XP Guardian manual removal:
Kill processes:
av.exe
Delete registry values:HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*
HKEY_CLASSES_ROOT\secfile\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Internet Explorer\iexplore.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = "1"
Delete files:%UserProfile%\\Local Settings\\Application Data\\av.exe %UserProfile%\\Local Settings\\Application Data\\WRblt8464P
i can open stuff again
If you follow the manual removal instructions don't just delete values, replace it with "%1" %* otherwise you will not be able to open any applications.
I COULD NOT EVEN RELOAD XP.
BLESSINGS
cant open anything got nod32 and Mozilla started.
I have to pay for spyware doctor to remove the threats?
What the hell?
THANKS!!
I WAS FREAKING OUT WHEN THAT SHIT POPPED UP
Thank you very much for such a wonderful site.
I did all till step 5 and rebooted my computer and it;s gone!
Currently running my scan now but it seems to be ok.
THANK YOU VERY MUCH!
SERIOUSLY.
Thank you!
how do i get rid of this one?
Step 1: open registry file by Start - > Run -> type regedit
Step 2: Go to Edit->Find and search "av.exe"
Step 3: delete entry
Step 4 : press F3 for find next and repeat step 3.
Step 5 : restart system after all entries are removed.
karole
Post Comment: