How to remove Security Guard

Thursday, March 18th, 2010 at 3:20 am
Home » Rogue Antispyware » Security Guard

Security Guard description

Security Guard is another rogue security program that may get into computers by downloading a fake multimedia coder/decoder from an unsecured websites. The parasite declares you need it for cleaning your computer which is infected. Security Guard stays unnoticed and user have no idea about its existence.

Malware has an ability begin its fake scans as the computer is started. Once the trojan is released bogus system masquerades and tries to trick user into thinking they need to purchase supposedly legitimate security tool. It shows numerous fraudulent pop-ups at your desktop. It is fully safe to ignore all the warnings. What is needed to do is to use reputable security tool and delete the parasite as soon as possible.

Security Guard is a Rogue Antispyware software

How to manually remove Security Guard

To remove Security Guard spyware you must block Security Guard sites, stop and remove processes, unregister DLL files, search and delete all other Security Guard files and registry utility. Follow the Security Guard detection and removal instructions below.

The most typical software removal method is to remove Security Guard by using "Add or Remove Programs" service. However there may be hidden Security Guard files, running processes and registries in your computer, so Security Guard may recreate all other files after reboot.

Security Guard manual removal instructions

Stop and remove Security Guard processes:
cb.exe
energy.exe
exec.exe
grid.exe
kernel32.exe
SICKBOY.exe
SG345d.exe
Read more how to kill Security Guard processes

Locate and delete Security Guard registry entries:
HKEY_CURRENT_USER\Software\64
HKEY_CLASSES_ROOT\SG345d.DocHostUIHandler
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes “URL” = “ht tp://findgala.com/?&uid=1002&q={searchTerms}”
HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes “URL” = “ht tp://findgala.com/?&uid=1002&q={searchTerms}”
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer “PRS” = “http://127.0.0.1:27777/?inj=%ORIGINAL%”
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “RunInvalidSignatures” = “1″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform “layout/2.01002″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Security Guard”
HKEY_CLASSES_ROOT\Software\Microsoft\Internet Explorer\SearchScopes “URL” = “ht tp://findgala.com/?&uid=1002&q={searchTerms}”
Read more how to delete Security Guard registry entries
Download RegistryBooster 2010 to scan errors caused by Security Guard

Search and unregister Security Guard DLL libraries:
cid.dll
eb.dll
mozcrt19.dll
sqlite3.dll
Read more how to unregister Security Guard DLL files

Detect and delete other Security Guard files:
%UserProfile%\Recent\ANTIGEN.sys
%UserProfile%\Recent\ANTIGEN.tmp
%UserProfile%\Recent\cb.exe
%UserProfile%\Recent\cid.dll
%UserProfile%\Recent\ddv.sys
%UserProfile%\Recent\eb.dll
%UserProfile%\Recent\eb.drv
%UserProfile%\Recent\energy.exe
%UserProfile%\Recent\exec.exe
%UserProfile%\Recent\exec.tmp
%UserProfile%\Recent\fan.drv
%UserProfile%\Recent\fix.tmp
%UserProfile%\Recent\grid.exe
%UserProfile%\Recent\kernel32.exe
%UserProfile%\Recent\runddlkey.drv
%UserProfile%\Recent\SICKBOY.exe
%UserProfile%\Recent\tempdoc.tmp
c:\Documents and Settings\All Users\Application Data\123f678
c:\Documents and Settings\All Users\Application Data\123f678\24.mof
c:\Documents and Settings\All Users\Application Data\123f678\mozcrt19.dll
c:\Documents and Settings\All Users\Application Data\123f678\SG345d.exe
c:\Documents and Settings\All Users\Application Data\123f678\SGD.ico
c:\Documents and Settings\All Users\Application Data\123f678\sqlite3.dll
c:\Documents and Settings\All Users\Application Data\123f678\BackUp\
c:\Documents and Settings\All Users\Application Data\123f678\Quarantine Items\
c:\Documents and Settings\All Users\Application Data\123f678\SGDSys\
c:\Documents and Settings\All Users\Application Data\123f678\SGDSys\vd952342.bd
c:\Documents and Settings\All Users\Application Data\SGZIQYEXRD
c:\Documents and Settings\All Users\Application Data\SGZIQYEXRD\SGWNLED.cfg

We strongly recommend you to use spyware remover to track Security Guard and automaticaly remove Security Guard processes, registries and files as well as other spyware threats.

Download does not start? Try a mirror download here

Tags: ,

One Response to

Security Guard

Trackbacks

Leave a Reply

Download does not start? Try a mirror download here