PUP.Optional.AdvancedSystemCare, [Key] - HKLM\SOFTWARE\CLASSES\DIRECTORY\SHELLEX\CONTEXTMENUHANDLERS\Advanced SystemCare
    PUP.Optional.AdvancedSystemCare, [Key] - HKLM\SOFTWARE\CLASSES\DRIVE\SHELLEX\CONTEXTMENUHANDLERS\Advanced SystemCare
    PUP.Optional.AdvancedSystemCare, [Key] - HKLM\SOFTWARE\CLASSES\LNKFILE\SHELLEX\CONTEXTMENUHANDLERS\Advanced SystemCare
    PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! SearchSet
    So to remove them, do I just need to highlight and "delete" them? (Sorry I'm so ignorant!)

    Additionally, there are 18 other PUP items without [Key] in them. Some are Files and some are Folders:
    6 PUP.Optional.AdvancedSystemCare items, 10 PUP.Optional.Legacy items , 1 PUP.Optional.ByteFence and 1 PUP.Optional.AmazonTB, C:\Users\Louise\AppData\Roaming. . . etc. Plus: ***** [ Firefox (and derivatives) ] *****PUP.Optional.AmazonTB, Plugin found: __MSG_appName__ -
    Should I remove these as well? The same way I bolded and underlined above?
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to remove anything reported that has ByteFence in it.

    Then reboot and rerun the three scans and attach the new logs.
     
  18. whitequeen96

    whitequeen96 Private First Class

    So to remove them, do I just need to highlight and "delete" them? (Sorry I'm so ignorant!)
     
  19. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

  20. whitequeen96

    whitequeen96 Private First Class

    I'm sorry, but I still don't know how to remove stuff. :eek:
    I'm looking at Notepad and attached it here. Is this where I'm supposed to remove the stuff?
    AdwCleaner 7.0.3.1 - Logfile created on Fri Nov 03 23:15:23 2017
    # Updated on 2017/29/09 by Malwarebytes
    # Database: 11-03-2017.1
    # Running on Windows 10 Pro (X64)
    # Mode: scan
    # Support: https://www.malwarebytes.com/support

    This is where I tried highlighting the bad stuff, then went to Edit, then "Delete" - but bad stuff keeps showing up when I rerun AdwCleaner.
    I've watched the video over and over. It shows him opening Control Panel and looking at the bad programs there, but my bad programs don't show there, so how can I remove/uninstal them? He mentioned Iobit, but I still don't understand how to do it. I feel like such an idiot! Hangs head in shame. :(
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    All you have to do is click the CLEAN tab. Don't worry about the other stuff in the log.
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you installed an Anti-virus program yet?
     
  23. whitequeen96

    whitequeen96 Private First Class

    WOW! So nice of you to follow up on me! No, I've been hit with a series of household disasters all at once and have only run the ADW and Malwarebytes scans so far. But my computer is certainly working better already, although I'm afraid to look at bank accounts, etc. I will try to finish up and attach the logs by end of this weekend. Thank you for your very kind concern! :)
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are very welcome....but please install an AV program now!!
     
  25. whitequeen96

    whitequeen96 Private First Class

    Yikes - I didn't think about that. OK, I installed 360 Total and ran it: 0 viruses (whew!). I didn't install any of the stuff they offered with it, except Opera, which just opened a page. Should/must I use that? It said my browser is out of date. (I like Firefox but may need to update it.) Thanks again!

    Also, I got something saying I need to turn on my Microsoft Security, whatever came with MS 10. Should I do that and still have 360 Total Security on?
     
    Last edited: Nov 5, 2017
  26. whitequeen96

    whitequeen96 Private First Class

    OK, here are the results - hope I did it right.
    You're earning great karma points here!
     

    Attached Files:

  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No. You should not have two AV programs running.

    Please rerun Hitman and remove everything it found. Reboot and rerun Hitman and attach the new log.
     
  28. whitequeen96

    whitequeen96 Private First Class

    Did just what you said. No threats found!
     

    Attached Files:

  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet....you are now clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Re-enable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8 or 10, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 or 10 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     
  30. whitequeen96

    whitequeen96 Private First Class

    OK, 1) I'll keep Malwarebytes, but should I pay for it? 2) Disk Emulation seemed to turn on automatically (on Win 10). OK?
    3) NO Hijackthis found. Already gone?
    4. Found C:/MG Tools/enable UAC in Search, resulted in "Keys and values in Mg Tools/enable UAC ..." have ben added to registry." OK?
    5. Went to MGtools and dble-clicked on MGclean.bat file. Didn't get chance to R click it but I think it ran the cleanup automatically because now I see "Drive Tools Window (C:)" and it says MGTools is unavailable on this PC. Does that means it's already removed? I've done a search for MGTools and MGclean.bat and they boths show "No results." Is this part finished?!!!
    I'll work on 6) (removing all the logs too, right?) and 7) later on today.
    I want to thank you a million times for your patience and find out where I can contribute something to the website. You saved me sooo much time and money and I appreciate it greatly!
     
  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No.

    Yes.

    Yes.

    You are most welcome. Safe surfing.
     
  32. whitequeen96

    whitequeen96 Private First Class

    Wait, wait! I know I've contributed something here before, but I don't remember where. Is there a link?
    I owe you BIG TIME! I'd name my 1st born son after you, but he's already 20. :rolleyes:
     
    Last edited: Nov 5, 2017
  33. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  34. whitequeen96

    whitequeen96 Private First Class

    No, that's not it. Well, sir, as a mark of gratitude, allow me to at least give you my first-born son. (He's 20, and you've solved so many of my other problems! :rolleyes: )

    Now, once I finish step 7, should I feel safe to check my credit card/banking accounts? I notice I'm having trouble with the Home Depot site since late last night (will no longer respond to Search and won't let me click on anything), but perhaps that's trouble with the site itself.
     
  35. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes. As to Home Depot, it could be their site. Or it could be your browser. Try a different browser to be sure.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds