Antivirus Live -- Nastiest Virus I've ever seen

CrusaderFrank

Diamond Member
May 20, 2009
149,752
73,417
2,330
My sons computer got the "Antivirus Live" attack and I've never seen anything like it.

It blew through McAfee, Windows Defender and took out Task Manager (so I cant stop it as a process) regedit (so I can't stop it) and System Restore (so I can't...well you get the idea)

I have to take it to the professional propeller heads.

My son claims it came in on a flash drive, a brand new one. We'll see.
 
My sons computer got the "Antivirus Live" attack and I've never seen anything like it.

It blew through McAfee, Windows Defender and took out Task Manager (so I cant stop it as a process) regedit (so I can't stop it) and System Restore (so I can't...well you get the idea)

I have to take it to the professional propeller heads.

My son claims it came in on a flash drive, a brand new one. We'll see.




STDs suck don't they?
 

That's where I started and could not figure out this part:

4. Now download renamed Process Explorer (explorer.com) and terminate Antivirus Live processes. Should be [random]sysguard.exe, for example: wmcqsysguard.exe.
You should be able to click on the embedded link and get the proper program.

But maybe these directions will work better for you.

Remove Antivirus Live (Uninstall Guide)

My daughter's computer got this last year and it took a bit of work to get rid of it.
 
My sons computer got the "Antivirus Live" attack and I've never seen anything like it.

It blew through McAfee, Windows Defender and took out Task Manager (so I cant stop it as a process) regedit (so I can't stop it) and System Restore (so I can't...well you get the idea)

I have to take it to the professional propeller heads.

My son claims it came in on a flash drive, a brand new one. We'll see.

My son just got a similar virus/spyware/maleware on his computer. It took 3 days to completely remove it. Not only did it do the usual browser redirects, but it would not allow any antispyware programs from running. I had to use Combofix along with the other usual programs like Spybot-S&D, Malwarebytes, SUPERAntiSpyware, etc.. In some cases, I had to change the name of the executable of the antispyware program to get it to run. The people who write this stuff that infects people's computers should be shot.

Let me know if you need any assistance.
 
My sons computer got the "Antivirus Live" attack and I've never seen anything like it.

It blew through McAfee, Windows Defender and took out Task Manager (so I cant stop it as a process) regedit (so I can't stop it) and System Restore (so I can't...well you get the idea)

I have to take it to the professional propeller heads.

My son claims it came in on a flash drive, a brand new one. We'll see.

My son just got a similar virus/spyware/maleware on his computer. It took 3 days to completely remove it. Not only did it do the usual browser redirects, but it would not allow any antispyware programs from running. I had to use Combofix along with the other usual programs like Spybot-S&D, Malwarebytes, SUPERAntiSpyware, etc.. In some cases, I had to change the name of the executable of the antispyware program to get it to run. The people who write this stuff that infects people's computers should be shot.

Let me know if you need any assistance.

They certainly should be shot, those fuckheads ruined my last PC.
 
My son's machine got that. It is now a doorstop, as nothing else will go.

One of the advantages of a Mac. I have yet to see a virus on any of my mac machines. I had to take my vista machine and have them pull the hard drive and do a fresh install it was so virus ridden.

My son does lots of chat, so it must have come through there.
 
Happened to my school's computers last year because they had no real firewall and people were bringing in viruses through the flashdrive by accident. Killed the whole system for a couple months.

Protip: Don't use a flash drive on computers you're not 100% sure about.
 
Antivirus Live -- Nastiest Virus I've ever seen

Then you haven't seen Ebola.

020406ebola.jpg
 
that happened to me last week but i was able to restore to a past date and it seems to have sloved the problem.
 
i was able to go into the antivirus live program and it had check marked to run automaticlly everytime i logged into IE. it would stop IE from running alltogether everytime i started the comp. the check marked areas were grayed out so i couldnt change them. i then went and did a system restore to feb 03 and it seems to be gone.
 
I got it this past week.

I got REALLY screwed over by it, but did manage to knock it out for the most part. As Jillian noted, the fix came from Malwarebyte's anti-malware program, required that the computer be re-opened in safe mode with networking option and ALSO required that IN that mode I run a program called rkill.com.

A company known (I do not kid you) as: bleepingcomputer.com is the place to go to get the stuff. I printed the 8 pages of the fix to have it all handy as I worked the fix.

It involves a set of rather lengthy SCANS. Took a couple of hours to get the job done once I figured out all the gobbledygook.

I still have residual problems on the computer, at this point, but those can be addressed separately. The malware is gone, though!

While the shit was running (trying to get me to buy the "protection racket" bullshit program known as "Antivirus Soft") it also repeatedly opened my browser to some porn web site and a site that sells Viagra. Seriously. A nasty malware indeed. But it's out of my operating system now.
 
Last edited:
My sons computer got the "Antivirus Live" attack and I've never seen anything like it.

It blew through McAfee, Windows Defender and took out Task Manager (so I cant stop it as a process) regedit (so I can't stop it) and System Restore (so I can't...well you get the idea)

I have to take it to the professional propeller heads.

My son claims it came in on a flash drive, a brand new one. We'll see.

My son just got a similar virus/spyware/maleware on his computer. It took 3 days to completely remove it. Not only did it do the usual browser redirects, but it would not allow any antispyware programs from running. I had to use Combofix along with the other usual programs like Spybot-S&D, Malwarebytes, SUPERAntiSpyware, etc.. In some cases, I had to change the name of the executable of the antispyware program to get it to run. The people who write this stuff that infects people's computers should be shot.

Let me know if you need any assistance.

Shot, no, handed over to some Apache Indians who still practice to old "techniques", yes. Broadcast it live over internet.
 

Forum List

Back
Top