Welcome to remove-malware.net
The ultimate resource for malware removal and virus protection
How to remove Av-guru.net hijacker
Malware Description:
What’s particular about Av-guru.net is the fact that it appears to be one of the multiple domains involved in promotion of scareware. Actually, it’s quite safe to visit Av-guru.net through typing its URL in your browser address field; if you do you can see that it’s about Antivirus Soft which is stated to be a really useful tool for one’s computer protection. Even the slogan “Protecting every second” implies that Antivirus Soft is safe and reliable. But that’s just the first impression which can often turn out misleading. The software being pimped on Av-guru.net is in fact rogue anti-spyware which targets workstations to eventually make people pay some money. This website under analysis turns into a real bug if you go there resulting from a browser redirect implemented by Antivirus Soft after it infiltrates your computer. In that case, you are very unlikely to be able to surf the Internet in a regular unhampered way. A random site you will try to go to will be automatically replaced by Av-guru.net. By the way, a certain URL extension of Av-guru.net may bring you to a bogus alert page which is shown on screenshot 2 below. The overwhelming idea of Av-guru.net and sibling insecure domains is to artificially generate traffic to online pages that distribute the paid commercial version of Antivirus Soft. So first, this rogueware scares you to make you start thinking something is amiss. Then, it’s Av-guru.net’s turn to make the finishing strokes and tell you that Antivirus Soft is the right tool for you to use for spyware defense (which is beyond doubt a deceitful statement). So if you get forcibly navigated to Av-guru.net it means you have some trojans on board. Resolving this issue is possible through a system cleanup procedure which will eliminate all threats that could potentially be causing this disgusting browser activity.
Malware Type: Browser Hijackers
Malware Author: Antivirus Soft, Inc.
Threat Level: ![]()
![]()
![]()
![]()
Critical
Advice: Immediately remove and scan for additional malware
Av-guru.net Hijacker Free Scanner and Remover:
Download Now
Av-guru.net Screenshot:

Antivirus Soft Fake Online Warning Screenshot:

How to remove Av-guru.net hijacker and affiliated threats manually:
Manual removal of Av-guru.net hijacker is a feasible objective if you have sufficient expertise in dealing with program files, processes, .dll files and registry entries.
The files to be deleted are listed below:
- %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string]sysguard.exe
The registry entries that need to be removed are as follows:
- HKEY_CURRENT_USER\Software\AvScan
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “RunInvalidSignatures” = “1″
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyOverride” = “”
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyServer” = “http=127.0.0.1:5555″
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[random string]“
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “[random string]“
Please, be aware that manual removal of Av-guru.net hijacker is a cumbersome process and does not always ensure complete deletion of the malware, due to the fact that some files might be hidden or may get reanimated automatically afterwards. Moreover, manual interference of this kind may cause damage to the system. That’s why we strongly recommend automatic removal of Av-guru.net hijacker, which will save your time and enable avoiding any system malfunctions and guarantee the needed result.
| Download Av-guru.net Hijacker Automatic Remover |
Like This Article? Let Others Know!
Related Articles:
There are currently no similar articles.
Reader's Comments:
Post a Comment:
Page Info:
-
March 5, 2010 -
2 comments
-
Comments RSS
Make it social:
Latest Removal Guides
Types of Malware
- Adware (6)
- Browser Hijackers (731)
- Fake Security Programs (108)
- Mac Scareware (1)
- Ransomware (3)
- Rogue Anti-Spyware (721)
- Security Alerts (29)
- Spyware (2)
- Toolbars (4)
- Trojan Horses (92)
- Worms (31)

instead of sysguard.exe i found oolbsftav.exe . and in the registry was HKEY_CURRENT_USER\software\avsoft
wasn’t able to find the “proxyoverride” or “proxyServer”= “http=127.0.0.1:5555″ or anything similar
hopefully that helps someone else
This was a great tool. I found “avsoft” in the HKEY_CURRENT_USER/Software folder as well, with many entries. AFTER copying the registry to a server location to have the option to restore if necessary, I deleted the entire “avsoft” folder.
I found all other HKEY’s you listed in the registry as well, except “proxyOverride = “”. I deleted them all.
That stopped the popups and internet redirects (fake porn websites, etc.)completely and allowed access back to .exe programs, TaskManager, etc.
It also enabled removal of the check box for proxy server in IE (Internet Options, Connections, LAN Settings) to get the browser settings back to normal.
Finally, doing that allowed Anti-Malware software to update and run. The scan found and checked 3 additional files that I allowed it to remove:
c:\Documents and Settings\”current logged on user name”\Local Settings\Time\Isuamd.exe
c:\Documents and Settings\”current logged on user name”\Local Settings\Temp\pnth.exe
HKEY-LOCAL-MACHINE\SOFTWARE\avsoft.
After 3 days of searching for the right tool, I’m glad I found this one. Thanks and I hope this helps someone else too.