Click on screenshot to zoom
Danger level 8
Type: Malware
Common infection symptoms:
  • Installs itself without permissions
  • Changes background
  • Normal system programs crash immediatelly

GARDA Virus

When you get infected with GARDA Virus you see a notification on your screen that says “Your computer has been blocked up for safety reasons listed below”. Unfortunately, GARDA Virus has nothing to do with computer safety, as it is a computer infected created by cyber criminals. They deny you desktop access in hopes of making you believe that you have committed a serious crime and now you need to pay (financially). However, do not succumb to these threats and remove GARDA Virus from your system as soon as you can. And while you are at it – remove all the other infections that are bound to be there.

GARDA Virus is part of the Ukash Virus group, just like FBI MoneyPak Virus and the most recent infections Australian Communications and Media Authority virus or Metropolitan British Police Virus. These computer threats are being distributed by Urausy Trojan, which means that you need to be extremely attentive when you browse the Internet or download various freeware applications. Avoid clicking on outgoing links to unreliable websites, and do not visit web pages that are full of adware and pop-up commercial ads – clicking on such an ad may result in getting infected with GARDA Virus at once.

This infection is intended for the computer users in Ireland. It is rather obvious, because it has Irish flag on its interface, as well the symbols and insignia of the Irish law enforcement authorities (The Guardians of the Peace of Ireland, The National Crime Prevention Unit). However, just because it is full of law enforcement authorities symbols it does not mean you need to trust it. The message displayed by GARDA Virus may seem threatening, but you need to realize that you have done nothing wrong, and the message is only a hoax designed to swindle you out of your money:

You are accused of viewing/storage and/or dissemination of banned pornography (child pornography/zoophilia/rape etc). You have violated World Declaration on non-proliferation of child pornography. You are accused of committing the crime envisaged by Article 161 of Ireland criminal law.

The penalty set must be paid in course of 48 hours as the breach. On expiration of the term, 48 hours that follow will be used for automatic collection of data on yourself and your misconduct, and criminal case will be opened against you.

Amount of fine is 100 Euro. You can settle the fine with Ukash or PaySafeCard vouchers.

By making use of Ukash and PaySafeCard, GARDA Virus is able to collect money even from those users who do not own a credit card or have a bank account. But that does not mean you have to be one of them. Follow the instructions below to unlock your PC and then remove GARDA Virus with a legitimate computer security tool. Do not hesitate to invest in your system security, because you can never know when another similar infection will arrive again.

How to restore desktop access

Windows 8

  1. Press Windows key for metro Start menu to show up.
  2. Click the built-in Internet Explorer tile.
  3. Type http://www.pcthreat.com/download-sph into the address bar and hit Enter.
  4. Click Run on the download dialog box and install SpyHunter.
  5. Scan your system.

Windows Vista & Windows 7

  1. Reboot the PC and press F8 repeatedly.
  2. When Advanced Boot Options menu shows up, select Safe Mode with Networking and press Enter.
  3. Access http://www.pcthreat.com/download-sph and download SpyHunter.
  4. Install the program and scan your PC.

Windows XP

  1. Follow the steps 1 and 2 above.
  2. Click Yes on a confirmation box.
  3. Download SpyHunter.
  4. Open Start menu and launch Run.
  5. Enter “msconfig” into the Open box and press OK.
  6. Select Startup tab on System Configuration Utility.
  7. Uncheck all programs on the list and press OK.
  8. Reboot the PC in Normal mode.
  9. Install SpyHunter and scan your system.

If you have any problem with GARDA Virus removal, feel free to leave a comment below and ask a question about it.

Download Spyware Removal Tool to Remove* GARDA Virus
  • Quick & tested solution for GARDA Virus removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove GARDA Virus

Files associated with GARDA Virus infection:

DA0B.exe
hwj3ba6j.dss
xmlfilter.exe
yaiiwockc.dll
administration.exe
00qbipeq.exe
%SystemDrive%\????????????
%APPDATA%\updates
%WINDIR%\Temp
Other.res
iner.exe
audipbrd.exe
mplayer2.exe
MusicCollector.exe
%TEMP%
wlsidten.dll
comeo.exe
skype.dat
secproc_isv.exe
xlqbteeb.exe
pmstcdjwz.exe
taskhost.exe.exe
zqmkrehUkpoKfsafsaZg.exe
csrsss.exe
scvhost.exe
m2PythonLoader.exe
%AppData%
bvhylsviw.exe
50E1.exe
puozlkmyj.dll
ex3b.dll
VaultSysUi.exe
ctfmon.exe
jsdhlexdqkllnbcxgai.bfg
ssntvs.exe
obvwo.exe
%LOCALAPPDATA%\lollipop
{097444e7-2d87-ba3c-2efe-9f54812d824a}.exe
UpgradeHelper.exe
p1.exe
rvcbcyks.exe
idiokbbrv.exe
ieudator.dll
NTServiceManager.exe
SyncHostps.exe
videotwisterSA.exe
Piranha.exe
brenasa.exe
sqlncli.exe
install_0_msi.exe
ubvhynpxh.exe
%ALLUSERSPROFILE%\Application Data
%WINDIR%\system32
%APPDATA%\Task Scheduler
WINDED6.exe
dqnbdq7.dss
cf6640a77ed4926a4c6be661ab93def9d13408753dd07e8d02836996a2f247b6.exe
3511172082012Build.exe
b34btbztdb0vavaw.exe
n.
%APPDATA%\system
%LOCALAPPDATA%\Temp
Nbt.exe
%UserProfile%
DLL321.dll
crack.exe
2084473.dll
msshell.exe
OmaSG21e.exe
bf8h8d02hf.exe
oygqyunapnp.exe
msdtmsrd.exe
96dddda4.dll
%ALLUSERSPROFILE%
xctqakcqbeo.dll
wlsidten.exe
svchost.exe
JfCqQ5JC.exe
gcrwcoak.exe
wgsdgsdgdsgsd.exe
Q3d38543.exe
wahneaqa.exe
魔法桌面第三方主题破解补丁V1.1.exe
msn.exe
msnmsgrr.exe
systemcpl.exe
uenovfiu.exe
Firewallservice.exe
najeoxtt.exe
bzsbkotiu.exe
wpbt0.dll
pYunY8m4VL3qLc.exe
acuvzomo.exe
xaZYOVJW.exe
msavfit.exe
%CommonProgramFiles%
questscan.dll
ACEIEAddOn.dll
Updating.exe
UpdatePriv.exe
Task Scheduler.exe
WinSyncMetastore.exe
00b5d693.exe
securitywindrv.exe
dyjdl.exe
87b2cb3916261d5c807bf44262755cb0.exe
TimeDateMUICallback.exe
C87C.exe
dtkmujvo.exe
ifgxpers.exe
aPr0hY9.exe
wjthvwjb.dss
rool0_pk.exe
setex.exe

GARDA Virus DLL's to remove:

yaiiwockc.dll
wlsidten.dll
ieudator.dll
DLL321.dll
2084473.dll
wpbt0.dll
puozlkmyj.dll
xctqakcqbeo.dll
96dddda4.dll
ACEIEAddOn.dll
ex3b.dll
questscan.dll

GARDA Virus processes to kill:

oygqyunapnp.exe
securitywindrv.exe
NTServiceManager.exe
msdtmsrd.exe
wahneaqa.exe
00b5d693.exe
cf6640a77ed4926a4c6be661ab93def9d13408753dd07e8d02836996a2f247b6.exe
rool0_pk.exe
TimeDateMUICallback.exe
msnmsgrr.exe
Updating.exe
{097444e7-2d87-ba3c-2efe-9f54812d824a}.exe
msn.exe
WINDED6.exe
wgsdgsdgdsgsd.exe
C87C.exe
xaZYOVJW.exe
msavfit.exe
brenasa.exe
bf8h8d02hf.exe
sqlncli.exe
dtkmujvo.exe
OmaSG21e.exe
JfCqQ5JC.exe
mplayer2.exe
87b2cb3916261d5c807bf44262755cb0.exe
setex.exe
SyncHostps.exe
secproc_isv.exe
bvhylsviw.exe
Q3d38543.exe
3511172082012Build.exe
ssntvs.exe
Firewallservice.exe
pmstcdjwz.exe
m2PythonLoader.exe
systemcpl.exe
pYunY8m4VL3qLc.exe
svchost.exe
00qbipeq.exe
ubvhynpxh.exe
gcrwcoak.exe
xmlfilter.exe
VaultSysUi.exe
uenovfiu.exe
Piranha.exe
DA0B.exe
MusicCollector.exe
wlsidten.exe
UpgradeHelper.exe
UpdatePriv.exe
administration.exe
p1.exe
videotwisterSA.exe
rvcbcyks.exe
scvhost.exe
dyjdl.exe
bzsbkotiu.exe
WinSyncMetastore.exe
xlqbteeb.exe
csrsss.exe
Task Scheduler.exe
aPr0hY9.exe
ifgxpers.exe
50E1.exe
obvwo.exe
acuvzomo.exe
魔法桌面第三方主题破解补丁V1.1.exe
comeo.exe
iner.exe
idiokbbrv.exe
ctfmon.exe
najeoxtt.exe
crack.exe
install_0_msi.exe
taskhost.exe.exe
audipbrd.exe
zqmkrehUkpoKfsafsaZg.exe
Nbt.exe
msshell.exe
b34btbztdb0vavaw.exe
Disclaimer

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.