Instructions for the elimination of live virus
Posted July 5th, 2009 by paramozAntivirus Live is a rogue antispyware software. It is very similar to the Antivirus System Pro. It is a fake spyware removal tool that spreads with the help of Trojans or other malicious software. Once installed, it will scan your computer and display fake security alerts, the scan results it detects are all fake. This rogue will ask you to pay for a full version of the software to remove these infections. Antivirus Live is a scam, Do Not buy this fake anti-virus, just ignore this message. It also blocks all the programs especially the antiviruses software. You may get this warning message when you try to run any program “Application cannot be executed”. The rogue will also hijack Internet Explorer and change proxy Settings to redirect you to the Antivirus Live site.
Manual removal instructions:
You should repair the proxy settings of Internet Explorer. Run Internet Explorer, Click Tools -> Internet Options. Select Connections Tab and click to LAN Settings Tab. Uncheck “Use a proxy server” box. Click OK. Click Apply. Click OK. Restart the computer into Safe Mode with Networking using your administrator account.
Kill processes:
Run task manager and kill the process ” sysguard.exe”
Delete registry values:
Click Start -> Run -> type regedit -> Enter. Search for these values using Ctrl+F and delete them:
HKEY_CURRENT_USERSoftwareAvScan
HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerDownload “RunInvalidSignatures” = “1″
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet Settings “ProxyOverride” = “”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet Settings “ProxyServer” = “http=127.0.0.1:5555″
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesAssociations “LowRiskFileTypes” = “.exe”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesAttachments “SaveZoneInformation” = “1″
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun “[random]”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun “[random]“
Search and delete these files:
%UserProfile%Local SettingsApplication Data
%UserProfile%Local SettingsApplication Datasysguard.exe
C:Documents and SettingsuserLocal SettingsApplication Dataovugbsrwjrsysguard.exe
C:Documents and SettingsuserLocal SettingsApplication Datalqtwnuwqcmsysguard.exe
