Emsisoft Malware-Info

Name: Adware.Win32.SysLive

Risklevel: Low Risk

Description:

SysLive will modify registry, modify IE start page, create new services, and shows popup ads (porn material).

Removal instructions for Adware SysLive:

To delete this malware infection, buy Emsisoft Anti-Malware.
Guaranteed removal of Adware SysLive.

Run a full scan on all drives and move all detected items to the quarantine.

More details about this danger:

Installation: Installed through EXE

Process: syslive.exe

Screenshots:

SysLiveSysLiveSysLiveSysLive

Used folders:

  • C:\Program Files\syslive\
  • C:\WINDOWS\
  • C:\WINDOWS\inf\
  • C:\WINDOWS\system32\
  • C:\WINDOWS\system32\CatRoot2\
  • C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\
  • C:\Documents and Settings\All Users\Desktop\
  • C:\Documents and Settings\All Users\Start Menu\
  • C:\Documents and Settings\All Users\Start Menu\Programs\???????\
  • C:\Documents and Settings\[USER]\Application Data\Microsoft\Internet Explorer\Quick Launch\
  • C:\Documents and Settings\[USER]\Cookies\
  • C:\Documents and Settings\[USER]\Favorites\
  • C:\Documents and Settings\[USER]\Local Settings\Temp\

Used files:

  • C:\Program Files\syslive\baidu.ico
    [2550 Bytes] ICO File
  • C:\Program Files\syslive\film.ico
    [23558 Bytes] ICO File
  • C:\Program Files\syslive\gg.ico
    [1150 Bytes] ICO File
  • C:\Program Files\syslive\inetinfoa.exe
    [24576 Bytes] EXE File
  • C:\Program Files\syslive\livetan.exe
    [65536 Bytes] EXE File
  • C:\Program Files\syslive\qq.ico
    [22486 Bytes] ICO File
  • C:\Program Files\syslive\shop.ico
    [23558 Bytes] ICO File
  • C:\Program Files\syslive\shopeee.ico
    [23558 Bytes] ICO File
  • C:\Program Files\syslive\SWTVtan.exe
    [20480 Bytes] EXE File
  • C:\Program Files\syslive\syslive.exe
    [167936 Bytes] EXE File
  • C:\Program Files\syslive\syslive.ico
    [23558 Bytes] ICO File
  • C:\Program Files\syslive\unins000.dat
    [5992 Bytes] DAT File
  • C:\Program Files\syslive\unins000.exe
    [733099 Bytes] EXE File
  • C:\Program Files\syslive\updatesyslive.exe
    [192512 Bytes] EXE File
  • C:\Program Files\syslive\winstephot.exe
    [45056 Bytes] EXE File
  • C:\Program Files\syslive\yx.ico
    [23558 Bytes] ICO File
  • C:\WINDOWS\setupapi.log
    [249202 Bytes] LOG File
  • C:\WINDOWS\inf\intl.PNF
    [424000 Bytes] PNF File
  • C:\WINDOWS\system32\inetinfoa.exe
    [24576 Bytes] EXE File
  • C:\WINDOWS\system32\livetan.exe
    [65536 Bytes] EXE File
  • C:\WINDOWS\system32\updatesyslive.exe
    [192512 Bytes] EXE File
  • C:\WINDOWS\system32\winstephot.exe
    [45056 Bytes] EXE File
  • C:\WINDOWS\system32\CatRoot2\dberr.txt
    [4743 Bytes] TXT File
  • C:\WINDOWS\system32\CatRoot2\edb.chk
    [8192 Bytes] CHK File
  • C:\WINDOWS\system32\CatRoot2\edb.log
    [131072 Bytes] LOG File
  • C:\WINDOWS\system32\CatRoot2\tmp.edb
    [1056768 Bytes] EDB File
  • C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
    [3153920 Bytes] File
  • C:\Documents and Settings\All Users\Desktop\QQ????.url
    [111 Bytes] URL File
  • C:\Documents and Settings\All Users\Desktop\?????.url
    [105 Bytes] URL File
  • C:\Documents and Settings\All Users\Desktop\???????.lnk
    [622 Bytes] LNK File
  • C:\Documents and Settings\All Users\Desktop\????.url
    [111 Bytes] URL File
  • C:\Documents and Settings\All Users\Start Menu\QQ??????.url
    [108 Bytes] URL File
  • C:\Documents and Settings\All Users\Start Menu\????????.url
    [120 Bytes] URL File
  • C:\Documents and Settings\All Users\Start Menu\?????.url
    [112 Bytes] URL File
  • C:\Documents and Settings\All Users\Start Menu\???????.lnk
    [622 Bytes] LNK File
  • C:\Documents and Settings\All Users\Start Menu\Programs\???????\GOOGLE????.url
    [107 Bytes] URL File
  • C:\Documents and Settings\All Users\Start Menu\Programs\???????\QQ??????.url
    [106 Bytes] URL File
  • C:\Documents and Settings\All Users\Start Menu\Programs\???????\???????.url
    [109 Bytes] URL File
  • C:\Documents and Settings\All Users\Start Menu\Programs\???????\?????.url
    [110 Bytes] URL File
  • C:\Documents and Settings\All Users\Start Menu\Programs\???????\???????.lnk
    [634 Bytes] LNK File
  • C:\Documents and Settings\All Users\Start Menu\Programs\???????\????????-???????????????.url
    [118 Bytes] URL File
  • C:\Documents and Settings\[USER]\Application Data\Microsoft\Internet Explorer\Quick Launch\QQ??????.url
    [105 Bytes] URL File
  • C:\Documents and Settings\[USER]\Application Data\Microsoft\Internet Explorer\Quick Launch\????????.url
    [105 Bytes] URL File
  • C:\Documents and Settings\[USER]\Application Data\Microsoft\Internet Explorer\Quick Launch\?????????.url
    [108 Bytes] URL File
  • C:\Documents and Settings\[USER]\Application Data\Microsoft\Internet Explorer\Quick Launch\??? Internet Explorer ?????.url
    [117 Bytes] URL File
  • C:\Documents and Settings\[USER]\Application Data\Microsoft\Internet Explorer\Quick Launch\?????.url
    [105 Bytes] URL File
  • C:\Documents and Settings\[USER]\Application Data\Microsoft\Internet Explorer\Quick Launch\???????.lnk
    [640 Bytes] LNK File
  • C:\Documents and Settings\[USER]\Cookies\user@down-down.ff22113[2].txt
    [516 Bytes] TXT File
  • C:\Documents and Settings\[USER]\Cookies\user@gjjgnjj.22mfdy[1].txt
    [698 Bytes] TXT File
  • C:\Documents and Settings\[USER]\Cookies\user@play.okead[1].txt
    [257 Bytes] TXT File
  • C:\Documents and Settings\[USER]\Favorites\7555???????-???????????????.url
    [49 Bytes] URL File
  • C:\Documents and Settings\[USER]\Favorites\GOOGLE????.url
    [107 Bytes] URL File
  • C:\Documents and Settings\[USER]\Favorites\QQ??????.url
    [51 Bytes] URL File
  • C:\Documents and Settings\[USER]\Favorites\???????.url
    [109 Bytes] URL File
  • C:\Documents and Settings\[USER]\Favorites\????????.url
    [51 Bytes] URL File
  • C:\Documents and Settings\[USER]\Favorites\?????????.url
    [52 Bytes] URL File
  • C:\Documents and Settings\[USER]\Favorites\?????.url
    [53 Bytes] URL File
  • C:\Documents and Settings\[USER]\Local Settings\Temp\updateppsap.ini
    [381 Bytes] INI File

Additional information might be found here:

Search at Google for Adware SysLive Search at Google for Adware SysLive
Search at Bing for Adware SysLive Search at Bing for Adware SysLive
Search at Yahoo for Adware SysLive Search at Yahoo for Adware SysLive

How can I protect myself from Adware SysLive?

Important!
You essentially need an antivirus product, that is not only able to clean infections, but also protect your PC permanently from new dangers. This is the only way to prevent data loss and unnecessary hassle and costs of new installations of your operating system.

Take your chance and buy the multiple awarded protection software Emsisoft Anti-Malware today!

Only $40 for the security of your computer.

Buy Emsisoft Anti-Malware online:

Buy Emsisoft Anti-Malware now

Trust only on the best protection software!

Spring Offer!

Don't miss this: To your bought 1-year license of Emsisoft Anti-Malware or Emsisoft Internet Security Pack or higher you can now get a free license of the CyberGhost Anonymizer for free.
Your advantage: Surf anonymously and visit websites that are restricted in your country.

Only a few days left! Order here

Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - Q1-Q3 2011
More independent reviews of anti-malware software