Home Malware Programs Rogue Anti-Spyware Programs Guardian Online

Guardian Online

Posted: October 14, 2011

Threat Metric

Threat Level: 8/10
Infected PCs: 16
First Seen: October 14, 2011
Last Seen: October 1, 2021
OS(es) Affected: Windows

Guardian Online (not to be confused with the famous United Kingdom magazine) is a new variant of rogue anti-virus programs from the group of fake AV scanners. Like other roge anti-virus programs, Guardian Online pretends to detect various infections and other problems with Windows, but the pop-ups that Guardian Online provides are fake and can only create inaccurate information. In addition to these persistent warnings, Guardian Online and affiliated types of harmful software may also attack your web browser with hijacks or block security-related programs. However, SpywareRemove.com malware researchers have found that Guardian Online can be deleted just as easily as Guardian Online's kin, as long as you have an up-to-date and competent anti-malware program and follow standard precautions for removing such PC threats.

Guardian Online – the PC Guardian with a Chronic Backstabbing Disorder

Like other fake anti-virus programs from the Guardian Online's family, Guardian Online markets itself in the form of a legitimate anti-virus product but, in reality, isn't able to find, identify or remove viruses, Trojans, keyloggers or other PC threats. Gardian Online's family members include SpywareRemove.com malware researchers note that the most likely method of infection by Guardian Online is a visit to a malicious website that uses drive-by-download Flash or Java scripts to install Guardian Online without consent; in many cases, these installation processes are concealed in fake movie player updates.

Detecting a Guardian Online infection is a fairly direct issue, since, once active, Guardian Online will use highly-visible fake alerts, warnings and other pop-ups to make it appear as though your PC is under attack by multiple forms of infections. SpywareRemove.com malware analysts note that Guardian Online errors are crafted to look relatively convincing, as seen with the examples below:

svchost.exe
svchost.exe was replaced with unauthorized program.
It has encountered a problem and needs to close.
If you were in the middle of something, the information you were working on might be lost.
Please tell Microsoft about this problem.
We have created an error report that you can send to us. We will treat this report as confidential and anonymous.

Windows Security Alert
To help protect your computer, Windows Firewall has blocked some features of this program.
Do you want to keep blocking this program?
Name: Zeus Trojan
Publisher: Unauthorized

Warning! Infection found
Unauthorized sending E-MAIL with subject "RE:" to [FAKE EMAIL] was CANCELLED.

Warning! Infection found
Unwanted software (malware) or tracking cookies have been found during last scan. It is highly recommended to remove it from your computer.
Keylogger Zeus was detected and put in quarantine.
Keylogger Zeus is a very dangerous software used by criminals to steal personal data such as credit card information, access to banking accounts, passwords to social networks and e-mails
.

Security Warning
Your computer continues to be infected with harmful viruses. In order to prevent permanent loss of your information and credit card data theft please activate your antivirus software. Click here to enable protection.

Security Warning
Malicious programs that may steal your private information and prevent your system from working properly are detected on your computer.
Click here to clean your PC immediately.

Security Warning
There are critical system files on your computer that were modified by malicious software.
It may cause permanent data loss.
Click here to remove malicious software.

Warning: Infection is Detected
Windows has found spyware infection on your computer!
Click here to update your Windows antivirus software

Warning: Spyware Detected
Windows has found spy programs running on your computer!
Click here to update your Windows antivirus software

Windows Security Center
Serious security vulnerabilities were detected on this computer. Your privacy and personal data may be unsafe. Do you want to protect your PC?

Because Guardian Online can't detect any of the PC threats that Guardian Online claims to detect and may actively harm your computer's security, you shouldn't give any credibility to Guardian Online's fake warnings. Ideally, removing all components of Guardian Online and stopping fake errors should be done with an anti-malware.

Putting the Guardian Online Genie Back Into Its Jar

Guardian Online has also been known to be installed alongside other PC threats, including ZeroAccess rootkit. Between Guardian Online and any accompanying rootkits or Trojans, your PC may also be subjected to other attacks that directly harm your security or privacy. SpywareRemove.com malware experts have found the most probable side attacks to consist of:

  • Blocked programs. Anti-virus scanners and other forms of security programs are very likely to be attacked by Guardian Online. However, attacks may also extend to basic Windows utilities like Notepad, Task Manager or MSConfig. Using Safe Mode or renaming a program file to a generic name (such as explorer.exe) will help to break down Guardian Online's program barricade, so that you can remove Guardian Online with an appropriate program.
  • Browser hijacks. Guardian Online may attempt to redirect your web browser to a Guardian Online website by changing your homepage, redirecting you when you click a link or redirecting you when you use your web browser's navigation bar.
Loading...