How to remove PC Security Guardian
Tuesday, May 10th, 2011 at 5:44 amHome » Rogue Antispyware » PC Security Guardian
PC Security Guardian description
If PC Security Guardian loads warnings about problems on your PC, the only security problem you should worry about is PC Security Guardian itself. The program is a typical rogue anti-spyware.
PC Security Guardian is promoted via fraudulent websites but it can also be installed secretly by trojans. Once PCSecurityGuardian is installed, it reports numerous infections and then it offers purchasing the program for deleting the threats. Files reported by PC SecurityGuardian are either nonexistent or they belong to PC Security Guardian. The rogue program may also hijack web browser and redirect it to malicious websites. Do not trust the tool and remove it with no doubt.
PC Security Guardian is a Rogue Antispyware software
How to manually remove PC Security Guardian
To remove PC Security Guardian spyware you must block PC Security Guardian sites, stop and remove processes, unregister DLL files, search and delete all other PC Security Guardian files and registry utility. Follow the PC Security Guardian detection and removal instructions below.
The most typical software removal method is to remove PC Security Guardian by using "Add or Remove Programs" service. However there may be hidden PC Security Guardian files, running processes and registries in your computer, so PC Security Guardian may recreate all other files after reboot.
PC Security Guardian manual removal instructions
Stop and remove PC Security Guardian processes:
dudl.exe
[random characters]_[random numbers].exe
Read more how to kill PC Security Guardian processes
Locate and delete PC Security Guardian registry entries:
HKCU\Software\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\URL = "http://findgala.com/?&uid=289&q={searchTerms}"
HKCU\Software\Microsoft\Internet Explorer\Download\RunInvalidSignatures = "1"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\0 = "msseces.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\1 = "MSASCui.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\2 = "ekrn.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\3 = "egui.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\4 = "avgnt.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\5 = "avcenter.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\6 = "avscan.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\7 = "avgfrw.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\8 = "avgui.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\9 = "avgtray.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\10 = "avgscanx.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\11 = "avgcfgex.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\12 = "avgemc.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\13 = "avgchsvx.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\14 = "avgcmgr.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\15 = "avgwdsvc.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\PC Security Guardian = ""%AllUsersProfile%\[random]\[random characters]_[random numbers].exe" /s /d"
HKLM\SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
HKLM\SOFTWARE\Classes\PSc99_289.DocHostUIHandler
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\Debugger = "svchost.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\Debugger = "svchost.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE\Debugger = "svchost.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\Debugger = "svchost.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\Debugger = "svchost.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\Debugger = "svchost.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\Debugger = "svchost.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\Debugger = "svchost.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AluSchedulerSvc.exe\Debugger = "svchost.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Virus Professional.exe\Debugger = "svchost.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiVirus_Pro.exe\Debugger = "svchost.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntispywarXP2009.exe\Debugger = "svchost.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus\Debugger = "svchost.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus.exe\Debugger = "svchost.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPro_2010.exe\Debugger = "svchost.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PsImSvc.exe\Debugger = "svchost.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PskSvc.exe\Debugger = "svchost.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quick Heal.exe\Debugger = "svchost.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QuickHealCleaner.exe\Debugger = "svchost.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafetyKeeper.exe\Debugger = "svchost.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Save.exe\Debugger = "svchost.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveArmor.exe\Debugger = "svchost.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveDefense.exe\Debugger = "svchost.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveKeep.exe\Debugger = "svchost.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secure Veteran.exe\Debugger = "svchost.exe"
Read more how to delete PC Security Guardian registry entries
Download RegistryBooster 2010 to scan errors caused by PC Security Guardian
Search and unregister PC Security Guardian DLL libraries:
snl2w.dll
PE.dll
FW.dll
ANTIGEN.dll
Read more how to unregister PC Security Guardian DLL files
Detect and delete other PC Security Guardian files:
%AllUsersProfile%\PSRWKWWDAG\
%AllUsersProfile%\PSRWKWWDAG\PSYITOENDG.cfg
%AllUsersProfile%\[random]\
%AllUsersProfile%\[random]\2218.mof
%AllUsersProfile%\[random]\288416.reg
%AllUsersProfile%\[random]\PSG.ico
%AllUsersProfile%\[random]\PSGSys\
%AllUsersProfile%\[random]\[random characters]_[random numbers].exe
%AllUsersProfile%\[random]\Quarantine Items\
%AllUsersProfile%\[random]\mcp.ico
%AppData%\Microsoft\Internet Explorer\Quick Launch\PC Security Guardian.lnk
%AppData%\Microsoft\Windows\Recent\ANTIGEN.dll
%AppData%\Microsoft\Windows\Recent\CLSV.drv
%AppData%\Microsoft\Windows\Recent\CLSV.sys
%AppData%\Microsoft\Windows\Recent\FW.dll
%AppData%\Microsoft\Windows\Recent\PE.dll
%AppData%\Microsoft\Windows\Recent\PE.drv
%AppData%\Microsoft\Windows\Recent\PE.sys
%AppData%\Microsoft\Windows\Recent\SICKBOY.drv
%AppData%\Microsoft\Windows\Recent\energy.drv
%AppData%\Microsoft\Windows\Recent\dudl.exe
%AppData%\Microsoft\Windows\Recent\energy.sys
%AppData%\Microsoft\Windows\Recent\exec.sys
%AppData%\Microsoft\Windows\Recent\exec.tmp
%AppData%\Microsoft\Windows\Recent\fan.tmp
%AppData%\Microsoft\Windows\Recent\snl2w.dll
%AppData%\Microsoft\Windows\Recent\tempdoc.sys
%AppData%\Microsoft\Windows\Start Menu\Programs\PC Security Guardian.lnk
%AppData%\Microsoft\Windows\Start Menu\PC Security Guardian.lnk
%AppData%\PC Security Guardian\
%AppData%\PC Security Guardian\Instructions.ini
%AppData%\PC Security Guardian\cookies.sqlite
%UserProfile%\Desktop\PC Security Guardian.lnk
We strongly recommend you to use spyware remover to track PC Security Guardian and automaticaly remove PC Security Guardian processes, registries and files as well as other spyware threats.


