Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

How Microsoft copied malware techniques to make Get Windows 10 the world's PC pest
The Register ^ | Mar 17, 2016 | Andrew Orlowski

Posted on 03/17/2016 8:18:48 PM PDT by dayglored

Note: I've posted numerous threads on the "Get Windows 10" nagware situation, and almost passed this one up -- but it's far and away the best I've seen, most complete, and most likely to be accurate. So have at it... - dayglored

Subtitle: Here's how to nuke this persistent menace

Microsoft uses techniques similar to aggressive malware to promote its “Get Windows 10” offer.

As many readers have discovered, the persistent and constantly changing methods Microsoft uses to continually reintroduce its “Get Windows 10” tool, or GWX, onto computers means it’s extremely difficult to avoid.

Windows users who decline to use it find it is repeatedly reintroduced. The language of the counter-malware industry is more appropriate than the language of enterprise IT for GWX.

GWX subverts a channel intended for one purpose (security hotfixes) for another (advertising); it changes its “attack vectors”, it “conceals itself” kinda like a rootkit; it uses “polymorphic” techniques; and it consistently overrides users' actions and permissions.

Much of the attention in the tech press on combatting GWX has been has focused on eliminating the work of one patch, KB3035583, which constantly reappears on users' PCs, even after removal. However, an investigation shows that ‘583 is a symptom, rather than the cause, of recurring GWX infestations.

The ‘583 patch is most commonly reinstalled by another patch, KB2952664. Once ‘664 is on a system, '583 will be requested for download and installation. Getting rid of, and thereby controlling, '664 could be the key to controlling the sophisticated "Get Windows 10" nagware network.

(Excerpt) Read more at theregister.co.uk ...


TOPICS: Business/Economy; Computers/Internet; Hobbies
KEYWORDS: gwx; microsoft; nagware; windows; windows10; windowspinglist
Navigation: use the links below to view more comments.
first 1-2021-4041-45 next last
I know some will say "Enough already with the complaints about Windows 10" but this isn't about the operating system -- which itself is quite nice in many respects. It's about the campaign to force it down everyone's throats.

I strongly recommend reading the entire article. Yes, it's rather technical in spots, and there are some listings you can safely skip. But if you're interested in avoiding this unending cycle of nagging, and the recent forays into forced upgrades against the user's will and settings, it's worth the read.

1 posted on 03/17/2016 8:18:48 PM PDT by dayglored
[ Post Reply | Private Reply | View Replies]

To: Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; amigatec; AppyPappy; arnoldc1; ATOMIC_PUNK; ...
Windows 10 - is this at last the solution to the nagging and forced upgrades? ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

2 posted on 03/17/2016 8:19:29 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

ping for later ...


3 posted on 03/17/2016 8:22:20 PM PDT by Springfield Reformer (Winston Churchill: No Peace Till Victory!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored
And please, Linux and Mac folks, we Windows users know those options exist. You needn't remind us yet again.

We're mainly just interested in Microsoft leaving our beloved Windows 7 (and even some 8.1) systems alone.

Thanks.

4 posted on 03/17/2016 8:22:38 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 2 | View Replies]

To: dayglored

Windows 10 is being forced on people without their consent. At the same time, MS is running around bragging about its adoption rate.

This is like a guy who uses roofies on women bragging that he beds down a lot of women. Windows 10 is basically date rape.


5 posted on 03/17/2016 8:23:41 PM PDT by DesertRhino ("I want those feeble mined asses overthrown,,,)
[ Post Reply | Private Reply | To 1 | View Replies]

To: DesertRhino
> Windows 10 is basically date rape.

Interesting analogy. And BTW, the bragging is somewhat muted these days. The uptake rates are falling faster than they'd like.

6 posted on 03/17/2016 8:26:22 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 5 | View Replies]

To: dayglored

GWX Control Panel ( http://ultimateoutsider.com/downloads ) does some good things, but it hasn’t kept up with the full list of KB updates that ought to be removed beyond just KB3035583, namely:

KB3035583
KB3022345
KB3068708
KB3075249
KB3080149
KB2990214
KB3044374
KB2952664
KB2976978
KB3021917
KB3112336
KB3112343
KB3083711
KB3083710
KB3123862
KB3012973
KB3146449
KB3139929

So I’ve made some easy-to-use tools to help put an end to this coerced Windows 10 installation nonsense. They can be downloaded from here and then unzipped:

https://drive.google.com/file/d/0B_hrA7ihzIPlVXpRUnJyc1AyNkU/view?usp=sharing

The three included tools uninstall the Windows 10 nagware and the Microsoft “telemetry” (spyware) “updates” from Windows 7 and Windows 8.x Operating Systems if they are installed, prevent the updates from being reinstalled, and remove the Windows 10 installer folder $WINDOWS.~BT if it is present.

These tools must be run from an account with Administrative privilege, which is the case (unfortunately) for most accounts. They can also be run from a non-Administrator account by right-clicking them and then left-clicking on “Run as Administrator”.

The tools are most effective when run in the following order:

1. Run PreventW10InstallationUAC.exe to set Microsoft Update to “manual only” mode and modify a couple of registry variables that tell the OS to never allow a newer OS to be installed. This tool will run quickly unless you accept the optional request (recommended) to make a System Restore Point before the tool makes it changes, in which case the Restore Point will take a while to make.

Note that after this procedure finishes, no more Microsoft updates will be applied unless you manually request a check for updates and then decide which updates to accept, though making such decisions requires knowledge that the average user usually does not possess. However, for mature operating systems I personally believe that blindly accepting Microsoft updates at this juncture has more downsides than upsides.

(If you DO want to attempt to manually check for updates, you’ll first have to change the Windows Update setting from “Never Check for Updates” to “Check for updates but let me choose whether to download and install them” before you click the “Check for updates” button.)

2. Run RemoveW10NagwareTool.exe to remove a set of Microsoft updates that relate to Windows 10 nagware (”white flag”) popup, Microsoft spyware, and the Windows 10 installer itself if any of them have been installed. Detection and uninstallation can take a few minutes to complete.

If any of this set of updates is found, you’ll need to reboot the system.

It might also be necessary to run this tool again after rebooting if the nagware update had previously been slated to be installed AGAIN, in which case after rebooting, you’ll STILL see the Windows 10 (”white flag”) nag. If that’s the case, just run this tool again and reboot again, and then run PreventW10InstallationUAC.exe again.

3. Finally, after you’re sure the Windows 10 nagware has been removed, run RemoveW10Folder.exe to detect and remove the Windows 10 install folder if it is found.


7 posted on 03/17/2016 8:28:50 PM PDT by catnipman (Cat Nipman: Vote Republican in 2012 and only be called racist one more time!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored; DesertRhino
> The uptake rates are falling faster than they'd like.

For example: Windows 10 upgrade not working like Microsoft hoped - adoption rate dropping off

8 posted on 03/17/2016 8:31:39 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 6 | View Replies]

To: dayglored

M4L Win 10 Malware


9 posted on 03/17/2016 8:32:03 PM PDT by Scrambler Bob (As always, /s is implicitly assumed. Unless explicitly labled /not s. Saves keystrokes.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: catnipman

Excellent summary and details — Thanks!!


10 posted on 03/17/2016 8:32:29 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 7 | View Replies]

To: dayglored

Why isn’t Bill Gates in Gitmo for this?

RICO.


11 posted on 03/17/2016 8:34:16 PM PDT by Scrambler Bob (As always, /s is implicitly assumed. Unless explicitly labled /not s. Saves keystrokes.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored
We've seen this before. Symantic/Norton "antivirus" morphed from a useful application to a system hogging nuisance.

Now microsoft windoze has taken the same dark path. Spying, targeted advertising, windoze store.

My advice: save an image of your OS, turn off updates, turn off scripting in your browser, turn off HTML in email, be careful with email attachments and any executables.


12 posted on 03/17/2016 8:34:40 PM PDT by 867V309 (It's over. It's over now.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

ping


13 posted on 03/17/2016 8:40:06 PM PDT by fulltlt
[ Post Reply | Private Reply | To 1 | View Replies]

To: 867V309
> My advice: save an image of your OS, turn off updates, turn off scripting in your browser, turn off HTML in email, be careful with email attachments and any executables.

That will work. But so will this, if you have a bit of CPU power, RAM, and disk to spare:

  1. Backup your Windows install, make sure you have the original install media or ISO, and your license key.
  2. Wipe Windows, install some standard Linux and VMware Player, VirtualBox, or equivalent free virtual host software.
  3. Make a VM and load your Windows install into it. Depending on the VM hosting software, you may be able to do this directly; otherwise you may have to install Windows fresh (never a bad idea anyway), reload your apps, and continue.
  4. Make a file copy of the Windows VM from time to time.
Now you don't have to worry AT ALL about malware or other infections. If you get hit, just delete the infected VM folder, and restore the latest backup copy. Ready to roll again in minutes.
14 posted on 03/17/2016 8:42:13 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 12 | View Replies]

To: dayglored
Backup your Windows install, make sure you have the original install media or ISO, and your license key.

Great advice. Except NOBODY buying a new notebook computer has any original install media or ISO.


15 posted on 03/17/2016 8:47:01 PM PDT by 867V309 (It's over. It's over now.)
[ Post Reply | Private Reply | To 14 | View Replies]

To: dayglored

thank you


16 posted on 03/17/2016 8:48:33 PM PDT by make no mistake
[ Post Reply | Private Reply | To 1 | View Replies]

To: catnipman

You’re my hero, CatNipMan!

Thanks for those files, and the assurance that nothing changes without my say-so on my desktop.


17 posted on 03/17/2016 8:49:26 PM PDT by bajabaja (Too ugly to be scanned at the airports.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: catnipman

I’ve been using GWX control panel, which is seemingly worked well but I’m going to download and explore your files. Thank you so much.


18 posted on 03/17/2016 8:56:02 PM PDT by catbertz
[ Post Reply | Private Reply | To 7 | View Replies]

To: catnipman

Bookmarked


19 posted on 03/17/2016 9:05:01 PM PDT by Sgt_Schultze (If a border fence isn't effective, why is there a border fence around the White House?)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Pontiac

Later


20 posted on 03/17/2016 9:16:15 PM PDT by Pontiac (The welfare state must fail because it is contrary to human nature and diminishes the human spirit.)
[ Post Reply | Private Reply | To 7 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-45 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson