FrEn

E-mail Print

Free malware removal tool to remove AV Guard Online

Written by Administrator  |  Wednesday, 05 October 2011 23:47
AddThis Social Bookmark Button
AV Guard Online is a another rogue Antispyware from the OpenCloud familly, it's a malware that pretends to be an Antivirus. AV Guard Online conducts a fake scan of your system; you are warned by a fake alarm that there are more malwares on your system. It’s true indeed, there is really a malware in your system but I think the only malware on your system is AV Guard Online itself. AV Guard Online invites you to purchase a license to remove malwares, do not, it's a scam, you need a license for a malware? This so-called Antivirus tries to scam you. Uninstall AV Guard Online immediately from your system.

AV Guard Online

To remove AV Guard Online (Uninstall AV Guard Online)

  • Restart your computer and as soon as your computer turns on hit the F8 key (repeatedly) until a screen comes up
  • Choose Start computer in SAFE MODE with network support
  • If you cannot connect to the Internet, do this :
    • Open Internet Explorer
    • Go to Tools => Internet Options => Connections Tab => LAN Settings
    • Uncheck "Use a proxy server"
    • Recheck "Automatically detect settings"
  • Download this free removal tool for AV Guard Online
  • Extract it
  • Launch
  • Click on the delete button

AV Guard Online will be removed from your system in 10s. Restart your computer when it’s finished.

Processes :

  • [random].exe
  • conhost.exe
  • csrss.exe

Files :

  • %System%\[RANDOM].exe
  • %AppData%\[RANDOM]AV Guard Online.ico
  • %TEMP%\[RANDOM NUMBERS].tmp
  • %Desktop%\AV Guard Online.lnk
  • %Programs%\AV Guard Online\AV Guard Online.lnk
  • %Windows%%\Temp\Cab[Random Number].tmp
  • %Windows%%\Temp\Tar[Random Number].tmp
  • %Windows%%\Temp\Cab[Random Number].tmp
  • %Windows%%\Temp\Tar[Random Number].tmp
  • %Windows%%\Temp\Cab[Random Number].tmp
  • %AppData%\Microsoft\CryptnetUrlCache\Content\A44F4E7CB3133FF765C39A53AD8FCFDD
  • %AppData%\Microsoft\CryptnetUrlCache\MetaData\A44F4E7CB3133FF765C39A53AD8FCFDD
  • %AppData%\conhost.exe
  • %AppData%\csrss.exe
  • %AppData%\Microsoft\csrss.exe
  • %AppData%\ldr.ini

Registry

Registry created values:

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    • [RANDOM] = "%System32%\[RANDOM].exe"
    • conhost=%AppData%\Microsoft\csrss.exe
    • [RANDOM]=%AppData%\csrss.exe”
  • HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\C0AB6693AB3202B4B9D95716ED5CE4A6\SourceList
    • LastUsedSource = "n;1;%ProgramFiles%\Common Files\Wise Installation Wizard\"
  • HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon
    • Shell=explorer.exe,%AppData%\conhost.exe
    • Load=%Systemt32%\lvvm.exe”

Registry deleted values:

  • HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\C0AB6693AB3202B4B9D95716ED5CE4A6\SourceList
    • LastUsedSource = "n;1;%ProgramFiles%\Common Files\Wise Installation Wizard\"

Registry modified values:

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ServiceCurrent
    • (Default) =
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ServiceCurrent
    • (Default) =

Download

Remove AV Guard Online Software manually :

  • Restart your computer in safe mode :
    • Restart your computer and as soon as your computer turns on hit the F8 key (repeatedly) until a screen comes up
    • Choose Start computer in SAFE MODE
  • Open the infected account
  • Open explorer, paste into the address bar the text %Temp% then press enter, it will open C:\Documents and Settings\Christian\Local Settings\Temp on my computer
  • Remove all .exe files and all random folders under this path
  • Open explorer, paste into the address bar the text %AppData% then press enter, it will open C:\Documents and Settings\Christian\Local Settings\Application Data on my computer
  • Remove all .exe files and all random folders under this path and the AV Guard Online folder
  • Remove AV Guard Online.lnk from your desktop
  • Remove AV Guard Online.lnk from your start menu
  • Click on the start menu button then click on run
  • Type msconfig and press enter
  • Go to the Startup tab
  • Uncheck all random character keys in it and click on the OK button
  • Restart your computer in normal mode
This will solve the problem but you can run the removal tool to remove the other registry keys and values.
 

Comments  

 
0 #3 2011-10-10 04:25
Hell yes!! Thank you so much. I can finally use my computer again!
Quote
 
 
0 #2 2011-10-07 00:59
I followed the manual removal instructions and it was very educational. I learned a lot and got rid of AV Guard. But now IE won't run. Mozilla seems OK but sort of slow. Any suggestions? Also does this method work with any malware/virus infection?
Quote
 
 
0 #1 2011-10-06 08:29
Thanks a lot!
Quote
 

Add comment


Security code
Refresh

Related articles
Latest posts
  • Free malware removal tool for Guard Online

    Written by %s admin 10/10/2011
    Guard Online is a another rogue Antispyware from the OpenCloud and AV Guard Online familly, it's a malware that pretends to be an Antivirus. Guard Online conducts a fake scan of your system; you are…
  • Free malware removal tool to remove AV Guard Online

    Written by %s admin 05/10/2011
    AV Guard Online is a another rogue Antispyware from the OpenCloud familly, it's a malware that pretends to be an Antivirus. AV Guard Online conducts a fake scan of your system; you are warned by a…
  • Free removal tool to remove Security Guard 2012

    Written by %s admin 05/10/2011
    Security Guard 2012 is a another rogue Antispyware from the OpenCloud familly, it's a malware that pretends to be an Antivirus. Security Guard 2012 conducts a fake scan of your system; you are warned…
  • Free removal tool for Advanced PC Shield 2012

    Written by %s admin 01/10/2011
    Advanced PC Shield 2012 is a another rogue Antispyware, it's a malware that pretends to be an Antivirus. Advanced PC Shield 2012 conducts a fake scan of your system; you are warned by a fake alarm…
  • Security Sphere 2012 Free Removal Tool

    Written by %s admin 01/10/2011
    Security Sphere 2012 is another spyware from the Security Tool family. Security Sphere 2012 is not a legit program; it's a fake, a counterfeit. Security Sphere 2012 claims to fix your system, but…
.
Information | Contact

© All Rights Reserved. net-studio.org 2009