Mar 07

Threat Description:

The new phony security solution called Win 7 Guardian 2010 is obviously maintaining the malware practices of its clone known as Antivirus Win 7 2010. In fact, these two programs are similar externally and functionally. As you may be prompted by the name, Win 7 Guardian 2010 affects Windows 7 Operating System; the exact same virus obtains a different shape and name if it contaminates some other OS. This innovative invention of hackers is quite intricate and gives them some advantage broadening the scope of potential infection. Like its precursors and pretty much every random rogue anti-spyware, Win 7 Guardian 2010 reconfigures the Registry when it penetrates into a new computer. After it’s done, Win 7 Guardian 2010 gets some of its executables (such as ‘Av.exe’) to run. This will cause active ad-generating activity which will be observed as pop-ups, scanners and similar security reports telling you that you’ve got some trouble with your PC. Win 7 Guardian 2010 will state that it has found lots of infections inside your system and then won’t fail to recommend you some malware cleanup assistance. You shouldn’t fall for Win 7 Guardian 2010 prompts though; this program cannot be of any help and will even call forth further system disruption. So unless you remove Win 7 Guardian 2010 from your workstation, it will become a major security issue for you.

Determine if your system is infected with Win 7 Guardian 2010 and related threats:

Win 7 Guardian 2010 Screenshot:

Win 7 Guardian 2010

How to remove this threat manually:

Win 7 Guardian 2010 manual uninstall procedure:

Get rid of the related corrupt files:

  • %Documents and Settings%\[UserName]\Application Data\av.exe
  • %Documents and Settings%\[UserName]\Application Data\WRblt8464P

Delete the associated registry entries:

  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command “(Default)” = “av.exe” /START “%1″ %*
  • HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command “(Default)” = “av.exe” /START “%1″ %*
  • HKEY_CLASSES_ROOT\.exe\shell\open\command “(Default)” = “av.exe” /START “%1″ %*
  • HKEY_CLASSES_ROOT\secfile\shell\open\command “(Default)” = “av.exe” /START “%1″ %*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command “(Default)” = “av.exe” /START “firefox.exe”
  • HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command “(Default)” = “av.exe” /START “firefox.exe” -safe-mode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command “(Default)” = “av.exe” /START “iexplore.exe”
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center “AntiVirusOverride” = “1″
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center “FirewallOverride” = “1″

Please note that Win 7 Guardian 2010 manual removal is a procedure of high complexity and should be performed with extreme caution. Lack of the required skills and even the slightest deviation from the instructions may cause irreparable system damage. To ensure trouble-free deletion, it is recommended to use the automatic removal tool below:

Download Win 7 Guardian 2010 Removal Tool

Leave a Reply