Computing.Net > Forums > Security and Virus > Malicious Code From Microsoft?

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Malicious Code From Microsoft?

Reply to Message Icon

Name: Namor27
Date: October 25, 2003 at 23:20:34 Pacific
OS: Windows XP
CPU/Ram: 2 ghz
Comment:

I'm sorry to bother everyone again, but I have a really strange problem-- I downloaded Tweak UI directly from Microsoft but I can't remove it. When I try to uninstall it, it deletes half the program, and then Norton pops up a warning.

"Alert: Malicious script detected
Object FileSystem Object
Activity DeleteFile
Your computer is halted and needs to do something about this script:
WINDOWS\System32\TweakUI.exe\uninstall.hta"

It then asks whether I should stop the script or allow it.
I downloaded a second version of the program from somewhere else. I thought I'd overwrite it and delete it, but the old version remained after the new version was removed. The new version also deleted without the "malicious code" warning. I can't use system restore because it wasn't on at the time, but I want this infernal program off my machine. Will someone please help me?



Sponsored Link
Ads by Google

Response Number 1
Name: Solarian
Date: October 25, 2003 at 23:33:04 Pacific
Reply:

Namor27:

Have you tried to delete Tweak UI in Safe Mode?

Also, check the registry for any entries left behind, both by the second (un-installed) version of Tweak UI and the original that's giving you the hard time.

Solarian


0

Response Number 2
Name: Namor27
Date: October 26, 2003 at 00:29:48 Pacific
Reply:

I tried Safe Mode as suggested, but it didn't seem to make a difference. I'm worried about working in the registry-- I'm just not that competent with my machine. I also discovered I was wrong, it doesn't even get as far as deleting any files, just the start menu icon (it shows a checklist). Is there some way I can get passed the malicious code part, so I can finish uninstalling?


0

Response Number 3
Name: Solarian
Date: October 26, 2003 at 01:20:23 Pacific
Reply:

Namor27:

Okay, first, Tweak UI is nothing malicious in and of itself. I've got it installed on my own PC. Strangely, I had to re-install it a couple of times because it kept disappearing! Go figure.

I know the Norton warnings are a pain in the butt, but that's all they are--an annoyance.

Before trying to delete that .exe file, it would be best to remove its associated keys out of the registry FIRST. You say you're uncomfortable going into the registry. Wisely, a lot of people are.

For safety in the registry and to speed things up, download a copy of RegSeeker. You'll find a free copy at:

www.webattack.com

Click on FREEWARE at the top of the page, then look through the listings for REGISTRY TOOLS. Click on it. Scroll down until you find RegSeeker then download it.

After it's installed and the interface is open, click in FIND IN REGISTRY. In the box enter "tweakui" WITHOUT the quotation marks. Click on SEARCH.

Let the program scan the registry. By the time its finished, you should have at least one or two registry keys for Tweak UI. If you do, click on HIGHLIGHT ALL, then right-click your mouse and click on DELETE. The keys will disappear.

Don't worry. RegSeeker makes a back-up of everything it removes. You can restore the keys if need be.

Then, try everything in Windows Explorer--I assume that's where you found the .exe--to delete Tweak UI.

If I'm not here when you post back, someone else will pick up the thread.

Good luck, Solarian



0

Response Number 4
Name: safeTsurfa
Date: October 26, 2003 at 03:14:36 Pacific
Reply:

This is the clue:
"WINDOWS\System32\TweakUI.exe\uninstall.hta"

Check your Norton settings, you will see it alerts on hta files trying to perform a system activity (here deletion of files). This is because hta can contain malicious scripts.

So either disable Norton auto protect while you uninstall, or temporarily downrate the level of protection it is providing until you are done.


0

Response Number 5
Name: Namor27
Date: October 27, 2003 at 23:38:43 Pacific
Reply:

Problem solved and everything is running smoothly. Thanks for all the help, Solarian, and thank you, SafeTsurfa. I'm grateful.


0

Related Posts

See More



Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Malicious Code From Microsoft?

Password from Microsoft www.computing.net/answers/security/password-from-microsoft/5076.html

Infected email from Microsoft? www.computing.net/answers/security/infected-email-from-microsoft/8762.html

cant download from microsoft www.computing.net/answers/security/cant-download-from-microsoft/24999.html