Home Malware Programs Rogue Anti-Spyware Programs Win 7 Guardian 2010

Win 7 Guardian 2010

Posted: March 9, 2010

Win 7 Guardian 2010 (or Win7Guardian2010) is a rogue anti-spyware program and a clone of Win 7 Guardian. Win 7 Guardian 2010 is promoted and installed through fake anti-malware scanners or Trojans. The fake scanners imitate a system scan and display numerous false infections. Then it recommends downloading Win 7 Guardian 2010 in order to remove the non-existent infections. Use a reliable anti-spyware program to remove Win7Guardian2010 from your system before it causes chaos on your computer.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\AppData\Local\av.exe
    2 %UserProfile%\AppData\Local\WRblt8464P

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = "av.exe" /START "firefox.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = "av.exe" /START "firefox.exe" -safe-modeHKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = "av.exe" /START "iexplore.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = "1?HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = "1?
Loading...