HELP - Vista Guardian 2010 virus

canspec

New member
Power User
Local time
5:45 PM
Messages
78
Location
Vancouver, Canada
HELP!!!
I have this virus called "Vista Guardian 2010" and it won't let me run Malwarebytes, my anti-virus program or anything else. A box pops up telling me about all these infections and to buy their program! I can't even get into "safe-mode(F8) to try to run Malwarebytes to get rid of it like an article on the net said to do. Is there any way to get into safe-mode other than F*? I can't get into system restore either! Thanks for any help with this!
 

My Computer My Computer

At a glance

Win 7 Home Premium-64bit2.34 gig
Computer Manufacturer/Model Number
Gateway
OS
Win 7 Home Premium-64bit
CPU
2.3
Memory
4 gig
stop: av.exe
remove:
Code:
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command “(Default)” = “av.exe” /START “%1? %*
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command “(Default)” = “av.exe” /START “%1? %*
HKEY_CLASSES_ROOT\.exe\shell\open\command “(Default)” = “av.exe” /START “%1? %*
remove:
Code:
\%Documents and Settings%\[UserName]\Application Data\av.exe
%Documents and Settings%\[UserName]\Application Data\WRblt8464P
 

My Computer My Computer

At a glance

7 Pro
OS
7 Pro
It is strongly recommended that your backup your registry before you proceeding with this method.

Kill the following process:

av.exe

Delete the following registries entries:

HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command “(Default)” = “av.exe” /START “%1? %*
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command “(Default)” = “av.exe” /START “%1? %*
HKEY_CLASSES_ROOT\secfile\shell\open\command “(Default)” = “av.exe” /START “%1? %*
HKEY_CLASSES_ROOT\.exe\shell\open\command “(Default)” = “av.exe” /START “%1? %*HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command “(Default)” = “av.exe” /START “firefox.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command “(Default)” = “av.exe” /START “firefox.exe” -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command “(Default)” = “av.exe” /START “iexplore.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center “AntiVirusOverride” = “1?
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center “FirewallOverride” = “1?

Delete the following if you have Firefox installed:

*HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command “(Default)” = “av.exe” /START “firefox.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command “(Default)” = “av.exe” /START “firefox.exe” -safe-mode

Search and remove the following files:

av.exe
 

My Computer My Computer

At a glance

64-bit Windows 8.1 ProCore(TM) i5 CPU 4330 Haswell @ 3.20GHz12.00 GBIntel(R) HD Graphics
Computer type
PC/Desktop
Computer Manufacturer/Model Number
LENOVO K450 @3.0GHZ
OS
64-bit Windows 8.1 Pro
CPU
Core(TM) i5 CPU 4330 Haswell @ 3.20GHz
Motherboard
LENOVO
Memory
12.00 GB
Graphics Card(s)
Intel(R) HD Graphics
Sound Card
Intel HD integtrated
Monitor(s) Displays
HP 25' ISP Monitor
Screen Resolution
1900/1020
Hard Drives
(1) ST1000DM003-1CH162 (2) Generic STORAGE DEVICE USB Device (3) Generic STORAGE DEVICE USB Device
Internet Speed
100mb down/10mb up
It is strongly recommended that your backup your registry before you proceeding with this method.

Kill the following process:

av.exe

Delete the following registries entries:

HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command “(Default)” = “av.exe” /START “%1? %*
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command “(Default)” = “av.exe” /START “%1? %*
HKEY_CLASSES_ROOT\secfile\shell\open\command “(Default)” = “av.exe” /START “%1? %*
HKEY_CLASSES_ROOT\.exe\shell\open\command “(Default)” = “av.exe” /START “%1? %*HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command “(Default)” = “av.exe” /START “firefox.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command “(Default)” = “av.exe” /START “firefox.exe” -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command “(Default)” = “av.exe” /START “iexplore.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center “AntiVirusOverride” = “1?
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center “FirewallOverride” = “1?

Delete the following if you have Firefox installed:

*HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command “(Default)” = “av.exe” /START “firefox.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command “(Default)” = “av.exe” /START “firefox.exe” -safe-mode

Search and remove the following files:

av.exe

Wouldnt backing up my registry also include backing up the virus into the registry?...Sorry just new at all of this...Thanks for your help.
 

My Computer My Computer

At a glance

Win 7 Home Premium-64bit2.34 gig
Computer Manufacturer/Model Number
Gateway
OS
Win 7 Home Premium-64bit
CPU
2.3
Memory
4 gig
technically yes, however if you ruin something, it's easier to recover with a virus filled registry then having nothing. /wink
 

My Computer My Computer

At a glance

7 Pro
OS
7 Pro
Now it won't let me into the Registry to delete the keys u guys recommended. I don't have restore discs as well to restore the entire system :(
 

My Computer My Computer

At a glance

Win 7 Home Premium-64bit2.34 gig
Computer Manufacturer/Model Number
Gateway
OS
Win 7 Home Premium-64bit
CPU
2.3
Memory
4 gig

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Now it won't let me into the Registry to delete the keys u guys recommended. I don't have restore discs as well to restore the entire system :(

Did you get an error when trying to run "regedit"?
 

My Computer My Computer

At a glance

7 Pro
OS
7 Pro
Try starting up in Safe Mode. Start up your computer and keep hitting F8 until the boot menu starts up. Hit Safe Mode. Unplug your internet cable so the virus doesn't try anything funny, and then try running Malwarebytes' and/or your Anti-Virus. Then, try running regedit.
 

My Computer My Computer

At a glance

Windows 7 Enterprise 64-bitAMD Phenom II X4 3.0GHz8GB G-Skill Ripjaws DDR3 1333PNY GeForce 460 GTX 1GB OC - Enthusiast Edition
OS
Windows 7 Enterprise 64-bit
CPU
AMD Phenom II X4 3.0GHz
Motherboard
ASUS M5A97
Memory
8GB G-Skill Ripjaws DDR3 1333
Graphics Card(s)
PNY GeForce 460 GTX 1GB OC - Enthusiast Edition
Sound Card
VIA High Definition Audio
Monitor(s) Displays
Dell 19"
Screen Resolution
1280x1024
Hard Drives
1TB - Primary
160GB - Secondary
250GB - External backup for important files
PSU
OCZ Fata1ty 700W Modular PSU
Case
ASUS
Keyboard
Microsoft Wireless Keyboard 2000
Mouse
Microsoft Wireless Mouse 2000
Internet Speed
3 Mbps/768 kbps
He can't get into safe mode, plus The scareware executes (av.exe) every time a .exe file is run.

Please read my post above :)
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio

My Computer My Computer

At a glance

Windows 7 Enterprise 64-bitAMD Phenom II X4 3.0GHz8GB G-Skill Ripjaws DDR3 1333PNY GeForce 460 GTX 1GB OC - Enthusiast Edition
OS
Windows 7 Enterprise 64-bit
CPU
AMD Phenom II X4 3.0GHz
Motherboard
ASUS M5A97
Memory
8GB G-Skill Ripjaws DDR3 1333
Graphics Card(s)
PNY GeForce 460 GTX 1GB OC - Enthusiast Edition
Sound Card
VIA High Definition Audio
Monitor(s) Displays
Dell 19"
Screen Resolution
1280x1024
Hard Drives
1TB - Primary
160GB - Secondary
250GB - External backup for important files
PSU
OCZ Fata1ty 700W Modular PSU
Case
ASUS
Keyboard
Microsoft Wireless Keyboard 2000
Mouse
Microsoft Wireless Mouse 2000
Internet Speed
3 Mbps/768 kbps

My Computer My Computer

At a glance

Win 7 Home Premium-64bit2.34 gig
Computer Manufacturer/Model Number
Gateway
OS
Win 7 Home Premium-64bit
CPU
2.3
Memory
4 gig
so no error? it simply just won't open?

Are you an admin on the machine?
 

My Computer My Computer

At a glance

7 Pro
OS
7 Pro
Try starting up in Safe Mode. Start up your computer and keep hitting F8 until the boot menu starts up. Hit Safe Mode. Unplug your internet cable so the virus doesn't try anything funny, and then try running Malwarebytes' and/or your Anti-Virus. Then, try running regedit.
Wont allow me to go into safemode(F*) :(
 

My Computer My Computer

At a glance

Win 7 Home Premium-64bit2.34 gig
Computer Manufacturer/Model Number
Gateway
OS
Win 7 Home Premium-64bit
CPU
2.3
Memory
4 gig
If you're having an issue with permissions being edited and such, download SUPER Antispyware if you can. It can restore your permissions back to normal and allow you to regedit and other things.
 

My Computer My Computer

At a glance

Windows 7 Enterprise 64-bitAMD Phenom II X4 3.0GHz8GB G-Skill Ripjaws DDR3 1333PNY GeForce 460 GTX 1GB OC - Enthusiast Edition
OS
Windows 7 Enterprise 64-bit
CPU
AMD Phenom II X4 3.0GHz
Motherboard
ASUS M5A97
Memory
8GB G-Skill Ripjaws DDR3 1333
Graphics Card(s)
PNY GeForce 460 GTX 1GB OC - Enthusiast Edition
Sound Card
VIA High Definition Audio
Monitor(s) Displays
Dell 19"
Screen Resolution
1280x1024
Hard Drives
1TB - Primary
160GB - Secondary
250GB - External backup for important files
PSU
OCZ Fata1ty 700W Modular PSU
Case
ASUS
Keyboard
Microsoft Wireless Keyboard 2000
Mouse
Microsoft Wireless Mouse 2000
Internet Speed
3 Mbps/768 kbps
When I try to import the reg script it says this:
"Cannot import C:\Users\bev\Desktop|trojan_fakerean_exe_fix.reg: The specified file is not a resistry script. You can only import binery registry files from within registry editor." Do I have the wrong spelling or something? Thanks again.
 

My Computer My Computer

At a glance

Win 7 Home Premium-64bit2.34 gig
Computer Manufacturer/Model Number
Gateway
OS
Win 7 Home Premium-64bit
CPU
2.3
Memory
4 gig
I've noticed that with 7 a lot. Right click and "edit" the .reg file. then copy it out into notepad... Then from start menu, just type in "regedit" then manually click down to the registry string you need to modify.
 

My Computer My Computer

At a glance

7 Pro
OS
7 Pro
Run an antivirus boot disk that can scan before Windows boots and possibly clean the infection. Avira has one - its an iso.
 

My Computer My Computer

At a glance

Windows 7 Ultimate x86-64[email protected] 1066MHz FSB6GB DDR3 1066MHz9300M GS 256MB Dedicated (Speed) + Intel4500M...
Computer Manufacturer/Model Number
Sony Vaio Z46GDU
OS
Windows 7 Ultimate x86-64
CPU
[email protected] 1066MHz FSB
Motherboard
Sony branded
Memory
6GB DDR3 1066MHz
Graphics Card(s)
9300M GS 256MB Dedicated (Speed) + Intel4500MHD (Stamina)
Sound Card
Realtek HD Audio
Monitor(s) Displays
13.1' WXGA
Screen Resolution
1600x900
Hard Drives
320GB 7200RPM w/ 16MB cache
Internet Speed
1MB/s

My Computer My Computer

At a glance

Windows 7 Enterprise 64-bitAMD Phenom II X4 3.0GHz8GB G-Skill Ripjaws DDR3 1333PNY GeForce 460 GTX 1GB OC - Enthusiast Edition
OS
Windows 7 Enterprise 64-bit
CPU
AMD Phenom II X4 3.0GHz
Motherboard
ASUS M5A97
Memory
8GB G-Skill Ripjaws DDR3 1333
Graphics Card(s)
PNY GeForce 460 GTX 1GB OC - Enthusiast Edition
Sound Card
VIA High Definition Audio
Monitor(s) Displays
Dell 19"
Screen Resolution
1280x1024
Hard Drives
1TB - Primary
160GB - Secondary
250GB - External backup for important files
PSU
OCZ Fata1ty 700W Modular PSU
Case
ASUS
Keyboard
Microsoft Wireless Keyboard 2000
Mouse
Microsoft Wireless Mouse 2000
Internet Speed
3 Mbps/768 kbps
Thanks to everyone! Working now!:)
 

My Computer My Computer

At a glance

Win 7 Home Premium-64bit2.34 gig
Computer Manufacturer/Model Number
Gateway
OS
Win 7 Home Premium-64bit
CPU
2.3
Memory
4 gig
Back
Top