Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Use a Flash Drive to Rescue a Malware-Infested PC ( Antivirus Live )
Bnet ^ | 1/30/2010 | Rick Broida

Posted on 01/30/2010 10:19:14 AM PST by dr_lew

There’s a particularly nasty virus making the rounds right now. It’s informally known as the Antivirus Live virus, as it bombards your PC with scary, real-looking security warnings and masquerades as a program — Antivirus Live (pictured) — that can protect and repair your system.

(Excerpt) Read more at blogs.bnet.com ...


TOPICS: Computers/Internet
KEYWORDS: antivirus; antiviruslive; computer; malware; rogue; security; virus
Navigation: use the links below to view more comments.
first 1-2021-4041-6061-65 next last
I got this Thursday night, just after posting to FR, but I had been viewing video and pictures from various sources, as well as logging into Photobucket, so I'm not sure how I got it. I sat there like a dope while it downloaded itself after I initiated a shutdown, as it took over my Windows blue screen which warned me not to power off because updates were in progress.

It is very scary and seems like a hopeless situation, since it won't let anything run, including the task manager. However, I had immediate success using the advice of this article, which I read Friday from my work computer. I put the SUPERAntiSpyware product linked in the article on a thumbdrive and ran it while I was disconnected from the internet. I can't make an expert recommendation, but I did have success.

I didn't run in safe mode, but followed a tip I read in a long list of comments at How To Geek. With "Antivirus Live" infection, you have a 20 or 30 second grace period after Windows XP boot where you can bring up the task manager and see the malware initializer running as XXXXsysguard.exe ( XXXX is a variable alphameric string. ) I was able to kill it from the task manager, and it didn't come back while I installed and ran SUPERAntiSpyware from the thumbdrive, and by all appearances I am rid of the thing, but you never know! I was certainly pleased by the apparent quick and easy success after the many dire accounts of its tenacity, so I just thought I'd share this experience with FR.

This seems like a pretty widespread problem, but maybe that's just because I got it.

1 posted on 01/30/2010 10:19:15 AM PST by dr_lew
[ Post Reply | Private Reply | View Replies]

To: dr_lew

bookmark


2 posted on 01/30/2010 10:20:39 AM PST by GiovannaNicoletta
[ Post Reply | Private Reply | To 1 | View Replies]

To: dr_lew

Thats been around a while, going by a lot of different names. It has also had a variant pretending to be Windows Defender and other things.

My niece got one and it took me a couple of hours to root it out and kill it. My real anti-virus was able to finally catch it on mine and qurantine it.


3 posted on 01/30/2010 10:22:26 AM PST by GeronL (http://tyrannysentinel.blogspot.com)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dr_lew

malwarebytes- free upload


4 posted on 01/30/2010 10:22:36 AM PST by silverleaf
[ Post Reply | Private Reply | To 1 | View Replies]

To: dr_lew

5 posted on 01/30/2010 10:23:25 AM PST by JoeProBono (A closed mouth gathers no feet)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dr_lew

I use

http://www.bleepingcomputer.com/

for malware related help ...


6 posted on 01/30/2010 10:23:57 AM PST by 08bil98z24 (The WOD is unconstitutional ------>>> NObama ... Anybody but him!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

/mark


7 posted on 01/30/2010 10:24:12 AM PST by KoRn (Department of Homeland Security, Certified - "Right Wing Extremist")
[ Post Reply | Private Reply | To 1 | View Replies]

To: dr_lew
I should mention that I followed the ( very easy ) procedure at Bleeping Computer for unsetting the Proxy Server option in my Windows IE. This seemed to be the only corruption of it, after I ran the SUPERAntiSpyware tool. I don't think that tool did anything to IE, though. It just cleaned up some files and my registry.
8 posted on 01/30/2010 10:27:21 AM PST by dr_lew
[ Post Reply | Private Reply | To 1 | View Replies]

To: dr_lew

my wife’s PC caught this form of comuter clap. It is now at the shop beng repaired. Had a partial fix in place with the thumb drive solution discussed, told her to stay off the internet and lo and behold, she tries to email someone and the thing crashed....

$^%$^%&%@@#


9 posted on 01/30/2010 10:28:46 AM PST by misterrob (Have you tea bagged a liberal today?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dr_lew

I received it last year. I was eventually able to clean out the virus. It appeared again last week and tried to install. I stopped the installation by immediately shutting down my PC. I restarted without any problems.


10 posted on 01/30/2010 10:29:30 AM PST by Man50D (Fair Tax, you earn it, you keep it! www.FairTaxNation.com)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dr_lew

@dr_lew: Thanks for this article and advise. My PC got killed this week by the very same virus. The problem is that it blocks your access to the internet and control panel so you can’t get any help. Can you elaborate on how you killed it once you booted the computer back up. Thanks in advance.


11 posted on 01/30/2010 10:30:19 AM PST by northwinds
[ Post Reply | Private Reply | To 1 | View Replies]

To: Man50D

Yeah, that’s what I do when things look weird - - I reach down to my stack and hold the button in for 5+ seconds until the thing shuts down.


12 posted on 01/30/2010 10:34:09 AM PST by Lancey Howard
[ Post Reply | Private Reply | To 10 | View Replies]

To: dr_lew

The best bet is to make an image of your hard drive and make incremental backups onto an external hard drive. This way you can always revert back to a state of PERFECT. I use “Acronis True Image Home” and can honestly say it saved my and my familys butt numerous times. Although we all use an antivirus program, sometimes things get through. To restore an infected PC back to a state of perfect takes about 20 min. This is by far the best software investment I have ever made.

On a side-note. It is wise to password protect your passwords in firefox & IE. My son just had to reimage his hardrive to prevent any more security leaks in his browser. Seems that he picked up some sort of virus that pulled out and sent all his passwords to an ip address in Nigeria, resulting in a mass funding transfer parade. Cost him thousands. PASSWORD PROTECT YOUR PASSWORDS.


13 posted on 01/30/2010 10:34:49 AM PST by foolishboi
[ Post Reply | Private Reply | To 8 | View Replies]

To: dr_lew

Had quite a time booting into safe mode with my wireless kbd.


14 posted on 01/30/2010 10:35:01 AM PST by Strident (Think. It's the new "feel".)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dr_lew

bttt


15 posted on 01/30/2010 10:35:08 AM PST by bmwcyle (Free the Navy Seals)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dr_lew

I got it twice first time i got rid of it,second time bombarded with all you had plus viagra and porn pop ups..
Called wife at work she asked the IT guy what to do,download Spybot search and destroy for free,cannot remember what site but i am sure if you google it it will show..
Finally go online thru Mozilla Firefox,oh yeah AVG for a free anti-virus.
Not had a problem in 2 years..


16 posted on 01/30/2010 10:35:23 AM PST by GSP.FAN (These are the times that try men's souls.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dr_lew

My PC caught this crap about two weeks ago (think my kid clicked on something). I ran Microsoft Security Essentials AND Avast and wiped it out.


17 posted on 01/30/2010 10:35:38 AM PST by manic4organic (Obama shot hoops, America lost troops.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Man50D

“...stopped the installation by immediately shutting down my PC...”

by saying that, I presume you mean hitting the switch rather than “shutting it down”, as in normal start-menu + shut down mouse clicks?


18 posted on 01/30/2010 10:36:43 AM PST by Vn_survivor_67-68 (CALL CONGRESSCRITTERS TOLL-FREE @ 1-800-965-4701)
[ Post Reply | Private Reply | To 10 | View Replies]

To: silverleaf

I got turned onto Malwarebytes by our IT team at work. It works well.


19 posted on 01/30/2010 10:37:20 AM PST by PrincessB ("if government X-rays are anything like the photos the DMV takes for your license, count me out" A.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: dr_lew

I was on the same site, and the same thing happened to me too. However, my McAfee caught it. So no issues over here.


20 posted on 01/30/2010 10:38:21 AM PST by Sprite518
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-6061-65 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson