G oog le BadWeB | Login/out | Topics | Search | Custodians | Register | Edit Profile


Buell Forum » Quick Board » Archives » Archive through January 22, 2010 » WHO DO I KILL? « Previous Next »

Author Message
Top of pagePrevious messageNext messageBottom of page Link to this message

Just_ziptab
Posted on Sunday, January 17, 2010 - 12:21 pm:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only)

I am SO PISSED OFF! My old computer (with a CRT) got too full and too slow to deal with. Bought a used computer with Ubuntu a few months ago and it works GREAT,cept it doesn't play a lot of youtube vids,pictures are hard to control and it doesn't want to play with my printer. It has a noisy fan and other little things that are just irritating...... to what I am used to,but could probably be fixed with drivers and patches...if I took the time to learn about it all. Bought a brandy new custom built PC with a flat screen and it has an anti virus..so I didn't install my AVG program on start up. Cleaned off my desk and started all over with the new computer system yesterday morning. Today,less than a couple hours of run time and safe surfing.... it is dead in the water with "Antivirus Live".Can't install AVG now or even open the current antivirus on the machine. Here is what I found:

Antivirus Live Is The Most Aggressive Rogue Anti-Spyware Around
Antivirus Live is a tricky “virus” to remove once it got on your computer. The first thing it will do is block out almost any program you are trying to load and tell you that it is infected. In addition, it will change your Internet Explorer Proxy settings so that the only site you can browse is the Antivirus Live site (so you can purchase it… but don’t do that). Antivirus Live will also display various security warnings and alerts on your computer, all of these telling you that your computer is infected. Do not believe these warnings. Antivirus Live is basically a virus in itself and you should remove it immediately using the removal guide.

This DAMNED virus works so good,it can't even open it's own net site to con you into buying the fix! looks like I am going to be on this back up computer for a while till I can get the new one straightened out and install Ubuntu on it.

How hard is it to buy their fix,track them down and send them all to jail FOREVER???????????
Top of pagePrevious messageNext messageBottom of page Link to this message

Mtch
Posted on Sunday, January 17, 2010 - 12:36 pm:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only)

i just copied the instructions from this site. it seems that antivirus live alters your connection settings in internet explorer

http://www.2-spyware.com/remove-antivirus-live.htm l


1. Open Internet Explorer. Click on the Tools menu and then select Internet Options.

2. In the the Internet Options window click on the Connections tab. Then click on the LAN settings button.

3. Now you will see Local Area Network (LAN) settings window. Uncheck the checkbox labeled Use a proxy server for your LAN under the Proxy Server section and press OK.

4. Now download renamed Process Explorer (explorer.com) and terminate Antivirus Live processes. Should be [random]sysguard.exe, for example: wmcqsysguard.exe.


http://www.2-spyware.com/images/data/explorer.com


NOTE: Do not reboot your computer after using Process Explorer and terminating Antivirus Live processes.

Now you should be able to download an automatic Antivirus Live removal tool or another anti-spyware application. Most importantly, do not purchase it. If you have already done that, please contact your credit card company and dispute the charges.
Top of pagePrevious messageNext messageBottom of page Link to this message

Froggy
Posted on Sunday, January 17, 2010 - 12:37 pm:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only)

They are probably based out of China or some similar country.

If you can get http://www.teamviewer.com/ to install, I can try and help you out with the cleanup remotely.
Top of pagePrevious messageNext messageBottom of page Link to this message

Xb12xmike
Posted on Sunday, January 17, 2010 - 12:44 pm:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only)

Custom built? If you have the OS CD just reinstall, then install your AVG. OR if it had bloatware installed (off the shelf system) restore then uninstall all bloatware then install AVG. You should be up an running by afternoon. Oh...and stop visiting porn sites and forwarding chain letter emails.
Top of pagePrevious messageNext messageBottom of page Link to this message

Mmmi_grad
Posted on Sunday, January 17, 2010 - 12:56 pm:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only)

Sounds like a wipe and reinstall, I am in the businees too, when the infection is too bad its best to wipe and start over? It almost sounds like you installed a anti virus program while another was already installed. That will blow up an OS. If not its infected. Really these infections can come from anywhere.
Top of pagePrevious messageNext messageBottom of page Link to this message

Just_ziptab
Posted on Sunday, January 17, 2010 - 01:57 pm:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only)

What a class "Buell community" act!Thanks guys, and Froggy for the remote offer,but I will try to attack it myself.I like the challenge of learning to fix my own stuff..even if it is a PITA. But now it looks like "myself" can't fix it. Everything I try to open is blocked by "Antivirus Live", because it is infected. I'm getting nowhere fast...on line or off line.........nothing works!!!! looks like I will have to succumb and take it in to the IT guy at work.My guess is that I picked up this crap when I downloaded a "safe site" spell checker utility. It didn't show up on my tool bar like it was supposed too and when I un installed it..... that's when the shit hit the fan. Right now I have a nice flatscreen and a $910.00 box of plastic peanuts........
Top of pagePrevious messageNext messageBottom of page Link to this message

Froggy
Posted on Sunday, January 17, 2010 - 02:33 pm:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only)

Being that the system is brand new, I would just do a factory restore (check your manuals, different procedure for every machine). Once you get up and running again, DO NOT USE AN ADMINISTRATOR ACCOUNT! I can't stress it enough, as 86% of all viruses and other security vulnerabilities are instantly eliminated. Macs and Linux don't give the admin account by default, that is part of what makes them more secure. : )
Top of pagePrevious messageNext messageBottom of page Link to this message

Ducxl
Posted on Sunday, January 17, 2010 - 02:36 pm:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only)

RE-FORMAT your hardrive?? I've had issues twice in the last 6 months.I now backup to DVD regularly
Top of pagePrevious messageNext messageBottom of page Link to this message

Just_ziptab
Posted on Sunday, January 17, 2010 - 03:08 pm:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only)

The worst part of this is that I have received all my email lately on this ubuntu computer and left it all(that I did not delete) on the server. I received ALL that mail on the new computer and it was removed from the server at that time. Not the end of the world,but it will be GONE forever if I have to reformat. The only good thing is that I sent all my bookmarks and email address's to my yahoo account as a back up.

Enuf crap...I gotta go move firewood in.......
Top of pagePrevious messageNext messageBottom of page Link to this message

Greg_e
Posted on Sunday, January 17, 2010 - 03:22 pm:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only)

Need a Bart PE disk with an antivirus program loaded. Then you might be able to clean the infection, repair thee settings, and reboot the machine. Al that said since this was a recently built machine, go back to where you bought it ans ask them WTF!
Top of pagePrevious messageNext messageBottom of page Link to this message

Ezblast
Posted on Sunday, January 17, 2010 - 03:29 pm:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only)

Malwarebytes will take that off your system, happened here and at work, downloaded and cleaned - its basic is free and one of the tools I use to keep the system clean - I scan with it one a month, I run Mcafee, and ParetoLogic, with the regular windows, but use different browsers, depending on what I'm doing. I only use Explorer for updates and such.
EZ
Top of pagePrevious messageNext messageBottom of page Link to this message

Ft_bstrd
Posted on Sunday, January 17, 2010 - 05:27 pm:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only)

I've had that virus. It's a beyotch.
Top of pagePrevious messageNext messageBottom of page Link to this message

Spiderman
Posted on Sunday, January 17, 2010 - 05:42 pm:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only)

Fatty once you have it you never get rid of it ; )
Top of pagePrevious messageNext messageBottom of page Link to this message

Steve_mackay
Posted on Sunday, January 17, 2010 - 05:43 pm:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only)

+1 for Malwarebytes.
It'll get rid of it.
Top of pagePrevious messageNext messageBottom of page Link to this message

Sifo
Posted on Tuesday, January 19, 2010 - 06:18 pm:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only)

Boy did that SUCK!

I got nailed yesterday! It prevents you from opening anything claiming it's all infected.

It can be cleaned off effectively, but it was a PITA! I used the same basic steps that Mtch posted in the first response. One problem is that it keeps changing the Local Area Network settings. You fix it, it changes back in a couple of seconds. Meanwhile you have to start the Process Explorer before the setting get changed back. That alone took a lot of tries. Meanwhile my screen is filling up with all kinds of messages that stay on top of other windows and I really didn't want to click on them.

Looks like I'm back now, with no data lost.
Top of pagePrevious messageNext messageBottom of page Link to this message

Just_ziptab
Posted on Tuesday, January 19, 2010 - 09:29 pm:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only)

HEY! I got to this point..not sure how but it was fast clicking to "agree" and get in before the virus stopped me. What do I kill here? The umbrella icon is the virus protection that came with the computer...........so I know it's not that one.
Top of pagePrevious messageNext messageBottom of page Link to this message

Just_ziptab
Posted on Tuesday, January 19, 2010 - 10:01 pm:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only)

I'm thinking it's the 3rd one from the bottom. It lights up when it pops up the bogus virus warning. The bottom one is a copy of the renamed process explorer that I renamed sysguard.exe .....just because I don't know what I'm doing. Do I simply right click on it and then left click "kill process"? Then what?
Top of pagePrevious messageNext messageBottom of page Link to this message

Just_ziptab
Posted on Tuesday, January 19, 2010 - 10:30 pm:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only)

Sifo just mailed me some instructions.I should have it on the run now.........
Top of pagePrevious messageNext messageBottom of page Link to this message

Wastegate
Posted on Tuesday, January 19, 2010 - 11:20 pm:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only)

Download Rkill.exe run it
http://download.bleepingcomputer.com/grinler/rkill .exe
It's kills all the bad processes running on your pc. If you still get fake antivirus warning run it again.

Also afterwords go in Internet Explorer - Tool- Options - Connections -Lan Setting - Recheck Automatic Detect uncheck others.

Then install, update, and full scan with Malwarebytes.
Show results- Remove all that it finds.


Also afterwords go in Internet Explorer - Tool- Options - Connections -Lan Setting - Recheck Automatic Detect uncheck others.

I get tired of removing this crap off systems at work.
Top of pagePrevious messageNext messageBottom of page Link to this message

J2blue
Posted on Tuesday, January 19, 2010 - 11:24 pm:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only)

I'm not trying to be a royal arse, but if you put as much time and effort into learning Ubuntu linux better as you are into chasing down the virus de jour on the Windows box... well you may find that you don't have the virus problems that affect over 90% of the consumer market. I'm not claiming linux is virus free or "secure", either. No operating system is 100% secure. But, by not following the path of least resistance you may find many benefits that make any investment of time and energy very worth while.

This particular virus hit a customer's PC today and I will be securing the critical data, and then either cleaning off the bug or reinstalling windows tomorrow. It's good money for me. They don't have an alternate PC running Ubuntu or any other non-Microsoft OS to fall back on. For now their business is on hold!

Good luck with the clean-up.
Top of pagePrevious messageNext messageBottom of page Link to this message

Wastegate
Posted on Tuesday, January 19, 2010 - 11:29 pm:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only)

Or just run Firefox with Adblock Plus add on.
Linux is still not as consumer friendly as Windows.
Top of pagePrevious messageNext messageBottom of page Link to this message

Just_ziptab
Posted on Wednesday, January 20, 2010 - 12:29 am:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only)

Thank you all! I'm up and running on the new computer.What a damned deal that this has been tonight! Really got educated on this one! I will look into the above suggestions.
Top of pagePrevious messageNext messageBottom of page Link to this message

Brinnutz
Posted on Wednesday, January 20, 2010 - 12:48 am:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only)

Just download Microsoft Security Essentials, it's free.

Seems to be alright so far.

Or, you can try Avira for free.

I question your surfing...I go to some sketchy places, yet I never have gotten a virus, and this is over the last decade btw.

Oh, I always go into my browsers options and disable the third party cookie option. I never did like that some advertising company (tracking cookies) could be saved on my machine, f that.
Top of pagePrevious messageNext messageBottom of page Link to this message

Froggy
Posted on Wednesday, January 20, 2010 - 01:42 am:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only)

nutz, he has Avira on there. I personally hated it on my laptop. I just installed MS security today on it, so I will see how it does. Still nothing on my desktop, which I upgraded to Win7 over the weekend. : D
Top of pagePrevious messageNext messageBottom of page Link to this message

Just_ziptab
Posted on Wednesday, January 20, 2010 - 06:18 am:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only)

Yeah,I'm not too impressed with Avira......since it missed the attack. AGV was working good on my 2005 computer and Ubuntu seems bullet proof on my back up spare PC...but it is "different" to navigate in the computer itself. Surfing with Ubuntu is the same....... and carefree
Top of pagePrevious messageNext messageBottom of page Link to this message

Mtch
Posted on Wednesday, January 20, 2010 - 07:05 am:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only)

hope that it gets sorted without too much more hassle. my earlier reply was just a result of searching for 'how to remove antivirus live'.

i stick with the variations of windows as i dont have the time to play with Linux, but maybe one day.

i use Opera browser, and have done for years now. not as common as Firefox, but i cant be bothered changing as Opera does what i want, and also i seem to suffer less from virus problems as i did with IE. i think thats to do with the way Opera deals with cookies etc, which are the main way a lot of viri get on board.

another nice program i use is Advanced System Care from IOBIT. it does a good job of speeding up my pc, is free( a pro version also) and has a good defragger.

im not trying to 'sell' you these it just the ones i prefer.
Top of pagePrevious messageNext messageBottom of page Link to this message

Sifo
Posted on Wednesday, January 20, 2010 - 06:35 pm:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only)

For what it's worth I'm running avast! anti-virus and this one slipped right through. Only the second virus I've been hit by in about 20 years. This one was must more of a pest than the first, but still wasn't destructive, just a hassle to remove. Is it worth going to Linux over this? Not to me at this point. Just my 2 cent opinion. Linux is much less of a target from the virus writing industry which does in theory make it safer.

Mtch, I hope you have things worked out. I'm happy to help out in any way I can. Tomorrow is a busy day for me and I will be out of contact until evening. Looks like you will get good support here too.

Funny thing is that I've lost more time and data from some MS updates than viruses. MS updates have been much better in recent years though.
Top of pagePrevious messageNext messageBottom of page Link to this message

Swampy
Posted on Friday, January 22, 2010 - 12:07 am:   Edit Post Delete Post View Post/Check IP Print Post    Move Post (Custodian/Admin Only)

Attorneys of course!



I couldn't help my self!
« Previous Next »

Add Your Message Here
Post:
Bold text Italics Underline Create a hyperlink Insert a clipart image

Username: Posting Information:
This is a private posting area. Only registered users and custodians may post messages here.
Password:
Options: Post as "Anonymous" (Valid reason required. Abusers will be exposed. If unsure, ask.)
Enable HTML code in message
Automatically activate URLs in message
Action:

Topics | Last Day | Tree View | Search | User List | Help/Instructions | Rules | Program Credits Administration