Trouble removing "Additional Guard" Rogue Software
Posted on 2009-12-17
I've been working on this XP Pro SP3 computer for an entire day! It has the Additional Guard rogue software on it.
It stopped the antivirus and Task Manager from working and browser hijacked to bogus sites.
I've run Malwarebytes AntiMalware, Smitfraudfix, SDFix. Removed over 700 infections. Still have it. Tried manual removal in safe mode using instructions found at various web sites - deleted specified registry keys, named files, tried to unreg the .dlls as instructed. This got the computer at least usable but Additional Guard is still running! And when I browse to Google.com it's a Netherlands home page!
Now I can access Task Manager but none of the processes match what is listed on the web. I used Process Explorer as well.
Anyone have any firsthand experience with this bug? I'm out of ideas at this point and the client can't run her business without the computer...