Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

How to remove a Programme installed by fraudulent means


  • Please log in to reply
4 replies to this topic

#1 LaneFHoffman

LaneFHoffman

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  

Posted 28 January 2024 - 03:49 PM

Individuals claiming to be from the London-based Bitcom Financial company with the name of the company where I had purchased invested in Bitcoins 5 years who knew my account number and exact amount had invested contacted me, In this process a programme was installed in my computer called AnyDesk and the functions permitting access to  my computer are on. I have removed/uninstalled this programme but what now must be manually unistalled removed are the Programme Folder as well as the Shell Association of AnyDesk. Does anyone know how to remove these?


Edited by hamluis, 28 January 2024 - 04:34 PM.
Moved from Intros to Gen Sec - Hamluis.


BC AdBot (Login to Remove)

 


#2 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 33,826 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:11 AM

Posted 28 January 2024 - 05:26 PM

Download and install min-toolbox from here: https://www.bleepingcomputer.com/download/minitoolbox/
 
minitoolbox.png
 
With the following:
 
Last 10 error messages from the logs
Installed Application
Problematic Devices 
List users and partitions

US Navy Veteran from 2002 to 2006

Masters in Computer and Digital Forensics Expert - Stevenson University Alumni 2015

Arch Desktop - https://termbin.com/epij

Arch Laptop - https://www.termbin.com/dnwk

Ubuntu Server - https://termbin.com/zvra


#3 0lds0d

0lds0d

  •  Avatar image
  • Members
  • 4,158 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Canada
  • Local time:11:11 PM

Posted 28 January 2024 - 09:41 PM

First what exactly are file extension(s) of this? 

It will be listed in the Root of the Registry - and can be deleted easily (in Safe Mode is easier). Also searching AnyDesk in the Registry and and it's main executable files (anydesk.exe for example, not accurate by any means, so make a list of the file first before deletion to be used for cleaning the registry) can be safely deleted in the Registry.

WARNING!!! Please make a backup of the Registry and a new System Restore before attempting to edit the Registry - just to be on the side of safety.

Something like a free registry cleaner (not always recommended but in this situation will be effective and useful) such as Wise Registry Cleaner will delete the file extensions in the Registry for you, but only after the files are all deleted from the drive.

 

As for folders in the Program Directory and ProgramData and in the User(s) Directories, these you must be able to either list for us or figure these out. Using Windows Search with AnyDesk can be quite useful to locate and determine the files and folders.

Still maybe even drivers or files can be left-over in the System32 directory that must be removed maybe manually. Again Windows Search will be an aid to find these for you.

And deleting those files/folders may require you to do so only in the Safe Mode if these are in use or locked by Windows.

 

Autoruns can be useful to help find some rogues - https://learn.microsoft.com/en-us/sysinternals/downloads/autoruns

And Process Explorer - https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer

 

An alternative is do a System Reinstall or Refresh - it will bring you up to a nice new and clean setup. 


Edited by 0lds0d, 28 January 2024 - 09:49 PM.

Proverbs 14:29


#4 Pkshadow

Pkshadow

  •  Avatar image
  • BC Advisor
  • 12,306 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:On the Brow of the Hill, West Coast, Canada
  • Local time:09:11 PM

Posted 28 January 2024 - 11:08 PM

Start a Topic in the Malware Removal Forum after reading and getting the Prep done before posting.

 

Note : Would be worried about your Bitcoins having been stolen. So do the above as fast as possible.

 

Also read the front Page of Bleepingcomputer.com daily for info you should be aware of. this is a known scam and others.

 

https://www.google.com/search?client=firefox-b-d&q=London-based+Bitcom+Financial+scam+bleepingcomputer.com


" mosquitoes really wake up everyday and choose violence "   — dalia (@_dalia7)
www.cnn.com/2020/07/23/health/mosquitoes-attraction-humans-future-wellness-scn/index.html
 

I-7 ASUS ROG Rampage II Extreme  / ASUS TUF Gaming F17 / I-7 4770K ASUS ROG Maximus VI Extreme


#5 midimusicman79

midimusicman79

    Sec & Web Browser Enthusiast


  •  Avatar image
  • BC Advisor
  • 4,639 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Norway
  • Local time:06:11 AM

Posted 29 January 2024 - 04:12 AM

You can start a new topic in the Virus, Trojan, Spyware, and Malware Removal Help Forum, for assistance by the Malware Response Team.

And to do that, please follow the instructions in the Malware Removal and Log Section Preparation Guide.

Good luck! :)

MS Win 10 Pro 64-bit V. 22H2 (19045) Desktop PC, EAMH Paid/EEK, MB 4 Prem., WPP, NVT OSA Free, and Unchecky, MDFW, FF with uBO, Grammarly Free, MBBG, and Acronis CPHOE (DI), SUMo Free. I have 28.5 Years of PC Experience.





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users