Fake Security AntiMalware Guard antiviruses for Win 7 XP or Vista


Call Toll Free in the US and Canada!


Title: Fake Security AntiMalware Guard antiviruses for Win 7 XP or Vista
Type: Rogue Antispyware

Remove Fake Security AntiMalware Guard antiviruses for Win 7 XP or Vista
. Removal instructions

 
Severity scale:Fake Security AntiMalware Guard antiviruses for Win 7 XP or Vista severity is 86  (86 / 100)

 

Creators of rogue antispyware programs have designed a new malicious application that comes under 27 different names. The name of the infection depends on the Windows Operating system the computer runs. Here is a list of the program names that it can use once infecting computer system:

XP Antispyware 2011 or XP Antispyware
Vista Antispyware 2011 or Vista Antispyware
Win 7 Antispyware 2011 or Win 7 Antispyware
XP Security 2011 or XP Security
Vista Security 2011 or Vista Security
Win 7 Security 2011 or Win 7 Security
XP Internet Security 2011 or XP Internet Security
Vista Internet Security 2011 or Vista Internet Security
Win 7 Internet Security 2011 or Win 7 Internet Security
Win 7 Antimalware
XP Antimalware 2011 or XP Antimalware
Vista Antimalware 2011 or Vista Antimalware
Win 7 Antimalware 2011
XP Guard
Vista Guard
Win 7 Guard

The program is installed with a help of Trojan viruses that imitate being Windows updates and are downloaded automatically. Once inside the application is ready to do everything in order to make it impossible to remove it. It will disable most of your programs including your Internet browser and once you try to launch it you will see firewall warning instead of the requested website. Instead of launching any executable the program will launch Vista Antispyware 2011, XP Guard, Win 7 Internt Security 2011 or any other program that infected your computer.

Here is how some of the alerts look like:

Win 7 Internet Security 2011 Firewall Alert
XP Antispyware 2011 has blocked a program from accessing the internet
Internet Explorer is infected with Trojan-BNK.Win32.Keylogger.gen
Private data can be stolen by third parties, including credit card details and passwords.
System danger!
Your system security is in danger. Privacy threats detected. Spyware, keyloggers or Trojans may be working the background right now. Perform an in-depth scan and removal now, click here.
System Hijack!
System security threat was detected. Viruses and/or spyware may be damaging your system now. Prevent infection and data loss or stealing by running a free security scan.
Privacy threat!
Spyware intrusion detected. Your system is infected. System integrity is at risk. Private data can be stolen by third parties, including credit card details and passwords. Click here to perform a security repair.
Stealth intrusion!
Infection detected in the background. Your computer is now attacked by spyware and rogue software. Eliminate the infection safely, perform a security scan and deletion now.

If you succeed to launch your Internet browser the rogue program will definitely block some of the websites so you couldn’t look for any information about the infection. Instead of displaying the websire you request the program will generate this message:

Internet Explorer alert. Visiting this site may pose a security threat to your system!
Possible reasons include:
– Dangerous code found in this site’s pages which installed unwanted software into your system.
– Suspicious and potentially unsafe network activity detected.
– Spyware infections in your system
– Complaints from other users about this site.
– Port and system scans performed by the site being visited.

Things you can do:
– Get a copy of Vista Antispyware 2011 to safeguard your PC while surfing the web (RECOMMENDED)
– Run a spyware, virus and malware scan
– Continue surfing without any security measures (DANGEROUS)

The rogue is started automatically after each computer reboot. It loads a fake scanner and simulates looking for infections on your system. When the scan finishes, the program displays a list of files and states that they pose risk to your computer. The truth is that these files either don’t exist at all or they are your legitimate computer programs. However, the program will ask purchasing its license in order to activate the program and remove those files.

Less experienced computer user might easily fall for this trick as the scanner and all warnings look like legitimate. The biggest mistake they can do is paying for the program hoping that this will fix everything. The truth is that you will only lose your money and get nothing in return.

You are highly advised to get rid of Win 7 Guard, XP Antimalware 2011, Win 7 Security 2011 and any other programs that go under before mentioned names as soon as possible. Pay attention to their executable file and stop it when trying to disable these malwares. Then run reliable anti-spyware, like Spyware Doctor or automatic removal tool, to eliminate all other files of Fake Antiviruses.


Related files: %UserProfile%AppDataLocalMSASCui.exe, %UserProfile%AppDataLocalpw.exe, %UserProfile%AppDataLocalopRSK, %UserProfile%Local SettingsApplication DataMSASCui.exe, %UserProfile%Local SettingsApplication Datapw.exe, %UserProfile%Local SettingsApplication DataopRSK

Fake Security AntiMalware Guard antiviruses for Win 7 XP or Vista properties:
• Shows commercial adverts
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Fake Security AntiMalware Guard antiviruses for Win 7 XP or Vista snapshot:

Fake Security AntiMalware Guard antiviruses for Win 7 XP or Vista removal

Automatic Fake Security AntiMalware Guard antiviruses for Win 7 XP or Vista removal:

remover for Fake Security AntiMalware Guard antiviruses for Win 7 XP or Vista


SpyHunter is recommended remover to uninstall Fake Security AntiMalware Guard antiviruses for Win 7 XP or Vista.
You should confirm using free trial that it detects current version of parasite.

Note:
Tested and Confirmed means that we have tested spyware remover with multiple versions of Fake Security AntiMalware Guard antiviruses for Win 7 XP or Vista and
got the best results. There might be updated or modified version of particular parasite that require manual killing of parasite process or an update.
In such case try other removers in the line.

Manual assistance required means that one or all of removers were unable to remove parasite without some manual intervention,
please read manul removal instructions below.

If you failed to remove Fake Security AntiMalware Guard antiviruses for Win 7 XP or Vista using SpyHunter please report this to us.

We might be affiliated with any product we recommend on the site. Full disclosure in our Agreement of Use.

Spyware Doctor

Tested and Confirmed! Spyware Doctor removes Fake Security AntiMalware Guard antiviruses for Win 7 XP or Vista (2010-11-13 04:29:25)

Malwarebytes Anti Malware

Tested and Confirmed! Malwarebytes Anti Malware removes Fake Security AntiMalware Guard antiviruses for Win 7 XP or Vista (2010-11-13 04:29:25)

Emsisoft Anti Malware

XoftSpySE Anti Spyware


Fake Security AntiMalware Guard antiviruses for Win 7 XP or Vista manual removal:

Kill processes:
pw.exe MSASCui.exe

HELP:
how to kill malicious processes

Delete registry values:
HKEY_CURRENT_USERSoftwareClassespezfile
HKEY_CLASSES_ROOTpezfile
HKEY_CURRENT_USERSoftwareClasses.exeshellopencommand “(Default)” = “%UserProfile%Local SettingsApplication Datapw.exe” /START “%1” %*
HKEY_CURRENT_USERSoftwareClassespezfileshellopencommand “(Default)” = “%UserProfile%Local SettingsApplication Datapw.exe” /START “%1” %*
HKEY_CLASSES_ROOT.exeshellopencommand “(Default)” = “%UserProfile%Local SettingsApplication Datapw.exe” /START “%1” %*
HKEY_CLASSES_ROOTpezfileshellopencommand “(Default)” = “%UserProfile%Local SettingsApplication Datapw.exe” /START “%1” %*
HKEY_LOCAL_MACHINESOFTWAREClientsStartMenuInternetFIREFOX.EXEshellopencommand “(Default)” = “%UserProfile%Local SettingsApplication Datapw.exe” /START “C:Program FilesMozilla Firefoxfirefox.exe”
HKEY_LOCAL_MACHINESOFTWAREClientsStartMenuInternetFIREFOX.EXEshellsafemodecommand “(Default)” = “%UserProfile%Local SettingsApplication Datapw.exe” /START “C:Program FilesMozilla Firefoxfirefox.exe” -safe-mode
HKEY_LOCAL_MACHINESOFTWAREClientsStartMenuInternetIEXPLORE.EXEshellopencommand “(Default)” = “%UserProfile%Local SettingsApplication Datapw.exe” /START “C:Program FilesInternet Exploreriexplore.exe”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center “AntiVirusOverride” = “1”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center “FirewallOverride” = “1”

HELP:
how to remove registry entries

Delete files:
%UserProfile%Local SettingsApplication DataopRSK %UserProfile%Local SettingsApplication Datapw.exe %UserProfile%Local SettingsApplication DataMSASCui.exe %UserProfile%AppDataLocalopRSK %UserProfile%AppDataLocalpw.exe %UserProfile%AppDataLocalMSASCui.exe

HELP:
how to remove harmful files

Information added: 2010-11-13 04:29:25
Information updated: 2012-01-19 13:16:12