Wednesday, October 5, 2011

Removal of AV Guard Online fake virus detector

AV Guard Online scan will make your computer infected regardless of such peculiarities as viruses actually integrated into the scanned computer memory.
Instead of scanning actual memory, the program is busy scanning its own memory, namely database of names of infections, to select by the method of random choice a sufficient number of threats to scare users into the action, for the sake of which the entire scam has been devised. The idea of the scam is to extort money from users by means of luring them into activation of the parasite, which turns out to be waste of money and an investment onto future malware.
The way the money extorted is not safe and very annoying. Therefore, a victim of the scam, to protect computer system and for the sake of convenience of PC usage needs to get rid of AV Guard Online and thus quit the trickery. Click here to launch free scan and remove AV Guard Online tricky software, as well as other malevolent programs detected by proper examination.






Manual removal guide:
Delete infected files:
%SystemRoot%\system32\W1ivD3onFaHsJfL.exe or RANDOM.exe
 %SystemRoot%\system32\lvvm.exe
 %AppData%\zA0uvS2ib3m5Q6EAV Guard Online.ico
 %AppData%\conhost.exe
 %AppData%\csrss.exe
 %AppData%\E84E.1B6
 %AppData%\ldr.ini
 %AppData%\VwjUVelIBz0c\
 %AppData%\zA0uvS2ib3m5Q6E\
 %AppData%\nTZqjYCwkVzN\
 %AppData%\Microsoft\csrss.exe
 %UserProfile%\Desktop\AV Guard Online.lnk
 %Temp%\4F.tmp
 %Temp%\53.tmp
 %Temp%\54.tmp
 %Temp%\55.tmp
 %UserProfile%\Start Menu\Programs\AV Guard Online\
 %UserProfile%\Start Menu\Programs\AV Guard Online\AV Guard Online.lnk

Delete infected registry entries:
HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run
 “gTZqjYCkIrOyAuS8234A=%SystemRoot%\system32\W1ivD3onFaHsJfL.exe”
 HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run
 “conhost=%AppData%\Microsoft\csrss.exe”
 HKEY_LOCAL_MACHINE\system\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings
 “ProxyEnable=00000001?
 HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Internet Settings
 “ProxyEnable=00000001?
 HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Internet Settings
 “ProxyServer=http=127.0.0.1:53717?
 HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
 “DefaultConnectionSettings=3C0000000B0000000…”
 HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
 “SavedLegacySettings=3C0000006B0000000…”
 HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
 “%RANDOM%=%AppData%\csrss.exe”
 HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Windows
 “Load=%SystemRoot%\system32\lvvm.exe”
 HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon
 “Shell=explorer.exe,%AppData%\conhost.exe”

2 comments:

Anonymous said...

I dowloaded Spyware Doctor, it took a long time, then I clicked the scan button and it did not scan or do anything. now it will not open, just like malwarebytes. This AV Guard Online keeps blocking it. I don't know what to do next.

Anonymous said...

restart into safe mode so that the antimalware could run free of the malware impact. spyware doctor removed av guard online scamware forme that way.