Fake MSE "clean computer" window

nottaclue9

New member
Member
VIP
Local time
12:57 PM
Messages
456
Location
San Antonio, TX
I've had this thing before, but I can't remember how to rid myself of it. I got it while I was on an ESPN page. I ran a Malware Bytes Pro scan which detected PUP malware. I deleted that and thought I was really smart. Restarted the computer, stupidly went back to the ESPN page, and the thing was still there. It's actually two windows: The original fake Microsoft-looking window and the one behind it, the Big Red "X" showing three standard scary-looking malware programs. with which I am supposedly infected. There is no way to get rid of it conventionally, and the scan didn't do it. I can still use the computer, but I know the thing is lurking.

Please tell me this is something simple to fix...
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 Home Premium 64-bit, service pack 1
CPU
Intel box core i5 4460
Motherboard
Asus B85MECSM 1150
Memory
Kingston Hyper X Fury BLK 1866 8GB 4x2
Monitor(s) Displays
Samsung 23" wide-screen
Screen Resolution
1920 X 1080
Hard Drives
WD Passport, 1 TB
Case
Win Z583 Mini Tower w/ USB3.0
Keyboard
Microsoft ergo wave
Mouse
Logitech wireless
Antivirus
Bitdefender; Malwarebytes Pro
Browser
IE11
Is it a simple popup or did something install again?

Run another Malwarebytes scan to see.

Do you have Java installed?
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Employer provided Dell Latitude
OS
W7 Pro SP1 64bit
CPU
i7
Memory
8GB
Graphics Card(s)
Intel HD Graphics
Hard Drives
crappy SSD
Antivirus
Employer mandated Symantec Endpoint Protection
Browser
Pale Moon 64bit, IE11 64bit & Chrome 64bit
Thanks for the reply usernameissues. I've got Java 7 (51) installed, but can't find any indication in Programs that the fake MSE installed itself. Will run another Malwarebytes scan now.

----------------------------------------------------------------------------------------------------------------

This time, Malwarebytes found no threating objects. But the fake Window is still present on the ESPN page.
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 Home Premium 64-bit, service pack 1
CPU
Intel box core i5 4460
Motherboard
Asus B85MECSM 1150
Memory
Kingston Hyper X Fury BLK 1866 8GB 4x2
Monitor(s) Displays
Samsung 23" wide-screen
Screen Resolution
1920 X 1080
Hard Drives
WD Passport, 1 TB
Case
Win Z583 Mini Tower w/ USB3.0
Keyboard
Microsoft ergo wave
Mouse
Logitech wireless
Antivirus
Bitdefender; Malwarebytes Pro
Browser
IE11
Uninstall Java and see if you miss it.

What antivirus app are you using?
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Employer provided Dell Latitude
OS
W7 Pro SP1 64bit
CPU
i7
Memory
8GB
Graphics Card(s)
Intel HD Graphics
Hard Drives
crappy SSD
Antivirus
Employer mandated Symantec Endpoint Protection
Browser
Pale Moon 64bit, IE11 64bit & Chrome 64bit
Anti-virus is just what's with MSE. I've tried AVAST & it was really annoying.

I'll uninstall Java now. Just curious: What's the connection between JAVA & fake MSE window?

-----------------------------------------------------------------------------------------------------------------

When I try to uninstall Java (update 51), the fake MSE window appears & aborts the uninstall.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 Home Premium 64-bit, service pack 1
CPU
Intel box core i5 4460
Motherboard
Asus B85MECSM 1150
Memory
Kingston Hyper X Fury BLK 1866 8GB 4x2
Monitor(s) Displays
Samsung 23" wide-screen
Screen Resolution
1920 X 1080
Hard Drives
WD Passport, 1 TB
Case
Win Z583 Mini Tower w/ USB3.0
Keyboard
Microsoft ergo wave
Mouse
Logitech wireless
Antivirus
Bitdefender; Malwarebytes Pro
Browser
IE11
Java has been used to infect computers. If you need Java, then it might be worth the risk of having it installed. If you do not need Java, then you are taking a risk for no gain.

Try to uninstall Java again and take/post a screenshot of this fake MSE window via Alt+Prnt Scrn
http://www.sevenforums.com/tutorials/9733-screenshots-files-upload-post-seven-forums.html
Alt+Prnt Scrn should capture just the window that has focus and not the whole desktop.

You might want to glance at this post about using MS Paint.

After you have posted the screenshot...
...boot to the safe mode
...try to uninstall Java again while in the safe mode.
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Employer provided Dell Latitude
OS
W7 Pro SP1 64bit
CPU
i7
Memory
8GB
Graphics Card(s)
Intel HD Graphics
Hard Drives
crappy SSD
Antivirus
Employer mandated Symantec Endpoint Protection
Browser
Pale Moon 64bit, IE11 64bit & Chrome 64bit
I finally got Java uninstalled late last night and then ran a full scan of Malwarebytes Pro. Since it took so long, I went to bed. This morning, the report indicated no malicious items. Under "Programs" in the control panel Java is gone. I still have the fake MSE windows. What should I try now?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 Home Premium 64-bit, service pack 1
CPU
Intel box core i5 4460
Motherboard
Asus B85MECSM 1150
Memory
Kingston Hyper X Fury BLK 1866 8GB 4x2
Monitor(s) Displays
Samsung 23" wide-screen
Screen Resolution
1920 X 1080
Hard Drives
WD Passport, 1 TB
Case
Win Z583 Mini Tower w/ USB3.0
Keyboard
Microsoft ergo wave
Mouse
Logitech wireless
Antivirus
Bitdefender; Malwarebytes Pro
Browser
IE11
Hey neighbor! (Relatively) Download and run AdwCleaner and see if it finds anything.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Built 2/11/2011
OS
Windows 7 Pro-x64
CPU
i7-2600 3.4GHz - 3.8GHz Turbo
Motherboard
Intel DH67BL-B3
Memory
8Gb - 2x4GB, Muskin 991770 PC3-1333
Graphics Card(s)
Integrated Intel HD 2000
Sound Card
Integrated Intel 10.1 HD, RealTek ALC892
Monitor(s) Displays
Asus LCD VH222H, Haier HL24XSL2a
Screen Resolution
1920x1080, 1920x1080
Hard Drives
Crucial SSD C300-128Gb,
Western Digital WD5002AALX - 500Gb,
Western Digital WD7501AALS - 750Gb
PSU
Seasonic 650W 80+ Gold Modular
Case
Rosewill Defender
Cooling
Stock CPU, Four 120mm case fans, PCH fan added
Keyboard
Logitech EX100 Y-RBH94 Wireless
Mouse
Logitech EX100 M-RCE95 Wireless
Internet Speed
3.0/1.5 Mbs
Antivirus
Microsoft Security Essentials
Browser
Microsoft Internet Explorer 11
Other Info
Antec Veris Premier-Multimedia IR Station,
Cyber Accoustics-3602 Speakers,
AFT XM-5U Card Reader,
Hauppauge TV-HVR-2250,
Sony LX300 USB Turntable
Hi, fellow South Texan. Thanks for the advice. I ran the Adwcleaner, and it didn't capture any bad guys. But for some reason, the MSE fake window has disappeared. I haven't had any positive scan results, and I still had the window after I uninstalled Java. So I have no idea what miracle has transpired, but I am grateful. Hopefully, I won't have to bother anyone again -- at least with this particular issue.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 Home Premium 64-bit, service pack 1
CPU
Intel box core i5 4460
Motherboard
Asus B85MECSM 1150
Memory
Kingston Hyper X Fury BLK 1866 8GB 4x2
Monitor(s) Displays
Samsung 23" wide-screen
Screen Resolution
1920 X 1080
Hard Drives
WD Passport, 1 TB
Case
Win Z583 Mini Tower w/ USB3.0
Keyboard
Microsoft ergo wave
Mouse
Logitech wireless
Antivirus
Bitdefender; Malwarebytes Pro
Browser
IE11
Please download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
Please download RogueKiller and save it to your desktop.

You can check here if you're not sure if your computer is 32-bit or 64-bit




  • RogueKiller 32-bit | RogueKiller 64-bit
  • Quit all running programs.
  • For Windows XP, double-click to start.
  • For Vista,Windows 7/8, Right-click on the program and select Run as Administrator to start and when prompted allow it to run.
  • Read and accept the EULA (End User Licene Agreement)
  • Click Scan to scan the system.
  • When the scan completes Close the program > Don't Fix anything!
  • Don't run any other options, they're not all bad!!
  • Post back the report which should be located on your desktop.
Please post logs back, People here might notice things in the logs that you might not have. Thanks
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Packard Bell
OS
Windows 7 Home Premium 64Bit
CPU
AMD A6-3420M 1.5GHZ OC - 2.0GHZ
Memory
4GB DDR3 1600MHZ
Graphics Card(s)
AMD RADEON 6520G+AMD RADEON HD7470M 1GB DDR3
Screen Resolution
1366x768
Hard Drives
500GB SATA
Internet Speed
18Mb Unlimited
Antivirus
AVAST!
Browser
MOZILLA FIREFOX
Without seeing the fake window we can't tell what it is. It may be an ad ESPN has which rotates with others.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built Desktop By DataTech
OS
Windows 7 Ultimate X64 SP1
CPU
Intel i5-2550K, Differing ~4.4-4.8GHz No built in GPU
Motherboard
ASUS P8Z68-V PRO/GEN3
Memory
16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GB
Graphics Card(s)
ASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Sound Card
Onboard Realtek 5-1
Monitor(s) Displays
Samsung P2570HD
Screen Resolution
1920x1080
Hard Drives
Samsung 840 Pro 256GB SSD for OS, 500GB Seagate Constellation (Enterprise drive) for Data
PSU
Corsair HX650W
Case
Inwin Dragon Rider
Cooling
Hyper 212 EVO w/two Noctua fans, push-pull, @1300 RPM
Keyboard
E-Z Eyes, bright yellow keys with large characters
Mouse
steelseries SENSEI Laser Pro Gaming
Internet Speed
48-51Mbs Mbs down, 11 Mbs up Xfinity Cable
Antivirus
Norton Internet Security 2013
Browser
IE 10, Opera, Pale Moon if needed
Other Info
4 case fans, LG BluRay-RE, ASUS DVD-RW, Mr. Fusion power supply, 1.21 gigawatts.
Please download TFC by Old Timer TFC - Temp File Cleaner by OldTimer - Geeks to Go Forums and save it to your desktop.
Save any unsaved work. TFC will close ALL open programs including your browser!
Double-click on TFC.exe to run it. If you are using Vista/Windows 7 right-click on the file and choose Run As Administrator.
Click the Start button to begin the cleaning process and let it run uninterrupted to completion.
Important! If TFC prompts you to reboot, please do so immediately. If not prompted, manually reboot the machine anyway to ensure a complete clean.


TFC (Temp File Cleaner) will clear out all temp folders for all user accounts (temp, IE temp, java, FF, Opera, Chrome, Safari), including Administrator, All Users, LocalService, NetworkService, and any other accounts in the user folder. It also cleans out the %systemroot%\temp folder and checks for .tmp files in the %systemdrive% root folder, %systemroot%, and the system32 folder (both 32bit and 64bit on 64bit OSs). It shows the amount removed for each location found (in bytes) and the total removed (in MB). Before running, it will stop Explorer and all other running apps.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
It's not an ESPN window; I've gotten it before on other sites. Just lucky, I guess. :rolleyes:

I'm not sure why I need to do these things if the window is now gone. Is there a possibility that it's lurking elsewhere?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 Home Premium 64-bit, service pack 1
CPU
Intel box core i5 4460
Motherboard
Asus B85MECSM 1150
Memory
Kingston Hyper X Fury BLK 1866 8GB 4x2
Monitor(s) Displays
Samsung 23" wide-screen
Screen Resolution
1920 X 1080
Hard Drives
WD Passport, 1 TB
Case
Win Z583 Mini Tower w/ USB3.0
Keyboard
Microsoft ergo wave
Mouse
Logitech wireless
Antivirus
Bitdefender; Malwarebytes Pro
Browser
IE11
It's all up to you to find out.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built Desktop By DataTech
OS
Windows 7 Ultimate X64 SP1
CPU
Intel i5-2550K, Differing ~4.4-4.8GHz No built in GPU
Motherboard
ASUS P8Z68-V PRO/GEN3
Memory
16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GB
Graphics Card(s)
ASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Sound Card
Onboard Realtek 5-1
Monitor(s) Displays
Samsung P2570HD
Screen Resolution
1920x1080
Hard Drives
Samsung 840 Pro 256GB SSD for OS, 500GB Seagate Constellation (Enterprise drive) for Data
PSU
Corsair HX650W
Case
Inwin Dragon Rider
Cooling
Hyper 212 EVO w/two Noctua fans, push-pull, @1300 RPM
Keyboard
E-Z Eyes, bright yellow keys with large characters
Mouse
steelseries SENSEI Laser Pro Gaming
Internet Speed
48-51Mbs Mbs down, 11 Mbs up Xfinity Cable
Antivirus
Norton Internet Security 2013
Browser
IE 10, Opera, Pale Moon if needed
Other Info
4 case fans, LG BluRay-RE, ASUS DVD-RW, Mr. Fusion power supply, 1.21 gigawatts.
I've been sailing along for two days now with no evidence of the blasted thing. I think it may have exited with the Java uninstall, and I didn't notice its absence until I did a restart.

I would very much like to save the instructions from the last two contributors, however. I'm not sure how I can do that as I can't print the page. There's always the hand-written option. UGH.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 Home Premium 64-bit, service pack 1
CPU
Intel box core i5 4460
Motherboard
Asus B85MECSM 1150
Memory
Kingston Hyper X Fury BLK 1866 8GB 4x2
Monitor(s) Displays
Samsung 23" wide-screen
Screen Resolution
1920 X 1080
Hard Drives
WD Passport, 1 TB
Case
Win Z583 Mini Tower w/ USB3.0
Keyboard
Microsoft ergo wave
Mouse
Logitech wireless
Antivirus
Bitdefender; Malwarebytes Pro
Browser
IE11
I would very much like to save the instructions from the last two contributors, however. I'm not sure how I can do that as I can't print the page. There's always the hand-written option. UGH.

Hi Notty,

You can select the thread tools at the top, then printable version.

thread tools.JPG

Just a suggestion as well, it may seem like it's gone but running those tools from our experts will let you know for sure, they are quite good at what they do. :)
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Built
OS
Win 10 Pro x64
CPU
Intel I5-2500K @3.3GHz
Motherboard
Asrock P67 Extreme4
Memory
16GB G.Skill Ripjaws X (4x4GB)
Graphics Card(s)
EVGA GeForce 750 Ti SC 2GB
Sound Card
ASUS Xonar DG 5.1 Channels 24-bit 96KHz PCI Interface Sound
Monitor(s) Displays
auria eq2367
Screen Resolution
1920 x 1080
Hard Drives
250GB Samsung 850 EVO SSD
1TB WD Blue
1TB Hitachi
PSU
SeaSonic X 650W 80 Plus Gold
Case
Corsair Obsidian 750D
Cooling
Corsair H60, Three 140mm case fans
Keyboard
Logitech Wireless Keyboard K520
Mouse
Logitech Wireless Mouse M310
Internet Speed
Wave Broadband ~ 100 dn 5 up
Antivirus
Windows Defender, Malwarebytes Premium
Browser
Edge, IE11, Chrome
Other Info
Laptop specs: HP g7-1365dx /
CPU: AMD A6-3420M APU with Radeon(tm) HD Graphics /
RAM: Crucial 8Gb (2x4Gb) /
SSD: Crucial M4-CT128M4SSD2 ATA Device/ FW 000F /
GFX: AMD Radeon HD 6520G /
OS: Windows 10 Pro x64
You could also copy the exact post you want to save and paste it in things like Word Pad, Note Pad or a word processor of choice.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
It's not an ESPN window; I've gotten it before on other sites. Just lucky, I guess. :rolleyes:

I'm not sure why I need to do these things if the window is now gone. Is there a possibility that it's lurking elsewhere?
It would root out other malware you may not (yet) know you have. They are easy and harmless to do. Free too. ;)
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built Desktop By DataTech
OS
Windows 7 Ultimate X64 SP1
CPU
Intel i5-2550K, Differing ~4.4-4.8GHz No built in GPU
Motherboard
ASUS P8Z68-V PRO/GEN3
Memory
16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GB
Graphics Card(s)
ASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Sound Card
Onboard Realtek 5-1
Monitor(s) Displays
Samsung P2570HD
Screen Resolution
1920x1080
Hard Drives
Samsung 840 Pro 256GB SSD for OS, 500GB Seagate Constellation (Enterprise drive) for Data
PSU
Corsair HX650W
Case
Inwin Dragon Rider
Cooling
Hyper 212 EVO w/two Noctua fans, push-pull, @1300 RPM
Keyboard
E-Z Eyes, bright yellow keys with large characters
Mouse
steelseries SENSEI Laser Pro Gaming
Internet Speed
48-51Mbs Mbs down, 11 Mbs up Xfinity Cable
Antivirus
Norton Internet Security 2013
Browser
IE 10, Opera, Pale Moon if needed
Other Info
4 case fans, LG BluRay-RE, ASUS DVD-RW, Mr. Fusion power supply, 1.21 gigawatts.
Good advice, all of it. I'm so slow at doing the procedures, but it is a good idea to making sure I'm running a clean machine. My computer does seem to have an "infect me" sign stuck on its back.

I'll be back! Just not right away. Y'all aren't so lucky. ;)
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 Home Premium 64-bit, service pack 1
CPU
Intel box core i5 4460
Motherboard
Asus B85MECSM 1150
Memory
Kingston Hyper X Fury BLK 1866 8GB 4x2
Monitor(s) Displays
Samsung 23" wide-screen
Screen Resolution
1920 X 1080
Hard Drives
WD Passport, 1 TB
Case
Win Z583 Mini Tower w/ USB3.0
Keyboard
Microsoft ergo wave
Mouse
Logitech wireless
Antivirus
Bitdefender; Malwarebytes Pro
Browser
IE11

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Employer provided Dell Latitude
OS
W7 Pro SP1 64bit
CPU
i7
Memory
8GB
Graphics Card(s)
Intel HD Graphics
Hard Drives
crappy SSD
Antivirus
Employer mandated Symantec Endpoint Protection
Browser
Pale Moon 64bit, IE11 64bit & Chrome 64bit
Back
Top