|
free virus removal tool for windows additional guard
|
|
Written by Administrator |
Monday, 16 November 2009 07:50
|
|
Windows Additional Guard is a rogue, ie malware that pretends to be an Antivirus when in reality he is a malware. It is a wolf in sheep's clothing. It conducts a fake scan of your system; you are warned by a fake alarm that there are more malwares in your system. It’s true indeed, there is really a malware in your system but I think the only malware on your system is Windows Additional Guard. It invites you to purchase a license to remove malware, do not, it's a scam, you need a license for a virus? This so-called Antivirus he tries to scam you.

To remove Windows Additional Guard from your system
- Download this free removal tool
- Extract
- Launch
- Click on the delete button
After running the patch, your homepage Internet Explorer becomes search.net-studio.org, done deliberately to erase all traces of then malware, BHOs (Browser Helper Object) are also deleted. You can always restore this setting in Internet Explorer options.
- WI345d.exe
- exec.exe
- ppal.exe
- cb.exe
- energy.dll
- ddv.dll
- FS.dll
- mozcrt19.dll
- sqlite3.dll
- %CommonAppData%\345d567
- %CommonAppData%\WINAGSys
- %CommonAppData%\345d567\WINAGSys
- %UserProfile%\Application Data\Windows Additional Guard
- %CommonAppData%\345d567\578.mof
- %CommonAppData%\345d567\mozcrt19.dll
- %CommonAppData%\345d567\sqlite3.dll
- %CommonAppData%\345d567\WI345d.exe
- %CommonAppData%\345d567\WINAG.ico
- %CommonAppData%\345d567\WINAGSys\vd952342.bd
- %CommonAppData%\WINAGSys\winag.cfg
- %ProgramFiles%\Mozilla Firefox\searchplugins\search.xml
- %UserProfile%\Application Data\Windows Additional Guard\cookies.sqlite
- %UserProfile%\Start Menu\Windows Additional Guard.lnk
- %UserProfile%\Start Menu\Programs\Windows Additional Guard.lnk
- %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Additional Guard.lnk
- %UserProfile%\Desktop\Windows Additional Guard.lnk
- HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
- HKEY_CLASSES_ROOT\WI345d.DocHostUIHandler
- HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes "URL" => "http://search-gala.com/?&uid=7&q={searchTerms}"
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "967907703"
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Windows Additional Guard"


|
Comments
RSS feed for comments to this post.