Question:
Help with an awful virus? It's an added icon called "Antivirus Live". It's constantly making it's virus scann?
anonymous
2010-01-03 23:59:24 UTC
Help with an awful virus?
It's an added icon called "Antivirus Live".

It's constantly making it's virus scanners pop up, they are a part of the virus. It won't let me open my other virus scanners or Internet Explorer. A pop up then says, "Secret Warning: Application cannot be executed. The file wmiprvse.exe is infected. Do you want to activate your antivirus software now?" Which, of course, IS the virus.

Since it takes a second for the virus to load when I first log onto my desktop, is was able to start McAfee, but it has yet to find anything. After the virus loads, I can't open anything any longer.

Also, the virus keeps making IE open porn links into new windows.

I need help to get rid of it! Anyone? PLEASE AND THANK YOU!

PS-I can't download anything either!
Five answers:
?
2010-01-04 08:46:47 UTC
antivirus tips and antivirus download:

http://merakit-komputer.com

http://merakit-komputer.com
Amanda
2010-01-04 00:15:24 UTC
I had the same problem. You need to do a system RECOVERY not RESTORE. This is a bad virus and somehow I got it twice. before you do a recovery remember to save anything that you cant get back like pictures and such. put them on an external hard drive or try to burn them to cd or dvd if possible. then when you do the system recovery on the screen where it asks if you want to continue click on "Advanced options" there it will tell you that its doing a "destructive" restore. it will basically take EVERYTHING off of your computer and pretty much make it like a brand new pc that you just pulled out of the box. you will have to go thru the same setup that you did the day you got your computer. Also if you have an HP or Compaq computer when you start up your computer hit F10 or whatever yours says to start system recovery. If it's not HP or Compaq you will have to do the restore from the disc or disc's that you recieved with your pc. If you dont have them check the manufacture's website and see if you can order the disc's for your pc. if you cant find it call their 1-800 number and ask them. you will need to know your computer make and model in order to get the right discs. After you do the recovery you will have to redownload some programs and any updated drivers.
Sky.
2010-01-04 01:36:17 UTC
Antivirus Live is a rogue anti-spyware and ransomware program from the same family as Antivirus System Pro. This infection is installed on your computer through Trojans that install it automatically without your permission. Once installed, Antivirus Live will be configured to start automatically when Windows starts. Once running it will scan your computer and display numerous infections, but will state it will not remove them until you purchase the program. In reality, the scan results it detects are all fake and do not actually exist on your computer.



This program is also very aggressive in how it protects itself from being removed. While the Antivirus Live process is running it will terminate almost all programs that you launch stating that they are infected. It will also change the Proxy settings in Internet Explorer so that you can not browse to any site other than the Antivirus Live site so that you can purchase the program. Using these two methods, the program essentially ransoms the normal use of your computer until you purchase the program or use the guide below to remove the infection.



Restart your pc go into Safe Mode with Networking rather than just Safe Mode. When the computer reboots into Safe Mode with Networking make sure you login with the username you normally use.



Kill the processes first: (random)sysguard.exe

Start Windows Task Manager

Press the following key combination: CTRL+ALT+DEL or CTRL+SHIFT+ESC. This will open the Windows Task Manager.

Once the Windows Task Manager is started, click on the Processes tab. The name of all the processes that are currently running are shown in the left column under Image Name. Using your mouse left click on the process you want to kill(sysguard.exe); the process will now be highlighted.

With the process now highlighted, press the “End Process” button on the Windows Task Manager. The process will now be killed.(if you can't open the taskbar,read below for more info)



The infection changes your Internet Explorer settings to use a proxy server that will not allow you to browse any pages on the Internet. Therefore, if you only have Internet Explorer installed,you need to fix this problem so that you can download the utilities needed to remove this infection.

Start Internet Explorer, and when the program is open, click on the Tools menu and then select Internet Options.Click on the Connections tab, now click on the Lan Settings button.Under the Proxy Server section, please uncheck the checkbox labeled Use a proxy server for your LAN. Then press the OK button to close this screen. Then press the OK button to close the Internet Options screen. Now that you have disabled the proxy server you will be able to browse the web again with Internet Explorer.



Download this Malwarebytes anti-malwware:

http://www.malwarebytes.org/



If you are unable to connect to the site to download Malwarebytes', please go back to proxy setting in the internet option again and make sure the infection has not reenabled the proxy settings.



After you download and install,run an update before you do a full scan of your system.Just delete or remove anything being found.If you can't insta it or having problem to install it.Just change the name of the setup file from mbam-setup.exe to xxx.exe



For manual Antivirus Live removal:

Kill processes: (random)sysguard.exe

Start Windows Task Manager

Press the following key combination: CTRL+ALT+DEL or CTRL+SHIFT+ESC. This will open the Windows Task Manager.

Once the Windows Task Manager is started, click on the Processes tab. The name of all the processes that are currently running are shown in the left column under Image Name. Using your mouse left click on the process you want to kill(sysguard.exe); the process will now be highlighted.

With the process now highlighted, press the “End Process” button on the Windows Task Manager. The process will now be killed. If you can’t open Windows Task Manager or if it closes immediately after you open it.

Try this:

Open up C:\WINDOWS\System32 and look for the file named taskmgr.



Make a copy of taskmgr by first clicking on it to highlight it and then press CTRL + C and then CTRL + V. Once this is down you will have a new file named taskmgr - Copy.

Rename taskmgr - Copy to iexplore by right-clicking on it and choosing “Rename.”

Double-click on the iexplore file and the task manager will run without being shutdown.

Delete these registry keys:

HKEY_CURRENT_USER\Software\AvScan

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:5555"

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = ".exe"

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = "1"

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "(random)"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "(random)"

Delete this files:

%UserProfile%\Local Settings\Application Data\(random)\(random)sysguard.exe

Delete this folders:

%UserProfile%\Local Settings\Application Data\(random)\



Or the easier way is to reinstall your OS
?
2010-01-04 00:24:25 UTC
Every time a window opens hit both the 'ctrl' and f4 key at the same time to close each window. When you have a change accress 'system configuration' and locate the virus in your start up tab and turn it off. The scan for viruses again.
Dominik
2010-01-04 00:13:36 UTC
Here are your instructions:



http://www.2-spyware.com/remove-antivirus-live.html


This content was originally posted on Y! Answers, a Q&A website that shut down in 2021.
Loading...