MS removal spyware...F me.
#1
Slowest Progress Ever
Thread Starter
iTrader: (26)
Join Date: Oct 2007
Location: The coal ridden hills of Pennsylvania
Posts: 6,022
Total Cats: 304
MS removal spyware...F me.
About 1 hour ago I was on google and I did a search for something, and a pop up ad came on my screen. I clicked the X to close it out, and then this little icon in the lower right of my screen says "MS removal tool" and starts telling me I have all kinds of spyware on my PC.
This is spyware itself. I know this because when I opened it, it asked me right away for my credit card number so I could purchase the registered version.
I googled "MS removal spyware" and it took me to this sight where it tolk me what the spyware I have on my PC was, and it told me how to remove it, but I needed to download "PC Tools Spyware Doctor". It scanned my PC and found a pile of stuff, but it won't let me remove anything until I enter my credit card information and download the registered version.
This SUCKS. I'm on MT.net right now in Safe mode, cause otherwise my PC keeps popping all kinds of bullshit up.
What can I download to fix this problem?
I tried Microsoft security essentials, but it found NOTHING.
This is spyware itself. I know this because when I opened it, it asked me right away for my credit card number so I could purchase the registered version.
I googled "MS removal spyware" and it took me to this sight where it tolk me what the spyware I have on my PC was, and it told me how to remove it, but I needed to download "PC Tools Spyware Doctor". It scanned my PC and found a pile of stuff, but it won't let me remove anything until I enter my credit card information and download the registered version.
This SUCKS. I'm on MT.net right now in Safe mode, cause otherwise my PC keeps popping all kinds of bullshit up.
What can I download to fix this problem?
I tried Microsoft security essentials, but it found NOTHING.
#2
System restore is worth a shot, I've had good luck with getting crap like that off and it doesn't affect anything on your computer (pictures/documents/etc), only programs and applications installed after the time you select.
Start > All Programs > Accessories > System Tools > System Restore
Takes 5-10 min.
Start > All Programs > Accessories > System Tools > System Restore
Takes 5-10 min.
#5
Boost Pope
iTrader: (8)
Join Date: Sep 2005
Location: Chicago. (The less-murder part.)
Posts: 33,017
Total Cats: 6,587
Manual removal guide: http://www.wiki-security.com/wiki/Pa.../MSRemovalTool
Remove MS Removal Tool manually
Another method to remove MS Removal Tool is to manually delete MS Removal Tool files in your system. Detect and remove the following MS Removal Tool files:
Processes
Other Files
Registry Keys
If this doesn't work, just google "MS Removal Tool". There are several other guides.
Remove MS Removal Tool manually
Another method to remove MS Removal Tool is to manually delete MS Removal Tool files in your system. Detect and remove the following MS Removal Tool files:
Processes
- %CommonAppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe
- %AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe
- C:\Documents and Settings\All Users\Application Data\oGcMaMjAlJj07003\oGcMaMjAlJj07003.exe
- C:\Documents and Settings\[USERNAME]\Local Settings\Temp\aC555.exe
Other Files
- %CommonAppData%\[RANDOM CHARACTERS]
- %AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].cfg
- %AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].bat
- C:\Documents and Settings\All Users\Application Data\oGcMaMjAlJj07003
- C:\Documents and Settings\[USERNAME]\Local Settings\Temp\aC555.tmp
Registry Keys
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\RunOnce\[RANDOM CHARACTERS]
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS]"
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS].exe"
- HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\RunOnce\oGcMaMjAlJj07003=C:\Documents and Settings\All Users\Application Data\oGcMaMjAlJj07003\oGcMaMjAlJj07003.exe
If this doesn't work, just google "MS Removal Tool". There are several other guides.
#13
-Greer
#16
2 Props,3 Dildos,& 1 Cat
iTrader: (8)
Join Date: Jun 2005
Location: Fake Virginia
Posts: 19,338
Total Cats: 573
believe it or not, the internets love microsoft security essentials over some of the other bigger fatter antivirus junk.
spyware is another story. windows defender might work to remove it. or not.
spyware is another story. windows defender might work to remove it. or not.
#18
Boost Czar
iTrader: (62)
Join Date: May 2005
Location: Chantilly, VA
Posts: 79,488
Total Cats: 4,077
RKill is a program developed at BleepingComputer.com that was originally designed for the use in our malware removal guides. It was created so that we could have an easy to use tool that kills known processes that stop the use of our normal anti-malware applications. Simple as that. Nothing fancy. Just kill known malware processes so that anti-malware programs can do their job.
So in summary, RKill just kills processes, imports a Registry file that removes incorrect file associations, removes and backs up proxy settings, and fixes policies that stop us from using certain tools. When done, RKill will then create a log listing all processes that were terminated while the program was running. Please note that this will include processes that were terminated manually by the user as well as RKill. I have whitelisted some processes that are commonly shown as being killed even though they weren't terminated by Rkill, including the program itself, to avoid confusion that a legitimate process was terminated. Other than what is listed above, it does nothing else.
Since RKill only terminates processes, after running it you should not reboot your computer as any malware processes that are set to start automatically, will just start up again. Instead, after running RKill you should scan your computer using your malware removal tool of choice. If there is a problem after running RKill, just reboot your computer and you will be back to where you started before running the program. Some great free tools that you can use to scan your computer after running RKill include MalwareBytes' Anti-Malware, SuperAntiSpyware, and Dr.Web CureIt.
http://www.bleepingcomputer.com/forums/topic308364.html
So in summary, RKill just kills processes, imports a Registry file that removes incorrect file associations, removes and backs up proxy settings, and fixes policies that stop us from using certain tools. When done, RKill will then create a log listing all processes that were terminated while the program was running. Please note that this will include processes that were terminated manually by the user as well as RKill. I have whitelisted some processes that are commonly shown as being killed even though they weren't terminated by Rkill, including the program itself, to avoid confusion that a legitimate process was terminated. Other than what is listed above, it does nothing else.
Since RKill only terminates processes, after running it you should not reboot your computer as any malware processes that are set to start automatically, will just start up again. Instead, after running RKill you should scan your computer using your malware removal tool of choice. If there is a problem after running RKill, just reboot your computer and you will be back to where you started before running the program. Some great free tools that you can use to scan your computer after running RKill include MalwareBytes' Anti-Malware, SuperAntiSpyware, and Dr.Web CureIt.
http://www.bleepingcomputer.com/forums/topic308364.html
#20
Slowest Progress Ever
Thread Starter
iTrader: (26)
Join Date: Oct 2007
Location: The coal ridden hills of Pennsylvania
Posts: 6,022
Total Cats: 304
Thanks Scott. I was just trying to verify that it wasn't a renamed file that was originally titled "formatyourcomputerforfree.exe" lol.
I'll do it up tonight and hopefully my pc will stop being down with the sickness.
I'll do it up tonight and hopefully my pc will stop being down with the sickness.