Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Use a Flash Drive to Rescue a Malware-Infested PC ( Antivirus Live )
Bnet ^ | 1/30/2010 | Rick Broida

Posted on 01/30/2010 10:19:14 AM PST by dr_lew

There’s a particularly nasty virus making the rounds right now. It’s informally known as the Antivirus Live virus, as it bombards your PC with scary, real-looking security warnings and masquerades as a program — Antivirus Live (pictured) — that can protect and repair your system.

(Excerpt) Read more at blogs.bnet.com ...


TOPICS: Computers/Internet
KEYWORDS: antivirus; antiviruslive; computer; malware; rogue; security; virus
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-65 next last
To: JoeProBono

Trouble with Avira is that the free version doesn’t scan emails


41 posted on 01/30/2010 11:21:08 AM PST by foolishboi
[ Post Reply | Private Reply | To 38 | View Replies]

To: Travis McGee

Read post 36


42 posted on 01/30/2010 11:21:24 AM PST by kempo
[ Post Reply | Private Reply | To 39 | View Replies]

To: kempo
Make sure you update malwarebytes everytime before you run a scan.
43 posted on 01/30/2010 11:22:47 AM PST by kempo
[ Post Reply | Private Reply | To 42 | View Replies]

To: HalfFull

mark


44 posted on 01/30/2010 11:24:22 AM PST by HalfFull ("Is life so dear, or peace so sweet, as to be purchased at the price of chains and slavery?" -PHenry)
[ Post Reply | Private Reply | To 1 | View Replies]

ph


45 posted on 01/30/2010 11:31:58 AM PST by xone
[ Post Reply | Private Reply | To 1 | View Replies]

To: dr_lew

This is the first malware script I’ve been infected with in 10 years.

It was simple to get rid of....First I unplugged my network cable then shut down the computer. Since it won’t let you open any executable programs after it boots up into memory, after restart, I immediately opened MSCONFIG and disabled it under the startup tab. Rebooted and it was gone. Searched for all remnants and removed them. Fixed the corrupt proxy setting with Hijack this!. 15 minutes tops....Harmless bugger.


46 posted on 01/30/2010 11:37:08 AM PST by Electric Graffiti (Well, we didn't get dressed up for nothin')
[ Post Reply | Private Reply | To 1 | View Replies]

To: Electric Graffiti

“This is the first malware script I’ve been infected with in 10 years.”

You must not surf the net much, or you have incredible luck.


47 posted on 01/30/2010 11:43:25 AM PST by foolishboi
[ Post Reply | Private Reply | To 46 | View Replies]

To: foolishboi

Actually I don’t think I’ve had a virus, trojan, worm, malware, script ever until this one and I’ve been online since Al Gore invented the internet. I don’t use an Anti-virus either. ;)


48 posted on 01/30/2010 11:53:58 AM PST by Electric Graffiti (Well, we didn't get dressed up for nothin')
[ Post Reply | Private Reply | To 47 | View Replies]

To: dr_lew

My brother in law, small cash register co owner, used the quick(grace) method to rid a customer of this bug.

I couldn’t get to the control panel on one of my customers PC. I booted to safe mode and used a flash drive to install Malwarebytes. I also ran the program from safe mode. Cleared it right up.


49 posted on 01/30/2010 11:54:51 AM PST by SeeRushToldU_So ( Go Braves! Braves are gone.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dr_lew

Ping for later.


50 posted on 01/30/2010 11:56:16 AM PST by PubliusMM (RKBA; a matter of fact, not opinion. 01-20-2013: Change we can look forward to.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dr_lew
This is also (or used to be)known as RapidAntivirus and it is horrible. I spent the better part of a weekend about a year ago trying to get rid of it. As the author indicates, it prevent the downloading of the removal tool so it was a pain.

Using the flashdrive is a great idea

51 posted on 01/30/2010 11:56:48 AM PST by muir_redwoods (Obama: The Fresh Prince of Bill Ayers)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Electric Graffiti

“I’ve been online since Al Gore invented the internet.”

LOL, Well God Bless, and I hope your luck holds out.


52 posted on 01/30/2010 11:57:06 AM PST by foolishboi
[ Post Reply | Private Reply | To 48 | View Replies]

To: dr_lew

@dr_lew: Thanks for the advice....I am now posting from my previously infected PC. Best Buys wanted $200 for what you and other Freepers helped me do in about an hour. But I did kind of back into the “fix”. Like you I put the flash drive with the downloaded program in before I started the “safe mode” start-up. Then I couldn’t get out of “safe-mode” without going through the “restore” process. I restored to a date prior to the trojan/virus showing up and everything is now fine. I guess there’s more than one way to “skin a rabbit”. Since I am pretty computer/software illiterate I am pretty darn proud of myself today. Thanks again for starting this thread.


53 posted on 01/30/2010 12:05:42 PM PST by northwinds
[ Post Reply | Private Reply | To 27 | View Replies]

To: northwinds

“I restored to a date prior to the trojan/virus showing up and everything is now fine.”

Very fortunate, most virus disable the sys restore functionality, even in safe mode.


54 posted on 01/30/2010 12:11:23 PM PST by foolishboi
[ Post Reply | Private Reply | To 53 | View Replies]

To: dr_lew

There is a version of this called Malware Defense that installs a rootkit on your PC. The rootkit has to be disposed of before you can remove the infection.

The rootkit can be killed with a program called TDSS Killer found at the Kaspersky antivirus site. You’ll need to download it on a different computer, then transfer it on a thumb drive.

Once you’ve run the TDSSKiller, the real AV software will come back and you can download and run Malware Bytes to get rid of the infection.

My mom’s PC was infected with this garbage. It shut off her antivirus and bombarded her with popups, shutting off everything except an IE window that went to the page where she could purchase the “full version” of this virus. Luckily, she called me before she entered a credit card.


55 posted on 01/30/2010 12:20:43 PM PST by MediaMole
[ Post Reply | Private Reply | To 1 | View Replies]

To: dr_lew

I got that crap and had to use AVG anti-virus. Then it came back and I used PC Tools anti-virus software called Spyware Doctor. It’s gone for good now!!!!


56 posted on 01/30/2010 12:37:57 PM PST by Jack Hydrazine
[ Post Reply | Private Reply | To 1 | View Replies]

To: kempo

Thanks, I’ll try that next time.


57 posted on 01/30/2010 12:55:13 PM PST by Travis McGee (---www.EnemiesForeignAndDomestic.com---)
[ Post Reply | Private Reply | To 42 | View Replies]

To: dr_lew
What this programs does:

Antivirus Live is a rogue anti-spyware and ransomware program from the same family as Antivirus System Pro. This infection is installed on your computer through Trojans that install it automatically without your permission. Once installed, Antivirus Live will be configured to start automatically when Windows starts. Once running it will scan your computer and display numerous infections, but will state it will not remove them until you purchase the program. In reality, the scan results it detects are all fake and do not actually exist on your computer.

Tools Needed for this fix:

Both my son and Mother In Law have had this type of virus. My advise. Install Malwarebytes' Anti-Malware before you have the problem and update it once in a while.

58 posted on 01/30/2010 1:04:18 PM PST by McGruff (Love ya Sarah but I will support and contribute to JD Hayworth.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: JoeProBono

Hmmm...looks suspiciously very similar to the AVG Free interface.


59 posted on 01/30/2010 1:29:16 PM PST by Bloody Sam Roberts (An armed man is a citizen. An unarmed man is a subject.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: dr_lew

Thanks for posting this. I have a Mac, but DH has a Dell.


60 posted on 01/30/2010 1:37:15 PM PST by Darnright (There can never be a complete confidence in a power which is excessive. - Tacitus)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-65 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson