Antivirus Live manual removal:
Kill processes:
[random]sysguard.exe
Delete registry values:HKEY_CURRENT_USER\Software\AvScan
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:5555"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = ".exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random]"
Delete files:[random]sysguard.exe
Delete directories:%UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS]\
%UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS]\[random]sysguard.exe
thanks again, saved me lots of time and precious files.
It may just have been for my version of the malware, but I found that opening the task manager immediately after startup meant that it didn't have time to disable it, and I could end the process.
Thanks in advance for your help.
Thanks!!
My version was tlgysysguard.exe
This is driving me crazy!!!!!!!!!
Thanks
NOW! How do we go about getting these F**KERS banned from teh internet?
Please review and if appropriate add this to your manual removal instructions - probably in the "Delete files" section
Once again, Thankyou :D
anyhow yea i just push f8 ..go into safe mode and systemrestore then ,,restore to a last restore point..it works
The key is to reboot into safe mode so it doesn't startup at all.
Thanks!!
As soon as I got the problem, and I got to this site. BAM! AVG cut it, and CCleaner allowed for forced removal. :D
boy did that proxy server stuff drive me crazy.
Isn't this illegal?????
Complain to the FTC?
Malware creators should be executed.
Also you can start up normally or on safe mode for some laptops, computers, and PC's.
I really appreciate it.
and whenever i try to open task manager, or process explorer, or killbox
the virus closes them
please help
I did it by starting in safe mode AND networking, then downloaded malware bytes anti malware through firefox which will scan your computer and delte the virus for you.
Thanks for taking time and creating these instructions. God bless you.
Thank you SO much for documenting this. Worked like a charm.
When not in safemode, i can at least have a connection, just can't use the internet because of the virus. but in safemode, it won't even let me connect.
Michael
I rebooted into Safe Mode and ran Malware and Supra. Lucky fir me it did the job.
Now that everything is back to normal, I intend to purchase the programs.
Some of the he joys of running Linux.
NO spyware
NO viruses
NO nasties
And best of all, NO Microsoft
Joy !!!!
How do I get online to reload IE orfirefox or anything.
Post Comment: