Sygyp manual removal:
Kill processes:
asistant_alert.exe, googleearthsetup.exe, netalert_v2.4.exe, netwatch_v1.0.3.exe, regverif32.exe, exploit_patcher_v1.0.0.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\regvfy32
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\EnableFirewall=0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\crashonauditfail=0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\forceguest=0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\limitblankpassworduse=0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify=0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusOverride=0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify=0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallOverride=0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify=0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskmgr=1
HKEY_CURRENT_USER\Identities\[Current User ID]\Software\Microsoft\Outlook Express\[Version]\Dont Show Dialogs\Compact Do Not Ask Again=1
HKEY_CURRENT_USER\Identities\[Current User ID]\Software\Microsoft\Outlook Express\[Version]\Dont Show Dialogs\Delete Thread Warning=6
HKEY_CURRENT_USER\Identities\[Current User ID]\Software\Microsoft\Outlook Express\[Version]\Dont Show Dialogs\Mail Empty Subject Warning=1
HKEY_CURRENT_USER\Identities\[Current User ID]\Software\Microsoft\Outlook Express\[Version]\Dont Show Dialogs\Send Mail Warning=1
HKEY_LOCAL_MACHINE\SOFTWARE\Gypsy\W32.Gypsy
Delete files:asistant_alert.exe, googleearthsetup.exe, netalert_v2.4.exe, netwatch_v1.0.3.exe, regverif32.exe, exploit_patcher_v1.0.0.exe, fwall32.reg, ntfs32.reg, oe32.reg, reg32.reg, sec32.reg, sys32.reg, w32info.reg
Delete directories:C:\Program Files\WindowsUpdate
Misc:The googleearthsetup.exe file arrives attached to Sygyp e-mail messages.
Exact file location:
googleearthsetup.exe - C:\Windows or C:\Winnt
asistant_alert.exe, netalert_v2.4.exe - C:\Program Files\WindowsUpdate\System Security
exploit_patcher_v1.0.0.exe, netwatch_v1.0.3.exe - C:\Program Files\WindowsUpdate\System Security\Updates.tmp
regverif32.exe, fwall32.reg, ntfs32.reg, oe32.reg, reg32.reg, sec32.reg, sys32.reg, w32info.reg - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
Post Comment: