Severity scale  
  (86/100)

Fake Security AntiMalware Guard antiviruses for Win 7 XP or Vista. How to Remove? (Uninstall Guide)

removal by - -   | Type: Rogue Antispyware
12
Creators of rogue antispyware programs have designed a new malicious application that comes under 27 different names. The name of the infection depends on the Windows Operating system the computer runs. Here is a list of the program names that it can use once infecting computer system:

XP Antispyware 2011 or XP Antispyware
Vista Antispyware 2011 or Vista Antispyware
Win 7 Antispyware 2011 or Win 7 Antispyware
XP Security 2011 or XP Security
Vista Security 2011 or Vista Security
Win 7 Security 2011 or Win 7 Security
XP Internet Security 2011 or XP Internet Security
Vista Internet Security 2011 or Vista Internet Security
Win 7 Internet Security 2011 or Win 7 Internet Security
Win 7 Antimalware
XP Antimalware 2011 or XP Antimalware
Vista Antimalware 2011 or Vista Antimalware
Win 7 Antimalware 2011
XP Guard
Vista Guard
Win 7 Guard


The program is installed with a help of Trojan viruses that imitate being Windows updates and are downloaded automatically. Once inside the application is ready to do everything in order to make it impossible to remove it. It will disable most of your programs including your Internet browser and once you try to launch it you will see firewall warning instead of the requested website. Instead of launching any executable the program will launch Vista Antispyware 2011, XP Guard, Win 7 Internt Security 2011 or any other program that infected your computer.

Here is how some of the alerts look like:


Win 7 Internet Security 2011 Firewall Alert
XP Antispyware 2011 has blocked a program from accessing the internet
Internet Explorer is infected with Trojan-BNK.Win32.Keylogger.gen
Private data can be stolen by third parties, including credit card details and passwords.



System danger!
Your system security is in danger. Privacy threats detected. Spyware, keyloggers or Trojans may be working the background right now. Perform an in-depth scan and removal now, click here.



System Hijack!
System security threat was detected. Viruses and/or spyware may be damaging your system now. Prevent infection and data loss or stealing by running a free security scan.



Privacy threat!
Spyware intrusion detected. Your system is infected. System integrity is at risk. Private data can be stolen by third parties, including credit card details and passwords. Click here to perform a security repair.



Stealth intrusion!
Infection detected in the background. Your computer is now attacked by spyware and rogue software. Eliminate the infection safely, perform a security scan and deletion now.


If you succeed to launch your Internet browser the rogue program will definitely block some of the websites so you couldn't look for any information about the infection. Instead of displaying the websire you request the program will generate this message:


Internet Explorer alert. Visiting this site may pose a security threat to your system!
Possible reasons include:
- Dangerous code found in this site's pages which installed unwanted software into your system.
- Suspicious and potentially unsafe network activity detected.
- Spyware infections in your system
- Complaints from other users about this site.
- Port and system scans performed by the site being visited.

Things you can do:
- Get a copy of Vista Antispyware 2011 to safeguard your PC while surfing the web (RECOMMENDED)
- Run a spyware, virus and malware scan
- Continue surfing without any security measures (DANGEROUS)


The rogue is started automatically after each computer reboot. It loads a fake scanner and simulates looking for infections on your system. When the scan finishes, the program displays a list of files and states that they pose risk to your computer. The truth is that these files either don't exist at all or they are your legitimate computer programs. However, the program will ask purchasing its license in order to activate the program and remove those files.

Less experienced computer user might easily fall for this trick as the scanner and all warnings look like legitimate. The biggest mistake they can do is paying for the program hoping that this will fix everything. The truth is that you will only lose your money and get nothing in return.

You are highly advised to get rid of Win 7 Guard, XP Antimalware 2011, Win 7 Security 2011 and any other programs that go under before mentioned names as soon as possible. Pay attention to their executable file and stop it when trying to disable these malwares. Then run reliable anti-spyware, like Spyware Doctor or automatic removal tool, to eliminate all other files of Fake Antiviruses.
Fake Security AntiMalware Guard antiviruses for Win 7 XP or Vista properties:
• Shows commercial adverts
• Connects itself to the internet
• Hides from the user
• Stays resident in background

It might be that we are affiliated with any of our recommended products. Full disclosure can be found in our Agreement of Use. By downloading any of provided Anti-spyware software you agree with our Privacy Policy and Agreement of Use.
Do it now!
Download
Reimage - remover Happiness
Guarantee
Compatible with Microsoft Windows
What to do if failed?
If you failed to remove infection using Reimage Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to uninstall Fake Security AntiMalware Guard antiviruses for Win 7 XP or Vista. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

More information about this program can be found in Reimage review.
Reimage is recommended to uninstall Fake Security AntiMalware Guard antiviruses for Win 7 XP or Vista. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

More information about this program can be found in Reimage review.
Not using OS X? Download a remover for Windows.
Press Mentions on Reimage
Alternate Software
Alternate Software
STOPzilla
Tested and Confirmed! STOPzilla removes Fake Security AntiMalware Guard antiviruses for Win 7 XP or Vista (2010-11-13 04:29:25)
Malwarebytes Anti Malware
Tested and Confirmed! Malwarebytes Anti Malware removes Fake Security AntiMalware Guard antiviruses for Win 7 XP or Vista (2010-11-13 04:29:25)
Plumbytes
We are testing Plumbytes's efficiency (2012-03-18 16:28)
Hitman Pro
STOPzilla
Tested and Confirmed! STOPzilla removes Fake Security AntiMalware Guard antiviruses for Win 7 XP or Vista (2010-11-13 04:29:25)
Malwarebytes Anti Malware
Tested and Confirmed! Malwarebytes Anti Malware removes Fake Security AntiMalware Guard antiviruses for Win 7 XP or Vista (2010-11-13 04:29:25)
Webroot SecureAnywhere AntiVirus
Fake Security AntiMalware Guard antiviruses for Win 7 XP or Vista screenshot
Fake Security AntiMalware Guard antiviruses for Win 7 XP or Vista snapshot

Fake Security AntiMalware Guard antiviruses for Win 7 XP or Vista manual removal

Kill processes:
pw.exe
MSASCui.exe
Delete registry values:
HKEY_CURRENT_USERSoftwareClassespezfile
HKEY_CLASSES_ROOTpezfile
HKEY_CURRENT_USERSoftwareClasses.exeshellopencommand "(Default)" = "%UserProfile%Local SettingsApplication Datapw.exe" /START "%1" %*
HKEY_CURRENT_USERSoftwareClassespezfileshellopencommand "(Default)" = "%UserProfile%Local SettingsApplication Datapw.exe" /START "%1" %*
HKEY_CLASSES_ROOT.exeshellopencommand "(Default)" = "%UserProfile%Local SettingsApplication Datapw.exe" /START "%1" %*
HKEY_CLASSES_ROOTpezfileshellopencommand "(Default)" = "%UserProfile%Local SettingsApplication Datapw.exe" /START "%1" %*
HKEY_LOCAL_MACHINESOFTWAREClientsStartMenuInternetFIREFOX.EXEshellopencommand "(Default)" = "%UserProfile%Local SettingsApplication Datapw.exe" /START "C:Program FilesMozilla Firefoxfirefox.exe"
HKEY_LOCAL_MACHINESOFTWAREClientsStartMenuInternetFIREFOX.EXEshellsafemodecommand "(Default)" = "%UserProfile%Local SettingsApplication Datapw.exe" /START "C:Program FilesMozilla Firefoxfirefox.exe" -safe-mode
HKEY_LOCAL_MACHINESOFTWAREClientsStartMenuInternetIEXPLORE.EXEshellopencommand "(Default)" = "%UserProfile%Local SettingsApplication Datapw.exe" /START "C:Program FilesInternet Exploreriexplore.exe"
HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center "AntiVirusOverride" = "1"
HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center "FirewallOverride" = "1"
Delete files:
%UserProfile%Local SettingsApplication DataopRSK
%UserProfile%Local SettingsApplication Datapw.exe
%UserProfile%Local SettingsApplication DataMSASCui.exe
%UserProfile%AppDataLocalopRSK
%UserProfile%AppDataLocalpw.exe
%UserProfile%AppDataLocalMSASCui.exe

Information updated:

Comments on Fake Security AntiMalware Guard antiviruses for Win 7 XP or Vista

0
0
Guest
This kind of virus is called FakeRean.

Post a comment

Attention: Use this form only if you have additional information about a parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.

Home page Name



«

(All fields are required)