Title: VirusGuardPlus
Type: Malware

Remove VirusGuardPlus. Removal instructions


 
Also known as: Virus Guard Plus, VirusGuard Plus
Severity scale:VirusGuardPlus severity is 70  (70 / 100)
 
VirusGuardPlus is a duplicate of another rogue application named VirtualPCGuard. Infact it is just a makeover of the former parasite skin: Couple changes to design made to mask its rogue past. VirusGuardPlus downloads using security blind-spot‘s of browser. When Virtual Guard Plus activates it starts automatic online scan, which always show falsified reports. And these errors can only be deleted with „full“version of VirusGuard Plus, which is not existant at the moment. Messages like Virus Guard Plus popups and scan results should be ignored as paying for this program might result to credit card information falling to wrong hands.

You can do some serious harm by downloading this program. Additional trojans, rootkits and other unwanted applications can easily access a PC infected with VirusGuardPlus. Thus we strongly recomend uninstaling this program using our manual instructions or reputable anti-spyware solution. Also, we recomend avoiding websites promoting VirusGuardPlus.

Related files: threats.log, dhlp.sys, msxml3a.dll, msvcp71.dll, mfc71.dll, capicom.dll, atl71.dll, updater.dat, up.dat, UBupdater.dat, PGupdater.dat, gup.exe, ASupdater.dat, sbiebho.dll, pblock.dll, license.rtf, lapv.dat, ga6p.gif, cross.gif, UADAILY.DLL, UA27604.DLL, UA27603.DLL, UA27602.DLL, UA27601.DLL, UNPEPACK.DLL, UNPACKS2.DLL, UNPACKS.DLL, UNPACK.DLL, UNMIME.DLL, unamscan.dll, UNADBX.DLL, UNACPU.DLL, SCANWIN1.DLL, SCANTROJ.DLL, SCANTOOL.DLL, SCANSCR.DLL, SCANOTHR.DLL, SCANMCR1.DLL, SCANKRNL.DLL, SCANFUNC.DLL, SCANEMUL.DLL, SCANDOS1.DLL, SCANDLDR.DLL, SCANBCDR.DLL, SCANADWR.DLL, borlndmm.dll, enemies.dat, vbpv.dat, pv.dat, index.dat, incmp.dat, cd.dat, bnlink.dat, BkSites.dat, Activate.dat, pgs.xml, unins000.exe, unins000.dat, sqlite3.dll, settings.ini, scnkrnl.dll, ResErrors.log, reload.exe, ptask.exe, pgs.exe, main.log, history.db, FWSettings.bin, dhlp.dll, al.dat, activate.exe, ugac.exe, bm.exe

VirusGuardPlus properties:
• Changes browser settings
• Shows commercial adverts
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic VirusGuardPlus removal:

SpyHunter is recommended remover to uninstall VirusGuardPlus. You should confirm using free trial that it detects current version of parasite.

Note: Manual assistance required means that one or all of removers were unable to remove parasite without some manual intervention, please read manul removal instructions below.

If you failed to remove VirusGuardPlus using SpyHunter please report this to us.

We might be affiliated with any product we recommend on the site. Full disclosure in our Agreement of Use.
STOPzilla
We are testing STOPzilla's efficiency at removing VirusGuardPlus (2008-09-29 02:57:50)
Malwarebytes Anti Malware
We are testing Malwarebytes Anti Malware's efficiency at removing VirusGuardPlus (2008-09-29 02:57:50)
Spyware Doctor
We are testing Spyware Doctor's efficiency at removing VirusGuardPlus (2008-09-29 02:57:50)
XoftSpySE Anti Spyware

VirusGuardPlus manual removal:

Kill processes:
bm.exe ugac.exe Activate.exe pgs.exe ptask.exe reload.exe unins000.exe gup.exe
Delete registry values:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5C3F6257-3E00-45C2-88D5-CB0F3A17BF0E}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6F87F145-DC2D-4766-AF03-3A3B96FFAD98}
HKEY_CURRENT_USER\Software\Opera Software
HKEY_CURRENT_USER\Software\VirusGuardPlus
HKEY_CLASSES_ROOT\AppID\{EA7522F6-87CF-411e-8A55-19EE4344B676}
HKEY_CLASSES_ROOT\AppID\pblock.DLL
HKEY_CLASSES_ROOT\CLSID\{079AA557-4A18-424A-8EEE-E39F0A8D41B9}\TypeLib
HKEY_CLASSES_ROOT\CLSID\{3124C396-FB13-4836-A6AD-1317F1713688}\TypeLib
HKEY_CLASSES_ROOT\CLSID\{3D813DFE-6C91-4A4E-8F41-04346A841D9C}\TypeLib
HKEY_CLASSES_ROOT\CLSID\{3E784A01-F3AE-4DC0-9354-9526B9370EBA}\TypeLib
HKEY_CLASSES_ROOT\CLSID\{4DD441AD-526D-4A77-9F1B-9841ED802FB0}\TypeLib
HKEY_CLASSES_ROOT\CLSID\{5C3F6257-3E00-45c2-88D5-CB0F3A17BF0E}
HKEY_CLASSES_ROOT\CLSID\{6F87F145-DC2D-4766-AF03-3A3B96FFAD98}
HKEY_CLASSES_ROOT\Interface\{2933BF96-7B36-11D2-B20E-00C04F983E60}
HKEY_CLASSES_ROOT\Interface\{2B8DE2FE-8D2D-11d1-B2FC-00C04FD915A9}
HKEY_CLASSES_ROOT\Interface\{3EFAA428-272F-11D2-836F-0000F87A7782}
HKEY_CLASSES_ROOT\Interface\{3EFAA429-272F-11D2-836F-0000F87A7782}
HKEY_CLASSES_ROOT\Interface\{C90352F7-643C-4FBC-BB23-E996EB2D51FD}
HKEY_CLASSES_ROOT\PopupBlocker.IEGPB
HKEY_CLASSES_ROOT\PopupBlocker.IEGPB.1
HKEY_CLASSES_ROOT\SBIEBHO.IEFW
HKEY_CLASSES_ROOT\SBIEBHO.IEFW.2
HKEY_CLASSES_ROOT\TypeLib\{D761645B-6B20-4698-AEE8-729981152A82}
HKEY_CLASSES_ROOT\TypeLib\{EA7522F6-87CF-411E-8A55-19EE4344B676}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C3F6257-3E00-45C2-88D5-CB0F3A17BF0E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6F87F145-DC2D-4766-AF03-3A3B96FFAD98}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UAVUN_is1
HKEY_LOCAL_MACHINE\SOFTWARE\Products
HKEY_LOCAL_MACHINE\SOFTWARE\ugac
HKEY_LOCAL_MACHINE\SOFTWARE\VirusGuardPlus
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\dhlp
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dhlp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "UGA6P11 2.2.366.12"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "BMN"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "ugac"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "VirusGuardPlus"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce "overinstall"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls "C:\WINDOWS\system32\atl71.dll"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls "C:\WINDOWS\system32\capicom.dll"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls "C:\WINDOWS\system32\mfc71.dll"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls "C:\WINDOWS\system32\msvcp71.dll"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls "C:\WINDOWS\system32\msxml3.dll"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls "C:\WINDOWS\system32\msxml3a.dll"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls "C:\WINDOWS\system32\msxml3r.dll"
Unregister DLLs:
dhlp.dll scnkrnl.dll sqlite3.dll BORLNDMM.DLL SCANADWR.DLL SCANBCDR.DLL SCANDLDR.DLL SCANDOS1.DLL SCANEMUL.DLL SCANFUNC.DLL SCANKRNL.DLL SCANMCR1.DLL SCANOTHR.DLL SCANSCR.DLL SCANTOOL.DLL SCANTROJ.DLL SCANWIN1.DLL UNACPU.DLL UNADBX.DLL unamscan.dll UNMIME.DLL UNPACK.DLL UNPACKS.DLL UNPACKS2.DLL UNPEPACK.DLL UA27601.DLL UA27602.DLL UA27603.DLL UA27604.DLL UADAILY.DLL atl71.dll capicom.dll mfc71.dll msvcp71.dll msxml3a.dll

Delete files:
c:\\Program Files\\Common Files\\VirusGuardPlus\\bm.exe c:\\Program Files\\Common Files\\VirusGuardPlus\\ugac.exe c:\\Program Files\\VirusGuardPlus\\Activate.exe c:\\Program Files\\VirusGuardPlus\\al.dat c:\\Program Files\\VirusGuardPlus\\dhlp.dll c:\\Program Files\\VirusGuardPlus\\FWSettings.bin c:\\Program Files\\VirusGuardPlus\\history.db c:\\Program Files\\VirusGuardPlus\\main.log c:\\Program Files\\VirusGuardPlus\\pgs.exe c:\\Program Files\\VirusGuardPlus\\ptask.exe c:\\Program Files\\VirusGuardPlus\\reload.exe c:\\Program Files\\VirusGuardPlus\\ResErrors.log c:\\Program Files\\VirusGuardPlus\\scnkrnl.dll c:\\Program Files\\VirusGuardPlus\\settings.ini c:\\Program Files\\VirusGuardPlus\\sqlite3.dll c:\\Program Files\\VirusGuardPlus\\unins000.dat c:\\Program Files\\VirusGuardPlus\\unins000.exe c:\\Program Files\\VirusGuardPlus\\Config\\pgs.xml c:\\Program Files\\VirusGuardPlus\\Dat\\Activate.dat c:\\Program Files\\VirusGuardPlus\\Dat\\BkSites.dat c:\\Program Files\\VirusGuardPlus\\Dat\\bnlink.dat c:\\Program Files\\VirusGuardPlus\\Dat\\cd.dat c:\\Program Files\\VirusGuardPlus\\Dat\\incmp.dat c:\\Program Files\\VirusGuardPlus\\Dat\\index.dat c:\\Program Files\\VirusGuardPlus\\Dat\\pv.dat c:\\Program Files\\VirusGuardPlus\\Engines\\AWBase\\vbpv.dat c:\\Program Files\\VirusGuardPlus\\Engines\\AWBase\\database\\enemies.dat c:\\Program Files\\VirusGuardPlus\\Engines\\PGBase\\vbpv.dat c:\\Program Files\\VirusGuardPlus\\Engines\\plugins\\BORLNDMM.DLL c:\\Program Files\\VirusGuardPlus\\Engines\\plugins\\SCANADWR.DLL c:\\Program Files\\VirusGuardPlus\\Engines\\plugins\\SCANBCDR.DLL c:\\Program Files\\VirusGuardPlus\\Engines\\plugins\\SCANDLDR.DLL c:\\Program Files\\VirusGuardPlus\\Engines\\plugins\\SCANDOS1.DLL c:\\Program Files\\VirusGuardPlus\\Engines\\plugins\\SCANEMUL.DLL c:\\Program Files\\VirusGuardPlus\\Engines\\plugins\\SCANFUNC.DLL c:\\Program Files\\VirusGuardPlus\\Engines\\plugins\\SCANKRNL.DLL c:\\Program Files\\VirusGuardPlus\\Engines\\plugins\\SCANMCR1.DLL c:\\Program Files\\VirusGuardPlus\\Engines\\plugins\\SCANOTHR.DLL c:\\Program Files\\VirusGuardPlus\\Engines\\plugins\\SCANSCR.DLL c:\\Program Files\\VirusGuardPlus\\Engines\\plugins\\SCANTOOL.DLL c:\\Program Files\\VirusGuardPlus\\Engines\\plugins\\SCANTROJ.DLL c:\\Program Files\\VirusGuardPlus\\Engines\\plugins\\SCANWIN1.DLL c:\\Program Files\\VirusGuardPlus\\Engines\\plugins\\UNACPU.DLL c:\\Program Files\\VirusGuardPlus\\Engines\\plugins\\UNADBX.DLL c:\\Program Files\\VirusGuardPlus\\Engines\\plugins\\unamscan.dll c:\\Program Files\\VirusGuardPlus\\Engines\\plugins\\UNMIME.DLL c:\\Program Files\\VirusGuardPlus\\Engines\\plugins\\UNPACK.DLL c:\\Program Files\\VirusGuardPlus\\Engines\\plugins\\UNPACKS.DLL c:\\Program Files\\VirusGuardPlus\\Engines\\plugins\\UNPACKS2.DLL c:\\Program Files\\VirusGuardPlus\\Engines\\plugins\\UNPEPACK.DLL c:\\Program Files\\VirusGuardPlus\\Engines\\plugins\\vbpv.dat c:\\Program Files\\VirusGuardPlus\\Engines\\plugins\\UpDate\\UA27601.DLL c:\\Program Files\\VirusGuardPlus\\Engines\\plugins\\UpDate\\UA27602.DLL c:\\Program Files\\VirusGuardPlus\\Engines\\plugins\\UpDate\\UA27603.DLL c:\\Program Files\\VirusGuardPlus\\Engines\\plugins\\UpDate\\UA27604.DLL c:\\Program Files\\VirusGuardPlus\\Engines\\plugins\\UpDate\\UADAILY.DLL c:\\Program Files\\VirusGuardPlus\\Graphics\\cross.gif c:\\Program Files\\VirusGuardPlus\\Graphics\\ga6p.gif c:\\Program Files\\VirusGuardPlus\\LA\\lapv.dat c:\\Program Files\\VirusGuardPlus\\LA\\License.rtf c:\\Program Files\\VirusGuardPlus\\Tools\\pblock.dll c:\\Program Files\\VirusGuardPlus\\Tools\\sbiebho.dll c:\\Program Files\\VirusGuardPlus\\Up\\ASupdater.dat c:\\Program Files\\VirusGuardPlus\\Up\\gup.exe c:\\Program Files\\VirusGuardPlus\\Up\\PGupdater.dat c:\\Program Files\\VirusGuardPlus\\Up\\UBupdater.dat c:\\Program Files\\VirusGuardPlus\\Up\\up.dat c:\\Program Files\\VirusGuardPlus\\Up\\updater.dat c:\\WINDOWS\\system32\\atl71.dll c:\\WINDOWS\\system32\\capicom.dll c:\\WINDOWS\\system32\\mfc71.dll c:\\WINDOWS\\system32\\msvcp71.dll c:\\WINDOWS\\system32\\msxml3a.dll c:\\WINDOWS\\system32\\drivers\\dhlp.sys %UserProfile%\\Application Data\\VirusGuardPlus\\Logs\\threats.log
Information added: 2008-09-26 07:54:52
Information updated: 2008-09-29 00:20:35

Additional resources related to VirusGuardPlus:

Attention: If you know or you have a website or page about VirusGuardPlus removal, feel free to add a link to this list: add url

more resources

Post Comment:

Attention: Use this form only if you have additional information about VirusGuardPlus parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.
Home page Name



«


* All field required
Latest spyware news:
Subscribe to news

Similar parasites:
Compare spyware removers
Compare free products

HijackThis Log Analyzer Beta 2 HijackThis Log Analyzer Beta 2

I failed to remove VirusGuardPlus using SpyHunter.

Email


Close

Spreading the knowledge:

It is very hard to fight Computer parasites alone in internet space. If you have a website we would be more than happy if you would help us to spread the knowledge about latest threats. You can help your visitors to manage their Computer system manually without aditional expences. Knowledge is the power, we just need to spread it.
add text box
rss feed
help other