Feb 28

Threat Description:

Dr. Guard (aka Dr.Guard) is a program that uses questionable practices for achieving its very fraudulent goals. Dr. Guard refers to the exact same group of malicious tools as Paladin Antivirus which has been one of the primary concern issues within the antimalware community during this month. The rogue antivirus software which is the subject of this article enters a computer without having to ask for your permission. It takes advantage of social engineering and can as well disguise itself as some program you might need. Anyway, we are driving at the point that Dr. Guard is unlikely to be prevented from infiltrating your system – it’ll probably prove to be just a bit too sophisticated and stealthy for your system defense. After this unhampered trespassing, Dr. Guard adjusts your system to perceive it as good and helpful software. It drops some files onto your system and changes Windows Registry. After that, you will keep receiving popup ads from Dr. Guard and its fake security scanners to try and convince you that it aims to help. This scam tool will be sure to tell you that it has allegedly intercepted multiple risks on your PC that must be eliminated. In order to remove those threats, you will be prompted to install and register Dr. Guard full version. Do not believe those fairy tales from Dr. Guard rogue anti-spyware. It’s trying to rip you off. So the most judicious way to go about the program being analyzed is to remove it without delay.

Determine if your system is infected with Dr. Guard and related threats:

Dr. Guard screenshot:

Dr. Guard

How to remove this threat manually:

Dr. Guard manual uninstall procedure:

Get rid of the related corrupt files:

  • %Documents and Settings%\[UserName]\Desktop\Dr. Guard Support.lnk
  • %Documents and Settings%\[UserName]\Desktop\Dr. Guard.lnk
  • %Documents and Settings%\[UserName]\Start Menu\Programs\Dr. Guard
  • %Documents and Settings%\[UserName]\Start Menu\Programs\Dr. Guard\About.lnk
  • %Documents and Settings%\[UserName]\Start Menu\Programs\Dr. Guard\Activate.lnk
  • %Documents and Settings%\[UserName]\Start Menu\Programs\Dr. Guard\Buy.lnk
  • %Documents and Settings%\[UserName]\Start Menu\Programs\Dr. Guard\Scan.lnk
  • %Documents and Settings%\[UserName]\Start Menu\Programs\Dr. Guard\Settings.lnk
  • %Documents and Settings%\[UserName]\Start Menu\Programs\Dr. Guard\Update.lnk
  • %Documents and Settings%\[UserName]\Application Data\Microsoft\Internet Explorer\Quick Launch\Dr. Guard.lnk
  • %Program Files%\Dr. Guard
  • %Program Files%\Dr. Guard\about.ico
  • %Program Files%\Dr. Guard\activate.ico
  • %Program Files%\Dr. Guard\buy.ico
  • %Program Files%\Dr. Guard\drg.db
  • %Program Files%\Dr. Guard\drgext.dll
  • %Program Files%\Dr. Guard\drghook.dll
  • %Program Files%\Dr. Guard\drguard.exe
  • %Program Files%\Dr. Guard\help.ico
  • %Program Files%\Dr. Guard\scan.ico
  • %Program Files%\Dr. Guard\settings.ico
  • %Program Files%\Dr. Guard\splash.mp3
  • %Program Files%\Dr. Guard\uninstall.exe
  • %Program Files%\Dr. Guard\update.ico
  • %Program Files%\Dr. Guard\virus.mp3
  • %Temp%\asr64_ldm.exe

Delete the associated registry entries:

  • HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\SimpleShlExt
  • HKEY_CLASSES_ROOT\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}
  • HKEY_CLASSES_ROOT\Folder\shellex\ContextMenuHandlers\SimpleShlExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Dr. Guard
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Dr. Guard
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr”
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Dr. Guard”
  • HKEY_CLASSES_ROOT\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved “{5E2121EE-0300-11D4-8D3B-444553540000}”
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = “1″

Please note that Dr. Guard manual removal is a procedure of high complexity and should be performed with extreme caution. Lack of the required skills and even the slightest deviation from the instructions may cause irreparable system damage. To ensure trouble-free deletion, it is recommended to use the automatic removal tool below:

Download Dr. Guard Removal Tool

Leave a Reply