Home Malware Programs Rogue Anti-Spyware Programs Win 7 Guardian

Win 7 Guardian

Posted: February 1, 2010

Win 7 Guardian is a rogue anti-spyware program which uses Trojan viruses to enter the PC and spread. Win 7 Guardian also uses malicious flash updates and other programs which pose as tools to watch online videos. Win 7 Guardian will change the system settings to run everytime you log in to Windows. Win 7 Guardian produces fake system scan results which states that certain files are corrupt and recommends removing them. If you decide to do this, you will be redirected to make a payment for Win 7 Guardian. According to Win 7 Guardian this is the only and best way to clean your system from parasites. Do not trust Win 7 Guardian and have the rogue removed using a reliable anti-spyware program.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 av.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-modeHKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Internet Explorer\iexplore.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security CenterHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = "1"HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\secfile\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*

Related Posts

Loading...