Type: Rogue Anti-Spyware
Malware Author: CoreGuard
Threat Level: Critical
Screenshot:

How to remove Dr. Guard manually:
It's possible to remove Dr. Guard manually, but you have to be very experienced in dealing with registry entries, program files and .dll files.
The files to be deleted:
%Documents and Settings%\[UserName]\Desktop\Dr. Guard Support.lnk
%Documents and Settings%\[UserName]\Desktop\Dr. Guard.lnk
%Documents and Settings%\[UserName]\Start Menu\Programs\Dr. Guard
%Documents and Settings%\[UserName]\Start Menu\Programs\Dr. Guard\About.lnk
%Documents and Settings%\[UserName]\Start Menu\Programs\Dr. Guard\Activate.lnk
%Documents and Settings%\[UserName]\Start Menu\Programs\Dr. Guard\Buy.lnk
%Documents and Settings%\[UserName]\Start Menu\Programs\Dr. Guard\Dr. Guard Support.lnk
%Documents and Settings%\[UserName]\Start Menu\Programs\Dr. Guard\Dr. Guard.lnk
%Documents and Settings%\[UserName]\Start Menu\Programs\Dr. Guard\Scan.lnk
%Documents and Settings%\[UserName]\Start Menu\Programs\Dr. Guard\Settings.lnk
%Documents and Settings%\[UserName]\Start Menu\Programs\Dr. Guard\Update.lnk
%Documents and Settings%\[UserName]\Application Data\Microsoft\Internet Explorer\Quick Launch\Dr. Guard.lnk
%Program Files%\Dr. Guard
%Program Files%\Dr. Guard\about.ico
%Program Files%\Dr. Guard\activate.ico
%Program Files%\Dr. Guard\buy.ico
%Program Files%\Dr. Guard\drg.db
%Program Files%\Dr. Guard\drgext.dll
%Program Files%\Dr. Guard\drghook.dll
%Program Files%\Dr. Guard\drguard.exe
%Program Files%\Dr. Guard\help.ico
%Program Files%\Dr. Guard\scan.ico
%Program Files%\Dr. Guard\settings.ico
%Program Files%\Dr. Guard\splash.mp3
%Program Files%\Dr. Guard\uninstall.exe
%Program Files%\Dr. Guard\update.ico
%Program Files%\Dr. Guard\virus.mp3
%Temp%\asr64_ldm.exe
Remove registry entries:
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\SimpleShlExt
HKEY_CLASSES_ROOT\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}
HKEY_CLASSES_ROOT\Folder\shellex\ContextMenuHandlers\SimpleShlExt
HKEY_LOCAL_MACHINE\SOFTWARE\Dr. Guard
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Dr. Guard
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Dr. Guard”
HKEY_CLASSES_ROOT\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved “{5E2121EE-0300-11D4-8D3B-444553540000}”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = “1″
Please be careful because manual removal of Dr. Guard may seriously damage operational system and sensitive data. Also there is a big possibility of incomplete removal, because some files could be hidden and program could re-install itself after you delete files and registry entries. So we strongly recommend you to use automatical removal tool.
No comments:
Post a Comment