Vista guard 2010

Problems? Post here...
Post Reply
User avatar
Tep
suck-o-fied!
suck-o-fied!
Posts: 86
Joined: 26 Sep 2006, 16:00
17
Location: USA, TN

Vista guard 2010

Post by Tep »

some how picked this up no idea how


but anyways im on my laptop which runs vista hence the name

ive end av.exe which is the virus

but when i go to delete parts of the registry it wont let me
nor edit the permissions


HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/security center

is the file i cant delete
others i can and already have

anyways any help would be awesome

thanks
-Tep

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Post by bad_brain »

hm, the path HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/security center is a valid one and you shouldn't delete it anyway, it would damage the system.
what entries are in there? :-k
Image

User avatar
Alien1
forum buddy
forum buddy
Posts: 21
Joined: 10 Sep 2009, 16:00
14

Post by Alien1 »

Why not try downloading Malwarebytes and installing and updating then running a scan, it should resolve that malware.

User avatar
Tep
suck-o-fied!
suck-o-fied!
Posts: 86
Joined: 26 Sep 2006, 16:00
17
Location: USA, TN

Post by Tep »

i was following the instructions at this link
http://www.spywareremove.com/removeVist ... n2010.html

under security center there is

monitoring and svc

monitoring i can delete but it'll come back all it holds is something called default which is a REG_SZ type file with no data value set

and svc holds another default

3 other files call Antispyware override, Antivirus override and firewall override all three files are REG_DWORD types and the values seem to be set to 0 (0x00000000 (0))

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Post by bad_brain »

hm, ok, anything to find in the autostart entries in msconfig?
Image

User avatar
DrVirus
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 383
Joined: 16 May 2007, 16:00
16
Contact:

Post by DrVirus »

@B_B: There is a malware called the security center. It installs itself in the computer and then detects imaginary viruses and demands money to remove them. Very much a mess. I had that problem few months back in the computer of a client of mine. Even wrote a post on the whole thing ! There you go http://www.suck-o.com/modules.php?name= ... ght=#60629

Found another one in here http://www.bleepingcomputer.com/virus-r ... ritycenter

Hope they are what u are looking for !!

DrV

User avatar
Tep
suck-o-fied!
suck-o-fied!
Posts: 86
Joined: 26 Sep 2006, 16:00
17
Location: USA, TN

Post by Tep »

ehh nothing that i can see no av.exe or anything like that

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Post by bad_brain »

well, if Windows is blocking the removal of those registry entries you can still get Knoppix and edit the registry from Linux:
http://www.extremetech.com/article2/0,2 ... 306,00.asp

:wink:
Image

User avatar
bozotheclown138
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 172
Joined: 07 Feb 2009, 17:00
15
Contact:

Post by bozotheclown138 »

if you have that.... restart in safe mode if allowed, or use erd commander 2005, and go ahead and delete the startup entries. that gets rid of the main problem and everything else is jsut left over which you can easily delete by malwarebytes.

User avatar
computathug
Administrator
Administrator
Posts: 2693
Joined: 29 Mar 2007, 16:00
17
Location: UK
Contact:

Post by computathug »

I repaired a pc with this last week.

VistaInternetSecurity2010 removal instructions:

1. Click Start->Run (or WinKey+R). Input: "command". Press Enter or click OK.
2. Type "notepad" as shown in the image below and press Enter. Notepad will open.
3. Copy and past the following text into Notepad:


Windows Registry Editor Version 5.00

[-HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command]
[-HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command]
[-HKEY_CLASSES_ROOT\.exe\shell\open\command]

[HKEY_CLASSES_ROOT\.exe]
@="exefile"
"Content Type"="application/x-msdownload"

[-HKEY_CLASSES_ROOT\secfile]

4. Save file as "exefix.reg" (without quotation-marks) to your Desktop.
NOTE: choose Save as type: All files
5. Double-click to open exefix.reg. Click "Yes" for Registry Editor prompt window.

Download and run malwarebytes in safe mode.
The devil can cite Scripture for his purpose.
-- William Shakespeare, "The Merchant of Venice"
https://tshirt-memes.com

Post Reply