Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi all,
Vanilla are planning an update to the site on April 24th (next Wednesday). It is a major PHP8 update which is expected to boost performance across the site. The site will be down from 7pm and it is expected to take about an hour to complete. We appreciate your patience during the update.
Thanks all.

Stubborn Garda virus

1235»

Comments

  • Registered Users Posts: 367 ✭✭jimmurt


    Lelantos wrote: »
    Did you enter a genuine Windows product key? If so, you shouldn't get this message, if you used a keygen you will see this message constantly until it's rectified

    I got the key off the back of the laptpo near the battery but it's not accepting it after a minute of verification.


  • Registered Users Posts: 21 superhotarrows


    iggy wrote: »
    Got rid of this nasty bugger today.
    Ran hitman pro on use stick and deleted the Skype.dat file.
    I was able to run malware bytes then.
    It wouldn't allow me enter safemode, it would just shutdown laptop.
    Hopefully it's gone for good.


    HI, mine keeps shutting down also in safe mode, how do I run the usb before if shuts down? Have Hitman Pro on the usb, Thanks


  • Registered Users Posts: 19 CHLuke


    Hi all,
    Just wanted to thank the posters who gave some information on how to remove this virus for 'non-techies', really helped out.

    Just in case others have encountered this, I found that when I ran the anti-malware, a programme that called itself 'MSConfig' was left over and ran at start up. Once I figured out this wasn't the legit MSconfig and 'ticked it' not to run at start up I had no further problems with it. I think I'll have to go and actively delete it now, but was confused for a while as to why msconfig was giving problems.

    Thanks again,
    CHLuke


  • Registered Users Posts: 562 ✭✭✭artvandelay48


    CHLuke wrote: »
    Hi all,
    Just wanted to thank the posters who gave some information on how to remove this virus for 'non-techies', really helped out.

    Just in case others have encountered this, I found that when I ran the anti-malware, a programme that called itself 'MSConfig' was left over and ran at start up. Once I figured out this wasn't the legit MSconfig and 'ticked it' not to run at start up I had no further problems with it. I think I'll have to go and actively delete it now, but was confused for a while as to why msconfig was giving problems.

    Thanks again,
    CHLuke

    Hi,
    I had this as well and found that it had installed a startup task called msconfig that ran a window exe using a .dat file in the application data directory. I disabled the task and ran mbam, spy bot and ccleaner. On normal restart, I downloaded and ran combofix and it deleted another few .dat files. It's a bit of a bugger to fix (I had it fixed when I inadvertently ran the msconfig link thinking it was the normal msconfig, der) but you should be able to fix it without taking it to the repair guy.
    Thanks for the help,
    Art


  • Registered Users Posts: 68 ✭✭FireBreather


    Got one of these today, didn't read it to see the fine, cause i will admit it give me a freight at first haha

    All i read is that Gardia has encrypted all my eyes files, shutting down my computer will lead to serious consequences, best thing is, im a Mac, so they couldn't l9ock Malware, but my god this is coming and i can see how it can trick something

    In anyway i think people should know straight away, since this is against the law, for The Guards to do that,

    this page looked alot more convincing than the images of the one i seen


  • Advertisement
  • Registered Users Posts: 1,094 ✭✭✭SamAK


    My question is - what sites were people visiting and HOW do they end up contracting this virus?

    I don't have it, just wondering where it comes from..


  • Posts: 0 [Deleted User]


    SamAK wrote: »
    My question is - what sites were people visiting and HOW do they end up contracting this virus?

    I don't have it, just wondering where it comes from..
    Usually sites that claim to provide "free" access to watch sporting events and the like, bypassing subscription services.


  • Banned (with Prison Access) Posts: 1,289 ✭✭✭sawdoubters




  • Registered Users Posts: 5,650 ✭✭✭Whatsisname


    Has anyone gotten this without the garda picture? unzipped a zip file earlier and got a pop up, which shut down everything else and told me to complete a survey and it would unlock my laptop. It had cryptolocker as the popups heading so I'm presuming its that.

    I'm in safe mode now running malwarebytes, hoping it works. Has only found 2 threats out of 91k files scanned though.


  • Registered Users Posts: 23,128 ✭✭✭✭TheDoc


    Yo

    I got the same virus last night., My first virus ever in over 15 years of home computing : /

    Dropped my firewall and my anti virus protection on my main pc, trying to resolve an internet connectivity issue on my laptop. Was google hoping trying to find an solution ( had installed ubuntu onto my old laptop but couldnt get internet) and went to a site that said it had a solution then bang my PC restarted, and when I boot up the desktop this thing is locking me down.

    I can boot into safe mode with networking so I can download things to remove it, just so far no luck.

    Tried Malwarebytes which located some stuff and removed it, but virus is still present when I boot up into normal windows.
    I ran spybot search and destroy and same thing.

    Would appreciate some recommendations of tools that will remove it, and if anyone who got it, successfully removed it and what you did to do so.

    I'm in work until this evneing but please reply, and I'll try everything when I get home and let you know how I get on.

    I see a few things in here that looks positive, and I can fully boot into safemode with networking so hopefully can get it removed.

    The disabling the Russian font looks like a good shout I didn't catch.

    I'm worried that I ran two relatively strong anti-virus scanners which caught somes tuff, but then failed to remove it entirely.

    Thanks,
    Doc.


  • Advertisement
  • Registered Users Posts: 8 Nijinksky


    If you've tried combofix, mbam, mbam+chameleon, etc, I always keep a cd with Trinity on it.
    http://www.tomsguide.com/us/download/Trinity-Rescue-Kit,0301-32458.html

    Don't worry if its out of date, when you run it, it auto updates all 5 A/Vs and A/Ts, and runs them.

    Please please everyone remember that malware stores itself in your "system restore" also. Open system restore, turn it off for a few minutes (you could disconnect from the net if you're nervous) and turn it back on again.

    Careful with Trinity,,, just run the antivirus - no need to do anything else -
    Cheers
    Tommy


  • Moderators, Computer Games Moderators, Technology & Internet Moderators Posts: 19,240 Mod ✭✭✭✭L.Jenkins


    Wife contracted the nasty little bástard of a virus this evening. Removing it now. Appears to be similar to the FBI virus.


  • Closed Accounts Posts: 322 ✭✭ppshay


    Trying to clean this at the minute. Booted to Kaspersky Rescue Disk first, no joy. Running Trinity now. Clam AV found some infections but not the Garda Virus. F-Prot found no infections. Running bit defender at now.

    This is a slow process.

    Can Hitman Pro run from CD?


  • Registered Users Posts: 98 ✭✭tippguy2


    ppshay wrote: »
    Trying to clean this at the minute. Booted to Kaspersky Rescue Disk first, no joy. Running Trinity now. Clam AV found some infections but not the Garda Virus. F-Prot found no infections. Running bit defender at now.

    This is a slow process.

    Can Hitman Pro run from CD?

    Malwarebytes


  • Registered Users Posts: 8 Nijinksky


    tippguy2 wrote: »
    Malwarebytes
    I recommend the following in case I havent posted this before :)

    Go to someone elses computer and download Trinity rescue CD
    or if you favour a different boot CD try this site - - - >
    xxx technibble.com/large-list-of-useful-computer-repair-cds/

    Go to xxx malwarebytes.org and d/l chameleon -
    also download and run mbam (you get a months trial of the payware0

    If you cant access another computer, then try d/l this

    xxx bleepingcomputer.com/download/rkill/

    If you've been following this thread, you have enough information now to write a book on FBI/Garda virus

    Please insert www dotbefore the addresses I [printed above as it keeps telling me I'm anew user and wont allow me to post URLs


Advertisement