How to Manually Remove Antivirus Live Malware

Опубликовал Admin
28-11-2020, 03:30
703
0
Antivirus Live is a vicious piece of malware that completely hijacks your computer and web browser, preventing you from browsing the internet and falsely reporting virus infections. It protects itself from being removed by normal means and other antivirus programs. You will need to roll up your sleeves and dive into the Windows Registry in order to purge it from your system. Follow this guide to learn how.

Steps

  1. Start your computer in Safe Mode with Networking. To access this, reboot your computer and repeatedly hit the F8 key until the Advanced Startup menu opens. Then select Safe Mode with Networking. If Windows loads without showing the menu, then you did not hit the F8 key in time, and you will have to retry.
  2. Readjust your LAN settings. AntiVirus Live hijacks your LAN settings to keep you from properly connecting to the internet. In order to download the tools you need, you will most likely need to fix these settings first. This step is not a permanent fix, as AntiVirus Live will reset the settings the next time it loads.
    • Open Internet Explorer and click the Tools menu. Select Internet Options from the menu.
    • Select the Connections tab. {"smallUrl":"https:\/\/www.wikihow.com\/images\/thumb\/a\/a7\/Manually-Remove-Antivirus-Live-Malware-Step-2Bullet2.jpg\/v4-460px-Manually-Remove-Antivirus-Live-Malware-Step-2Bullet2.jpg","bigUrl":"\/images\/thumb\/a\/a7\/Manually-Remove-Antivirus-Live-Malware-Step-2Bullet2.jpg\/aid731515-v4-728px-Manually-Remove-Antivirus-Live-Malware-Step-2Bullet2.jpg","smallWidth":460,"smallHeight":345,"bigWidth":"728","bigHeight":"546","licensing":"<div class=\"mw-parser-output\"><p>License: <a target=\"_blank\" rel=\"nofollow noreferrer noopener\" class=\"external text\" href=\"https:\/\/creativecommons.org\/licenses\/by-nc-sa\/3.0\/\">Creative Commons<\/a><br>\n<\/p><p><br \/>\n<\/p><\/div>"}
    • Click the LAN settings button. {"smallUrl":"https:\/\/www.wikihow.com\/images\/thumb\/5\/57\/Manually-Remove-Antivirus-Live-Malware-Step-2Bullet3.jpg\/v4-460px-Manually-Remove-Antivirus-Live-Malware-Step-2Bullet3.jpg","bigUrl":"\/images\/thumb\/5\/57\/Manually-Remove-Antivirus-Live-Malware-Step-2Bullet3.jpg\/aid731515-v4-728px-Manually-Remove-Antivirus-Live-Malware-Step-2Bullet3.jpg","smallWidth":460,"smallHeight":345,"bigWidth":"728","bigHeight":"546","licensing":"<div class=\"mw-parser-output\"><p>License: <a target=\"_blank\" rel=\"nofollow noreferrer noopener\" class=\"external text\" href=\"https:\/\/creativecommons.org\/licenses\/by-nc-sa\/3.0\/\">Creative Commons<\/a><br>\n<\/p><p><br \/>\n<\/p><\/div>"}
    • Uncheck the box that is labeled “Use a proxy server for your LAN”. Press OK. This will keep AntiVirus Live from redirecting you when you open your web browser. {"smallUrl":"https:\/\/www.wikihow.com\/images\/thumb\/0\/06\/Manually-Remove-Antivirus-Live-Malware-Step-2Bullet4.jpg\/v4-460px-Manually-Remove-Antivirus-Live-Malware-Step-2Bullet4.jpg","bigUrl":"\/images\/thumb\/0\/06\/Manually-Remove-Antivirus-Live-Malware-Step-2Bullet4.jpg\/aid731515-v4-728px-Manually-Remove-Antivirus-Live-Malware-Step-2Bullet4.jpg","smallWidth":460,"smallHeight":345,"bigWidth":"728","bigHeight":"546","licensing":"<div class=\"mw-parser-output\"><p>License: <a target=\"_blank\" rel=\"nofollow noreferrer noopener\" class=\"external text\" href=\"https:\/\/creativecommons.org\/licenses\/by-nc-sa\/3.0\/\">Creative Commons<\/a><br>\n<\/p><p><br \/>\n<\/p><\/div>"}
  3. Download Process Explorer from the Microsoft TechNet website. Rename procexp.exe to explorer.com before saving it to your computer. This will help allow you to run it without AntiVirus Live interfering.
  4. Use Process Explorer to end the AntiVirus Live program. It will be labeled as “[RANDOM]sysguard.exe”, with random characters before “sysguard”. For example, it may be labeled “xjgvsysguard.exe”.
  5. Delete the application folders. Navigate to %UserProfile%\Local Settings\Application Data\ "(For vista/Windows 7/Windows8 - %UserProfile%\Appdata\local\)" delete the following folder: [RANDOM CHARACTERS]\. The characters will be different for every system. If you open the directory, you should see the sysguard application. This means that you need to delete that folder.
  6. Remove the AntiVirus Live registry entries. Open Windows Registry Editor by clicking Start and searching for “regedit”. Remove the following registry values. Always be careful when deleting registry entries, because deleting the wrong entries can cause your computer to malfunction.
    • HKEY_CURRENT_USER\Software\AvScan
    • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1" {"smallUrl":"https:\/\/www.wikihow.com\/images\/thumb\/2\/2e\/Manually-Remove-Antivirus-Live-Malware-Step-6Bullet2.jpg\/v4-460px-Manually-Remove-Antivirus-Live-Malware-Step-6Bullet2.jpg","bigUrl":"\/images\/thumb\/2\/2e\/Manually-Remove-Antivirus-Live-Malware-Step-6Bullet2.jpg\/aid731515-v4-728px-Manually-Remove-Antivirus-Live-Malware-Step-6Bullet2.jpg","smallWidth":460,"smallHeight":345,"bigWidth":"728","bigHeight":"546","licensing":"<div class=\"mw-parser-output\"><p>License: <a target=\"_blank\" rel=\"nofollow noreferrer noopener\" class=\"external text\" href=\"https:\/\/creativecommons.org\/licenses\/by-nc-sa\/3.0\/\">Creative Commons<\/a><br>\n<\/p><p><br \/>\n<\/p><\/div>"}
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = "" {"smallUrl":"https:\/\/www.wikihow.com\/images\/thumb\/d\/d1\/Manually-Remove-Antivirus-Live-Malware-Step-6Bullet3.jpg\/v4-460px-Manually-Remove-Antivirus-Live-Malware-Step-6Bullet3.jpg","bigUrl":"\/images\/thumb\/d\/d1\/Manually-Remove-Antivirus-Live-Malware-Step-6Bullet3.jpg\/aid731515-v4-728px-Manually-Remove-Antivirus-Live-Malware-Step-6Bullet3.jpg","smallWidth":460,"smallHeight":345,"bigWidth":"728","bigHeight":"546","licensing":"<div class=\"mw-parser-output\"><p>License: <a target=\"_blank\" rel=\"nofollow noreferrer noopener\" class=\"external text\" href=\"https:\/\/creativecommons.org\/licenses\/by-nc-sa\/3.0\/\">Creative Commons<\/a><br>\n<\/p><p><br \/>\n<\/p><\/div>"}
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:5555" {"smallUrl":"https:\/\/www.wikihow.com\/images\/thumb\/6\/60\/Manually-Remove-Antivirus-Live-Malware-Step-6Bullet4.jpg\/v4-460px-Manually-Remove-Antivirus-Live-Malware-Step-6Bullet4.jpg","bigUrl":"\/images\/thumb\/6\/60\/Manually-Remove-Antivirus-Live-Malware-Step-6Bullet4.jpg\/aid731515-v4-728px-Manually-Remove-Antivirus-Live-Malware-Step-6Bullet4.jpg","smallWidth":460,"smallHeight":345,"bigWidth":"728","bigHeight":"546","licensing":"<div class=\"mw-parser-output\"><p>License: <a target=\"_blank\" rel=\"nofollow noreferrer noopener\" class=\"external text\" href=\"https:\/\/creativecommons.org\/licenses\/by-nc-sa\/3.0\/\">Creative Commons<\/a><br>\n<\/p><p><br \/>\n<\/p><\/div>"}
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = ".exe" {"smallUrl":"https:\/\/www.wikihow.com\/images\/thumb\/1\/1f\/Manually-Remove-Antivirus-Live-Malware-Step-6Bullet5.jpg\/v4-460px-Manually-Remove-Antivirus-Live-Malware-Step-6Bullet5.jpg","bigUrl":"\/images\/thumb\/1\/1f\/Manually-Remove-Antivirus-Live-Malware-Step-6Bullet5.jpg\/aid731515-v4-728px-Manually-Remove-Antivirus-Live-Malware-Step-6Bullet5.jpg","smallWidth":460,"smallHeight":345,"bigWidth":"728","bigHeight":"546","licensing":"<div class=\"mw-parser-output\"><p>License: <a target=\"_blank\" rel=\"nofollow noreferrer noopener\" class=\"external text\" href=\"https:\/\/creativecommons.org\/licenses\/by-nc-sa\/3.0\/\">Creative Commons<\/a><br>\n<\/p><p><br \/>\n<\/p><\/div>"}
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = "1" {"smallUrl":"https:\/\/www.wikihow.com\/images\/thumb\/2\/23\/Manually-Remove-Antivirus-Live-Malware-Step-6Bullet6.jpg\/v4-460px-Manually-Remove-Antivirus-Live-Malware-Step-6Bullet6.jpg","bigUrl":"\/images\/thumb\/2\/23\/Manually-Remove-Antivirus-Live-Malware-Step-6Bullet6.jpg\/aid731515-v4-728px-Manually-Remove-Antivirus-Live-Malware-Step-6Bullet6.jpg","smallWidth":460,"smallHeight":345,"bigWidth":"728","bigHeight":"546","licensing":"<div class=\"mw-parser-output\"><p>License: <a target=\"_blank\" rel=\"nofollow noreferrer noopener\" class=\"external text\" href=\"https:\/\/creativecommons.org\/licenses\/by-nc-sa\/3.0\/\">Creative Commons<\/a><br>\n<\/p><p><br \/>\n<\/p><\/div>"}
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM]" {"smallUrl":"https:\/\/www.wikihow.com\/images\/thumb\/b\/b7\/Manually-Remove-Antivirus-Live-Malware-Step-6Bullet7.jpg\/v4-460px-Manually-Remove-Antivirus-Live-Malware-Step-6Bullet7.jpg","bigUrl":"\/images\/thumb\/b\/b7\/Manually-Remove-Antivirus-Live-Malware-Step-6Bullet7.jpg\/aid731515-v4-728px-Manually-Remove-Antivirus-Live-Malware-Step-6Bullet7.jpg","smallWidth":460,"smallHeight":345,"bigWidth":"728","bigHeight":"546","licensing":"<div class=\"mw-parser-output\"><p>License: <a target=\"_blank\" rel=\"nofollow noreferrer noopener\" class=\"external text\" href=\"https:\/\/creativecommons.org\/licenses\/by-nc-sa\/3.0\/\">Creative Commons<\/a><br>\n<\/p><p><br \/>\n<\/p><\/div>"}
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[RANDOM]" {"smallUrl":"https:\/\/www.wikihow.com\/images\/thumb\/7\/7a\/Manually-Remove-Antivirus-Live-Malware-Step-6Bullet8.jpg\/v4-460px-Manually-Remove-Antivirus-Live-Malware-Step-6Bullet8.jpg","bigUrl":"\/images\/thumb\/7\/7a\/Manually-Remove-Antivirus-Live-Malware-Step-6Bullet8.jpg\/aid731515-v4-728px-Manually-Remove-Antivirus-Live-Malware-Step-6Bullet8.jpg","smallWidth":460,"smallHeight":345,"bigWidth":"728","bigHeight":"546","licensing":"<div class=\"mw-parser-output\"><p>License: <a target=\"_blank\" rel=\"nofollow noreferrer noopener\" class=\"external text\" href=\"https:\/\/creativecommons.org\/licenses\/by-nc-sa\/3.0\/\">Creative Commons<\/a><br>\n<\/p><p><br \/>\n<\/p><\/div>"}
  7. Reboot your computer. Let the computer boot normally. AntiVirus Live should no longer load and hijack your browser.
  8. Dispute your credit card charges. If you we tricked into paying for AntiVirus Live, contact your financial institution and dispute the charges to their company. Inform the credit card company that you were scammed.

Tips

Теги:
Information
Users of Guests are not allowed to comment this publication.