• Win 10 Laptop Hijacked

    From jaugustine@3:633/10 to All on Sat Jul 4 14:45:28 2026
    Hi,

    One of my laptops has Windows 10.

    I downloaded what I thought was a FREE Roku app. After installing, I discovered "PC App Store" installed with a full screen application requiring Credit Card info. I was unable to un install this App or get rid of this Application using a Credit Card window. Note: I regret that I never made a Restore point.

    Do you know what I should try next?

    Thank You in advance, John


    --- PyGate Linux v1.5.18
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)
  • From s|b@3:633/10 to All on Sat Jul 4 22:07:42 2026
    On Sat, 04 Jul 2026 14:45:28 -0400, jaugustine@verizon.net wrote:

    One of my laptops has Windows 10.

    I downloaded what I thought was a FREE Roku app. After installing, I discovered "PC App Store" installed with a full screen application requiring Credit Card info. I was unable to un install this App or get rid of this Application using a Credit Card window. Note: I regret that I never made a Restore point.

    Restore points are crap; the couple times I used it it left a lot of
    shit behind. IMO you're better off creating an image. I use Macrium
    Backup for that.

    Do you know what I should try next?

    Ctrl+Shift+Esc to open Task Manager

    If you can find which process is running, then select > rightclick > End
    task

    Download and install Malwarebytes:
    <https://www.malwarebytes.com/>

    There's a free download, at the top on the right.

    Maybe boot in safe mode before installing and running it.

    <https://support.microsoft.com/en-us/windows/experience/startup-boot/windows-startup-settings>

    --
    s|b

    --- PyGate Linux v1.5.18
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)
  • From VanguardLH@3:633/10 to All on Sat Jul 4 15:38:26 2026
    <jaugustine@verizon.net> wrote:

    One of my laptops has Windows 10.

    I downloaded what I thought was a FREE Roku app. After installing, I discovered "PC App Store" installed with a full screen application
    requiring Credit Card info. I was unable to un install this App or
    get rid of this Application using a Credit Card window. Note: I
    regret that I never made a Restore point.

    Do you know what I should try next?

    I've used Revo Uninstaller in the past (both free and paid versions).
    They use a database of known software to know what file and registry
    remnants to get rid of. Sorry, without the program name, I can't lookup
    in Revo if they have the uninstall steps recorded for whatever is your
    untoward software. I didn't find (but didn't look that hard) if they
    provide a list of known apps for which they have additional deletions
    recorded in their database.

    https://www.youtube.com/watch?v=-s7gFg3TngU

    However, it is possible the untoward software did not install itself,
    but just copied files, and added registry entries, like to auto-load on startup. That is, an "installer" that merely copies files but doesn't
    register anything is the same as you copying files: there won't be
    anything detectable as an installed program. If the software did not
    install, there's nothing Revo can list to help you out. Revo, and
    others like it, are uninstall enhancers. They dig deeper for a cleaner uninstall *if* they know what to target.

    I have no idea what is "PC App Store". Sounds like some software you
    installed that homes a library of software, but obviously whomever runs
    that store does not curate the software they proffer to ensure it is
    safe. Is this it? Did you instead mean the Microsoft Store, or
    something else entirely, like:

    https://pcapp.store/

    Did you read their FAQs?

    https://pcapp.store/?p=lpd_appstore-faq
    Is the PC APP STORE? Free?
    You can download and install PC APP STORE?, as well as receive
    recommendations for free. But PC APP STORE? is a store and to enjoy
    the offers you need a valid payment method linked with your account.

    So, they are NOT offering their apps for free. In fact, you have the
    PAY them to use their store. Since they are SELLING apps, but their
    "store" app is free, maybe you use their "store" app to get rid of any
    of their payware apps you installed using their "store".

    sb's mentioned killing the untoward process using Task Manager.
    SysInternals' Process Explorer is a more robust task manager, like
    properties on a process telling you from where and how it got started,
    but it can (optionally) link to Virustotal.com to help identify iffy or malicious processes. You could also use SysInternals' AutoRuns which
    lists where startup programs can hide, and not just in the typical
    startup locations. For example, it will list startup programs that are
    defined as winlogon events (they load when you login), in Task
    Scheduler, and elsewhere.

    Forget relying on System Restore points. They are to fix the operating
    system, not to eliminate software. Do you have regularly scheduled
    backups from which you could restore an image of your drive(s)? If not scheduled, most users tend to forget to do backups before installs, so
    they either have no backups, or they are very old which means losing a
    lot of wanted changes since the backup. Backups should be scheduled to eliminate user prompting or initializing.

    Do you do backups? If so, are they logical file backups, or drive image backups? Restores from file backups will not get rid of anything that
    was added after the backup, so malware survives. Restores from image
    backups restore a drive back to its prior state. Not only are image
    backups handy to get rid of badware, but also any software you installed
    that after testing you find you don't want. Instead of doing an
    uninstall, and trying to eradicate the file and registry remnants, an
    image restore saved before the install puts the drive back in the exact
    state it was in at the time of the backup. You don't just uninstall
    some files while leaving other changes, your drive is exactly how it was
    before the install. System Restore is a file restore, so what you end
    up with is some files stepped on to restore the OS, and other changes
    left behind which might be what you really want to eradicate.

    --- PyGate Linux v1.5.18
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)
  • From Carlos E. R.@3:633/10 to All on Sat Jul 4 22:51:36 2026
    On 2026-07-04 22:38, VanguardLH wrote:
    <jaugustine@verizon.net> wrote:


    I have no idea what is "PC App Store". Sounds like some software you installed that homes a library of software, but obviously whomever runs
    that store does not curate the software they proffer to ensure it is
    safe. Is this it? Did you instead mean the Microsoft Store, or
    something else entirely, like:

    https://pcapp.store/

    Did you read their FAQs?

    https://pcapp.store/?p=lpd_appstore-faq
    Is the PC APP STORE? Free?
    You can download and install PC APP STORE?, as well as receive
    recommendations for free. But PC APP STORE? is a store and to enjoy
    the offers you need a valid payment method linked with your account.

    So, they are NOT offering their apps for free. In fact, you have the
    PAY them to use their store. Since they are SELLING apps, but their
    "store" app is free, maybe you use their "store" app to get rid of any
    of their payware apps you installed using their "store".


    Maybe the rogue application is the PC app store itself. Apps require
    payment, so they ask for the plastic card info upfront. Just uninstall it.



    --
    Cheers,
    Carlos E.R.
    ES??, EU??;

    --- PyGate Linux v1.5.18
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)
  • From Paul@3:633/10 to All on Sat Jul 4 17:44:40 2026
    On Sat, 7/4/2026 2:45 PM, jaugustine@verizon.net wrote:
    Hi,

    One of my laptops has Windows 10.

    I downloaded what I thought was a FREE Roku app. After installing, I discovered "PC App Store" installed with a full screen application requiring Credit Card info. I was unable to un install this App or get rid of this Application using a Credit Card window. Note: I regret that I never made a Restore point.

    Do you know what I should try next?

    Thank You in advance, John


    If you scroll down, there may be a "Skip payment method" orange bar
    you can click. The nature of rapidly changing scam-apps though,
    means it's only a matter of time until they remove the button.
    It's like all the tricks Amazon pulls, to bill you for Prime you
    didn't ask for.

    There are also a lot of scams, where the owner of the phishing App asks
    for cash money. Roku is supposed to be Free, and the <cough> "purpose" of
    the CC detail, is to make it "easier" to set up Trial Subscriptions.

    You options are:

    1) Phone App doesn't have "Skip" at bottom
    2) Windows App has "Skip" at bottom
    A phishing app (non-legit) may be asking for cash money (bitcoins, Wells Fargo,
    third-world payment method).
    3) You can fill out a CC detail, then turn around and "remove payment method",
    the idea being, you can fill out the payment method again, when you
    actually want to purchase something.

    *******

    alt-F4 used to exit Metro.Apps as well as Win32 GUI applications.
    You can try that. But if ctrl-alt-delete is blocked by the malware,
    it can just as easily block alt-f4. Microsoft has block ctrl-alt-delete
    before, for some of its "bands" that cover the screen.

    I was going to give you a recipe to install an F8 Safe Boot button in
    your boot menu, but this is generally too hard to do.

    This is one for an old MSDOS-prepared disk on Win10.

    F8 boot menu for Windows 10 (using Win10 installer DVD : Troubleshooting : Command Prompt)
    The installer DVD boots off an OS on X: , leaving the letter C: to point to your HDD OS.

    dir /AH C:\boot\BCD # verify it is there (each environment has multiple clever
    # places to hide the BCD).

    bcdedit /store C:\boot\BCD /set {bootmgr} displaybootmenu True

    Just about everything involved here, is a pain to do. And a pain to write up.

    The BCD file can be dumped by typing "bcdedit", on a properly running machine. You can see my Safe Boot (menu) line, in this example. I have two OS partitions on
    this disk. My copy of Visual Studio Community Edition, is installed in the Win10 partition (just to give some idea how the junk is distributed).

    bcdedit

    Windows Boot Manager
    --------------------
    identifier {bootmgr}
    device partition=\Device\HarddiskVolume1
    path \EFI\MICROSOFT\BOOT\BOOTMGFW.EFI
    description Windows Boot Manager
    locale en-US
    inherit {globalsettings}
    default {current}
    resumeobject {497fe39c-30d1-11f1-8a51-e8ea6a0992ff}
    displayorder {current}
    {60ab5740-710c-11f0-9717-2cf05dd9f734} toolsdisplayorder {memdiag}
    timeout 30
    displaybootmenu Yes <=== This gives me F8 in my boot menu

    Windows Boot Loader
    -------------------
    identifier {current}
    device partition=C:
    path \WINDOWS\system32\winload.efi
    description Windows 11
    locale en-US
    inherit {bootloadersettings}
    recoverysequence {497fe39f-30d1-11f1-8a51-e8ea6a0992ff} displaymessageoverride Recovery
    recoveryenabled Yes
    isolatedcontext Yes
    allowedinmemorysettings 0x15000075
    osdevice partition=C:
    systemroot \WINDOWS
    resumeobject {497fe39c-30d1-11f1-8a51-e8ea6a0992ff}
    nx OptIn
    bootmenupolicy Standard
    hypervisorlaunchtype Auto

    Windows Boot Loader
    -------------------
    identifier {60ab5740-710c-11f0-9717-2cf05dd9f734}
    device partition=H:
    path \WINDOWS\system32\winload.efi
    description Windows 10
    locale en-us
    inherit {bootloadersettings}
    recoverysequence {255d39a0-3bcd-11f0-99b1-de400c6acc90}
    recoveryenabled Yes
    allowedinmemorysettings 0x15000075
    osdevice partition=H:
    systemroot \WINDOWS
    resumeobject {60ab573f-710c-11f0-9717-2cf05dd9f734}
    nx OptIn
    bootmenupolicy Standard

    Paul



    --- PyGate Linux v1.5.18
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)
  • From VanguardLH@3:633/10 to All on Sat Jul 4 18:19:02 2026
    "Carlos E. R." <robin_listas@es.invalid> wrote:

    On 2026-07-04 22:38, VanguardLH wrote:
    <jaugustine@verizon.net> wrote:

    I have no idea what is "PC App Store". Sounds like some software you
    installed that homes a library of software, but obviously whomever runs
    that store does not curate the software they proffer to ensure it is
    safe. Is this it? Did you instead mean the Microsoft Store, or
    something else entirely, like:

    https://pcapp.store/

    Did you read their FAQs?

    https://pcapp.store/?p=lpd_appstore-faq
    Is the PC APP STORE? Free?
    You can download and install PC APP STORE?, as well as receive
    recommendations for free. But PC APP STORE? is a store and to enjoy
    the offers you need a valid payment method linked with your account.

    So, they are NOT offering their apps for free. In fact, you have the
    PAY them to use their store. Since they are SELLING apps, but their
    "store" app is free, maybe you use their "store" app to get rid of any
    of their payware apps you installed using their "store".

    Maybe the rogue application is the PC app store itself. Apps require payment, so they ask for the plastic card info upfront. Just uninstall it.

    Might be one of those where the user thinks they are just getting an
    app, but it is bundled with some "store" app. Because the site I found
    is charging for the apps they provide, they want payment info. At the
    site I found on the vague description by Jaugustine, they make it very
    clear they are selling apps, but not on their home page.

    Their "Help Center" is a popup window for a Zendesk chatbot. They have
    phone numbers and an e-mail address for support. Jaugustine should
    start there.

    I did see on their home page a hyperlink to "Uninstall instructions" at:

    https://pcapp.store/?p=lpd_uninstall_r1

    This assumes pcapp.store is the "PC App Store" he mentions. With a
    vague name, could be somewhere else he got the store and "free" app.

    --- PyGate Linux v1.5.18
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)
  • From Paul@3:633/10 to All on Sun Jul 5 02:55:17 2026
    On Sat, 7/4/2026 8:26 PM, Format HD wrote:
    On 04/07/2026 19:45, jaugustine@verizon.net wrote:
    Do you know what I should try next?

    Have you considered reformatting the hard disk and starting again? A
    clean machine is always a safe machine. If you delete all partitions
    before installing Windows 10, there's no risk of a rootkit. ESU is still available to new users who know how to access it.


    Well, it's not a root kit. That's overly dramatic.

    I tried this a month ago. It's mostly for show, as the scan is
    running, it will claim it found things, then at the end, the
    summary will say "0 detected". Some things never change :-) There is
    probably some intended limitation here, that when you execute it
    that it will be scanning the OS (which is X: if using a Windows Installer DVD and Troubleshooting : Command Prompt to run it, and it would be C: if you could manage to run it from the running OS, which won't be very often in serious cases of exploitation). This isn't controllable enough for a variety of scenarios of application. This is most likely to be a signature scanner,
    it just doesn't have the same capabilities as a Kaspersky trial install would.

    https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-offline

    Download the 64-bit version (msstool64.exe)
    Download the 32-bit version (msstool32.exe)

    *******

    You could do a side-by-side install, but that implies you are confident there is space to the right of the existing install to do that.

    The Microsoft recipe for achieving Safe Mode, is a long road to annoyance.

    F8 boot menu for Windows 10 (MSDOS partitioning maybe, several cases possible):

    dir /AH C:\boot\BCD # verify it is there.

    bcdedit /store C:\boot\BCD /set {bootmgr} displaybootmenu True # Run from a WinPE environment

    bcdedit /set {bootmgr} displaybootmenu True # If C: was running, and Admin Terminal available

    On a UEFI/GPT setup, you would be more likely to need to
    assign a drive letter to the EFI System Partition (ESP).

    diskpart.exe # Admin terminal, can be Troubleshooting : Command Prompt of an Installer DVD
    list disk
    select disk 0
    list partition

    DISKPART> list partition

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 System 100 MB 1024 KB <=== ESP, "near" MBR
    Partition 2 Reserved 16 MB 101 MB
    Partition 3 Primary 118 GB 117 MB
    Partition 4 Recovery 1024 MB 118 GB
    Partition 5 Primary 128 GB 119 GB
    Partition 6 Recovery 1025 MB 248 GB
    Partition 7 Primary 682 GB 249 GB
    Partition 8 Primary 2794 GB 931 GB

    select partition 1
    assign letter=K
    exit

    dir /AH K:\EFI\Microsoft\boot\BCD # Where I expect the working BCD file, on a modern setup

    bcdedit /store K:\EFI\Microsoft\boot\BCD /set {bootmgr} displaybootmenu True

    And that much, will give you a boot menu on the C: real setup, that
    will include an option to press F8 and select a Safe Mode (like 4 or F4).
    The advantage of Safe Mode, is for cases that aren't real exploits,
    you might have some leverage to run msconfig and see what is in Startup items.
    Msconfig might just point you to Task Manager, to list the items.

    Xbox (listed as disabled)
    SecurityHealthSystray.exe
    RtkAudUService64.exe RealTek Audio
    ReflectUl.exe Macrium support service
    ms-teams.exe Teams
    msedge.exe (Browser, "warmup")
    Mobile devices
    Microsoft Defender
    CNSLMAIN.EXE Canon printer
    BJMYPRT.EXE Canon printer
    Microsoft 365 Copilot (listed as disabled)
    Microsoft Teams
    Phone Link as if...

    MSConfig, also has a tick box in Boot tab, to start in a specific
    Safe Mode, and it would keep doing that, until you went back
    into MSConfig and unticked the box again.

    It's unlikely the pest would be in there, but
    that pest has to be wired up somehow.

    Paul



    --- PyGate Linux v1.5.18
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)
  • From jaugustine@3:633/10 to All on Sun Jul 5 13:41:03 2026
    On Sun, 5 Jul 2026 02:55:17 -0400, Paul <nospam@needed.invalid> wrote:

    On Sat, 7/4/2026 8:26 PM, Format HD wrote:
    On 04/07/2026 19:45, jaugustine@verizon.net wrote:
    Do you know what I should try next?

    Have you considered reformatting the hard disk and starting again? A
    clean machine is always a safe machine. If you delete all partitions
    before installing Windows 10, there's no risk of a rootkit. ESU is still
    available to new users who know how to access it.

    Hi Paul,

    As a last resort, I may replace the HD (I have spares) and install Win10 64bit from an ISO (burn a DVD) I downloaded not that long ago.

    I have a prepaid Visa debit card I tried to use in order to get rid of
    this Payment window, but it was rejected. Note: I no longer use prepaid Debit cards.

    I could NOT get Task Manager to display a list of running apps. I thought
    I could disable it this way.

    I got their email address and phone number (I will call Monday). I sent an email about this ISSUE. support@pcappstore.com. 1 800-828-1299

    Maybe this "high jacker" is not the real PC App Store?

    Again, Thanks to everyone for your responses, John


    l, it's not a root kit. That's overly dramatic.

    I tried this a month ago. It's mostly for show, as the scan is
    running, it will claim it found things, then at the end, the
    summary will say "0 detected". Some things never change :-) There is
    probably some intended limitation here, that when you execute it
    that it will be scanning the OS (which is X: if using a Windows Installer DVD >and Troubleshooting : Command Prompt to run it, and it would be C: if you could
    manage to run it from the running OS, which won't be very often in serious >cases of exploitation). This isn't controllable enough for a variety of >scenarios of application. This is most likely to be a signature scanner,
    it just doesn't have the same capabilities as a Kaspersky trial install would.

    https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-offline

    Download the 64-bit version (msstool64.exe)
    Download the 32-bit version (msstool32.exe)

    *******

    You could do a side-by-side install, but that implies you are confident there >is space to the right of the existing install to do that.

    The Microsoft recipe for achieving Safe Mode, is a long road to annoyance.

    F8 boot menu for Windows 10 (MSDOS partitioning maybe, several cases possible):

    dir /AH C:\boot\BCD # verify it is there.

    bcdedit /store C:\boot\BCD /set {bootmgr} displaybootmenu True # Run from a WinPE environment

    bcdedit /set {bootmgr} displaybootmenu True # If C: was running, and Admin Terminal available

    On a UEFI/GPT setup, you would be more likely to need to
    assign a drive letter to the EFI System Partition (ESP).

    diskpart.exe # Admin terminal, can be Troubleshooting : Command Prompt of an Installer DVD
    list disk
    select disk 0
    list partition

    DISKPART> list partition

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 System 100 MB 1024 KB <=== ESP, "near" MBR
    Partition 2 Reserved 16 MB 101 MB
    Partition 3 Primary 118 GB 117 MB
    Partition 4 Recovery 1024 MB 118 GB
    Partition 5 Primary 128 GB 119 GB
    Partition 6 Recovery 1025 MB 248 GB
    Partition 7 Primary 682 GB 249 GB
    Partition 8 Primary 2794 GB 931 GB

    select partition 1
    assign letter=K
    exit

    dir /AH K:\EFI\Microsoft\boot\BCD # Where I expect the working BCD file, on a modern setup

    bcdedit /store K:\EFI\Microsoft\boot\BCD /set {bootmgr} displaybootmenu True

    And that much, will give you a boot menu on the C: real setup, that
    will include an option to press F8 and select a Safe Mode (like 4 or F4).
    The advantage of Safe Mode, is for cases that aren't real exploits,
    you might have some leverage to run msconfig and see what is in Startup items.
    Msconfig might just point you to Task Manager, to list the items.

    Xbox (listed as disabled)
    SecurityHealthSystray.exe
    RtkAudUService64.exe RealTek Audio
    ReflectUl.exe Macrium support service
    ms-teams.exe Teams
    msedge.exe (Browser, "warmup")
    Mobile devices
    Microsoft Defender
    CNSLMAIN.EXE Canon printer
    BJMYPRT.EXE Canon printer
    Microsoft 365 Copilot (listed as disabled)
    Microsoft Teams
    Phone Link as if...

    MSConfig, also has a tick box in Boot tab, to start in a specific
    Safe Mode, and it would keep doing that, until you went back
    into MSConfig and unticked the box again.

    It's unlikely the pest would be in there, but
    that pest has to be wired up somehow.

    Paul



    --- PyGate Linux v1.5.18
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)
  • From Carlos E. R.@3:633/10 to All on Sun Jul 5 19:54:43 2026
    On 2026-07-05 19:41, jaugustine@verizon.net wrote:
    On Sun, 5 Jul 2026 02:55:17 -0400, Paul <nospam@needed.invalid> wrote:

    On Sat, 7/4/2026 8:26 PM, Format HD wrote:
    On 04/07/2026 19:45, jaugustine@verizon.net wrote:
    Do you know what I should try next?

    Have you considered reformatting the hard disk and starting again? A
    clean machine is always a safe machine. If you delete all partitions
    before installing Windows 10, there's no risk of a rootkit. ESU is still >>> available to new users who know how to access it.

    Hi Paul,

    As a last resort, I may replace the HD (I have spares) and install Win10 64bit from an ISO (burn a DVD) I downloaded not that long ago.

    I have a prepaid Visa debit card I tried to use in order to get rid of this Payment window, but it was rejected. Note: I no longer use prepaid Debit cards.

    So you still have that window using all the display space?

    Did you try ctrl-alt-del?

    What about powering off via power button? On reboot, if the application
    is honest, it should not be running.


    --
    Cheers,
    Carlos E.R.
    ES??, EU??;

    --- PyGate Linux v1.5.18
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)
  • From Paul@3:633/10 to All on Sun Jul 5 14:10:31 2026
    On Sun, 7/5/2026 1:54 PM, Carlos E. R. wrote:
    On 2026-07-05 19:41, jaugustine@verizon.net wrote:
    On Sun, 5 Jul 2026 02:55:17 -0400, Paul <nospam@needed.invalid> wrote:

    On Sat, 7/4/2026 8:26 PM, Format HD wrote:
    On 04/07/2026 19:45, jaugustine@verizon.net wrote:
    Do you know what I should try next?

    Have you considered reformatting the hard disk and starting again? A
    clean machine is always a safe machine. If you delete all partitions
    before installing Windows 10, there's no risk of a rootkit. ESU is still >>>> available to new users who know how to access it.

    Hi Paul,

    ÿÿÿ As a last resort, I may replace the HD (I have spares) and install Win10 >> 64bit from an ISO (burn a DVD) I downloaded not that long ago.

    ÿÿÿ I have a prepaid Visa debit card I tried to use in order to get rid of >> this Payment window, but it was rejected. Note: I no longer use prepaid Debit
    cards.

    So you still have that window using all the display space?

    Did you try ctrl-alt-del?

    What about powering off via power button? On reboot, if the application is honest, it should not be running.



    If it won't listen to alt-F4, then chances are it won't listen to anything else either.

    Paul

    --- PyGate Linux v1.5.18
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)
  • From Carlos E. R.@3:633/10 to All on Sun Jul 5 23:16:55 2026
    On 2026-07-05 20:10, Paul wrote:
    On Sun, 7/5/2026 1:54 PM, Carlos E. R. wrote:
    On 2026-07-05 19:41, jaugustine@verizon.net wrote:
    On Sun, 5 Jul 2026 02:55:17 -0400, Paul <nospam@needed.invalid> wrote:

    On Sat, 7/4/2026 8:26 PM, Format HD wrote:
    On 04/07/2026 19:45, jaugustine@verizon.net wrote:
    Do you know what I should try next?

    Have you considered reformatting the hard disk and starting again? A >>>>> clean machine is always a safe machine. If you delete all partitions >>>>> before installing Windows 10, there's no risk of a rootkit. ESU is still >>>>> available to new users who know how to access it.

    Hi Paul,

    ÿÿÿ As a last resort, I may replace the HD (I have spares) and install Win10
    64bit from an ISO (burn a DVD) I downloaded not that long ago.

    ÿÿÿ I have a prepaid Visa debit card I tried to use in order to get rid of >>> this Payment window, but it was rejected. Note: I no longer use prepaid Debit
    cards.

    So you still have that window using all the display space?

    Did you try ctrl-alt-del?

    What about powering off via power button? On reboot, if the application is honest, it should not be running.



    If it won't listen to alt-F4, then chances are it won't listen to anything else either.

    In the past, ctrl-alt-del was special. And the power up/dn button can
    not be hijacked. At worst, press 4 second and the firmware intervenes.
    The machine also probably has a hard reset button, accessible with a
    metal pin.

    --
    Cheers,
    Carlos E.R.
    ES??, EU??;

    --- PyGate Linux v1.5.18
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)
  • From jaugustine@3:633/10 to All on Sun Jul 5 17:28:44 2026
    Hi,

    UPDATE, PROBLEM FIXED

    I forgot about an app that is set to STARTUP after Windows boots.
    Note: You can NOT un install an app while it is running.

    I received a reply from support@pcappstore.com that told me
    to look at bottom right corner and click the upward arrow to see hidden icons. Click on it and look for PC App Store icon. Right click on it and select Settings.. Go to General section and toggle switch for startup to "Off"

    John


    --- PyGate Linux v1.5.18
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)
  • From VanguardLH@3:633/10 to All on Sun Jul 5 20:19:32 2026
    Format HD <hdd@invalid.invalid> wrote:

    On 04/07/2026 19:45, jaugustine@verizon.net wrote:
    Do you know what I should try next?

    Have you considered reformatting the hard disk and starting again? A
    clean machine is always a safe machine. If you delete all partitions
    before installing Windows 10, there's no risk of a rootkit. ESU is still available to new users who know how to access it.

    Your "format it" suggestion is always an extreme an unresponsible
    response. From what I found, the "PC App Store" is easily uninstalled.

    Formatting all partitions on a drive does NOT obviate the use of a
    rootkit buried in UEFI which even Windows can make use of. Usually UEFI rootkit is part of software inventorying to see what is on the company's workstations, or finder software to locate stolen laptops.

    While Microsoft intends on using the UEFI rootkit for beneficial uses
    (to the owners of the computers, not necessarily to the users), it can
    be misused by malware.


    UEFI & Windows: A rootkit for everyone.

    A "feature" of UEFI (with Microsoft's involvement) is a program can be specified in the UEFI to run on Windows startup. Despite regulating any startup programs, or scanning for malware, there could sit a call to a
    program in the UEFI. It could, for example, be used for starting
    execution of tracking software (how the computer is used), or for
    software inventorying on workstations. I've only seen it used by
    companies that wanted to add usage tracking, location, anti-theft, or inventorying to their workstations. However, it could also be used by
    malware, and I don't know if any AVs check for a program load specified
    in the UEFI. As I recall, some mobos (Lenovo, Gigabyte, ASUS) use this
    trick to run services or diagnostics on Windows startup. The AV should
    catch malware for whatever the UEFI program load specifies; that is, the
    .exe in UEFI usually calls some other program that runs under Windows.

    It is a "feature" only with UEFI. When Windows loads, it has a program (C:\Windows\system32\wpbbin.exe) that runs to determine if the UEFI
    specified a start program. The UEFI start program is in one of the ACPI
    tables in the BIOS. One trick is to rename the loader program in
    Windows called the UEFI Bootkit dubbed BlackLotus.

    Use Nirsoft's Firmware Tables View to see the ACPI tables in UEFI. Look
    for the "Windows Platform Binary Table" (WPBT). Nirsoft will show the
    ACPI table, if it is defined, but won't let you delete it. When I found
    out about this, Nirsoft didn't show a WPBT table, but then I have many
    options disabled in the BIOS. I also don't have the wpbbin.exe program
    (that checks the UEFI for an .exe file to load) in my Windows
    installation.

    Although pundits attempt to tout UEFI, Secure Boot, and other later
    security measures as protecting users, there are UEFI Bootkits that
    bypass all those measures, even Secure Boot, like BlackLotus.

    https://arstechnica.com/information-technology/2023/03/unkillable-uefi-malware-bypassing-secure-boot-enabled-by-unpatchable-windows-flaw/

    Those are different beasts than the UEFI program load specified in an
    ACPI table that Windows checks if it is defined, and if found will run
    the UEFI-specified program. I'm noting the UEFI program load on Windows
    launch because refurbs often are company workstations that were leased,
    and then disposed of. Companies may employ tracking, location, or
    software inventorying that the Windows-loaded UEFI-specified program
    will start. You won't find that method listed in, say, SysInternals'
    Autoruns. Windows loads, checks the UEFI for the bootkit/rootkit
    program, and runs that program under Windows. Since Secure Boot okays
    the load of Windows, and since it is a program under Windows that loads
    the .exe in the UEFI, Secure Boot won't catch this tactic.

    https://eclypsium.com/blog/everyone-gets-a-rootkit/

    There are tools to nullify the .exe in the WPBT ACPI table in UEFI by
    deleting it from memory before Windows reads the ACPI tables, like:

    https://github.com/Jamesits/dropWPBT#from-windows

    This removes the WPBT table from system memory, so you have it run as a
    startup program (that loads with Windows startup, not until whenever you
    log into your Windows account).

    For your own computer, you don't want WPBT employed. WPBT started with
    Windows 8. Probably the easiest way to disable WPBT is to rename,
    delete, or move the wpbbin.exe if it exists on your system. An update
    could replace it, so you might use Task Scheduler to run a delete
    command on every Windows startup; however, the scheduled event runs
    after the bootkit, if specified, has run, so this protects against a
    bootkit on the next startup of Windows. The Github article talks about different methods of disabling WPBT, but they're rather complicated instructions.

    --- PyGate Linux v1.5.18
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)
  • From Paul@3:633/10 to All on Mon Jul 6 01:31:08 2026
    On Sun, 7/5/2026 5:28 PM, jaugustine@verizon.net wrote:
    Hi,

    UPDATE, PROBLEM FIXED

    I forgot about an app that is set to STARTUP after Windows boots.
    Note: You can NOT un install an app while it is running.

    I received a reply from support@pcappstore.com that told me
    to look at bottom right corner and click the upward arrow to see hidden icons.
    Click on it and look for PC App Store icon. Right click on it and select Settings.. Go to General section and toggle switch for startup to "Off"

    John


    Which means the item has not gone from the machine entirely,
    but using Startup Items as a persistence mechanism can be stopped
    for the moment.

    Now that you're in control of the machine again, look in the Settings wheel
    in the Apps section and see if a named instance is there, so you can
    get rid of it from there.

    It could also fashion a Scheduled Task for itself.

    Paul

    --- PyGate Linux v1.5.18
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)
  • From VanguardLH@3:633/10 to All on Mon Jul 6 12:28:54 2026
    Paul <nospam@needed.invalid> wrote:

    On Sun, 7/5/2026 5:28 PM, jaugustine@verizon.net wrote:
    Hi,

    UPDATE, PROBLEM FIXED

    I forgot about an app that is set to STARTUP after Windows boots.
    Note: You can NOT un install an app while it is running.

    I received a reply from support@pcappstore.com that told me
    to look at bottom right corner and click the upward arrow to see hidden icons.
    Click on it and look for PC App Store icon. Right click on it and select
    Settings.. Go to General section and toggle switch for startup to "Off"

    John


    Which means the item has not gone from the machine entirely,
    but using Startup Items as a persistence mechanism can be stopped
    for the moment.

    Now that you're in control of the machine again, look in the Settings wheel in the Apps section and see if a named instance is there, so you can
    get rid of it from there.

    It could also fashion a Scheduled Task for itself.

    I already mentioned they have a link on their home page on how to
    uninstall their "PC App Store" app, and it's the same way you uninstall
    most Windows software. However, if the app the OP actually downloaded
    and installed is listed, I'd uninstall that first, and the PC App Store
    last. Since the OP was flabbergasted about something asking for a
    payment, the OP doesn't want to pay for any apps from them, so get rid
    of them all: all apps from their store, and their store app.

    As for stopping a program from auto-starting, I also mentions AutoRuns
    which will expose the various locations use for startup. Besides the
    Startup registry entries (both user and common), it looks in Task
    Scheduler, Winlogon events, and more. You can delete the entry in
    Autoruns whether the software is running, or not.

    --- PyGate Linux v1.5.18
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)
  • From Paul@3:633/10 to All on Mon Jul 6 17:33:21 2026
    On Mon, 7/6/2026 1:28 PM, VanguardLH wrote:
    Paul <nospam@needed.invalid> wrote:

    On Sun, 7/5/2026 5:28 PM, jaugustine@verizon.net wrote:
    Hi,

    UPDATE, PROBLEM FIXED

    I forgot about an app that is set to STARTUP after Windows boots.
    Note: You can NOT un install an app while it is running.

    I received a reply from support@pcappstore.com that told me
    to look at bottom right corner and click the upward arrow to see hidden icons.
    Click on it and look for PC App Store icon. Right click on it and select >>> Settings.. Go to General section and toggle switch for startup to "Off"

    John


    Which means the item has not gone from the machine entirely,
    but using Startup Items as a persistence mechanism can be stopped
    for the moment.

    Now that you're in control of the machine again, look in the Settings wheel >> in the Apps section and see if a named instance is there, so you can
    get rid of it from there.

    It could also fashion a Scheduled Task for itself.

    I already mentioned they have a link on their home page on how to
    uninstall their "PC App Store" app, and it's the same way you uninstall
    most Windows software. However, if the app the OP actually downloaded
    and installed is listed, I'd uninstall that first, and the PC App Store
    last. Since the OP was flabbergasted about something asking for a
    payment, the OP doesn't want to pay for any apps from them, so get rid
    of them all: all apps from their store, and their store app.

    As for stopping a program from auto-starting, I also mentions AutoRuns
    which will expose the various locations use for startup. Besides the
    Startup registry entries (both user and common), it looks in Task
    Scheduler, Winlogon events, and more. You can delete the entry in
    Autoruns whether the software is running, or not.


    It is the practice of Roku to "ask for a credit card" as a means
    of identification, as well as "greasing the rails for future purchases".
    You can apparently fill out CC details (which will be checked) and
    then "Remove payment details" and pretend you have removed your CC details,
    and then if you did incur a charge for some reason, the transaction should not go through.

    This means the "official" application is just as crooked as the phishers.

    Thus, when seeing the name now, I don't even have to entertain the concept
    or think of installing it. The conclusion is foregone. It's a "FREE" activity that trades on private information.

    Paul


    --- PyGate Linux v1.5.18
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)