How to remove Av-guru.net hijacker

Malware Description:
What’s particular about Av-guru.net is the fact that it appears to be one of the multiple domains involved in promotion of scareware. Actually, it’s quite safe to visit Av-guru.net through typing its URL in your browser address field; if you do you can see that it’s about Antivirus Soft which is stated to be a really useful tool for one’s computer protection. Even the slogan “Protecting every second” implies that Antivirus Soft is safe and reliable. But that’s just the first impression which can often turn out misleading. The software being pimped on Av-guru.net is in fact rogue anti-spyware which targets workstations to eventually make people pay some money. This website under analysis turns into a real bug if you go there resulting from a browser redirect implemented by Antivirus Soft after it infiltrates your computer. In that case, you are very unlikely to be able to surf the Internet in a regular unhampered way. A random site you will try to go to will be automatically replaced by Av-guru.net. By the way, a certain URL extension of Av-guru.net may bring you to a bogus alert page which is shown on screenshot 2 below. The overwhelming idea of Av-guru.net and sibling insecure domains is to artificially generate traffic to online pages that distribute the paid commercial version of Antivirus Soft. So first, this rogueware scares you to make you start thinking something is amiss. Then, it’s Av-guru.net’s turn to make the finishing strokes and tell you that Antivirus Soft is the right tool for you to use for spyware defense (which is beyond doubt a deceitful statement). So if you get forcibly navigated to Av-guru.net it means you have some trojans on board. Resolving this issue is possible through a system cleanup procedure which will eliminate all threats that could potentially be causing this disgusting browser activity.

Malware Type: Browser Hijackers

Malware Author: Antivirus Soft, Inc.

Threat Level: Critical

Advice: Immediately remove and scan for additional malware

Av-guru.net Hijacker Free Scanner and Remover: Download Now

Av-guru.net Screenshot:

Av-guru.net

Antivirus Soft Fake Online Warning Screenshot:

Antivirus Soft Fake Online Warning

How to remove Av-guru.net hijacker and affiliated threats manually:
Manual removal of Av-guru.net hijacker is a feasible objective if you have sufficient expertise in dealing with program files, processes, .dll files and registry entries.

The files to be deleted are listed below:

  • %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string]sysguard.exe

The registry entries that need to be removed are as follows:

  • HKEY_CURRENT_USER\Software\AvScan
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “RunInvalidSignatures” = “1″
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyOverride” = “”
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyServer” = “http=127.0.0.1:5555″
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[random string]“
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “[random string]“

Please, be aware that manual removal of Av-guru.net hijacker is a cumbersome process and does not always ensure complete deletion of the malware, due to the fact that some files might be hidden or may get reanimated automatically afterwards. Moreover, manual interference of this kind may cause damage to the system. That’s why we strongly recommend automatic removal of Av-guru.net hijacker, which will save your time and enable avoiding any system malfunctions and guarantee the needed result.

Download Av-guru.net Hijacker Automatic Remover

Like This Article? Let Others Know!

Related Articles:

There are currently no similar articles.

Reader's Comments:

  1. harley |

    instead of sysguard.exe i found oolbsftav.exe . and in the registry was HKEY_CURRENT_USER\software\avsoft
    wasn’t able to find the “proxyoverride” or “proxyServer”= “http=127.0.0.1:5555″ or anything similar
    hopefully that helps someone else

  2. Hampton3268 |

    This was a great tool. I found “avsoft” in the HKEY_CURRENT_USER/Software folder as well, with many entries. AFTER copying the registry to a server location to have the option to restore if necessary, I deleted the entire “avsoft” folder.

    I found all other HKEY’s you listed in the registry as well, except “proxyOverride = “”. I deleted them all.

    That stopped the popups and internet redirects (fake porn websites, etc.)completely and allowed access back to .exe programs, TaskManager, etc.

    It also enabled removal of the check box for proxy server in IE (Internet Options, Connections, LAN Settings) to get the browser settings back to normal.

    Finally, doing that allowed Anti-Malware software to update and run. The scan found and checked 3 additional files that I allowed it to remove:
    c:\Documents and Settings\”current logged on user name”\Local Settings\Time\Isuamd.exe
    c:\Documents and Settings\”current logged on user name”\Local Settings\Temp\pnth.exe
    HKEY-LOCAL-MACHINE\SOFTWARE\avsoft.

    After 3 days of searching for the right tool, I’m glad I found this one. Thanks and I hope this helps someone else too.

Post a Comment: