Wednesday, December 9, 2009

Antivirus Live Removal GuideAntivirus Live Removal Guide

Antivirus Live Removal Guide
Antivirus Live (also known as AntivirusLive) is the latest Rogue Anti-Spyware creation from the notorious Magic Software stable. Antivirus Live uses malicious cutting-edge techniques, including the use of backdoor Trojans. Once active, Antivirus Live disables the computer's security options, making it extremely difficult to uninstall through the Control Panel or via Safe Mode. Antivirus Live then starts spewing annoying popup ads and runs a security scan which reports the fake detection of numerous viruses and threats. Antivirus Live will recommend buying its licensed copy to solve the alleged spyware problems. Do not fall for Antivirus Live's trickery. This hazardous parasite should be terminated from the system immediately

Removal Tool: Remove Fake Antivirus. (Download it here.)

Removal Guide
Kill Process
(How to kill a process effectively?)
[random]sysguard.exe

Unregister DLL files
iehelper.dll

Delete Registry
HKLM "SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}"
HKCU "Software\AvScan"
HKCR "CLSID\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}"
HKCU "Software\Microsoft\Internet Explorer\Download" "RunInvalidSignatures"
HKCU "Software\Microsoft\Windows\CurrentVersion\Internet Settings" "ProxyOverride"
HKCU "Software\Microsoft\Windows\CurrentVersion\Internet Settings" "ProxyServer"
HKCU "Software\Microsoft\Windows\CurrentVersion\Policies\Associations" "LowRiskFileTypes"
HKCU "Software\Microsoft\Windows\CurrentVersion\Policies\Attachments" "SaveZoneInformation"

Remove Folders and Files
$WINDIR\[random]sysguard.exe
$SYSDIR\iehelper.dll

Read more:
Constants in manual removal guide

No comments:

Post a Comment