FrEn

E-mail Print PDF

Free malware removal tool to remove Vista Guardian 2010

Written by Administrator  |  Monday, 01 February 2010 18:48
AddThis Social Bookmark Button
Vista Guardian 2010 is a rogue antispyware that may reprensent security risk for your system, it's a malware that pretends to be an Antivirus. It is a wolf in sheep's clothing. It conducts a fake scan of your system; you are warned by a fake alarm that there are more malwares on your system. It’s true indeed, there is really a malware in your system but I think the only malware on your system is Vista Guardian 2010. It invites you to purchase a license to remove malware, do not, it's a scam, you need a license for a malware? This so-called Antivirus tries to scam you. Uninstall Vista Guardian 2010 immediately from your system.

Vista Guardian 2010

To remove Vista Guardian 2010 (Uninstall Vista Guardian 2010)

  • Download this free removal tool for Vista Guardian 2010
  • Extract it
  • Launch
  • Click on the delete button

Vista Guardian 2010 will be removed from your system in 10s. Restart your computer when it’s finished.

This removal tool for Vista Guardian 2010 works also for

  • Antivirus XP 2010
  • Antivirus Vista 2010
  • Antivirus Win 7 2010
  • XP Antivirus Pro
  • XP AntiSpyware 2010
  • XP Internet Security
  • XP Internet Security 2010
  • XP Guardian
  • Vista Antispyware 2010
  • Vista Guardian
  • Vista Antivirus Pro
  • Vista Internet Security
  • Vista Internet Security 2010
  • Win 7 Antivirus Pro
  • Win 7 Antispyware 2010
  • Win 7 Internet Security
  • Win 7 Internet Security 2010
  • Win 7 Guardian

Processes :

  • av.exe

Files :

  • %AppData%\av.exe
  • %AppData%\[random]
  • %Temp%\[random].dll

Registry

Registry keys created

  • HKEY_CURRENT_USER\Software\Classes\.exe
  • HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\open
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\start
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\start\command
  • HKEY_CURRENT_USER\Software\Classes\secfile
  • HKEY_CURRENT_USER\Software\Classes\secfile\DefaultIcon
  • HKEY_CURRENT_USER\Software\Classes\secfile\shell
  • HKEY_CURRENT_USER\Software\Classes\secfile\shell\open
  • HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command
  • HKEY_CURRENT_USER\Software\Classes\secfile\shell\runas
  • HKEY_CURRENT_USER\Software\Classes\secfile\shell\runas\command
  • HKEY_CURRENT_USER\Software\Classes\secfile\shell\start
  • HKEY_CURRENT_USER\Software\Classes\secfile\shell\start\command

Registry values created

  • HKEY_CURRENT_USER\Software\Microsoft\Windows
    • Identity = 0x5B2C8CF8
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command
    • (Default) = ""%AppData%\av.exe" /START "%1" %*"
    • IsolatedCommand = ""%1" %*"
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command
    • (Default) = ""%1" %*"
    • IsolatedCommand = ""%1" %*"
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\start\command
    • (Default) = ""%1" %*"
    • IsolatedCommand = ""%1" %*"
  • HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon
    • (Default) = "%1"
  • HKEY_CURRENT_USER\Software\Classes\.exe
    • (Default) = "secfile"
    • Content Type = "application/x-msdownload"
  • HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command
    • (Default) = ""%AppData%\av.exe" /START "%1" %*"
    • IsolatedCommand = ""%1" %*"
  • HKEY_CURRENT_USER\Software\Classes\secfile\shell\runas\command
    • (Default) = ""%1" %*"
    • IsolatedCommand = ""%1" %*"
  • HKEY_CURRENT_USER\Software\Classes\secfile\shell\start\command
    • (Default) = ""%1" %*"
    • IsolatedCommand = ""%1" %*"
  • HKEY_CURRENT_USER\Software\Classes\secfile\DefaultIcon
    • (Default) = "%1"
  • HKEY_CURRENT_USER\Software\Classes\secfile
    • (Default) = "Application"
    • Content Type = "application/x-msdownload"

Registry values changed

  • HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
    • (Default) =
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center
    • AntiVirusOverride =
    • FirewallOverride =

Download

 

 

Comments  

 
0 #10 Jordale Brewster 2010-03-10 10:01
U GUYS............ YOU GUYS ARE FUKIN GENIUS'S........... IM GONNA PASTE THIS EVERYWHERE. THANX!!!!!!!!!! !!!!!!!!!!!!!!! !!!!!!!!!!!!!!! !!!!!!!!!!!!!!! !!!!!!!!!!!!!!! !!!!!!!!!!!!!!! !!!!!!!!!!!!!!! !1
Quote
 
 
0 #9 mareeyum 2010-03-08 19:28
this works
thank you
Quote
 
 
0 #8 Barry 2010-03-07 20:17
Hi

My bad, I'd run it again as Administrator and it worked a treat. Big thumbs up!!

Baz
Quote
 
 
0 #7 Barry 2010-03-07 20:09
Hi

I tried this removal tool. Why I tried running it I got a message saying, Failed to set data for'CheckValue'
Anyone any ideas?
Quote
 
 
+1 #6 Chelsea 2010-03-06 01:43
It seems to have worked so far! Thanks sooo much
Quote
 
 
0 #5 sandy 2010-03-02 01:42
This is worked great on windows vista 64 bit to remove Vista Guardian

Thanks so much
Quote
 
 
0 #4 amna 2010-03-01 16:49
This has really workedd
thank youu soo much x
Quote
 
 
0 #3 April 2010-02-18 02:57
How do you know FOR SURE that the virus was deleted???
Quote
 
 
0 #2 ILIANA 2010-02-02 20:55
LET ME SEE IF THIS WORK ITS OK BUT I HOPE THIS WORKS TNX
Quote
 
 
+1 #1 thx 2010-02-02 01:22
many thx
Quote
 

Add comment


Security code
Refresh

Related articles
Latest posts
Free malware removal tool to remove Dr. Guard
_WRITTEN_BY Administrator 01/03/2010
Dr. Guard is a rogue Antispyware from the Paladin Antivirus Family, it's a malware that pretends to be an Antivirus. It is a wolf in sheep's clothing. It conducts a fake scan of your system; you are…Read more...
Free malware removal tool to remove Paladin Antivirus
_WRITTEN_BY Administrator 27/02/2010
Paladin Antivirus is a rogue Antispyware, a scareware, it's a malware that pretends to be an Antivirus. It is a wolf in sheep's clothing. It conducts a fake scan of your system; you are warned by a…Read more...
Free malware removal tool to remove PC Defender
_WRITTEN_BY Administrator 24/02/2010
PC Defender is a rogue Antispyware, it's a malware that pretends to be an Antivirus. It is a wolf in sheep's clothing. It conducts a fake scan of your system; you are warned by a fake alarm that…Read more...
Free malware removal tool to remove Control Manager
_WRITTEN_BY Administrator 24/02/2010

Control Manager is another fake Antivirus that install itself on your computer. Once installed, it tries to trick you into buying a full version of the program, that doesn't even exist, because…Read more...

Free virus removal tool to remove Mal.Resdro-A
_WRITTEN_BY Administrator 24/02/2010

Resdro-A is a virus that may reprensent a security risk for your system. Mal/Resdro-A shows a Adobe Flash Player Update, ignore this, this is a fake warning.

Once on your system, this fake…Read more...

.
Information | Contact

© All Rights Reserved. net-studio.org 2009