02-11-2010 09:23 PM
I've been having problems with this malware called Vista Guardian 2010. I have searched through the internet for answers and such and have only come to Spyware Doctor... but I don't have the money for that. I'm not sure what else to do... Norton AntiVirus had picked up a Trojan Horse and got rid of that (which caused the pop ups and everything to stop for about a half an hour). That, however, didn't last long and it "re-downloaded" itself using Windows' Updates onto my computer. I was going to reformat my computer to just get rid of it, but it seems that I don't even have a copy of Vista around. So, if there is anyone who can help me out... I'd be very thank for it!
Oh and I have also tried to download free scanners such as Malwarebytes Anti-Malware... but, Vista Guardian blocks it from downloading.
02-11-2010 09:30 PM
1. Download Hijackthis with the clean system, if not able to on the infected PC) from here http://free.antivirus.com/hijackthis/ Download the version 2.0.2 executable on the right hand side ( Not the Installer)
Before Transfering, or just needing to rename "Hijackthis.exe" to "Hijackthis.com" then transfer to your desktop of the infected machine, run and save a log.
Other names you could rename Hijackthis to are or should be,
Then post the Log back here
02-11-2010 09:54 PM
It keeps giving me "Windows cannot access the specified device, path, or file. You may not have the apprpriate permissions to access the item." So, I must have done something wrong...
so, i downloaded it... renamed it and moved it to my desktop...
Sorry for all the trouble, it's my first time dealing with something like this.
02-11-2010 10:09 PM
The error happens at times if you
a) Vista you don't have Full Admin rights Try right clicking the file and choose "Run as Administrator"
b) With The Rogue if you have it named "hijackthis.exe" You may have the file settings set not to show common file extensions, In that case when you renamed it to "hijackthis.com" the name would actually be "Hijackthis.com.exe"
c) Try naming it "winlogon.exe"