Rogue 'MS Removal Tool' has defeated me

Discussion in 'Malware Help (A Specialist Will Reply)' started by Succotash, Mar 29, 2011.

  1. Succotash

    Succotash Private E-2

    Hi. I'm a first time poster but have used Major Geeks Malware Removal guide successfully in the past.

    However this time the pesky 'MS Removal Tools' programme has defeated me.

    Working through the Major Geeks READ & RUN ME FIRST Malware Removal Guide...

    I have 32 bit Windows XP and use Comodo Firewall Pro; and use AVG free 9.0 antivirus.

    MS Removal Tool allowed me to remove My Way Search Assistant through Add/Remove programmes.
    It didn't allow me to run previously installed CC Cleaner (last run routinely yesterday morning prior to this infection).
    It did allow me to check if I had 32/64 bit windows.
    It did allow me to make visible file extensions
    It did not allow me to run msconfig.
    I checked the Malware list and do not have anything on the list (though can't remove the unlisted 'MyFreeze toobar!)
    I'm pretty sure I do not have disk emulation software but pc crashes when I try to access www.bleepingcomputer.com It allow...one can help I'd be very grateful. Succotash
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hello there. Are you at least able to run MGTools.exe? Perhaps that would give me enough information to go on to help get you fixed up. Let me know if you can run it if not there are other avenues to try.
     
  3. Succotash

    Succotash Private E-2

    Dear Kestrel,
    Thank you for your prompt reply.
    In starting up again this time AVG seemed to catch MS Removal Tool for the first time and offered the option of putting it in the Virus Vault.

    It found 2 infections:
    "Infection";"Trojan horse Generic21.BMNG";"c:\Documents and Settings\All Users\Application Data\pLoAgHiBmHa16633\pLoAgHiBmHa16633.exe";"";"29/03/2011, 12:17:23"
    "Infection";"Trojan horse Generic21.BMNG";"C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1104\A0349659.exe";"";"29/03/2011, 13:59:05"

    On putting them in the vault I was able to run CCleaner and the popups have ceased.
    Do you advise running right through the Malware removal routine now from the start or just doing MGTools.exe?
    Thanks,
    Succotash
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It would be best if you do the requested scans:
    SAS
    MBAM
    RootRepeal --- if it runs.
    ComboFix
    C:\MGLogs.zip
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds