Wednesday, July 4, 2012

The presence of VANGUARD.EXE file means that your PC is compromissed

All PC holders are at the risk group to detect VANGUARD.EXE hazardous file among decent ones. If you notice it on your PC, remove it without hesitation.


The short report of this malware analysis

Full path on a computer: %SysDir%\Vanguard.exe
VANGUARD.EXE is known under the name of Trojan.Lypserat

In the process of installation it adds the following registry entries:

 HKLM\Software\Microsoft\Active Setup\Installed Components\{51PRH-F2ER3-JV90G-1PXE8-DCQ9E}\StubPath: “%SysDir%\Vanguard.exe”
 HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Vanguard Server: “%SysDir%\Vanguard.exe”
 HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Vanguard Server: “%SysDir%\Vanguard.exe”

The files are caused by this malware

 %Temp%\CryptedFile.exe
 %SysDir%\Vanguard.exe

To neutralize its malicious activity, we recommend you to launch GridinSoft Trojan Killer, a reputable antivirus tool. It will remove this unwanted file and check your computer system for other insecure stuff.

VANGUARD.EXE file remover:

malware removal tool

No comments:

Post a Comment