Insert BS here A place to discuss anything you want

MS removal spyware...F me.

Old 04-09-2011, 12:06 PM
  #1  
Slowest Progress Ever
Thread Starter
iTrader: (26)
 
thirdgen's Avatar
 
Join Date: Oct 2007
Location: The coal ridden hills of Pennsylvania
Posts: 6,022
Total Cats: 304
Default MS removal spyware...F me.

About 1 hour ago I was on google and I did a search for something, and a pop up ad came on my screen. I clicked the X to close it out, and then this little icon in the lower right of my screen says "MS removal tool" and starts telling me I have all kinds of spyware on my PC.
This is spyware itself. I know this because when I opened it, it asked me right away for my credit card number so I could purchase the registered version.
I googled "MS removal spyware" and it took me to this sight where it tolk me what the spyware I have on my PC was, and it told me how to remove it, but I needed to download "PC Tools Spyware Doctor". It scanned my PC and found a pile of stuff, but it won't let me remove anything until I enter my credit card information and download the registered version.
This SUCKS. I'm on MT.net right now in Safe mode, cause otherwise my PC keeps popping all kinds of bullshit up.

What can I download to fix this problem?
I tried Microsoft security essentials, but it found NOTHING.
thirdgen is offline  
Old 04-09-2011, 12:14 PM
  #2  
Elite Member
iTrader: (17)
 
pdexta's Avatar
 
Join Date: Aug 2007
Location: Knoxville, TN
Posts: 2,949
Total Cats: 182
Default

System restore is worth a shot, I've had good luck with getting crap like that off and it doesn't affect anything on your computer (pictures/documents/etc), only programs and applications installed after the time you select.

Start > All Programs > Accessories > System Tools > System Restore

Takes 5-10 min.
pdexta is offline  
Old 04-09-2011, 12:15 PM
  #3  
Newb
 
Joe_Mama's Avatar
 
Join Date: Nov 2010
Posts: 16
Total Cats: 0
Default

AVG antivirus free version.
Blocks and removes **** like this automatically.
Joe_Mama is offline  
Old 04-09-2011, 12:18 PM
  #4  
Slowest Progress Ever
Thread Starter
iTrader: (26)
 
thirdgen's Avatar
 
Join Date: Oct 2007
Location: The coal ridden hills of Pennsylvania
Posts: 6,022
Total Cats: 304
Default

Might help to mention, It's my home pc with windows xp.
thirdgen is offline  
Old 04-09-2011, 12:38 PM
  #5  
Boost Pope
iTrader: (8)
 
Joe Perez's Avatar
 
Join Date: Sep 2005
Location: Chicago. (The less-murder part.)
Posts: 33,017
Total Cats: 6,587
Default

Manual removal guide: http://www.wiki-security.com/wiki/Pa.../MSRemovalTool

Remove MS Removal Tool manually
Another method to remove MS Removal Tool is to manually delete MS Removal Tool files in your system. Detect and remove the following MS Removal Tool files:

Processes
  • %CommonAppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe
  • %AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe
  • C:\Documents and Settings\All Users\Application Data\oGcMaMjAlJj07003\oGcMaMjAlJj07003.exe
  • C:\Documents and Settings\[USERNAME]\Local Settings\Temp\aC555.exe

Other Files
  • %CommonAppData%\[RANDOM CHARACTERS]
  • %AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].cfg
  • %AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].bat
  • C:\Documents and Settings\All Users\Application Data\oGcMaMjAlJj07003
  • C:\Documents and Settings\[USERNAME]\Local Settings\Temp\aC555.tmp

Registry Keys
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\RunOnce\[RANDOM CHARACTERS]
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS]"
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS].exe"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\RunOnce\oGcMaMjAlJj07003=C:\Documents and Settings\All Users\Application Data\oGcMaMjAlJj07003\oGcMaMjAlJj07003.exe



If this doesn't work, just google "MS Removal Tool". There are several other guides.
Joe Perez is offline  
Old 04-09-2011, 12:44 PM
  #6  
Slowest Progress Ever
Thread Starter
iTrader: (26)
 
thirdgen's Avatar
 
Join Date: Oct 2007
Location: The coal ridden hills of Pennsylvania
Posts: 6,022
Total Cats: 304
Default

Ill try that stuff, right now I gotta go to work. Thanks for the advice guys!
thirdgen is offline  
Old 04-09-2011, 12:52 PM
  #7  
Senior Member
iTrader: (1)
 
revlimiter's Avatar
 
Join Date: Jan 2009
Location: ABQ, NM
Posts: 518
Total Cats: 95
Default

On my one Windows box at home, I use Avast antivirus/spyware. It seems less resource heavy than AVG. And is also free.

Also, what the others said.
revlimiter is offline  
Old 04-09-2011, 01:01 PM
  #8  
Junior Member
 
shooterschmidty's Avatar
 
Join Date: May 2009
Location: Dayton, OH
Posts: 320
Total Cats: 14
Default

Malwarebyte's Anti-Malware is a pretty powerful malware removal tool.
shooterschmidty is offline  
Old 04-09-2011, 01:55 PM
  #9  
Slowest Progress Ever
Thread Starter
iTrader: (26)
 
thirdgen's Avatar
 
Join Date: Oct 2007
Location: The coal ridden hills of Pennsylvania
Posts: 6,022
Total Cats: 304
Default

I just want FREE and fast. I'll try the manual removal that Joe posted once I get home.
thirdgen is offline  
Old 04-09-2011, 02:32 PM
  #10  
Boost Czar
iTrader: (62)
 
Braineack's Avatar
 
Join Date: May 2005
Location: Chantilly, VA
Posts: 79,488
Total Cats: 4,077
Default

you need to download an exe file called rkill.exe to completely stop to process of the spyware to be able to remove it.
Braineack is offline  
Old 04-09-2011, 02:55 PM
  #11  
Tnn
Newb
iTrader: (1)
 
Tnn's Avatar
 
Join Date: Apr 2010
Location: Dallas, TX
Posts: 33
Total Cats: 0
Default

Download malwarebytes free edition from malwarebytes.com. Run full scan in safe mode and remove whatever it finds.

Also get ComboFix.. run this (safe mode with networking) after malwarebytes.. it'll get rid of most of the hard to remove malware.
Tnn is offline  
Old 04-09-2011, 02:57 PM
  #12  
Elite Member
iTrader: (4)
 
Pen2_the_penguin's Avatar
 
Join Date: Dec 2009
Location: Reno, NV
Posts: 3,686
Total Cats: 95
Default

ComboFix
Pen2_the_penguin is offline  
Old 04-09-2011, 03:05 PM
  #13  
Junior Member
iTrader: (2)
 
g_reichow's Avatar
 
Join Date: Nov 2010
Location: NoVa
Posts: 161
Total Cats: 0
Default

Originally Posted by shooterschmidty
Malwarebyte's Anti-Malware is a pretty powerful malware removal tool.
This should do the trick. Additionally, install the app on a different computer, than copy the app directory to a USB key. Rename the main executable to something other than mab or antibytes like your name. Then take the USB key and insert onto infected computer. Run executable from usb key and let it do its magic. Some of the new tools will stop removal tools like MAB from executing. And yes, it is free.

-Greer
g_reichow is offline  
Old 04-09-2011, 03:33 PM
  #14  
Boost Czar
iTrader: (62)
 
Braineack's Avatar
 
Join Date: May 2005
Location: Chantilly, VA
Posts: 79,488
Total Cats: 4,077
Default

i bet you anything this spyware prevents the installation of malwarebyes. and then rkill is needed.
Braineack is offline  
Old 04-09-2011, 04:40 PM
  #15  
Elite Member
iTrader: (5)
 
pusha's Avatar
 
Join Date: Nov 2009
Location: Miami, FL
Posts: 7,330
Total Cats: -29
Default

Originally Posted by Braineack
i bet you anything this spyware prevents the installation of malwarebyes. and then rkill is needed.
I've had that **** before. It sucks.
pusha is offline  
Old 04-09-2011, 04:46 PM
  #16  
y8s
2 Props,3 Dildos,& 1 Cat
iTrader: (8)
 
y8s's Avatar
 
Join Date: Jun 2005
Location: Fake Virginia
Posts: 19,338
Total Cats: 573
Default

believe it or not, the internets love microsoft security essentials over some of the other bigger fatter antivirus junk.

spyware is another story. windows defender might work to remove it. or not.
y8s is offline  
Old 04-09-2011, 05:55 PM
  #17  
Slowest Progress Ever
Thread Starter
iTrader: (26)
 
thirdgen's Avatar
 
Join Date: Oct 2007
Location: The coal ridden hills of Pennsylvania
Posts: 6,022
Total Cats: 304
Default

So if I google "rkill.exe" I should find it. What exactly does it do?
thirdgen is offline  
Old 04-09-2011, 06:04 PM
  #18  
Boost Czar
iTrader: (62)
 
Braineack's Avatar
 
Join Date: May 2005
Location: Chantilly, VA
Posts: 79,488
Total Cats: 4,077
Default

RKill is a program developed at BleepingComputer.com that was originally designed for the use in our malware removal guides. It was created so that we could have an easy to use tool that kills known processes that stop the use of our normal anti-malware applications. Simple as that. Nothing fancy. Just kill known malware processes so that anti-malware programs can do their job.

So in summary, RKill just kills processes, imports a Registry file that removes incorrect file associations, removes and backs up proxy settings, and fixes policies that stop us from using certain tools. When done, RKill will then create a log listing all processes that were terminated while the program was running. Please note that this will include processes that were terminated manually by the user as well as RKill. I have whitelisted some processes that are commonly shown as being killed even though they weren't terminated by Rkill, including the program itself, to avoid confusion that a legitimate process was terminated. Other than what is listed above, it does nothing else.

Since RKill only terminates processes, after running it you should not reboot your computer as any malware processes that are set to start automatically, will just start up again. Instead, after running RKill you should scan your computer using your malware removal tool of choice. If there is a problem after running RKill, just reboot your computer and you will be back to where you started before running the program. Some great free tools that you can use to scan your computer after running RKill include MalwareBytes' Anti-Malware, SuperAntiSpyware, and Dr.Web CureIt.

http://www.bleepingcomputer.com/forums/topic308364.html
Braineack is offline  
Old 04-09-2011, 06:19 PM
  #19  
Junior Member
iTrader: (2)
 
g_reichow's Avatar
 
Join Date: Nov 2010
Location: NoVa
Posts: 161
Total Cats: 0
Default

Brain, thats why I suggested installing malware on another pc and renaming the exe before trying it ont he infected computer. works like a champ 99.999% of the time.
g_reichow is offline  
Old 04-09-2011, 06:57 PM
  #20  
Slowest Progress Ever
Thread Starter
iTrader: (26)
 
thirdgen's Avatar
 
Join Date: Oct 2007
Location: The coal ridden hills of Pennsylvania
Posts: 6,022
Total Cats: 304
Default

Thanks Scott. I was just trying to verify that it wasn't a renamed file that was originally titled "formatyourcomputerforfree.exe" lol.
I'll do it up tonight and hopefully my pc will stop being down with the sickness.
thirdgen is offline  

Thread Tools
Search this Thread
Quick Reply: MS removal spyware...F me.



All times are GMT -4. The time now is 10:33 PM.