Mar 1, 2010

Remove Dr. Guard - Dr. Guard Removal Information

Dr. Guard is a badware that worms into your computer with the help of execrable files that are spread out from misleading Internet sources. All in all, once this infection is inside Dr. Guard will be installed and the system will be rebooted. The very first thing Dr. Guard is going to commit is to scan your system with the only purpose to detect as many infections as possible even though they do not exist inside your computer. This strategy is very active, though it is not brand new. Another feature that should be avoided is flooding trustless alerts that warn users about the threats that supposedly are perilous for the security of your machine. What is more, Dr. Guard is constructed the way it will use harsh techniques in order to protect itself from removing and detecting. For this reason, all legitimate security programs will be blocked or removed, and all access to security web sites would be denied. Without a doubt, you would notice anything illegal is going on your PC, until it is too late. What you have to memories is that Dr. Guard is the application that cannot be trusted and must be removed till the time it would be impossible to save your beloved machine from unpredictable destructions.


Type: Rogue Anti-Spyware
Malware Author: CoreGuard

Threat Level: Critical
Screenshot:


How to remove Dr. Guard manually:
It's possible to remove Dr. Guard manually, but you have to be very experienced in dealing with registry entries, program files and .dll files.

The files to be deleted:

%Documents and Settings%\[UserName]\Desktop\Dr. Guard Support.lnk
%Documents and Settings%\[UserName]\Desktop\Dr. Guard.lnk
%Documents and Settings%\[UserName]\Start Menu\Programs\Dr. Guard
%Documents and Settings%\[UserName]\Start Menu\Programs\Dr. Guard\About.lnk
%Documents and Settings%\[UserName]\Start Menu\Programs\Dr. Guard\Activate.lnk
%Documents and Settings%\[UserName]\Start Menu\Programs\Dr. Guard\Buy.lnk
%Documents and Settings%\[UserName]\Start Menu\Programs\Dr. Guard\Dr. Guard Support.lnk
%Documents and Settings%\[UserName]\Start Menu\Programs\Dr. Guard\Dr. Guard.lnk
%Documents and Settings%\[UserName]\Start Menu\Programs\Dr. Guard\Scan.lnk
%Documents and Settings%\[UserName]\Start Menu\Programs\Dr. Guard\Settings.lnk
%Documents and Settings%\[UserName]\Start Menu\Programs\Dr. Guard\Update.lnk
%Documents and Settings%\[UserName]\Application Data\Microsoft\Internet Explorer\Quick Launch\Dr. Guard.lnk
%Program Files%\Dr. Guard
%Program Files%\Dr. Guard\about.ico
%Program Files%\Dr. Guard\activate.ico
%Program Files%\Dr. Guard\buy.ico
%Program Files%\Dr. Guard\drg.db
%Program Files%\Dr. Guard\drgext.dll
%Program Files%\Dr. Guard\drghook.dll
%Program Files%\Dr. Guard\drguard.exe
%Program Files%\Dr. Guard\help.ico
%Program Files%\Dr. Guard\scan.ico
%Program Files%\Dr. Guard\settings.ico
%Program Files%\Dr. Guard\splash.mp3
%Program Files%\Dr. Guard\uninstall.exe
%Program Files%\Dr. Guard\update.ico
%Program Files%\Dr. Guard\virus.mp3
%Temp%\asr64_ldm.exe


Remove registry entries:

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\SimpleShlExt
HKEY_CLASSES_ROOT\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}
HKEY_CLASSES_ROOT\Folder\shellex\ContextMenuHandlers\SimpleShlExt
HKEY_LOCAL_MACHINE\SOFTWARE\Dr. Guard
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Dr. Guard
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Dr. Guard”
HKEY_CLASSES_ROOT\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved “{5E2121EE-0300-11D4-8D3B-444553540000}”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = “1″


Please be careful because manual removal of Dr. Guard may seriously damage operational system and sensitive data. Also there is a big possibility of incomplete removal, because some files could be hidden and program could re-install itself after you delete files and registry entries. So we strongly recommend you to use automatical removal tool.

No comments:

/