Remove Syginre. Description and removal instructions

 
Title: Syginre

Type: Trojans
Severity scale:Syginre severity is 70  (70 / 100)
 
Syginre is a trojan carrying destructive payload. The parasite deletes some text documents, images, archives, audio and video files as well as local web pages and program sources. It also attempts to erase all the system files and remove installed software. This destroys the system and prevents it from booting. Syginre can also modify essential system settings, change keyboard and mouse options and disable important system tools such as the Registry Editor or the Run utility. Furthermore, it can change the Internet Explorer default home page, alter Microsoft Word security options, disable the Windows Firewall and create numerous infected files. The trojan secretly runs on every Windows startup.


Related files: adobe global hack.exe, aim triton6.0.exe, alg.exe, aluscheduler.exe, cachemanxp.exe, calculator.exe, ccApp.exe, ccProxy.exe, csrss.exe, Dllhost.exe, floppy options.exe, important information.exe, kdb34894234.exe, limewirepro.exe, lsass.exe, minesweeper.exe, motivebrowser.exe, msdtc.exe, myspace password cracker.exe, nopde.exe, NPROTECT.EXE, rundll32.exe, services32.exe, smss.exe, Spoolsv.exe, svchost.exe, system.exe, system idle process.exe, readme.exe, taskmanager.exe, virus scanner.exe, winlogon.exe, win32dll.exe, zlclient.exe, 123 copy dvd.exe

Syginre properties:
• Changes browser settings
• Hides from the user
• Stays resident in background

Automatic Syginre removal:

remover for Syginre

Syginre manual removal:

Kill processes:
adobe global hack.exe, aim triton6.0.exe, alg.exe, aluscheduler.exe, cachemanxp.exe, calculator.exe, ccapp.exe, ccproxy.exe, csrss.exe, dllhost.exe, floppy options.exe, important information.exe, kdb34894234.exe, limewirepro.exe, lsass.exe, minesweeper.exe, motivebrowser.exe, msdtc.exe, myspace password cracker.exe, nopde.exe, nprotect.exe, rundll32.exe, services32.exe, smss.exe, spoolsv.exe, svchost.exe, system.exe, system idle process.exe, readme.exe, taskmanager.exe, virus scanner.exe, winlogon.exe, win32dll.exe, zlclient.exe, 123 copy dvd.exe
Delete registry values:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\csrss
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\nprotect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\spoolsv
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\syscheck
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\system idle process
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\winlogon
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\aluscheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\nav
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\smss
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\svchost
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\windows update
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\win services
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\zlclient
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\zone labs client
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\services
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisableRegistryTools=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\HideClock=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoAddPrinter=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoClose=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDesktop=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives=0x1B39
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFind=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetworkConnections=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSaveSettings=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetTaskbar=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSMHelp=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSMMyDocs=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\RestrictRun=1
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoBrowserClose=1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\RestrictAnonymous=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\EnableDCOM=n
HKEY_CURRENT_USER\Control Panel\Keyboard\KeyboardDelay=9
HKEY_CURRENT_USER\Control Panel\Mouse\MouseSpeed=0
Delete files:
adobe global hack.exe, aim triton6.0.exe, alg.exe, aluscheduler.exe, cachemanxp.exe, calculator.exe, ccapp.exe, ccproxy.exe, csrss.exe, dllhost.exe, floppy options.exe, important information.exe, kdb34894234.exe, limewirepro.exe, lsass.exe, minesweeper.exe, motivebrowser.exe, msdtc.exe, myspace password cracker.exe, nopde.exe, nprotect.exe, rundll32.exe, services32.exe, smss.exe, spoolsv.exe, svchost.exe, system.exe, system idle process.exe, readme.exe, taskmanager.exe, virus scanner.exe, winlogon.exe, win32dll.exe, zlclient.exe, 123 copy dvd.exe
Misc:
Exact file location:
floppy options - A:
calculator.exe - C:
aim triton6.0.exe - C:\Program Files
win32dll.exe - C:\WINDOWS\System32 or C:\WINNT\System32
limewirepro.exe - C:\Program Files\LimeWire\.NetworkShare
123 copy dvd.exe - C:\Documents and Settings\All Users\Desktop
adobe global hack.exe - C:\Documents and Settings\[Current User]\Shared
kdb34894234.exe, minesweeper.exe, services32.exe - C:\WINDOWS or C:\WINNT
important information.exe, readme.exe - C:\Documents and Settings\All Users\Start Menu
myspace password cracker.exe - C:\Documents and Settings\All Users\Shared Documents
service host.exe, virus scanner.exe - C:\Documents and Settings\All Users\Start Menu\Programs
alg.exe, aluscheduler.exe, cachemanxp.exe, ccapp.exe, ccproxy.exe, csrss.exe, dllhost.exe, lsass.exe, motivebrowser.exe, msdtc.exe, nopde.exe, nprotect.exe, rundll32.exe, smss.exe, spoolsv.exe, svchost.exe, system.exe,system idle process.exe, taskmanager.exe, winlogon.exe, zlclient.exe - the root of local hard drive (usually, C:)

Other programs to remove Syginre:

• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download

Information added: 06/03/07
Information updated: 06/03/07

Additional resources related to Syginre:

Attention: If you know or you have a website or page about Syginre removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Syginre parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: