Click on screenshot to zoom
Danger level 8
Type: Malware
Common infection symptoms:
  • Installs itself without permissions
  • Changes background
  • Normal system programs crash immediatelly

GARDA Virus

When you get infected with GARDA Virus you see a notification on your screen that says “Your computer has been blocked up for safety reasons listed below”. Unfortunately, GARDA Virus has nothing to do with computer safety, as it is a computer infected created by cyber criminals. They deny you desktop access in hopes of making you believe that you have committed a serious crime and now you need to pay (financially). However, do not succumb to these threats and remove GARDA Virus from your system as soon as you can. And while you are at it – remove all the other infections that are bound to be there.

GARDA Virus is part of the Ukash Virus group, just like FBI MoneyPak Virus and the most recent infections Australian Communications and Media Authority virus or Metropolitan British Police Virus. These computer threats are being distributed by Urausy Trojan, which means that you need to be extremely attentive when you browse the Internet or download various freeware applications. Avoid clicking on outgoing links to unreliable websites, and do not visit web pages that are full of adware and pop-up commercial ads – clicking on such an ad may result in getting infected with GARDA Virus at once.

This infection is intended for the computer users in Ireland. It is rather obvious, because it has Irish flag on its interface, as well the symbols and insignia of the Irish law enforcement authorities (The Guardians of the Peace of Ireland, The National Crime Prevention Unit). However, just because it is full of law enforcement authorities symbols it does not mean you need to trust it. The message displayed by GARDA Virus may seem threatening, but you need to realize that you have done nothing wrong, and the message is only a hoax designed to swindle you out of your money:

You are accused of viewing/storage and/or dissemination of banned pornography (child pornography/zoophilia/rape etc). You have violated World Declaration on non-proliferation of child pornography. You are accused of committing the crime envisaged by Article 161 of Ireland criminal law.

The penalty set must be paid in course of 48 hours as the breach. On expiration of the term, 48 hours that follow will be used for automatic collection of data on yourself and your misconduct, and criminal case will be opened against you.

Amount of fine is 100 Euro. You can settle the fine with Ukash or PaySafeCard vouchers.

By making use of Ukash and PaySafeCard, GARDA Virus is able to collect money even from those users who do not own a credit card or have a bank account. But that does not mean you have to be one of them. Follow the instructions below to unlock your PC and then remove GARDA Virus with a legitimate computer security tool. Do not hesitate to invest in your system security, because you can never know when another similar infection will arrive again.

How to restore desktop access

Windows 8

  1. Press Windows key for metro Start menu to show up.
  2. Click the built-in Internet Explorer tile.
  3. Type http://www.pcthreat.com/download-sph into the address bar and hit Enter.
  4. Click Run on the download dialog box and install SpyHunter.
  5. Scan your system.

Windows Vista & Windows 7

  1. Reboot the PC and press F8 repeatedly.
  2. When Advanced Boot Options menu shows up, select Safe Mode with Networking and press Enter.
  3. Access http://www.pcthreat.com/download-sph and download SpyHunter.
  4. Install the program and scan your PC.

Windows XP

  1. Follow the steps 1 and 2 above.
  2. Click Yes on a confirmation box.
  3. Download SpyHunter.
  4. Open Start menu and launch Run.
  5. Enter “msconfig” into the Open box and press OK.
  6. Select Startup tab on System Configuration Utility.
  7. Uncheck all programs on the list and press OK.
  8. Reboot the PC in Normal mode.
  9. Install SpyHunter and scan your system.

If you have any problem with GARDA Virus removal, feel free to leave a comment below and ask a question about it.

Download Spyware Removal Tool to Remove* GARDA Virus
  • Quick & tested solution for GARDA Virus removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove GARDA Virus

Files associated with GARDA Virus infection:

pmstcdjwz.exe
WINDED6.exe
%APPDATA%\Task Scheduler
taskhost.exe.exe
Task Scheduler.exe
scvhost.exe
2084473.dll
rool0_pk.exe
Other.res
87b2cb3916261d5c807bf44262755cb0.exe
setex.exe
WinSyncMetastore.exe
DA0B.exe
msavfit.exe
rvcbcyks.exe
JfCqQ5JC.exe
%UserProfile%
C87C.exe
OmaSG21e.exe
3511172082012Build.exe
wpbt0.dll
SyncHostps.exe
%SystemDrive%\????????????
TimeDateMUICallback.exe
skype.dat
audipbrd.exe
VaultSysUi.exe
%APPDATA%\updates
jsdhlexdqkllnbcxgai.bfg
wlsidten.dll
dtkmujvo.exe
ifgxpers.exe
{097444e7-2d87-ba3c-2efe-9f54812d824a}.exe
videotwisterSA.exe
UpgradeHelper.exe
acuvzomo.exe
aPr0hY9.exe
Firewallservice.exe
UpdatePriv.exe
%ALLUSERSPROFILE%\Application Data
puozlkmyj.dll
xmlfilter.exe
dyjdl.exe
MusicCollector.exe
xlqbteeb.exe
cf6640a77ed4926a4c6be661ab93def9d13408753dd07e8d02836996a2f247b6.exe
ubvhynpxh.exe
b34btbztdb0vavaw.exe
%LOCALAPPDATA%\Temp
n.
msdtmsrd.exe
securitywindrv.exe
oygqyunapnp.exe
wjthvwjb.dss
questscan.dll
iner.exe
bzsbkotiu.exe
00qbipeq.exe
pYunY8m4VL3qLc.exe
install_0_msi.exe
ssntvs.exe
msshell.exe
%WINDIR%\system32
administration.exe
msn.exe
%WINDIR%\Temp
NTServiceManager.exe
Nbt.exe
00b5d693.exe
wlsidten.exe
DLL321.dll
najeoxtt.exe
m2PythonLoader.exe
svchost.exe
dqnbdq7.dss
魔法桌面第三方主题破解补丁V1.1.exe
xaZYOVJW.exe
brenasa.exe
uenovfiu.exe
%AppData%
%ALLUSERSPROFILE%
Piranha.exe
gcrwcoak.exe
bvhylsviw.exe
Updating.exe
obvwo.exe
mplayer2.exe
hwj3ba6j.dss
%CommonProgramFiles%
ACEIEAddOn.dll
idiokbbrv.exe
comeo.exe
systemcpl.exe
sqlncli.exe
crack.exe
Q3d38543.exe
%APPDATA%\system
bf8h8d02hf.exe
ex3b.dll
ieudator.dll
csrsss.exe
xctqakcqbeo.dll
%LOCALAPPDATA%\lollipop
secproc_isv.exe
ctfmon.exe
yaiiwockc.dll
wgsdgsdgdsgsd.exe
50E1.exe
zqmkrehUkpoKfsafsaZg.exe
wahneaqa.exe
96dddda4.dll
msnmsgrr.exe
p1.exe
%TEMP%

GARDA Virus DLL's to remove:

wlsidten.dll
puozlkmyj.dll
2084473.dll
ieudator.dll
questscan.dll
ACEIEAddOn.dll
96dddda4.dll
DLL321.dll
yaiiwockc.dll
ex3b.dll
xctqakcqbeo.dll
wpbt0.dll

GARDA Virus processes to kill:

secproc_isv.exe
SyncHostps.exe
00qbipeq.exe
xlqbteeb.exe
systemcpl.exe
UpdatePriv.exe
rool0_pk.exe
install_0_msi.exe
VaultSysUi.exe
taskhost.exe.exe
msn.exe
msshell.exe
msavfit.exe
WINDED6.exe
pYunY8m4VL3qLc.exe
Task Scheduler.exe
OmaSG21e.exe
wlsidten.exe
JfCqQ5JC.exe
iner.exe
{097444e7-2d87-ba3c-2efe-9f54812d824a}.exe
wahneaqa.exe
bvhylsviw.exe
pmstcdjwz.exe
zqmkrehUkpoKfsafsaZg.exe
oygqyunapnp.exe
audipbrd.exe
TimeDateMUICallback.exe
comeo.exe
UpgradeHelper.exe
3511172082012Build.exe
魔法桌面第三方主题破解补丁V1.1.exe
setex.exe
securitywindrv.exe
MusicCollector.exe
Updating.exe
acuvzomo.exe
cf6640a77ed4926a4c6be661ab93def9d13408753dd07e8d02836996a2f247b6.exe
dtkmujvo.exe
wgsdgsdgdsgsd.exe
xaZYOVJW.exe
C87C.exe
bf8h8d02hf.exe
Firewallservice.exe
NTServiceManager.exe
m2PythonLoader.exe
WinSyncMetastore.exe
DA0B.exe
brenasa.exe
sqlncli.exe
svchost.exe
xmlfilter.exe
videotwisterSA.exe
Nbt.exe
obvwo.exe
rvcbcyks.exe
bzsbkotiu.exe
dyjdl.exe
idiokbbrv.exe
gcrwcoak.exe
msnmsgrr.exe
b34btbztdb0vavaw.exe
ubvhynpxh.exe
87b2cb3916261d5c807bf44262755cb0.exe
najeoxtt.exe
mplayer2.exe
ssntvs.exe
Q3d38543.exe
scvhost.exe
crack.exe
ctfmon.exe
p1.exe
00b5d693.exe
50E1.exe
administration.exe
aPr0hY9.exe
msdtmsrd.exe
Piranha.exe
uenovfiu.exe
ifgxpers.exe
csrsss.exe
Disclaimer

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.