Click on screenshot to zoom
Danger level 8
Type: Malware
Common infection symptoms:
  • Installs itself without permissions
  • Changes background
  • Normal system programs crash immediatelly

GARDA Virus

When you get infected with GARDA Virus you see a notification on your screen that says “Your computer has been blocked up for safety reasons listed below”. Unfortunately, GARDA Virus has nothing to do with computer safety, as it is a computer infected created by cyber criminals. They deny you desktop access in hopes of making you believe that you have committed a serious crime and now you need to pay (financially). However, do not succumb to these threats and remove GARDA Virus from your system as soon as you can. And while you are at it – remove all the other infections that are bound to be there.

GARDA Virus is part of the Ukash Virus group, just like FBI MoneyPak Virus and the most recent infections Australian Communications and Media Authority virus or Metropolitan British Police Virus. These computer threats are being distributed by Urausy Trojan, which means that you need to be extremely attentive when you browse the Internet or download various freeware applications. Avoid clicking on outgoing links to unreliable websites, and do not visit web pages that are full of adware and pop-up commercial ads – clicking on such an ad may result in getting infected with GARDA Virus at once.

This infection is intended for the computer users in Ireland. It is rather obvious, because it has Irish flag on its interface, as well the symbols and insignia of the Irish law enforcement authorities (The Guardians of the Peace of Ireland, The National Crime Prevention Unit). However, just because it is full of law enforcement authorities symbols it does not mean you need to trust it. The message displayed by GARDA Virus may seem threatening, but you need to realize that you have done nothing wrong, and the message is only a hoax designed to swindle you out of your money:

You are accused of viewing/storage and/or dissemination of banned pornography (child pornography/zoophilia/rape etc). You have violated World Declaration on non-proliferation of child pornography. You are accused of committing the crime envisaged by Article 161 of Ireland criminal law.

The penalty set must be paid in course of 48 hours as the breach. On expiration of the term, 48 hours that follow will be used for automatic collection of data on yourself and your misconduct, and criminal case will be opened against you.

Amount of fine is 100 Euro. You can settle the fine with Ukash or PaySafeCard vouchers.

By making use of Ukash and PaySafeCard, GARDA Virus is able to collect money even from those users who do not own a credit card or have a bank account. But that does not mean you have to be one of them. Follow the instructions below to unlock your PC and then remove GARDA Virus with a legitimate computer security tool. Do not hesitate to invest in your system security, because you can never know when another similar infection will arrive again.

How to restore desktop access

Windows 8

  1. Press Windows key for metro Start menu to show up.
  2. Click the built-in Internet Explorer tile.
  3. Type http://www.pcthreat.com/download-sph into the address bar and hit Enter.
  4. Click Run on the download dialog box and install SpyHunter.
  5. Scan your system.

Windows Vista & Windows 7

  1. Reboot the PC and press F8 repeatedly.
  2. When Advanced Boot Options menu shows up, select Safe Mode with Networking and press Enter.
  3. Access http://www.pcthreat.com/download-sph and download SpyHunter.
  4. Install the program and scan your PC.

Windows XP

  1. Follow the steps 1 and 2 above.
  2. Click Yes on a confirmation box.
  3. Download SpyHunter.
  4. Open Start menu and launch Run.
  5. Enter “msconfig” into the Open box and press OK.
  6. Select Startup tab on System Configuration Utility.
  7. Uncheck all programs on the list and press OK.
  8. Reboot the PC in Normal mode.
  9. Install SpyHunter and scan your system.

If you have any problem with GARDA Virus removal, feel free to leave a comment below and ask a question about it.

Download Spyware Removal Tool to Remove* GARDA Virus
  • Quick & tested solution for GARDA Virus removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove GARDA Virus

Files associated with GARDA Virus infection:

%APPDATA%\system
scvhost.exe
%WINDIR%\system32
m2PythonLoader.exe
ssntvs.exe
setex.exe
Piranha.exe
n.
csrsss.exe
JfCqQ5JC.exe
%LOCALAPPDATA%\lollipop
xaZYOVJW.exe
%TEMP%
rool0_pk.exe
%APPDATA%\updates
uenovfiu.exe
SyncHostps.exe
msnmsgrr.exe
obvwo.exe
svchost.exe
skype.dat
comeo.exe
taskhost.exe.exe
%AppData%
pYunY8m4VL3qLc.exe
Firewallservice.exe
%APPDATA%\Task Scheduler
pmstcdjwz.exe
oygqyunapnp.exe
p1.exe
dtkmujvo.exe
msshell.exe
%ALLUSERSPROFILE%\Application Data
bf8h8d02hf.exe
yaiiwockc.dll
msavfit.exe
xctqakcqbeo.dll
ieudator.dll
administration.exe
xmlfilter.exe
rvcbcyks.exe
wahneaqa.exe
securitywindrv.exe
OmaSG21e.exe
50E1.exe
sqlncli.exe
msn.exe
gcrwcoak.exe
acuvzomo.exe
b34btbztdb0vavaw.exe
%WINDIR%\Temp
cf6640a77ed4926a4c6be661ab93def9d13408753dd07e8d02836996a2f247b6.exe
audipbrd.exe
zqmkrehUkpoKfsafsaZg.exe
systemcpl.exe
videotwisterSA.exe
Other.res
魔法桌面第三方主题破解补丁V1.1.exe
wpbt0.dll
bzsbkotiu.exe
crack.exe
{097444e7-2d87-ba3c-2efe-9f54812d824a}.exe
wlsidten.exe
%LOCALAPPDATA%\Temp
WINDED6.exe
87b2cb3916261d5c807bf44262755cb0.exe
Task Scheduler.exe
TimeDateMUICallback.exe
3511172082012Build.exe
brenasa.exe
aPr0hY9.exe
%ALLUSERSPROFILE%
puozlkmyj.dll
00qbipeq.exe
jsdhlexdqkllnbcxgai.bfg
C87C.exe
2084473.dll
wlsidten.dll
Nbt.exe
%SystemDrive%\????????????
msdtmsrd.exe
UpgradeHelper.exe
DA0B.exe
Updating.exe
idiokbbrv.exe
96dddda4.dll
questscan.dll
hwj3ba6j.dss
%CommonProgramFiles%
NTServiceManager.exe
install_0_msi.exe
xlqbteeb.exe
Q3d38543.exe
dyjdl.exe
MusicCollector.exe
najeoxtt.exe
00b5d693.exe
dqnbdq7.dss
VaultSysUi.exe
DLL321.dll
wjthvwjb.dss
secproc_isv.exe
ACEIEAddOn.dll
bvhylsviw.exe
ubvhynpxh.exe
UpdatePriv.exe
ctfmon.exe
mplayer2.exe
ifgxpers.exe
WinSyncMetastore.exe
iner.exe
ex3b.dll
%UserProfile%
wgsdgsdgdsgsd.exe

GARDA Virus DLL's to remove:

DLL321.dll
wlsidten.dll
puozlkmyj.dll
ACEIEAddOn.dll
96dddda4.dll
wpbt0.dll
xctqakcqbeo.dll
yaiiwockc.dll
2084473.dll
ieudator.dll
questscan.dll
ex3b.dll

GARDA Virus processes to kill:

Firewallservice.exe
zqmkrehUkpoKfsafsaZg.exe
Piranha.exe
pmstcdjwz.exe
p1.exe
DA0B.exe
Task Scheduler.exe
UpdatePriv.exe
mplayer2.exe
xlqbteeb.exe
scvhost.exe
m2PythonLoader.exe
uenovfiu.exe
msshell.exe
oygqyunapnp.exe
idiokbbrv.exe
rvcbcyks.exe
rool0_pk.exe
setex.exe
bf8h8d02hf.exe
00b5d693.exe
cf6640a77ed4926a4c6be661ab93def9d13408753dd07e8d02836996a2f247b6.exe
3511172082012Build.exe
MusicCollector.exe
WinSyncMetastore.exe
aPr0hY9.exe
00qbipeq.exe
audipbrd.exe
iner.exe
crack.exe
C87C.exe
OmaSG21e.exe
bvhylsviw.exe
systemcpl.exe
msdtmsrd.exe
videotwisterSA.exe
brenasa.exe
dtkmujvo.exe
comeo.exe
xmlfilter.exe
b34btbztdb0vavaw.exe
install_0_msi.exe
Q3d38543.exe
50E1.exe
secproc_isv.exe
administration.exe
sqlncli.exe
魔法桌面第三方主题破解补丁V1.1.exe
TimeDateMUICallback.exe
VaultSysUi.exe
ctfmon.exe
csrsss.exe
xaZYOVJW.exe
wahneaqa.exe
WINDED6.exe
wgsdgsdgdsgsd.exe
ubvhynpxh.exe
msavfit.exe
acuvzomo.exe
87b2cb3916261d5c807bf44262755cb0.exe
obvwo.exe
Updating.exe
UpgradeHelper.exe
NTServiceManager.exe
securitywindrv.exe
svchost.exe
taskhost.exe.exe
najeoxtt.exe
bzsbkotiu.exe
{097444e7-2d87-ba3c-2efe-9f54812d824a}.exe
ssntvs.exe
pYunY8m4VL3qLc.exe
dyjdl.exe
Nbt.exe
msn.exe
ifgxpers.exe
gcrwcoak.exe
JfCqQ5JC.exe
SyncHostps.exe
msnmsgrr.exe
wlsidten.exe
Disclaimer

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.