RC-Monster Forums  

Go Back   RC-Monster Forums > RC-Monster Area > General Discussion

Reply
 
Thread Tools Rate Thread Display Modes
Old
  (#16)
BrianG
RC-Monster Admin
 
BrianG's Avatar
 
Offline
Posts: 14,609
Join Date: Nov 2005
Location: Des Moines, IA
01.27.2010, 10:47 AM

Quote:
Originally Posted by scarletboa View Post
that's exactly what it is. the blue shield thing isn't visible after a few seconds after the program starts after start-up because it is soon replaced by those red shields with x's.


how did you combat it? my avira antivir couldn't detect it.
If it's called "Antivirus Live", this should kill it. This is what we used at work and it fixed all the computers with it.


1: Reboot the PC in safe mode: As soon as the PC gets beyond the BIOS POST screen, press the F8 key (maybe repeatedly). When a “DOS” menu appears, select “Safe Mode”. This step is needed to make sure the virus is not loaded into memory, which would make it impossible to remove otherwise.


2: Once you are able, log in as the user experiencing the issue. This virus can run under all users, but since most computers are operated by a single primary user, this issue is most likely confined to that user. If more than one user has been operating the machine, steps 3-7 must be repeated for each user.


3: Run Regedit: Click Start -> Run -> type “regedit” and hit “enter”.


4: It is advised to back up the registry hive affected, but I did not. If you wish to do so, highlight “HKEY_CURRENT_USER”, go to file, export, and save it.


5: Delete the following registry keys:

HKEY_CURRENT_USER\Software\AvScan
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download -> “RunInvalidSignatures” = “1″
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Internet Settings -> ”ProxyOverride” = “”
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Internet Settings -> “ProxyServer” = “http=127.0.0.1:5555″
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\Associations -> “LowRiskFileTypes” = “.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\Attachments -> “SaveZoneInformation” = “1″
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run -> “[RANDOM CHARACTERS]”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run -> “[RANDOM CHARACTERS]”

The virus program may not be listed in one of the last two entries above. It will definitely be in one place, but maybe both.


6: Remove the following files:

For Vista:
C:\ Users \ [user] \ AppData \ Local \ [RANDOM CHARACTERS] \
C:\ Users \ [user] \ AppData \ Local \ [RANDOM CHARACTERS] \ [RANDOM CHARACTERS]sysguard.exe
C:\ Users \ [user] \ AppData \ Local \ sysguard.exe

For XP:
C:\ document and settings \ [user] \ local settings \ Application Data \ [RANDOM CHARACTERS] \
C:\ document and settings \ [user] \ local settings \ Application Data \ [RANDOM CHARACTERS]sysguard.exe
C:\ document and settings \ [user] \ local settings \ Application Data \ sysguard.exe


7: Reboot the computer normally, log in as the user again, and check task manager for any questionable processes. Also open Internet Explorer and make sure other websites are available (Yahoo, rcm, etc).

Last edited by BrianG; 01.27.2010 at 04:23 PM.
  Send a message via Yahoo to BrianG Send a message via MSN to BrianG  
Reply With Quote
Old
  (#17)
tashpop
RC-Monster Aluminum
 
Offline
Posts: 641
Join Date: Aug 2007
Location: lake conroe area, tx
01.27.2010, 02:17 PM

Quote:
Originally Posted by JThiessen View Post
I assume you are referring to "system restore"? In the case of my daughters pc, it wouldn''t run System restore, even in Safe mode. Somehow, it disabled it.
yes you are correct, but like i said you have to first prevent the software from starting then system restore. thats key otherwise you cannot do anything unless you have software that can remove it.


Current Projects
CEN GST Mgm 22418
castle 1717
6s lipo

Losi Aftershock
Infinite 160a esc
Motor Not sure yet
   
Reply With Quote
Old
  (#18)
Savage03
RC-Monster Carbon Fiber
 
Offline
Posts: 197
Join Date: Oct 2005
Location: California
01.27.2010, 03:40 PM

Been dealing with this stupid thing myself lately and its not kool, had pretty much the same issues as boa and I know some about pc's and tried many things but this thing locked everything up and even deleted all my restore points and it would even start in safe mode so at that point it was obvious a format was in order. Gonna save those steps posted but if he has as bad as I did dont think its gonna help him.
   
Reply With Quote
Old
  (#19)
Arct1k
RC-Monster Mod
 
Arct1k's Avatar
 
Offline
Posts: 6,597
Join Date: Apr 2007
Location: NJ
01.27.2010, 06:02 PM

Yeah - It actually infected safe mode on Harrolds PC
   
Reply With Quote
Old
  (#20)
scarletboa
RC-Monster Aluminum
 
scarletboa's Avatar
 
Offline
Posts: 929
Join Date: Mar 2009
Location: Las Vegas NV
01.27.2010, 06:19 PM

Quote:
Originally Posted by BrianG View Post
If it's called "Antivirus Live", this should kill it. This is what we used at work and it fixed all the computers with it.


that's exactly what it is. antivirus live

i'm not a complete pc noob. i just forgot how to do safe mode. i am pretty familiar with the registry and task manager, so now that i have that list of commands, i'm sure i'll be able to kill this thing.


They say a good mechanic only needs 2 tools - WD40 & Duct tape. If it moves, and its not supposed to, duct tape. If it doesn't move, and its supposed to, WD40.
   
Reply With Quote
Old
  (#21)
Overdriven
Destroyer of Tires
 
Overdriven's Avatar
 
Offline
Posts: 626
Join Date: Feb 2009
01.27.2010, 07:51 PM

My Pc modo is, if after an hour of trying to fix it with no luck, format and reinstall. But if you don't have a DVD writer to backup your pics, favorites, etc, get one. Or better yet an external hard drive. $125 will get you 1 terabyte these days. Makes starting all over alot easier, especially if you save an image of the drive (Norton Ghost or similar) on the external drive.


LST XXL MMM 1717 Custom Fabbed Conversion
   
Reply With Quote
Old
  (#22)
scarletboa
RC-Monster Aluminum
 
scarletboa's Avatar
 
Offline
Posts: 929
Join Date: Mar 2009
Location: Las Vegas NV
01.27.2010, 08:55 PM

ok, well i couldn't find these files:

For XP:
C:\ document and settings \ [user] \ local settings \ Application Data \ [RANDOM CHARACTERS] \
C:\ document and settings \ [user] \ local settings \ Application Data \ [RANDOM CHARACTERS]sysguard.exe
C:\ document and settings \ [user] \ local settings \ Application Data \ sysguard.exe

or

HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run -> “[RANDOM CHARACTERS]”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run -> “[RANDOM CHARACTERS]”

but everything seems normal at the moment. i am able to use my itunes and ccleaner, but the internet is not working due to firewall settings? i am doing a virus scan right now


They say a good mechanic only needs 2 tools - WD40 & Duct tape. If it moves, and its not supposed to, duct tape. If it doesn't move, and its supposed to, WD40.
   
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump







Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, vBulletin Solutions Inc.
vBulletin Skin developed by: vBStyles.com