<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Remove Spyware Protect 2009/SysGuard.exe (Removal Info)</title>
	<atom:link href="http://www.xp-vista.com/spyware-removal/spyware-protect-2009-removal/feed" rel="self" type="application/rss+xml" />
	<link>http://www.xp-vista.com/spyware-removal/spyware-protect-2009-removal</link>
	<description>Your Ultimate Source for Windows Security</description>
	<lastBuildDate>Mon, 15 Mar 2010 05:47:18 -0400</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: emlarge</title>
		<link>http://www.xp-vista.com/spyware-removal/spyware-protect-2009-removal/comment-page-6#comment-26123</link>
		<dc:creator>emlarge</dc:creator>
		<pubDate>Sat, 06 Feb 2010 16:26:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.xp-vista.com/?p=1747#comment-26123</guid>
		<description>For those of you who can&#039;t access the internet after being hit by this marware, I found that it had added a value in my system registry to the following key:  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\InternetSettings\ProxyServer    If you remove this value you should be able to access the internet again.  (Start -&gt; Run -&gt; Type regedit, browse to the directory above, and remove the value (don&#039;t delete the key though, just remove the value).</description>
		<content:encoded><![CDATA[<p>For those of you who can&#8217;t access the internet after being hit by this marware, I found that it had added a value in my system registry to the following key:  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\InternetSettings\ProxyServer    If you remove this value you should be able to access the internet again.  (Start -&gt; Run -&gt; Type regedit, browse to the directory above, and remove the value (don&#8217;t delete the key though, just remove the value).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chrisy</title>
		<link>http://www.xp-vista.com/spyware-removal/spyware-protect-2009-removal/comment-page-6#comment-26016</link>
		<dc:creator>Chrisy</dc:creator>
		<pubDate>Thu, 21 Jan 2010 19:29:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.xp-vista.com/?p=1747#comment-26016</guid>
		<description>Boot to Safe Mode. Go to run and type msconfig&gt;click on Launch system restore&gt;choose restore my computer to an earlier time&gt;pick a date from when you know the system was not infected (it will be in bold) and restore your system to that time. It will reboot and finish up the job after the reboot and you log in.</description>
		<content:encoded><![CDATA[<p>Boot to Safe Mode. Go to run and type msconfig&gt;click on Launch system restore&gt;choose restore my computer to an earlier time&gt;pick a date from when you know the system was not infected (it will be in bold) and restore your system to that time. It will reboot and finish up the job after the reboot and you log in.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LOP</title>
		<link>http://www.xp-vista.com/spyware-removal/spyware-protect-2009-removal/comment-page-6#comment-26009</link>
		<dc:creator>LOP</dc:creator>
		<pubDate>Wed, 20 Jan 2010 15:47:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.xp-vista.com/?p=1747#comment-26009</guid>
		<description>I found the malware installed at the following location on my computer: D:\Documents and Settings\{USERNAME HERE}\Local Settings\Application Data\gxexoo\mryisysguard.exe
It also modified my startup routine to include refrence to this mryisysguard.exe such that it start up anytime I start my computer
Then it modified my IE internet option - Connection - LAN Settings - Use Automatic Configuration Script. It placed a refrence to a .pac file from my C:drive that direct the IE to a website!!!
Clean the malware by searching for text that contain sysguard in safe mode, you will probably get some variant of the spellings with sysguard.exe Delete the file and the folder, restore your IE LAN settings by removing text in the Address field on the: Use Automatic Configuration Script
More importantly, follow all the suggested steps by good people on this thread</description>
		<content:encoded><![CDATA[<p>I found the malware installed at the following location on my computer: D:\Documents and Settings\{USERNAME HERE}\Local Settings\Application Data\gxexoo\mryisysguard.exe<br />
It also modified my startup routine to include refrence to this mryisysguard.exe such that it start up anytime I start my computer<br />
Then it modified my IE internet option &#8211; Connection &#8211; LAN Settings &#8211; Use Automatic Configuration Script. It placed a refrence to a .pac file from my C:drive that direct the IE to a website!!!<br />
Clean the malware by searching for text that contain sysguard in safe mode, you will probably get some variant of the spellings with sysguard.exe Delete the file and the folder, restore your IE LAN settings by removing text in the Address field on the: Use Automatic Configuration Script<br />
More importantly, follow all the suggested steps by good people on this thread</p>
]]></content:encoded>
	</item>
</channel>
</rss>
