Re: Win32/NugelE anti-virusLive





--
Yrs Quilly (Winchester UK)


"Buffalo" <Eric@xxxxxxxxxxxxxxxx> wrote in message news:hgj2dl$9je$1@xxxxxxxxxxxxxxxxxxxxxxxxxxxxx


Quilljar wrote:
I have suddenly been infected with a nasty which may be called
Win32/NugelE (there is a file called abjsysguard.exe which windows 7
notification has come up with.)

It is preventing me from using Malarebytes and keeps alerting me to a
supposed virus whch directs me to a web page about Anti-Viruus Live.
this is obviously a scam and I would like to know how to gt rid of
it.

I have started a long scan with MS Security Essentials, which does
not seem to be infected, but wll take ages.
I am having to write this on another computer as the attack has
affected my ability to get on line.

Curious if you are using the pro version of MBAM and was it running in
real-time when you got infected?
Thanks,
Buffalo
PS: http://www.2-spyware.com/remove-antivirus-live.html

The above page describes how to manually delete the "anti-virus live"
trojan.
It sounds pretty simple if you are comfortable deleting entries in the
Registry.

One suggestion was to use msconfig and boot into diagnostic mode
and then run MBAM.

However, read the whole page and choose what you want to do.



.



Relevant Pages

  • Win32/NugelE anti-virusLive
    ... I have suddenly been infected with a nasty which may be called Win32/NugelE ... (there is a file called abjsysguard.exe which windows 7 notification has come up with.) ...
    (alt.comp.anti-virus)
  • Re: How to block system copy commands at driver level
    ... about GUI level windows internals, but there are a number of tricks you ... Open Source&Dest/Read Source/Write Dest loop, and you're not going to be ... thats the reason our task is limited to restrict standerd copy/paste ... #3 + preventing someone opening the file in notepad, ...
    (microsoft.public.development.device.drivers)
  • Re: Desktop Still Crashing
    ... the place, the taskbar jumping up to the side, which I hate.. ... Classic Theme and Notification Area: ... If you are using the Windows Classic theme in Windows XP, ... >> To restart Explorer, Not sure why I needed to restart Explorer, not ...
    (microsoft.public.windowsxp.basics)
  • Re: How to remove the genuine Windows Validation message
    ... did not pass genuine Windows Validation." ... I got scared too when I saw this dreaded notification. ... Windows Genuine Advantage notification UPDATE). ... must be something in registry that controls this. ...
    (microsoft.public.windowsxp.general)
  • Re: inter process communication
    ... a notification that it's ... Windows messaging system for the application. ... communicate with this separate process. ... CreateProcessAPI which is invoked from the managed app. ...
    (microsoft.public.windowsce.embedded.vc)