Quick note, my computer got hit with that Service Shield virus (I think that's what it's called) - it prompts you to purchase an anti-virus program, but gives no way to remove the 'trial version', and in the meantime it prevents you from opening any program, claiming the files are corrupted. If you or anyone you know has gotten infected -- don't believe the corrupted files warning and don't purchase the program! It's a scam, to be sure - fortunately, I didn't go the ransom route. After many attempts, I figured out A) how to get rid of it and B) why my current anti-virus didn't detect it.
It won't be detected as it isn't exactly a virus.. it's a program. To remove it (for windows XP anyway), reboot your computer and as soon as windows loads, right click the Taskbar at the bottom and open Task Manager. Go to the Processes tab and find a program listed that is a bunch of jumbled letters that look something like fhqwgads and end the process as quick as possible before it can take effect. If you have a lot of programs that load with the startup, it might be a problem.
After you've ended the process, open regedit and go to Current User -> Software -> Microsoft -> Windows -> CurrentVersion -> Run --- there you'll find the program listed to startup with the computer. Remove that, but also take note of the extra info of the program's location. It should be located in the Users->(Name)->Appdata->Local folder in a directory with another jumbled mess for a name. Delete that folder and you're rid of the program. The main trick is catching Task manager at the start and ending the process.
It'll mess with your internet proxy, too. I just set it to auto-detect.
=========================================
USEFUL LINKS
-----------------------------------------
* Garrett Blair official website -
[link]* Commission types and prices -
[link]* Garrett Blair Online Store -
[link]* My eBay auctions -
[link]* GB2K on MySpace -
[link]* Garrett Blair Google Group -
[link]=========================================
I would be surfing through pictures here and all of a sudden on page-load it would say "Warning, your computer may be infected. Click now to scan for viruses. Okay & Cancel"
Scared to click Okay or Cancel because of the ramifications, I'd have to close the browser, and start browsing again from scratch.
If I ever find whoever wrote that malware, I would be sorely tempted to vigorously apply a ball-peen hammer to cranial and hand bones. Not that I would encourage such extra-legal behavior.
Thos. Merchant
the Download from happening... Heard from others that this
virus works well with microsoft's browser (of course) Versions
of this are always an Ad for Antivirus Program, and it is hard to
tell from the Adware that it is a Scam. This is generated by some Aussie Bastards who use it as an Extortion Scam that the 'laws' down under don't address as a Fraud... some people should spend more time F-ing 'roos instead of messing with people on the 'net. BTW, Safe Mode Start
USUALLY will prevent Autorun-type Viruses from opening,
but if the Virus Loads itself into the MS Code Files, not always. Back up your stuff on Chips or External Drives, and
if you have a Copy of the Win Software as a Backup, you can always Wipe out the Drive and start over. My Panasonic CF-29 has a Removable HDD and I have a Hot
Spare with Windows and my Settings... I do not use my
Desktop Online, but that may not be an option for some
people. Hackers should Rot in Hell, but Soulless Creatures
don't meet the entrance requirements...
just update their versions once a week!
i'm beau coup paranoid about my system , so i've got heavy armor and hardened os settings, but insurance is nice. found 3 malware in 6 months , in downloaded files. os settings prevented install, a2 and cure-it scrubbed them out all the way to boot level and restore points. good to go. you can get a2 emergency kit , dr.web cure-it , and clamwin [ in mobile/usb or standard versions] , and online armor for free. and they rock.
I got it through a fake Email link sent to me. The Email stated very bluntly that somebody had posted something on my Facebook wall. Went to check it out, and when I saw the little icon pop up in the system tray, I knew immediately I'd been nailed.
The damn thing would bring up that fake purchase prompt before I could even login to Windows, and Safe Mode didn't prevent it from occurring. After several hours of different attempts, I upgraded to Windows 7.