Forum Home

Master Index of Archived Threads


I need help

Rockin' Doc
May 30 2011 04:08 PM

My computer has been infected with the rogue virus/malware MS Removal Tool. It poses as a legitimate antivirus program and tells me my computer is infected. Of course it is the infection as it tries to sell me a bogus software program to get rid of the virus.

AVG, Malwarebytes, and Spybot Search & Destroy have not been able to remove the problem. I'm running the computer in safe mode and am at a loss for what to do to get rid of this rogue virus.

Any suggestions?

dgwphotography
May 30 2011 04:18 PM
Re: I need help

Can you do a restore to an earlier date in safe mode?

Rockin' Doc
May 30 2011 04:26 PM
Re: I need help

I tried that, but it didn't help.

dgwphotography
May 30 2011 04:39 PM
Re: I need help

Did you try installing and then running malwarebytes while in safe mode?

Rockin' Doc
May 30 2011 06:27 PM
Re: I need help

I already had Malwarebytes installed on my computer when I got this. I have run it both in regular mode and again in safe mode to no avail. Should I delete Malwarebytes and reinstall it while in safe mode?

I should have mentioned that the name of the rogue virus that is causing the trouble is "MS Removal Tool". Thus far, it's not the most debilitating bug, but it is rather annoying.

metirish
May 30 2011 06:34 PM
Re: I need help

I have had this twice in the past , if it's the same one I had I couldn't even download programs to help. IIRC I had to wipe the PC clean.

Thinking back though the tech guy at work had me do some things in safe mode and I may have resolved it that way.

The Second Spitter
May 30 2011 11:09 PM
Re: I need help

Not sure which operating system you're running, but you may find this link useful

http://www.microsoft.com/downloads/en/d ... laylang=en

As a future tip, it's probably better to use a more obscure web browser, something like Opera.

Number 6
May 31 2011 06:08 PM
Re: I need help

I'm late to this, but try rkill. I have used it to fix sveral machines with similar bugs. It disables running malware processes so you can run programs like MalwareBytes effectively. Generally knocks down the more sophisticated bugs that disable the more popular and effective anti-malware programs.

Mind you, it is not a cure in itself, you will still have to run MalwareBytes after the processes are disabled (ie, do not restart immediately after running rkill, run MalwareBytes first).

http://download.cnet.com/RKill/3000-802 ... 64676.html

Number 6
May 31 2011 06:30 PM
Re: I need help

BTW, if you need help with any of this message me, happy to provide further info or even get on the phone to help out.

The Second Spitter
May 31 2011 08:04 PM
Re: I need help

FACT: In New Zealand, they use sheep to perform functions us ordinary folk use computers for.

Edgy DC
Jun 01 2011 07:41 AM
Re: I need help

"I Need Help" sounds like a rejected Beatles screenplay.

metsmarathon
Jun 05 2011 10:58 AM
Re: I need help

ugh. for the first time in many many years, i've been struck by a virus. it appears to be a very similar thing, only its called "windows 7 restore" where it looks like a ligit warning from microsoft that something dire has just malfunctioned with your computer. the tipoff is that it asks you to purchase an upgrade that'll allow it to fix these issues. fairly convincing overall.

its also sophisticated in that it tries to block other antivirus programs.

i'm a little annoyed, too, because i have mcafee running on my system, hogging up resources, and it got through.

it looks like it has eliminated all of my user data - desktop, documents, anything that was in the users directory. my desktop is blank, and none of my programs show up in the quicklaunch. happily, none of my photos were in there - they're all in a separate drive. i'm now very worried that said drive is now a carrier of malicious code, of course. it's been unplugged and will only be plugged back in once i'm satisfied the main drive is clean.

this serves unfortunately to not only highlight the importance of me getting off my lazy high-risk ass and backing up my photos somewhere, but also delays such action.

the user data might be hiding in my recycle bin.

John Cougar Lunchbucket
Jun 06 2011 08:17 AM
Re: I need help

I run Mozy, which does a daily cloud backup of your shit just in case this kinda stuff happens. Small price to pay for a little POM.

Rockin' Doc
Jun 06 2011 08:34 PM
Re: I need help

Damn, sorry to here of your computer woes marathon. It sounds like you got the computer virus equivalent of the Swine flu while I'm battling an annoyingly persistent cold.

Best of luck battling your computer virus. I hope your information is retrievable.