Monday, October 17, 2011

AV Guard Online Virus - Removal Guide

AV Guard Online is a rogue antivirus program from the same family who created Open Cloud Security software. These rogue products are being distributed all over the net via various channels and there is no end in sight. Both products look exactly same and try to cheat naive consumers by showing fake infection alerts.

The main channel of distributing such rogue products is hacked websites. If you visit a good website which is in control of hackers on that particular time, your computer can get infected silently provided your computer's security is vulnerable. Rogue products like AV Guard online enters in a disguised way into your computer. For example, you visit a site and you are asked to download a flash update. You'll download that update and install it in your computer not knowing that you are installing AV guard Online virus yourself.

AV Guard online will enter silently and then start bugging you with false infection reports. It will produce forged infection reports and tell you that your system is in danger and Av Guard Online can help you remove all the infections. You'll be asked to purchase full version of AV Guard online which is useless and can't help you with anything. Here is a scree nshot of AV Guard Online doing a fake scan :


Another screen shot showing false infection warning and urging you to get full version of AV Guard Online virus :

Don't trust any screenshots of pop-ups shown by AV Guard Online. These alerts are pre-programmed and real state of your computer is totally different. There is no virus in your computer except AV Guard Online itself. Read the removal guide below to learn how to clear this infection completely.

How to Remove AV Guard Online

AV Guard Online tend to block legitimate applications and this makes its removal very hard. When this rogue won't let you run any software on your computer, how will you remove it?

After doing an extensive study on this rogue, we recommend these removal methods to remove av guard on-line easily and quickly :

1. Automatic Removal Method

We highly recommend this method for complete av guard online removal. Security companies are working relentlessly to release new remedies for new threats and you can take advantage of their efforts. All you need to do is, use a genuine Spyware Remover and clear the infections.

In our research lab, we used Spyware Doctor against AV Guard online and It worked perfectly. Complete removal of the rogue software hardly took 30 minutes and this time includes installing and updating the software. You need to follow all these steps in "Safe Mode With Networking' mode. To enter into this mode, continue pressing "F8" key when your computer boots up. Next steps that you need to follow :-

A) First of all, you need to download Spyware Doctor by clicking the button below. Spyware Doctor is a very powerful software and It can deal with such fake products very easily.

After downloading Spyware Doctor, install it in your machine and update its virus database. Now click on "Scan" button and do a full scan of your computer.

Spyware Doctor will examine each and every file on your computer and since its virus database contains full information about AV Guard On-line virus, all the files related to this malware will get caught. Once the scanning is done, click "Fix Checked" button and you are done.

Automatic removal method guarantees full deletion of rogue software and you don't need to waste your time on other methods which don't work.

2. Manual Removal Method.

Manual removal of AV Guard Online is only meant for advanced computer users who have very good knowledge of Windows Operating System. If you follow manual removal method, you need to find infected files yourself as well as clear up the registry. If you have not done such things before, then you should not try your hands on manual removal steps.

At best, you will not be able to remove the rogue and at worst, your computer may stop booting up completely If you delete a system file from your computer.

Please follow these steps at your own risk :

1. Reboot your computer and when computer reboots, repeatedly press "F8" key on your keyboard. This will show a menu. Use up and down arrow keys to select "Safe Mode with Networking" and press enter.

2. AV Guard Online will not bug you in this mode. Find and delete these infected files from your computer :

C:\WINDOWS\system32\[SET OF RANDOM CHARACTERS].exe
C:\Documents and Settings\[UserName]\Application Data\conhost.exe
C:\Documents and Settings\[UserName]\Application Data\csrss.exe
C:\Documents and Settings\[UserName]\Application Data\[SET OF RANDOM CHARACTERS].1B6
C:\Documents and Settings\[UserName]\Application Data\ldr.ini
C:\Documents and Settings\[UserName]\Application Data\zA0uvS2ib3m5Q6EAV Guard Online.ico
C:\Documents and Settings\[UserName]\Application Data\Microsoft\csrss.exe
C:\Documents and Settings\[UserName]\Desktop\AV Guard Online.lnk
C:\Documents and Settings\[UserName]\Local Settings\Temp\[SET OF RANDOM CHARACTERS].tmp
C:\Documents and Settings\[UserName]\Local Settings\Temp\[SET OF RANDOM CHARACTERS].tmp
C:\Documents and Settings\[UserName]\Start Menu\Programs\AV Guard Online\AV Guard Online.lnk

Please note that the rogue software creates random filenames and it is going to be very hard to identify the suspicious files.

3. Once you are done deleting the infected files, open Registry Editor and delete/correct these registry entries :

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ""

Now reboot your computer in Normal mode and see If you've gotten rid of the virus. If the problem still persists, follow automatic removal steps instead. We don't recommend manual removal method for anyone as automatic removal method is extremely effective and works all the time. Manual removal method is not really worth the risk.


No comments:

Post a Comment