Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.




222 posts

Master Geek
+1 received by user: 1


Topic # 82199 23-Apr-2011 20:32
Send private message

How do I remove Ms Removal tool?

Tried Malware Bytes

Tried Malware Bytes in Safe-mode 

I'm unable to open Task manager.

Help. D: Running windows 7

Create new topic
3746 posts

Uber Geek
+1 received by user: 206

Trusted

  Reply # 461869 23-Apr-2011 20:38
Send private message

Download Microsoft security essentials and run a scan in safe mode. There is a download link in my signature.




Do whatever you want to do man.

  



222 posts

Master Geek
+1 received by user: 1


  Reply # 461874 23-Apr-2011 20:53
Send private message

unable to install in normal mode, application cannot be executed due to this @$%@$#$#% virus and it says the application cannot be installed in safe mode.

 
 
 
 




222 posts

Master Geek
+1 received by user: 1


  Reply # 461879 23-Apr-2011 21:03
Send private message

any other ideas?

1574 posts

Uber Geek
+1 received by user: 11


  Reply # 461880 23-Apr-2011 21:12
Send private message

http://www.avg.com/us-en/avg-rescue-cd

Burn the AVG rescue CD and then boot from it.
Run a full scan and hope for the best.
:)

51 posts

Master Geek


  Reply # 461881 23-Apr-2011 21:17
Send private message
Banana?
4010 posts

Uber Geek
+1 received by user: 836

Subscriber

  Reply # 461907 24-Apr-2011 08:49
Send private message

Try ComboFix http://www.bleepingcomputer.com/download/anti-virus/combofix
It can be a bit dangerous, but I have used it lots and never had a PC not start afterwards. Use at your own risk however.

You could try SuperAntiSpyware, or download something that hunts out Rootkits. I would say however that ComboFix will do the trick.

Are you sure that you updated MBAM? Unusual for it not to get rid of most of these sorts of malware.

135 posts

Master Geek
+1 received by user: 30

Subscriber

  Reply # 461908 24-Apr-2011 09:02
Send private message

Here's a fix a fix i use:


Start the pc up in safe mode with networking

Download CCleaner and install.

Open  CCleaner, go to the Tools, Startup.  You'll see that there are some unusual, things in the startup listing, what you are looking for is something like c:\documents and settings\applications\temp\ ndeehemdkwkw.exe (some random letters.exe)


Delete this entry and anyothers that look like they are starting up from a Docsand settings or User Temp location.


This will remove the entry.


Download Malwarebytes in safe mode, the restart nomally and run another scan.


Normally fixed in under 15mins.           
    

    



222 posts

Master Geek
+1 received by user: 1


  Reply # 461923 24-Apr-2011 09:52
Send private message

Thanks guys, finally managed to remove it

Banana?
4010 posts

Uber Geek
+1 received by user: 836

Subscriber

  Reply # 461924 24-Apr-2011 09:55
Send private message

What did you use?



222 posts

Master Geek
+1 received by user: 1


  Reply # 462005 24-Apr-2011 19:11
Send private message

I ran Microsoft safety scanner and Clamwin portable in safemode which seemed to remove it, but also ran Microsoft security essential afterwards in normal mode which picked up two more infected files.




8019 posts

Uber Geek
+1 received by user: 385

Trusted
Subscriber

  Reply # 462216 25-Apr-2011 16:55
Send private message

I would recommend you (or get a tech) do a backup of all your personal files and data then do a format and a clean install, just in case.

360 posts

Ultimate Geek


  Reply # 472173 22-May-2011 11:04
Send private message

Hi. Microsoft security scan / Avg etc wont get rid of it

do the following in safe mode with networking

Use Malwarebytes.

you may have to run this script sometimes it screws with the exe and wont let you run exe files. it will say not compltly updated or somthing to that effect but will work. make sure you update it. http://filext.com/WinXP_EXE_Fix.reg



Admitdly this is not going to get rid of all of this virus but will get rid of most if it.

also run ccleaner as well.




Hu? did i do that?
16Mb (EDO RAM), K6-II processor, 2Mb of onboard graphics. 32k dial up modem. 12 speed CD ROM. 5¼-inch floppy drive. 500Mb HDD.

1410 posts

Uber Geek
+1 received by user: 11


  Reply # 476087 31-May-2011 09:11
Send private message

one of my friends had this virus, i download a process blocker in safe mode and blocked the process from running. just an idea for others reading this thread. then backup data and clean installed windows. now running Microsoft Security Essentials and all going well




gz ftw


Create new topic



Twitter »

Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:





News »

Vocus New Zealand on the block as Aussies bail
Posted 23-Oct-2017 17:06


Vodafone TV — television in the cloud
Posted 17-Oct-2017 19:29


Nokia 8 review: Classy midrange pure Android phone
Posted 16-Oct-2017 07:27


Why carriers might want to embrace Commerce Commission study, MVNOs
Posted 13-Oct-2017 09:42


Fitbit launches Ionic, its health and fitness smartwatch
Posted 12-Oct-2017 15:52


Xero launches machine learning automation to improve coding accuracy for small businesses
Posted 12-Oct-2017 15:45


Bank of New Zealand uses Intel AI to detect financial crime
Posted 12-Oct-2017 15:39


Sony launches Xperia XZ1, a smartphone with real-time 3D capture
Posted 11-Oct-2017 10:26


Notes on Nokia’s phone comeback
Posted 10-Oct-2017 10:06


Air New Zealand begins Inflight Wi-Fi rollout
Posted 9-Oct-2017 20:16


The latest mobile phones in perspective
Posted 9-Oct-2017 18:34


Review: Acronis True Image 2018 — serious backup
Posted 8-Oct-2017 11:22


Lenovo launches ThinkPad Anniversary Edition 25
Posted 7-Oct-2017 23:16


Less fone, more tech as Vodafone gets brand make-over
Posted 6-Oct-2017 08:16


API Talent Achieves AWS MSP Partner Status
Posted 5-Oct-2017 21:20



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.