Additional Guard manual removal:
Kill processes:
WI339.exe exec.exe FS.exe ppal.exe
Delete registry values:HKEY_CURRENT_USER\Software\3
HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
HKEY_CLASSES_ROOT\xp_e0ebf.DocHostUIHandler
HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes "URL" = "http://search-gala.com/?&uid=7&q={searchTerms}"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "[xSP_2:117fc3395e69e29f71abba93a68c4181_7]"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "99660903"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Additional Guard"
Unregister DLLs:mozcrt19.dll sqlite3.dll cid.dll ddv.dll energy.dll
Delete files:WI339.exe WINAG.ico 2414.mof mozcrt19.dll sqlite3.dll vd952342.bd winag.cfg cookies.sqlite Instructions.ini Additional Guard.lnk search.xml ANTIGEN.drv ANTIGEN.tmp cid.dll CLSV.tmp ddv.dll eb.drv eb.exe energy.dll energy.sys exec.exe exec.tmp fan.drv FS.drv FS.exe kernel32.drv PE.sys ppal.exe
Delete directories:c:\Documents and Settings\All Users\Application Data\117fc
c:\Documents and Settings\All Users\Application Data\117fc\Quarantine Items
c:\Documents and Settings\All Users\Application Data\117fc\WINAGSys
c:\Documents and Settings\All Users\Application Data\WINAGSys
%UserProfile%\Application Data\Additional Guard
Post Comment: