Read me

Discussion in 'Malware Help (A Specialist Will Reply)' started by tomadams, May 28, 2010.

  1. tomadams

    tomadams Private E-2

    Recently went thru most of the steps in you read and run mr first steps for malware removal. I am having an error 126 message. I got thu step 8 and downloaded the required programs when i installed the super spyware and my computer rebooted I could not get online. So I had to do a system restore. I assume I am back where I started have 32 bit xp Thanks
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just skip the SAS log. Continue on and attach all the requested logs that you can get.
     
  3. tomadams

    tomadams Private E-2

    Re: Read me Tried again

    I was able to run the portable superantispyware and got a few hits but no log--I got adware hotbar1 awcoupn bar 2 awzango 3 aw shop at home 3 aw tracking cookie 7 and awgame vance 1
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The log you attached indicates no action was taken. Did you save the log before you removed what it found?

    I still would like:
    ComboFix Log
    C:\MGLogs.zip --> from running the C:\MGTools.exe
     
  5. tomadams

    tomadams Private E-2

    I will start completrely over and get back Thanks again-
     
  6. tomadams

    tomadams Private E-2

    Root repealfound 1 locked file c:/hiberfil.sys
    When i tried to start up root repeal error invalid PE image found Spyware found the same adware as yesterday Thanks
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I still need to see the C:\MGlogs.zip.

    In the meantime, are you running two AV programs as Combo indicates? :
    AV: CA Anti-Virus *On-access scanning disabled*
    AV: McAfee VirusScan *On-access

    You can use windows explorer to find and delete:
    c:\windows\IDB.zip
    c:\windows\UDB.zip
     
  8. tomadams

    tomadams Private E-2

    It is not on my computer --that I can find and I have looked.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download the latest version of MGtools and save it to your root folder. You should now have C:\MGTools.exe.

    Double click it (Note: if using Vista, don't double click, use right click and select Run As Administrator). Let it run until it tells you to hit any key.

    Your resultant log will be here: C:\MGLogs.zip
     
  10. tomadams

    tomadams Private E-2

    I am running only Av Anti virus and none of the links you sent do anything. Also I cannot find anything in my computer Also when I mhit your link for mG tools I got the error message/chaslang/files/MGtools.exe)*
    File Not Found! I have not restored my computer and am running with no anti virus shoul I restore to yesterday?? Thanks
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you try using a different browser to try to download the file? It works fine for me, or use the link in the Read and Run First Instructions. Either way, disable your AV program before trying to download it.

    If you can do a system restore, go back before you started having issues. ;)
     
  12. tomadams

    tomadams Private E-2

    Ok I am not getting the error 126 message anymor--Great!! I do have one other problem When I did a defrag i HAVE A SECTION OF FILES THAT COULD NOT BE DEFRaGED. Is ther a seperate forum for this?? Also i have 2 programs that said they could not be removed with my add/remove programs on the control panel Spyware doctor and Easy spanish? Thanks again Tom
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is not unusual to have some files that cant be defragged. Are you going to attach the log (s)?
     
  14. tomadams

    tomadams Private E-2

    It says fatal execution error0x7927f26e Thanks sorry for the delay
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you do a restore? What issues are you still having?
     
  16. tomadams

    tomadams Private E-2

    I did a restore and i am still getting the same error message when trying to open Spware Doctor Caanot find import dll may be missing corrupt file
    rtl70bpl error 126 I get the same message if I try to uninstall spyware doctor or reinstall
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Is Spyware Doctor a paid for version or freeware version?
     
  18. tomadams

    tomadams Private E-2

    Free version also the big spot on myhard drive that will not defrag is fairly new and is about 4 gb
     
  19. tomadams

    tomadams Private E-2

    You can get a free version with gmail with antivirus
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The free version of Spyware Doctor is not worth having. It does a very poor job. I would uninstall it.
     
  21. tomadams

    tomadams Private E-2

    Please see 3rd previos message I cannot uninsrall it when i try to uninstall it I get the error messageCan anything be done about the error message??
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Edit by chaslang: I suggest 1st trying to use Revo Uninstaller to uninstall SpywareDoctor and if that fails, continue on with what TimW posted below.


    Use windows explorer to find and delete:
    C:\Program Files\Spyware Doctor --> delete what is in the folder, and then the folder.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now tell me what issues you still have?
     
    Last edited by a moderator: May 30, 2010
  23. tomadams

    tomadams Private E-2

    The revo installer got it Thanks One question When running revo was I supposed to check anything that comes that comes in highlighted or just the ones that say Spyware D\octor??Thanks again Should I delete all the programs I downloaded for the read me first??
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We were only trying to remove Spyware Doctor, but if you have other programs that you are having difficulty in removing, you can certainly use it to remove them.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds