Additional Guard - How to remove November 23, 2009 By 2-viruses authors Additional Guard sounds like the kind of program, which you might use just to make absolutely sure that your cyber security can not be compromised. Well, if you thought that – surprise! Additional Guard is no more than a fake security program, which uses illicit methods both to spread and to sell. This parasite is a clone of Windows System Defender, and is every which way identical to it’s predecessor: it uses trojans to enter the system, and relies on misleading information to trick users into purchasing it’s “full version”. Once inside, Additional Guard will try to fool you by displaying annoying popups, which claim your system is infected, and urge you to protect your system using this program in particular. Then there’s the absolute classic, which is the fake system scan. This thing seems honest enough, and has a status bar – what more does an antivirus need? Rhetorical though that question may be, i would like to answer it anyway; what a decent antivirus needs – besides a status bar – is the ability to detect parasites,- something that is clearly not the greatest part of Additional Guard. In a nutshell, Additional Guard is like paying money to get screwed over – do NOT trust it, and dispose of it as soon as possible. Automatic Malware removal tools Download Spyhunter for Malware detection(Win) Note: Spyhunter trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions, Download Combo Cleaner for Malware detection(Mac) Note: Combo Cleaner trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions, Refund Policy , Manual removal Processes: AG345d.exe cb.exe exec.exe ppal.exe FS.exe eb.exe WI339.exe Dll: mozcrt19.dll sqlite3.dll ddv.dll energy.dll FS.dll cid.dll Files: %UserProfile%\\Application Data\\2565da61\\AG345d.exe %UserProfile%\\Application Data\\2565da61\\278.mof %UserProfile%\\Application Data\\2565da61\\mozcrt19.dll %UserProfile%\\Application Data\\2565da61\\sqlite3.dll %UserProfile%\\Application Data\\2565da61\\AG.ico %UserProfile%\\Application Data\\2565da61\\AGSys %UserProfile%\\Application Data\\2565da61\\AGSys\\vd952342.bd %UserProfile%\\Application Data\\2565da61\\ag.cfg %UserProfile%\\Application Data\\Microsoft\\Internet Explorer\\Quick Launch\\Additional Guard.lnk %UserProfile%\\Application Data\\Additional Guard\\cookies.sqlite %UserProfile%\\Desktop\\Additional Guard.lnk %UserProfile%\\Recent\\cb.exe %UserProfile%\\Recent\\CLSV.tmp %UserProfile%\\Recent\\ddv.dll %UserProfile%\\Recent\\dudl.drv %UserProfile%\\Recent\\energy.dll %UserProfile%\\Recent\\energy.sys %UserProfile%\\Recent\\exec.exe %UserProfile%\\Recent\\fan.drv %UserProfile%\\Recent\\FS.dll %UserProfile%\\Recent\\PE.drv %UserProfile%\\Recent\\ppal.exe %UserProfile%\\Recent\\SICKBOY.tmp %UserProfile%\\Recent\\tjd.sys %UserProfile%\\Start Menu\\Additional Guard.lnk %UserProfile%\\Start Menu\\Programs\\Additional Guard.lnk %Program Files%\\Mozilla Firefox\\searchplugins\\search.xml c:\\Documents and Settings\\All Users\\Application Data\\117fc c:\\Documents and Settings\\All Users\\Application Data\\117fc\\WI339.exe c:\\Documents and Settings\\All Users\\Application Data\\117fc\\WINAG.ico c:\\Documents and Settings\\All Users\\Application Data\\117fc\\2414.mof c:\\Documents and Settings\\All Users\\Application Data\\117fc\\mozcrt19.dll c:\\Documents and Settings\\All Users\\Application Data\\117fc\\sqlite3.dll c:\\Documents and Settings\\All Users\\Application Data\\117fc\\Quarantine Items c:\\Documents and Settings\\All Users\\Application Data\\117fc\\WINAGSys c:\\Documents and Settings\\All Users\\Application Data\\117fc\\WINAGSys\\vd952342.bd c:\\Documents and Settings\\All Users\\Application Data\\WINAGSys c:\\Documents and Settings\\All Users\\Application Data\\WINAGSys\\winag.cfg %UserProfile%\\Application Data\\Additional Guard %UserProfile%\\Application Data\\Additional Guard\\cookies.sqlite %UserProfile%\\Application Data\\Additional Guard\\Instructions.ini %UserProfile%\\Application Data\\Microsoft\\Internet Explorer\\Quick Launch\\Additional Guard.lnk %UserProfile%\\Desktop\\Additional Guard.lnk %UserProfile%\\Start Menu\\Additional Guard.lnk %UserProfile%\\Start Menu\\Programs\\Additional Guard.lnk c:\\Program Files\\Mozilla Firefox\\searchplugins\\search.xml %UserProfile%\\Recent\\ANTIGEN.drv %UserProfile%\\Recent\\ANTIGEN.tmp %UserProfile%\\Recent\\cid.dll %UserProfile%\\Recent\\CLSV.tmp %UserProfile%\\Recent\\ddv.dll %UserProfile%\\Recent\\eb.drv %UserProfile%\\Recent\\eb.exe %UserProfile%\\Recent\\energy.dll %UserProfile%\\Recent\\energy.sys %UserProfile%\\Recent\\exec.tmp %UserProfile%\\Recent\\fan.drv %UserProfile%\\Recent\\FS.drv %UserProfile%\\Recent\\FS.exe %UserProfile%\\Recent\\kernel32.drv %UserProfile%\\Recent\\PE.sys Registers: HKEY_CLASSES_ROOT\\CLSID\\{3F2BBC05-40DF-11D2-9455-00104BC936FF} HKEY_CLASSES_ROOT\\xp_7a9be.DocHostUIHandler HKEY_CURRENT_USER\\Software\\Classes\\Software\\Microsoft\\Internet Explorer\\SearchScopes “URL” = “http://search-gala.com/?&uid=220&q={searchTerms}” HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Download “RunInvalidSignatures” = “1? HKEY_CLASSES_ROOT\\Software\\Microsoft\\Internet Explorer\\SearchScopes “URL” = “http://search-gala.com/?&uid=220&q={searchTerms}” HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run “Additional Guard” Additional Guard facts Type: Rogue Anti-Spyware Download Spyhunter for Malware detection(Win) Note: Spyhunter trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions, Download Combo Cleaner for Malware detection(Mac) Note: Combo Cleaner trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions, Refund Policy , TOC Leave a ReplyYour email address will not be published. Required fields are marked *Comment * Name * Email * Website