AdditionalGuard Removal Instructions
Rogue security applications such as AdditionalGuard pretend to be added security for your computer, but these kinds of programs are not created protect anything at all. Rather, they are designed to try to scare computer users into buying a shoddy software product by pretending to warn about the computer becoming infested with malware. AdditionalGuard actually provides no “additional guard” whatsoever.
This rogue security application will even go so far as to copy real security notifications that would be received from the Windows Security Center. It will also lie about the presence of malware and viruses in order to intimidate the computer user. Rather than providing security, AdditionalGuard is only in the business of trying to deceive and spook the computer user. Because of this, it is advisable to immediately remove the program from any computer.
Manual Removal Instructions: With the right skill set, some people will wish to try to remove AdditionalGuard manually. In order to accomplish this, the initial step is to kill these processes:
WI339.exe, exec.exe, FS.exe, ppal.exe
Type:
Rogue Security Application
Related file contents:
ppal.exe
PE.sys
kernel32.drv
FS.exe
FS.drv
fan.drv
exec.tmp
exec.exe
energy.sys
energy.dll
eb.exe
eb.drv
ddv.dll
CLSV.tmp
cid.dll
ANTIGEN.tmp
ANTIGEN.drv
search.xml
Additional Guard.lnk
Instructions.ini
cookies.sqlite
sqlite3.dll
mozcrt19.dll
2414.mof
WINAG.ico
WI339.exe
winag.cfg
vd952342.bd
Known As:
Additional Guard
Next, be sure to delete these registry values:
HKEY_CURRENT_USER\Software\3
HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
HKEY_CLASSES_ROOT\xp_e0ebf.DocHostUIHandler
HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes “URL” = “http://search-gala.com/?&uid=7&q={searchTerms}”
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “RunInvalidSignatures” = “1”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform “[xSP_2:117fc3395e69e29f71abba93a68c4181_7]”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform “99660903”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “Additional Guard”
Unregister these DLLs:
mozcrt19.dll
sqlite3.dll
cid.dll
ddv.dll
energy.dll
Do not overlook the deletion of these files:
WI339.exe, WINAG.ico, 2414.mof, mozcrt19.dll, sqlite3.dll, vd952342.bd, winag.cfg, cookies.sqlite, Instructions.ini, Additional Guard.lnk, search.xml, ANTIGEN.drv, ANTIGEN.tmp, cid.dll, CLSV.tmp, ddv.dll, eb.drv, eb.exe, energy.dll, energy.sys, exec.exe, exec.tmp, fan.drv, FS.drv, FS.exe, kernel32.drv PE.sys ppal.exe
Finally, delete these directories:
c:\Documents and Settings\All Users\Application Data\117fc
c:\Documents and Settings\All Users\Application Data\117fc\Quarantine Items
c:\Documents and Settings\All Users\Application Data\117fc\WINAGSys
c:\Documents and Settings\All Users\Application Data\WINAGSys
%UserProfile%\Application Data\Additional Guard
It is important to note that while manual removal can remove AdditionalGuard, this will not guarantee freedom from other problems or malware. It also does nothing to prevent reinfection with AdditionalGuard. There are definite benefits to selecting an antispyware program to manage the removal of all of these kinds of security issues. Blue Penguin software company’s excellent antispyware product called SpyZooka offers guaranteed service against all of these kinds of malware, as well as security against developing threats in the immediate future.
I have no idea how this virus came into my computer, but I receive pop-ups like crazy.. I receive warnings about AdditionalGuard virus, but my anti-virus is not able to delete it. I’m happy that I found this site and it made it’s job. Thanks for the help!
I spent a few months looking for a good anti-spyware software. After all the ones I looked at, I could not find one that worked as well as SpyZooka did. It is fast and if there is a problem, it will find it.