Welcome, Guest. Please login or register.
July 22, 2025, 05:49:29 AM

Login with username, password and session length

Search:     Advanced search
we're back, baby
*
Home Help Search Login Register
f13.net  |  f13.net General Forums  |  General Discussion  |  Topic: PC Live Guard 0 Members and 1 Guest are viewing this topic.
Pages: [1] Go Down Print
Author Topic: PC Live Guard  (Read 2617 times)
rk47
Terracotta Army
Posts: 6236

The Patron Saint of Radicalthons


on: December 31, 2009, 04:58:04 PM

OK some idiots at work decided to click 'yes' one too many times when prompted with pop-outs.
Who the hell knows what they surf on New Year's Eve while at night shift, yes?

So far I noticed:
1. Task Manager disabled.
2. Pop outs telling me of virus this and virus that.
3. And I think the software messed with windows protection as well.
4. Mozilla keeps telling me any site I went to as 'dangerous' including F13.net LOL

Is this desktop really screwed? Do I have to nuke the windows XP?
Is it safe to plug in a thumbdrive to recover some important datas? Will my drive get infected?

So....(insert bat-logo Help F13! image)

Colonel Sanders is back in my wallet
Prospero
Terracotta Army
Posts: 1473


Reply #1 on: December 31, 2009, 05:04:04 PM

Not positive, but I'm pretty sure there are some freeware AV apps you can stick on a thumbdrive and then send in to do battle. It would be worth googling around.
Chimpy
Terracotta Army
Posts: 10633


WWW
Reply #2 on: December 31, 2009, 06:23:44 PM

You can always make a linux boot CD with bitdefender on it, boot into that, and have it clean the drive. That usually gets rid of a lot of the nasties you cannot get rid of in windows directly.

'Reality' is the only word in the language that should always be used in quotes.
Engels
Terracotta Army
Posts: 9029

inflicts shingles.


Reply #3 on: December 31, 2009, 09:21:39 PM

A lot of the latest spyware/trojans out there masquerade as anti-virus programs that try to get you to click on their pretend gui (the popups you describe) for further infection goodness. At this stage, with the varieties of symptoms you're describing, I think its a fair guess that your registry is now a pock marked hell hole. Although for the purposes of data retrieval I would follow my fellow f13ers advice, such as the linux cd with bit defender, after you have secured your data, nuke that hard drive from orbit and reinstall. Its the only way to be sure that's a safe computer to use for any secure transactions.

I should get back to nature, too.  You know, like going to a shop for groceries instead of the computer.  Maybe a condo in the woods that doesn't even have a health club or restaurant attached.  Buy a car with only two cup holders or something. -Signe

I LIKE being bounced around by Tonkors. - Lantyssa

Babies shooting themselves in the head is the state bird of West Virginia. - schild
Trippy
Administrator
Posts: 23657


Reply #4 on: December 31, 2009, 09:37:04 PM

OK some idiots at work decided to click 'yes' one too many times when prompted with pop-outs.
Who the hell knows what they surf on New Year's Eve while at night shift, yes?

So far I noticed:
1. Task Manager disabled.
2. Pop outs telling me of virus this and virus that.
3. And I think the software messed with windows protection as well.
4. Mozilla keeps telling me any site I went to as 'dangerous' including F13.net LOL

Is this desktop really screwed? Do I have to nuke the windows XP?
Is it safe to plug in a thumbdrive to recover some important datas? Will my drive get infected?

So....(insert bat-logo Help F13! image)
If you don't care about any other apps/junk that may have been installed before the infection you can use System Restore to hopefully get the machine back into a usable state.

Edit: care
« Last Edit: January 01, 2010, 12:58:07 AM by Trippy »
Engels
Terracotta Army
Posts: 9029

inflicts shingles.


Reply #5 on: January 01, 2010, 12:46:54 AM

Cept a lot of these buggers infect system restore files as well :/

I should get back to nature, too.  You know, like going to a shop for groceries instead of the computer.  Maybe a condo in the woods that doesn't even have a health club or restaurant attached.  Buy a car with only two cup holders or something. -Signe

I LIKE being bounced around by Tonkors. - Lantyssa

Babies shooting themselves in the head is the state bird of West Virginia. - schild
Numtini
Terracotta Army
Posts: 7675


Reply #6 on: January 01, 2010, 07:55:49 AM

Some of the fake AV infections are pretty nasty, but so far I haven't had any that didn't eventually get cleaned out by booting into safe mode and running malwarebytes. You might need to run it three or four times though.

If you can read this, you're on a board populated by misogynist assholes.
Kail
Terracotta Army
Posts: 2858


Reply #7 on: January 01, 2010, 08:10:03 AM

Got hit with this about a month ago, and ended up buying this useless PC Doctor thing to get rid of it, but it didn't work too well (kept catching the virus, but it wasn't able to get rid of it completely on it's own for some reason and kept re-installing every time I rebooted).

The thing has a process in the task manager you can kill manually if you can open it (generally has "sysguard" somewhere in it, as far as I can gather, on my computer it was "qwqhsysguard").  If you can't get in to the task manager, microsoft has a utility called PSTools which you can use to list (PSList) and kill (PSKill [name]) processes from the command prompt.  I don't know if this is universal, but I couldn't open my command prompt once this thing was loaded, but right after the computer booted up I could load the command prompt and then kill the process as long as I was quick.  I had a batch file set up to do it until I tried running another scan with Avast (which was blocked while the process was active) which managed to scrub it fairly well.  Things have worked fine since then.
« Last Edit: January 01, 2010, 08:12:52 AM by Kail »
rk47
Terracotta Army
Posts: 6236

The Patron Saint of Radicalthons


Reply #8 on: January 01, 2010, 06:41:41 PM

OK managed to clear it with Malwarebytes Anti-Malware removal software. Fuck, after getting hit with brontok.a virus last month, it's pretting refreshing to see a threat removal going so smoothly as it did. Fucking Live Guard is a scam software planting virus-infected files to make me buy their removal software. why so serious?

Asked the night shift wtf they did and they claimed they 'accidently misclicked' while trying to print something.

"Yeah, but what did you surf on the interwebz at that moment, dipshit?", I wanted to ask but I'll leave it to my Boss to settle.

Colonel Sanders is back in my wallet
Karlsmith
Guest


Email
Reply #9 on: January 06, 2010, 08:54:03 PM

first clean all your drivers with newest AV before nuking your XP ..  Ohhhhh, I see.
NiX
Wiki Admin
Posts: 7770

Locomotive Pandamonium


Reply #10 on: January 07, 2010, 07:31:18 AM

first clean all your drivers with newest AV before nuking your XP ..  Ohhhhh, I see.

Less reflective text, please!
Pages: [1] Go Up Print 
f13.net  |  f13.net General Forums  |  General Discussion  |  Topic: PC Live Guard  
Jump to:  

Powered by SMF 1.1.10 | SMF © 2006-2009, Simple Machines LLC