AntiSpyGuard

AntiSpyGuard is a fake anti-spyware and anti-virus application that will trick user to obtain the registered version by displaying fake results that can only be removed with the full version of the program. AntiSpyGuard will also display excessive pop-up alerts and warning messages stating that system is highly infected with various kinds of threat. AntiSpyGuard may enter the system by exploiting software and security vulnerabilities. It can be installed without user’s full knowledge of its fraudulent operation. AntiSpyGuard is considered as a virus that will disguise itself as security product.

Screen Shot Image:

Damage Level: Medium

Systems Affected: Windows 9x, 2000, XP, Windows Vista

Technical Details and Additional Information:

Malicious Files Added by AntiSpyGuard
%%UserProfile%\Cookies\syssp.exe
%UserProfile%\Local Settings\Temp\tmpFile1.exe
%UserProfile%\Local Settings\Temp\tmpFile1.tmp
%UserProfile%\Local Settings\Temp\tmpFile2.ini
%UserProfile%\Local Settings\Temp\tmpFile2.tmp
%ProgramFiles%\AntiSpyGuard 2007\AntiSpyGuard.exe
%ProgramFiles%\AntiSpyGuard 2007\asgengine.exe
%ProgramFiles%\AntiSpyGuard 2007\asgenglib.dll
%ProgramFiles%\AntiSpyGuard 2007\ASGServ.exe
%ProgramFiles%\AntiSpyGuard 2007\fres.ini
%ProgramFiles%\AntiSpyGuard 2007\pthreadVC2.dll
%ProgramFiles%\AntiSpyGuard 2007\scanlists\normalsys.scl
%ProgramFiles%\AntiSpyGuard 2007\scanlists\quicksys.scl
%ProgramFiles%\AntiSpyGuard 2007\scanlists\remove.scl
%ProgramFiles%\AntiSpyGuard 2007\startup.ini
%ProgramFiles%\AntiSpyGuard 2007\stat.ini
%ProgramFiles%\AntiSpyGuard 2007\UnInstall.exe
%ProgramFiles%\AntiSpyGuard 2007\vars.ini
%ProgramFiles%\AntiSpyGuard 2007\verinfo.ini
%System%\scaner.exe
%Windir%\svshost.exe

Associated Windows Registry Entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\”AntiSpyGuard” = “”C:\Program Files\AntiSpyGuard 2007\AntiSpyGuard.exe” -AUTORUN”
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Run\”AntiSpyGuard” = “”C:\Program Files\AntiSpyGuard 2007\AntiSpyGuard.exe” -AUTORUN”

AntiSpyGuard – Removal

Removing AntiSpyGuard Manually:
1. If using Windows ME or XP, System Restore must be disabled to prevent the threat from restoring itself. [Windows XP System Restore]
2. Update the virus definitions.
3. Reboot Windows in SafeMode [how to]
4. Run a full system scan and clean/delete all infected file(s)
5. Delete/Modify any values added to the registry. [how to edit registry]
6. Exit registry editor and restart Windows.

Anti-virus Tools

Manual removal provided on this page may or may not successfully remove AntiSpyGuard. To completely get rid of the virus and other malicious software that may have been installed, we suggest running these tools.

In order to completely remove AntiSpyGuard from a system, click here to download and run Malwarebytes Anti-Malware. Sometimes, Trojans will block the downloading and installation of MBAM. If this happens, download it from a clean PC and rename the executable file before executing on the infected machine.

Using Portable SuperAntiSpyware:
To thoroughly remove a virus, it is best to do a separate scan of another security program so that other infected files not detected by anti-virus application can be remove as well. Click here to download and run SAS Portable Scanner.

What to do next...