I been having some problems with Spyware Guard 2008 and all. This happen 1-2 weeks ago. I noticed some problem and then after a while I assume just to go look for Spyware Guard 2008 stuff, just because it was out there. After a bit of learning some more tricks and all, I keep deleting more stuff that is related to the "SG'08". I went trough search, manually through my comp, check through command prompt, and went through Regidit (though I am not really sure how Regidit work, but I only deleted "SG'08" stuff). The problem is 'rebooting' and also When I go back to normal mode and see if it is deleted, it is not. I am wondering is there more than just deleting it all? Side thing for you all to know are; I do know comp stuff and persueing in Comp Sci., I keep finding more files the more time I check online for what to deleted and I wonder if there is a site to check if the program is bad or just normal. I don't know what else I should post so I'll just let you say what I should do.

Dani AI

Generated

This thread describes a persistent rogue anti-spyware that keeps reappearing after manual deletions. reported the infection returning after restarts, and correctly pointed out that simply deleting files rarely removes all persistence mechanisms. Rogue scanners often spread components into startup locations, services and restore points so they come back unless those locations are cleaned too.

Recommended cleanup workflow:

  • Boot into Safe Mode (or Safe Mode with Networking) to limit malware activity.
  • Stop running malicious processes first (tools like RKill are useful), then run an up-to-date on-demand scanner such as Malwarebytes to remove detected components.
  • Use an autorun/startup viewer to remove leftover startup entries, scheduled tasks and unknown services.
  • Temporarily disable and clear System Restore to prevent infected restore points from reintroducing files, then recreate a clean restore point after cleaning.
  • If the infection resists removal, scan from outside Windows with a rescue/boot CD or an offline scanner to remove items that lock while Windows runs.
  • If compromise is deep or sensitive credentials were entered while infected, back up data (avoid copying executables), wipe the disk and reinstall Windows.

For suspicious binaries, check multi-engine scans before trusting them (for example, VirusTotal). For startup and persistence analysis, Microsoft/Sysinternals Autoruns is the standard tool (Autoruns).

I can't get as to what exactly you are saying?? Does your computer reboot on startup??

As far as deleting is concerned..just doing that does not clear traces of a file. you must uninstall it..try doing that now from 'Add or remove programs'..A software(anti-spyware\virus,etc.) installs various files of itself in various parts and finding them individually and identifying is too much of a daunting task..

I can't get as to what exactly you are saying?? Does your computer reboot on startup??

As far as deleting is concerned..just doing that does not clear traces of a file. you must uninstall it..try doing that now from 'Add or remove programs'..A software(anti-spyware\virus,etc.) installs various files of itself in various parts and finding them individually and identifying is too much of a daunting task..

Well... It like when I try to reboot or I think also for the ms config, it seems to have the same effect as 'restore to last good checkpoint' and that checkpoint is before I delete the files. So pretty much it just restarting the files again where I deleted them. I check everywhere, and I tried that even and it like nothing really just the same as spywareguard.exe on process from 'alt-ctrl-delete'. And the uninstall does nothing.

Well it seems like it could have been partly due to the Fix-it being on after Mac-a-Fee been on a while. Fix-it was before I started school and it was not used.. Though it is fix now.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.