Free Republic
Browse · Search
General/Chat
Topics · Post Article

I got this Thursday night, just after posting to FR, but I had been viewing video and pictures from various sources, as well as logging into Photobucket, so I'm not sure how I got it. I sat there like a dope while it downloaded itself after I initiated a shutdown, as it took over my Windows blue screen which warned me not to power off because updates were in progress.

It is very scary and seems like a hopeless situation, since it won't let anything run, including the task manager. However, I had immediate success using the advice of this article, which I read Friday from my work computer. I put the SUPERAntiSpyware product linked in the article on a thumbdrive and ran it while I was disconnected from the internet. I can't make an expert recommendation, but I did have success.

I didn't run in safe mode, but followed a tip I read in a long list of comments at How To Geek. With "Antivirus Live" infection, you have a 20 or 30 second grace period after Windows XP boot where you can bring up the task manager and see the malware initializer running as XXXXsysguard.exe ( XXXX is a variable alphameric string. ) I was able to kill it from the task manager, and it didn't come back while I installed and ran SUPERAntiSpyware from the thumbdrive, and by all appearances I am rid of the thing, but you never know! I was certainly pleased by the apparent quick and easy success after the many dire accounts of its tenacity, so I just thought I'd share this experience with FR.

This seems like a pretty widespread problem, but maybe that's just because I got it.

1 posted on 01/30/2010 10:19:15 AM PST by dr_lew
[ Post Reply | Private Reply | View Replies ]


Navigation: use the links below to view more comments.
first previous 1-2021-36 last
To: dr_lew
Last week I had to flatline my daughter's PC and reinstall windows due to a similar virus "Internet Security 2010" (it might even be the same virus with a different alias). It was ugly.

Take frequent incremental backups.

29 posted on 01/30/2010 10:56:40 AM PST by PapaBear3625 (Public healthcare looks like it will work as well as public housing did.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: dr_lew

I solved this problem about 3.5 years ago. I bought the wife a Mac and used Ubuntu on my computer.

The iMac I bought for her works as well today as it did that day I bought it in 2006. Actually it works better with Snow Leopard on it.

I know all the arguments people make about Mac—too expensive, etc. But we simply haven’t had to spend a penny on anti-virus, nor a minute of time on removing viruses.

And I don’t see the need to replace that computer for years to come.

In the end, I would rather enjoy a worry free computing experience instead of all the stuff I see on this post.


32 posted on 01/30/2010 11:12:42 AM PST by comps4spice (Obama = Going a long way in making Jimmy Carter look competent.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: dr_lew
Turn your computer on while holding down your F8 key. This put your computer in safe mode. Toggle down to “safe mode in network” and download Malwarebytes, which you can get off cnet downloads and it's free. It will remove it. Good luck.
36 posted on 01/30/2010 11:16:02 AM PST by kempo
[ Post Reply | Private Reply | To 1 | View Replies ]

To: dr_lew

My computer was nailed by this 3 days ago. I took it to the pros and they cleaned it up for $70. Everything I tried didn’t work, including running the malwarebytes program. I’ll try this if it happens again.


37 posted on 01/30/2010 11:17:22 AM PST by Travis McGee (---www.EnemiesForeignAndDomestic.com---)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: HalfFull

mark


44 posted on 01/30/2010 11:24:22 AM PST by HalfFull ("Is life so dear, or peace so sweet, as to be purchased at the price of chains and slavery?" -PHenry)
[ Post Reply | Private Reply | To 1 | View Replies ]

ph


45 posted on 01/30/2010 11:31:58 AM PST by xone
[ Post Reply | Private Reply | To 1 | View Replies ]

To: dr_lew

This is the first malware script I’ve been infected with in 10 years.

It was simple to get rid of....First I unplugged my network cable then shut down the computer. Since it won’t let you open any executable programs after it boots up into memory, after restart, I immediately opened MSCONFIG and disabled it under the startup tab. Rebooted and it was gone. Searched for all remnants and removed them. Fixed the corrupt proxy setting with Hijack this!. 15 minutes tops....Harmless bugger.


46 posted on 01/30/2010 11:37:08 AM PST by Electric Graffiti (Well, we didn't get dressed up for nothin')
[ Post Reply | Private Reply | To 1 | View Replies ]

To: dr_lew

My brother in law, small cash register co owner, used the quick(grace) method to rid a customer of this bug.

I couldn’t get to the control panel on one of my customers PC. I booted to safe mode and used a flash drive to install Malwarebytes. I also ran the program from safe mode. Cleared it right up.


49 posted on 01/30/2010 11:54:51 AM PST by SeeRushToldU_So ( Go Braves! Braves are gone.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: dr_lew

Ping for later.


50 posted on 01/30/2010 11:56:16 AM PST by PubliusMM (RKBA; a matter of fact, not opinion. 01-20-2013: Change we can look forward to.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: dr_lew
This is also (or used to be)known as RapidAntivirus and it is horrible. I spent the better part of a weekend about a year ago trying to get rid of it. As the author indicates, it prevent the downloading of the removal tool so it was a pain.

Using the flashdrive is a great idea

51 posted on 01/30/2010 11:56:48 AM PST by muir_redwoods (Obama: The Fresh Prince of Bill Ayers)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: dr_lew

There is a version of this called Malware Defense that installs a rootkit on your PC. The rootkit has to be disposed of before you can remove the infection.

The rootkit can be killed with a program called TDSS Killer found at the Kaspersky antivirus site. You’ll need to download it on a different computer, then transfer it on a thumb drive.

Once you’ve run the TDSSKiller, the real AV software will come back and you can download and run Malware Bytes to get rid of the infection.

My mom’s PC was infected with this garbage. It shut off her antivirus and bombarded her with popups, shutting off everything except an IE window that went to the page where she could purchase the “full version” of this virus. Luckily, she called me before she entered a credit card.


55 posted on 01/30/2010 12:20:43 PM PST by MediaMole
[ Post Reply | Private Reply | To 1 | View Replies ]

To: dr_lew

I got that crap and had to use AVG anti-virus. Then it came back and I used PC Tools anti-virus software called Spyware Doctor. It’s gone for good now!!!!


56 posted on 01/30/2010 12:37:57 PM PST by Jack Hydrazine
[ Post Reply | Private Reply | To 1 | View Replies ]

To: dr_lew
What this programs does:

Antivirus Live is a rogue anti-spyware and ransomware program from the same family as Antivirus System Pro. This infection is installed on your computer through Trojans that install it automatically without your permission. Once installed, Antivirus Live will be configured to start automatically when Windows starts. Once running it will scan your computer and display numerous infections, but will state it will not remove them until you purchase the program. In reality, the scan results it detects are all fake and do not actually exist on your computer.

Tools Needed for this fix:

Both my son and Mother In Law have had this type of virus. My advise. Install Malwarebytes' Anti-Malware before you have the problem and update it once in a while.

58 posted on 01/30/2010 1:04:18 PM PST by McGruff (Love ya Sarah but I will support and contribute to JD Hayworth.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: dr_lew

Thanks for posting this. I have a Mac, but DH has a Dell.


60 posted on 01/30/2010 1:37:15 PM PST by Darnright (There can never be a complete confidence in a power which is excessive. - Tacitus)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: dr_lew

I got a similar virus about a month ago. Basically it took over the pc. Every program I tried to run would come back with a message saying “the exe file is infected” and then tried to blackmail you into buying “the cure”.

Finally was able to boot up in safe mode and reload the OS. It was a pain in the rear. I hope these crooks get caught.


61 posted on 01/30/2010 2:05:00 PM PST by HOP
[ Post Reply | Private Reply | To 1 | View Replies ]

To: dr_lew

I got it last week too...instead of Windows’ antispyware I have two other programs running constantly, hence I knew the “warning” was bogus. I immediately shut down, restarted in safe mode, ran System Restore, then a SuperAntiSpyware scan. Problem solved.


63 posted on 01/30/2010 7:37:39 PM PST by VampireStateNY (Bleeding taxpayers dry since 1788!)
[ Post Reply | Private Reply | To 1 | View Replies ]


Navigation: use the links below to view more comments.
first previous 1-2021-36 last

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson