Should I run MGTools again?

Discussion in 'Malware Help (A Specialist Will Reply)' started by jamie365, Apr 6, 2009.

  1. jamie365

    jamie365 Private E-2

    Good evening

    I have been running the processes to clean Windows XP of Malware.

    I have run SUPERAntiSpyware, MalWarebytes AntiMalware, combo fix.

    I was running MGTools when i got the following message:

    C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll could not be loaded.

    I assumed this was an Error Message Type 4 installed the .NET Framework software via the link given.

    Do I now need to run MGTools again?

    Thankyou for any help.
     
  2. jamie365

    jamie365 Private E-2

    Laptop still slow to start up after Malware Removal process.

    Good evening

    Having run the Malware Removal process for windows XP, the laptop is still slow to start up, and when I try to restart, it hangs indefinitely. Also was unable to install some windows updates, and couldn't turn windows firewall back on. Have installed Jetico v1 instead for now.

    I'm attaching the logs, I don't know how to interpret them or whether they confirm I had malware. Help would be much appreciated.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You didnt run or attach the logs from SAS or MBAM. However I am not seeing any malware in the other logs.

    You do need to use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 10"
    J2SE Runtime Environment 5.0 Update 9"
    Java 2 Runtime Environment, SE v1.4.2"
    Java(TM) 6 Update 2"
    Java(TM) 6 Update 3"
    Java(TM) 6 Update 5"
    Java(TM) SE Runtime Environment 6 Update 1

    Then reboot and download and install:
    Java Runtime 6

    Your slowness could be any of a number of reasons. One might be your desktop.

    I strongly advise you to cleanup your Desktop. Remove everything but links to run programs. Do not download and save programs here and definitely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  4. jamie365

    jamie365 Private E-2

    Thankyou very much for your help

    Hi Tim

    Thank you for your help. I have cleaned up my desktop and deleted my surplus versions of Java and replaced with runtime 6 as advised. It's not apparent that my laptop is much quicker though, it has been slowed a lot by NET optimiser (which i have learned to turn off), avgrsx (which other threads suggest should be left alone for safety), and svchost.

    But i guess these are softweare issues rather than malware problems so thankyou again.

    James
     
  5. jamie365

    jamie365 Private E-2

    Good evening

    As a precaution i ran SAS and Malwarebytes again, both of which didn't find anything. However I found my previous MB log which I am attaching. I unfortunately deleted the first SASlog in error.

    Do i need to do anything to deal with the registry keys and files infected or has MB dealt with it?

    Any advice appreciated.

    James
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    MBAM has dealt with them as you can see from the latest scan. It shows you are clean.
     
  7. jamie365

    jamie365 Private E-2

    Thankyou very much for your help.

    James
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome.....go forth and surf. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds