Removal Tool: Remove Fake Antivirus. (Download it here.)
Removal Guide
Kill Process
(How to kill a process effectively?)
[random]sysguard.exe
Delete Registry
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Run "Antivirus Soft"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run "Antivirus Soft"
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Run "[random]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run "[random]"
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Policies\Attachments "SaveZoneInformation" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Internet Settings "ProxyServer" = "http=127.0.0.1:5555"
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Policies\Associations "Files" = ".exe"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""
HKEY_CURRENT_USER\Software\AvScan
Remove Folders and Files
%UserProfile%\Local Settings\Application Data\[random]
%Program Files%\Antivirus Soft
Removal Guide
Kill Process
(How to kill a process effectively?)
[random]sysguard.exe
Delete Registry
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Run "Antivirus Soft"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run "Antivirus Soft"
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Run "[random]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run "[random]"
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Policies\Attachments "SaveZoneInformation" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Internet Settings "ProxyServer" = "http=127.0.0.1:5555"
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Policies\Associations "Files" = ".exe"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""
HKEY_CURRENT_USER\Software\AvScan
Remove Folders and Files
%UserProfile%\Local Settings\Application Data\[random]
%Program Files%\Antivirus Soft
2 comments:
This is what worked for me, doesnt sound particularly fancy but worked even after a restart
All i did was downloaded Rkill (google it) which only works using firefox, if not try starting your pc in safe mode:
(for xp repeatedly press F8 while your computer is starting up and select SAFE MODE WITH NETWORKING)
Restart your computer once you have downloaded this small file and quickly run it before Antivirus Soft has a chance to start, this should kill the virus
To be extra safe, download Malwarebytes' Anti-Malware program and perform a full system scan to make sure all traces of the virus have been removed.
Hope this helps!
P.s. Who ever created Antivirus Soft & Antvirus Live etc.. is going to get a kick in the C**T :)
Thanks!
Post a Comment