We help IT Professionals succeed at work.

Check out our new AWS podcast with Certified Expert, Phil Phillips! Listen to "How to Execute a Seamless AWS Migration" on EE or on your favorite podcast platform. Listen Now

x

MS Removal Tool

digisel
digisel asked
on
Medium Priority
583 Views
Last Modified: 2013-11-22
I have been attempting to remove this MS Removal Tool disaster.
I have done the following:
Run Malwarebytes anti-malware - to no avail
I have run rkill.com this removed a couple of fileds but not the correct ones.
I cannot accesss my ESET antiq virus

I believe thekey file is
04-HKCU\,,\RunOnce:[FHrPqDaZcC802547]C:\ProgramDAta\FHrPqDADcCg02547.exe

I have Windows 7 OS Home Edition and cannot get into ProgramData to delete this file.

Does anyone know a simple and effective way of getting rid of this.

I am not good enough to go into Registry files etc.
Thanks
Comment
Watch Question

Commented:
Unlock this solution with a free trial preview.
(No credit card required)
Get Preview
CERTIFIED EXPERT
Author of the Year 2011
Top Expert 2006
Commented:
Unlock this solution with a free trial preview.
(No credit card required)
Get Preview

Author

Commented:
To bmsjeff
I have looked in the directory and the 04-HKCU edtc. RuncOnce file is not there

To Younghv: I had already followed the steps of bleepingcomputer to no avail.   I have repeated them  And also managed to download the latest version of malbytes which I ran - to no avail

I also ran ESET in Safemoade - it found only one suspect file and it did not apply to this problem
The MS Removal Tool probl;em remains.

Any other thoughts or actions please

Author

Commented:
P.S. I shall also be following the links suggested by Younghx and acting accordingly.
If you have any other suggestions they will be most welcome

Commented:
This file will change.  Run Malwarebytes again. Make sure you update it first.  See what the name of the new file is and delete it.
CERTIFIED EXPERT
Top Expert 2007

Commented:
If the problem persists:

Try running unhide.exe to remove hidden flags.
Download and run Unhide.exe to remove the hidden flags on files and folders.
http://download.bleepingcomputer.com/grinler/unhide.exe


If needed you can download ComboFix and if it doesn't delete it on its first run we can delete it using its script function.

1.  Please download ComboFix by sUBs:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe 

STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply.
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

ComboFix tutorial:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Author

Commented:
Thanks for your time and trouble.
Unlock the solution to this question.
Thanks for using Experts Exchange.

Please provide your email to receive a free trial preview!

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.