deviant art

Deviant Login Shop  Join deviantART for FREE Take the Tour
[x]
more ▶

Featured in Groups:

Details

August 14, 2010
Link
Thumb

Statistics

Comments: 68
Favourites: 0
Views: 644 (1 today)
[x]

Service Shield virus

Sat Aug 14, 2010, 4:33 PM
Quick note, my computer got hit with that Service Shield virus (I think that's what it's called) - it prompts you to purchase an anti-virus program, but gives no way to remove the 'trial version', and in the meantime it prevents you from opening any program, claiming the files are corrupted. If you or anyone you know has gotten infected -- don't believe the corrupted files warning and don't purchase the program! It's a scam, to be sure - fortunately, I didn't go the ransom route. After many attempts, I figured out A) how to get rid of it and B) why my current anti-virus didn't detect it.

It won't be detected as it isn't exactly a virus.. it's a program. To remove it (for windows XP anyway), reboot your computer and as soon as windows loads, right click the Taskbar at the bottom and open Task Manager. Go to the Processes tab and find a program listed that is a bunch of jumbled letters that look something like fhqwgads and end the process as quick as possible before it can take effect. If you have a lot of programs that load with the startup, it might be a problem.

After you've ended the process, open regedit and go to Current User -> Software -> Microsoft -> Windows -> CurrentVersion -> Run --- there you'll find the program listed to startup with the computer. Remove that, but also take note of the extra info of the program's location. It should be located in the Users->(Name)->Appdata->Local folder in a directory with another jumbled mess for a name. Delete that folder and you're rid of the program. The main trick is catching Task manager at the start and ending the process.

It'll mess with your internet proxy, too. I just set it to auto-detect.

=========================================
USEFUL LINKS
-----------------------------------------
* Garrett Blair official website - [link]
* Commission types and prices - [link]
* Garrett Blair Online Store - [link]
* My eBay auctions - [link]
* GB2K on MySpace - [link]
* Garrett Blair Google Group - [link]
=========================================
Add a Comment:
 
:iconmythical-mommy:
~Mythical-Mommy Oct 3, 2010   General Artist
I just got hit with this yesterday. Thank you so much for sharing this information. I remembered seeing it and it helped me to get rid of it. THANKS!
Reply
:iconcuddlestheoctopus:
Thanks for the info!
Reply
:iconblue-blade32:
I got hit by the antivirus live version 4 times earlier this year just by surfing on deviantart.
Reply
:iconmcherry1:
I used to get that message a bunch of times - from deviantart!!!

I would be surfing through pictures here and all of a sudden on page-load it would say "Warning, your computer may be infected. Click now to scan for viruses. Okay & Cancel"

Scared to click Okay or Cancel because of the ramifications, I'd have to close the browser, and start browsing again from scratch.
Reply
:iconxxxxanonymousxxxx:
!xxxxAnonymousxxxx Aug 17, 2010   Interface Designer
This is called the Win32 virus it attacks all exe files and scr <- screensavers the only way to get rid of this is to reformat your Pc. Don't bother backing up any software you might have on your pc because you will just end up re-infecting yourself. This virus cannot attack images,or zip/rar files unless there in a self extracting file. Also any text documents you have are infected as will. This is what you need to do. Reformat your PC and do not install any software or documents or text files you had on your computer when the infection occurred. Re-download them from the original site to make sure there clean. To protect yourself from this happening again just backup your software on a CD or in a zip/rar or locker file this way these files cannot be attacked I like to use a safe or or an ISO file. Hope this helps and I enjoy your work.
Reply
:icontommerch:
~tommerch Aug 16, 2010  Hobbyist Writer
i had the exact same problem earlier this year. I think the source may well have been an adserver (and one which may serve up ads to "Deviant"Arts, I believe). I join the chorus singing Malwarebytes' praises.

If I ever find whoever wrote that malware, I would be sorely tempted to vigorously apply a ball-peen hammer to cranial and hand bones. Not that I would encourage such extra-legal behavior.

Thos. Merchant
Reply
:icongryphon2001:
Use Malwarebytes and COMODO over Firefox, that will stop
the Download from happening... Heard from others that this
virus works well with microsoft's browser (of course) Versions
of this are always an Ad for Antivirus Program, and it is hard to
tell from the Adware that it is a Scam. This is generated by some Aussie Bastards who use it as an Extortion Scam that the 'laws' down under don't address as a Fraud... some people should spend more time F-ing 'roos instead of messing with people on the 'net. BTW, Safe Mode Start
USUALLY will prevent Autorun-type Viruses from opening,
but if the Virus Loads itself into the MS Code Files, not always. Back up your stuff on Chips or External Drives, and
if you have a Copy of the Win Software as a Backup, you can always Wipe out the Drive and start over. My Panasonic CF-29 has a Removable HDD and I have a Hot
Spare with Windows and my Settings... I do not use my
Desktop Online, but that may not be an option for some
people. Hackers should Rot in Hell, but Soulless Creatures
don't meet the entrance requirements...
Reply
:iconnickieboy2004:
I just had to "clean" my desktop from the very same virus. I found a link on-line, using a different computer, which advised to run ccleaner, rkill and malwarebyte, but my fix came from System Restore. Very anxious moments though, leading up to that!
Reply
:icontabbat8:
you should check out having a usb-key with an auto-loading antivirus/antimalware prog on it, and set your bios to load usb first , then cd/dvd, then harddrive. that gives you the option of using an av cd or usb to load up before your os, and scrub out with a binary or dos based prog. dr web cure-it and clamwin are good choices, as is a2...
just update their versions once a week!

i'm beau coup paranoid about my system , so i've got heavy armor and hardened os settings, but insurance is nice. found 3 malware in 6 months , in downloaded files. os settings prevented install, a2 and cure-it scrubbed them out all the way to boot level and restore points. good to go. you can get a2 emergency kit , dr.web cure-it , and clamwin [ in mobile/usb or standard versions] , and online armor for free. and they rock.
Reply
:iconvest:
Ahh, I know that one.

I got it through a fake Email link sent to me. The Email stated very bluntly that somebody had posted something on my Facebook wall. Went to check it out, and when I saw the little icon pop up in the system tray, I knew immediately I'd been nailed.

The damn thing would bring up that fake purchase prompt before I could even login to Windows, and Safe Mode didn't prevent it from occurring. After several hours of different attempts, I upgraded to Windows 7.
Reply
Add a Comment: