Remove Vista Guardian. Description and removal instructions

 
Title: Vista Guardian
Also known as: VistaGuardian
Type: Spyware
Severity scale:Vista Guardian severity is 72  (72 / 100)
 
Vista Guardian is a rogue anti-spyware program that deliberately displays exaggerated scan results to make you think your computer has many infections and security/privacy risks. This program is usually promoted through the use of fake online scanners, that state that your computer is badly infected and that you should download and install Vista Guardian in order to remove infections and to protect yourself. When Vista Guardian is installed and active it will automatically perform a fake system scan when you login to Windows. After the scan it will display numerous infections of exaggerated security threats on your computer and then state that you should purchase the program in order to remove the infections or threats which don't even exist. Don't pay for this bogus software and uninstall it as soon as possible. If you are infected with this virus, then please use the removal guide stated below to remove Vista Guardian from your computer manually for free or with an automatic removal tool.

While VistaGuardian is running you will also find your computer flooded with various alerts stating that your computer is infected with malware. This program will hijack both Internet Explorer and Firefox to randomly display messages about insecure Internet activity when browsing the web and state that you should purchase Vista Guardian to protect your computer from possible attacks. These alerts, like web browser hijacks are just another attempt to trick you into believing that you are infected with Trojans, worms and other viruses. However, the worst thing is that this parasite blocks anti-virus and anti-spyware software as well as useful Windows functions (Task Manager and Regedit). In order to remove this virus you will have to either use another PC or re-enable default Windows registry settings. To do this, please use the guide below.

Vista Guardian removal instructions:

1. Click Start->Run (or WinKey+R). Input: "command". Press Enter or click OK.
2. Type "notepad" as shown in the image below and press Enter. Notepad will open.
3. Copy and past the following text into Notepad:


Windows Registry Editor Version 5.00

[-HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command]
[-HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command]
[-HKEY_CLASSES_ROOT\.exe\shell\open\command]

[HKEY_CLASSES_ROOT\.exe]
@="exefile"
"Content Type"="application/x-msdownload"

[-HKEY_CLASSES_ROOT\secfile]

4. Save file as "exefix.reg" (without quotation-marks) to your Desktop.
NOTE: choose Save as type: All files
5. Double-click to open exefix.reg. Click "Yes" for Registry Editor prompt window.
6. Download Spyware Doctor or an automatic removal tool below. Update Spyware Doctor and run a full system scan.

If you can't complete the above steps then please use another PC to download an automatic removal tool and exefix.reg (Right Click (Save Target As)) to download file. Copy these files to USB flash drive or any other external media and transfer them to infected computer. Launch exefix.reg file first and then install Spyware Doctor.


Related files: WRblt8464P, av.exe

Vista Guardian properties:
• Changes browser settings
• Shows commercial adverts
• Connects itself to the internet
• Stays resident in background

Automatic Vista Guardian removal:

remover for Vista Guardian

Vista Guardian manual removal:

Kill processes:
av.exe
Delete registry values:
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*
HKEY_CLASSES_ROOT\secfile\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Internet Explorer\iexplore.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = "1"
Delete files:
%UserProfile%\\AppData\\Local\\av.exe %UserProfile%\\AppData\\Local\\WRblt8464P

Other programs to remove Vista Guardian:

• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download

Information added: 29/01/10
Information updated: 09/03/10

Additional resources related to Vista Guardian:

Attention: If you know or you have a website or page about Vista Guardian removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Vista Guardian parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:


Comments from visitors:


1. by . 2010-03-09 03:03:48
where do these thing come from? dont want to get it again!

2. by . 2010-03-08 23:03:43
are they?

3. by . 2010-03-06 23:03:05
just wanted to see if these posts were legit

4. by . 2010-03-02 19:03:03
Thank you!!!

5. by . 2010-03-01 01:03:37
I can't find the last file at the end... help?

6. by . 2010-02-21 14:02:55
I did the first command: Kill the process: av.exe
Regedit cannot be found.
Internet explorer is broken and won't work.
what next?
any help, please

7. by . 2010-02-14 07:02:50
You still cannot remove it for free.. you must pay for a key after using spyware doctor......

8. by . 2010-02-13 13:02:46
THANKS! i put it off for 3 days it was dumb... it was fu-kin easy to do. took 20 seconds!

9. by a thanker. 2010-02-10 04:02:14
Thanks a lot, it worked like a charme!

10. by handy. 2010-02-07 11:02:32
when deleting manually, do not delete everything, let "%1" %* stand, else you wont be able to open .exe files. (except with right click and start as an admin)

11. by . 2010-02-05 08:02:09
u have to pay for the spyware

12. by . 2010-02-05 07:02:17
Thanks a lot dude. Its really effective. You are better than these antivirus companies dude.....keep up the good work.... :)

13. by . 2010-02-05 07:02:31
its really worked! thanks alot! awsome work done! thumbs up

14. by Javier. 2010-02-03 00:02:00
It says to me that I dont have access to the device, route of access or file specify. It is possible that it does not have permissions adapted to have access to the element. HELP PLEASE!

15. by . 2010-01-30 16:01:41
any one use


Latest spyware news:
Similar parasites:
Related discussions: