My PC was hijacked by a virus - Update: Thanks!

Imzadi

♥ Saved by an angel in a trench coat!
Joined
Oct 29, 2004
Messages
40,170
My AVG antivirus kept alerting me every several days that there it found a Trojan Horse. It would "fix" it. But, since the warning kept coming back, I knew it was deeper in the registry.

Well, yesterday it took over, full out. It's a Trojan horse called "Antivirus Live." It's holding my PC hostage. It mimics Windows Security features, saying I have to run Windows Antivirus, only it comes up instead. It won't let me onto any other webpage or run any programs except a page to BUY and install their antivirus program. :mad: Not doing that, of course.

I'm running my PC now in Safe Mode. I ran THREE different antivirus programs yesterday for 5 friggin hours yesterday, and couldn't get rid of it: :headache: :badpc:

I ran the short version of Microsoft's Malicious Software Removal Tool. I should have just run the longer, full scan as I knew there was a virus. :headache: The short scan didn't find anything. When I tried to run it again. The "RUN" command prompt is now missing from my Start commands. :confused3 I think the virus disabled my access to the Command Prompt.

Then I ran an AVG antivirus scan. It didn't find anything, not even the old Trojan Horse alert it used to find.

Last, I went to the Microsoft website to see if I could get the Malicious Software Removal Tool run another way. They had something called Windows Live Onecare. It took FOUR friggin hours to run. :sad2: It DID find the Trojan and said it removed it. But, when I went to reboot, the Trojan is still there, hijacking my system. :badpc:

I Googled how to remove this "Antivirus Live" virus. I found 2-3 webpages, but they tell me I have to download some tool to get rid of this virus. I'm sure I do have to download something (if I don't do a Clean Install,) but I don't know the legitimacy of any of these sites. For all I know, I could be at another malicious site that works with this Trojan, telling me to download their tool - which actually, totally kills my PC. :scared1:


I don't have access to the links in My Favorites, so I can't find my links to legitimate PC helping sites. I know there are a few.

I'd prefer NOT to do a Clean Install/reformat at this time. It takes me several DAYS :headache: to reformat, delete all the crap that came bundled with the system, then reload drivers & programs, then find the newest updates online and update Windows, HP, the drivers, the programs, etc., etc., etc. :headache: It right before Christmas. I don't have time to do a Clean Install.


Anyone have the links to a legitimate site with directions to clean this "Antivirus Live" off my laptop? Thanks! :surfweb: :(
 
Will your legitmate antivirus software give you the name and location of the file causing the problem? Can you manually change the name of the file, reboot, and if everything looks OK, delete the file?

I had to do that for a virus a few years ago...the virus software couldn't fix it, but it told me where it was located so I could fix it manually.
 
http://www.malwarebytes.org/mbam.php

See if it'll let you install and run it at all.

Have fun.

P.S. There are many versions of this Malware out there. Some of them do so many changes in the registry trying to hide and protect itself, it’s easier and quicker to reinstall, trust me.
 
Try Avast (www.avast.com). It's free.

CNet rates it 5 stars and user ratings put it at 4.5 stars (over 12,000 reviews).

I use it and have no issues.
 

Definitely try malwarebytes first.

I had a similar trojan, it hijacked everything and redirected every web query to their website trying to get you to buy their software to remove it. Installed malwarebytes from a disk in safe mode. It found and removed it right away.
 
Will your legitmate antivirus software give you the name and location of the file causing the problem? Can you manually change the name of the file, reboot, and if everything looks OK, delete the file?

I had to do that for a virus a few years ago...the virus software couldn't fix it, but it told me where it was located so I could fix it manually.

In Safe Mode, I only get the screen to run my AVG antivirus. I can't seem to find the button to read the logs of what it removed before. :(


http://www.malwarebytes.org/mbam.php

See if it'll let you install and run it at all.

Have fun.

P.S. There are many versions of this Malware out there. Some of them do so many changes in the registry trying to hide and protect itself, it’s easier and quicker to reinstall, trust me.

Definitely try malwarebytes first.


Thanks. I'll try this. This was the download on one of the Google page, giving directions. I wanted to be sure this download is legit. :thumbsup2

Going in! :surfweb:
 
I have gotten it twice, and malwarebytes got rid of it.

Good luck!
 
Same prblem here.
I could not get mayleware bytes to run.

I ran spyware doctor from 2-spyware.com

I had to use / downoad the alternate location because this virus somehow
prevents malware scans from running
 
Thanks for the Malewarebytes recommendation. :thumbsup2

I fought for several hours with the Trojan, :mad: it wouldn't let me install the Malewarebytes and another tool to activate them. :headache: Or, it would shut the computer completely down, knowing a reboot would activate it again. I Googled two remedies, including renaming the Malewarebytes.exe file and still no go. :badpc:

Finally, I did a System Restore in Safe Mode back to several days ago. I knew it was still in the computer, but at least it was dormant back then. Only then, was I able to install and run the Malewarebytes program. :woohoo:

It found and removed THREE Trojans in the registry (including the one my AVG antivirus kept finding & removing,) and 173 other infections of a stealth VideoEgg adware installation that must have bundled itself with some other download I did. :mad:

I reinstalled the latest version of Spybot, to make sure there are no kinks and removed off almost every non-essential program. My computer is working beautifully again! :dance3:
 
Once your computer is infected, the only real way to fix the problem 100 percent is to 'nuke and pave'
You have no way of knowing if this trojan has installed other malicious software that can't be found by anti-virus/malware programs.
 
I know. I'm hoping to put off a clean install for when I upgrade to Windows 7. Nd5056 did say it would have been easier & quicker to do a reinstall, and with all the time I ended up spending, he was probably right. But, I don't have all my program disks & drivers organized well. I'd be searching for all of them as well as the web links to download all the updates. Then there are programs like Kindle for PC and a couple others that were downloaded online as a direct, one time install and registered to a single computer. I'd have to figure out what email address and registration info & I used to register for the product & "get permission" to reinstall the programs again and have it recognise it IS the same computer as that info would be wiped from the registry. :headache:
 















Receive up to $1,000 in Onboard Credit and a Gift Basket!
That’s right — when you book your Disney Cruise with Dreams Unlimited Travel, you’ll receive incredible shipboard credits to spend during your vacation!
CLICK HERE













DIS Facebook DIS youtube DIS Instagram DIS Pinterest DIS Tiktok DIS Twitter DIS Bluesky

Back
Top