What is Additional Guard

Additional Guard is a rogue software. A rogue software application designed to trick users into buying a fake product by using scare tactics. It will bombard you with pop ups in order to try and scam you out of money. This infection can come into after fake video codec installation/adult sites that usually comes with malware.

Aliases : Additional Guard, AdditionalGuard Virus
Infection Type : Rogue Software
Risk Level : Dangerous
System Affected : Windows Operating Systems

Download Removal Utility for Additional Guard

General Symptoms

  • Displays fake warning messages and “Safety Center Alert ” popups alerts.
  • Flashing icons appear on your system tray (Near of your system clock).
  • Hijacked homepage to unknown webpage.

Image of Additional Guard

Image of Additional Guard

Manual Removal of Additional Guard

Important

If you are unable to run our software in normal mode then please start your computer in SAFE MODE and then run our suggested software to remove the Additional Guard Virus.

Kill Spyware Processes ( Help )
WI339.exe

Get rid of Files and Folder ( Help )
C:\Documents and Settings\All Users\Application Data\117fc
C:\Documents and Settings\All Users\Application Data\117fc\WI339.exe
C:\Documents and Settings\All Users\Application Data\117fc\WINAG.ico
C:\Documents and Settings\All Users\Application Data\117fc\2414.mof
C:\Documents and Settings\All Users\Application Data\117fc\mozcrt19.dll
C:\Documents and Settings\All Users\Application Data\117fc\sqlite3.dll
C:\Documents and Settings\All Users\Application Data\117fc\Quarantine Items
C:\Documents and Settings\All Users\Application Data\117fc\WINAGSys
C:\Documents and Settings\All Users\Application Data\117fc\WINAGSys\vd952342.bd
C:\Documents and Settings\All Users\Application Data\WINAGSys
C:\Documents and Settings\All Users\Application Data\WINAGSys\winag.cfg

%UserProfile%\Application Data\Additional Guard
%UserProfile%\Application Data\Additional Guard\cookies.sqlite
%UserProfile%\Application Data\Additional Guard\Instructions.ini
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Additional Guard.lnk
%UserProfile%\Desktop\Additional Guard.lnk
%UserProfile%\Start Menu\Additional Guard.lnk
%UserProfile%\Start Menu\Programs\Additional Guard.lnk

C:\Program Files\Mozilla Firefox\searchplugins\search.xml

%UserProfile%\Recent\ANTIGEN.drv
%UserProfile%\Recent\ANTIGEN.tmp
%UserProfile%\Recent\cid.dll
%UserProfile%\Recent\CLSV.tmp
%UserProfile%\Recent\ddv.dll
%UserProfile%\Recent\eb.drv
%UserProfile%\Recent\eb.exe
%UserProfile%\Recent\energy.dll
%UserProfile%\Recent\energy.sys
%UserProfile%\Recent\exec.exe
%UserProfile%\Recent\exec.tmp
%UserProfile%\Recent\fan.drv
%UserProfile%\Recent\FS.drv
%UserProfile%\Recent\FS.exe
%UserProfile%\Recent\kernel32.drv
%UserProfile%\Recent\PE.sys
%UserProfile%\Recent\ppal.exe

Delete following folders ( Help )
Additional Guard,
WINAGSys

Delete Registry Values ( Help )

HKEY_CURRENT_USER\Software\3
HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
HKEY_CLASSES_ROOT\xp_e0ebf.DocHostUIHandler
HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes “URL” = “http://search-gala.com/?&uid=7&q={searchTerms}”
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “RunInvalidSignatures” = “1″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform “[xSP_2:117fc3395e69e29f71abba93a68c4181_7]”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform “99660903″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “Additional Guard”

 
Download Removal Utility for Additional Guard

 
Other Removal Source, Check Below Links