Sunday, January 15, 2012

Remove Internet Security Guard fake antivirus that runs like trojan and rootkit

Internet Security Guard is true to the habits of rootkits and trojans. It is detected as a combined threat by computer security technologies.
Regular users simply treat is a s a program that has either become installed without consulting their opinion or as a result of aggressive advertisement that users have trusted, but now are considering it rather suspicious.
Removal of Internet Security Guard is not routinely provided in a way available for legitimate programs as the tricky application tries to protect its entries putting them into unexpected locations. Needless to say, the uninstall option is not provided for due to the installation peculiarities.
Click here to start free computer examination and get rid of Internet Security Guard as the software product is another phony antivirus. Instead of pursuing computer infections the rogue program behaves like one of them violating user’s right to know and choose deliberately software products to be installed, as well as to easily get rid of the programs, which are inappropriate in user’s opinion. The extermination available with the above suggestion will certainly cover true infections in the course of the fake antivirus extermination.

Internet Security Guard screnshots:

Internet Security Guard unlock code (activation number \ license key):

Manual removal guide:
Delete Internet Security Guard files:
 %AllUsersProfile%\Application Data\[SET OF RANDOM CHARACTERS]\
%AppData%\Internet Security Guard\
%AppData%\Microsoft\Internet Explorer\Quick Launch\Internet Security Guard.lnk
%UserProfile%\Desktop\Internet Security Guard
%UserProfile%\Start Menu\Internet Security Guard.lnk
%UserProfile%\Start Menu\Programs\Internet Security Guard.lnk

Delete Internet Security Guard registry entries:
HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run\Internet Security Guard = "%AllUsersProfile%\Application Data\58d584\HS126.exe" /s /d
HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\RunOnce\HSS = "%Temp%\scandsk221d_5201.exe" /cs:1
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\[RANDOM].exe\Debugger = svchost.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun = 01000000

 Rename the remover to "explorer.exe" or try to install from Safe Mode if virus blocks download\installation

No comments: