Severity scale  
  (72/100)

XP Guardian. How to Remove? (Uninstall Guide)

removal by - -   Also known as XPGuardian | Type: Rogue Antispyware
12
XP Guardian is a fake anti-spyware program that is distributed through the use of Trojans or comes bundled with other malware. Once a Trojan virus is installed, it will impersonate an Automatic Windows Updates window and download the rogue program onto your computer. When the rogue program is active, it will imitate a system scan and report false system security threats. What is more, XPGuardian will constantly display fake security alerts and impersonate Windows Security Center to make the scam look more realistic. Finally it will ask you to pay for a full version of the program to remove the infections which don't even exist. Don't purchase it and remove XP Guardian virus from your computer upon detection.

XP Guardian graphical user interface
[Figure 1. XP Guardian graphical user interface]

The worst thing about XP Guardian is that it actually protects itself quite well. It blocks legitimate security software and hijack web browsers. In some cases it blocks all programs, not only anti-virus or anti-spyware software. Furthermore, it will detect many of well known and reputable websites as harmful and display fake security alert stating that you may infect your PC if you open a particular website. And of course, it disables certain Windows functions such as Task Manager or Regedit. It's possible to remove it manually, but you have to re-enable those Windows functions at first. You may also download an automatic removal tool, but again have to fix some registry entries and terminate the main process of XPGuardian which is AV.exe to be able to run the removal tool.

XP Guardian removal instructions:

1. Click Start->Run (or WinKey+R). Input: "command". Press Enter or click OK.


2. Type "notepad" as shown in the image below and press Enter. Notepad will open.


3. Copy and past the following text into Notepad:


Windows Registry Editor Version 5.00

[-HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command]
[-HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command]
[-HKEY_CLASSES_ROOT\.exe\shell\open\command]

[HKEY_CLASSES_ROOT\.exe]
@="exefile"
"Content Type"="application/x-msdownload"

[-HKEY_CLASSES_ROOT\secfile]

4. Save file as "exefix.reg" (without quotation-marks) to your Desktop.
NOTE: choose Save as type: All files


5. Double-click to open exefix.reg. Click "Yes" for Registry Editor prompt window.

6. Download Spyware Doctor or an automatic removal tool below. Update Spyware Doctor and run a full system scan.

If you can't complete the above steps then please use another PC to download an automatic removal tool and exefix.reg (Right Click (Save Target As)) to download file. Copy these files to USB flash drive or any other external media and transfer them to infected computer. Launch exefix.reg file first and then install Spyware Doctor. XP Guardian properties:
• Changes browser settings
• Shows commercial adverts
• Connects itself to the internet
• Stays resident in background

It might be that we are affiliated with any of our recommended products. Full disclosure can be found in our Agreement of Use. By downloading any of provided Anti-spyware software you agree with our Privacy Policy and Agreement of Use.
Do it now!
Download
Reimage - remover Happiness
Guarantee
Compatible with Microsoft Windows
What to do if failed?
If you failed to remove infection using Reimage Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to uninstall XP Guardian. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

More information about this program can be found in Reimage review.
Reimage is recommended to uninstall XP Guardian. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

More information about this program can be found in Reimage review.
Not using OS X? Download a remover for Windows.
Press Mentions on Reimage
Alternate Software
Alternate Software
STOPzilla
Tested and Confirmed! STOPzilla removes XP Guardian (2010-01-28 05:14:37)
Malwarebytes Anti Malware
Tested and Confirmed! Malwarebytes Anti Malware removes XP Guardian (2010-01-28 05:14:37)
Plumbytes
We are testing Plumbytes's efficiency (2010-04-25 08:04)
Hitman Pro
STOPzilla
Tested and Confirmed! STOPzilla removes XP Guardian (2010-01-28 05:14:37)
Malwarebytes Anti Malware
Tested and Confirmed! Malwarebytes Anti Malware removes XP Guardian (2010-01-28 05:14:37)
Webroot SecureAnywhere AntiVirus

XP Guardian manual removal

Kill processes:
av.exe
Delete registry values:
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*
HKEY_CLASSES_ROOT\secfile\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Internet Explorer\iexplore.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = "1"
Delete files:
%UserProfile%\\Local Settings\\Application Data\\av.exe
%UserProfile%\\Local Settings\\Application Data\\WRblt8464P

Geolocation of XP Guardian

Map reveals the prevalence of XP Guardian. Countries and regions that have been affected the most are: India, United Kingdom and United States.

Information updated:

Comments on XP Guardian

0
0
<Guest>
I am also getting the message "editing registry is disabled by your admiistrator." What to I do? HELP PLEASE
0
0
<Guest>
Um.. i tried to edit my registry, but it said "editing registry is disabled by your admiistrator." What to I do?
0
0
<Guest>
I also got the "binary only" error message when I created the regedit file myself. So I downloaded regedit and Windows Defender to another computer and transferred to the infected computer on a thumb drive and the procedure worked perfectly!
0
0
<Guest>
Help please i have followed all the instructions BUT when spy doctor is installing and there is only 32kb to go. I am getting an error message. and the guardian is still doing my head in. I'm no expert on computers need an idiots guide
karole
0
0
<Guest>
worked perfectly fine. Another way is to
Step 1: open registry file by Start - > Run -> type regedit
Step 2: Go to Edit->Find and search "av.exe"
Step 3: delete entry
Step 4 : press F3 for find next and repeat step 3.
Step 5 : restart system after all entries are removed.
0
0
<Guest>
Worked perfectly! I am so glad there is help against these terrible spyware programs that work and are free. THANK YOU!!
0
0
<Guest>
thankyou, saved alot of time and effort
0
0
<Guest>
im getting the binary code when i open it from the desktop even when saves under all files so then i tried to open it in the registry and it says some keys are open by the system or other process, any suggestions?
0
0
PR
i did all the registry edits, up until the file that needs to be deleted "%UserProfile%Local SettingsApplication Dataav.exe %UserProfile%Local SettingsApplication DataWRblt8464P "

how do i get rid of this one?
0
0
<Guest>
Thanks man, worked like a charm A++++++++
More comments »

Post a comment

Attention: Use this form only if you have additional information about a parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.

Home page Name



«

(All fields are required)