Home Malware Programs Trojans Win32/Adware.Virtumonde

Win32/Adware.Virtumonde

Posted: August 19, 2008

Win32/Adware.Virtumonde is an imaginary Trojan name used to threaten and trick users into buying the rogue anti-spyware application XP-Guard. The user gets infected after downloading the video codec that infects the computer with a nasty Trojan. In most cases, the trojan that infects the PC is called Zlob.

Zlob then displays false warning messages stating "Your browser was hijacked by Win32/Adware.Virtumonde" and recommends to download a rogue anti-spyware program, most probably XP-Guard, to allegedly remove Win32/Adware.Virtumonde. However, XP-Guard will not remove Win32/Adware.Virtumonde or fix your PC of other threats but may actually expose you to more security threats.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Desktop\XP-Guard.lnk
    2 %UserProfile%\Start Menu\Programs\XPGuard\XP-Guard Web Site.lnk
    3 %UserProfile%\Start Menu\Programs\XPGuard\XP-Guard.lnk
    4 c:\Program Files\XPGuard\install.log
    5 c:\Program Files\XPGuard\unwise.exe
    6 c:\Program Files\XPGuard\XP-Guard Web Site.url
    7 c:\Program Files\XPGuard\XP-Guard.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "XPGuard"HKEY_CURRENT_USER\Software\XPGuardHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}XP-Guard

Related Posts

2 Comments

  • RACHEL GOLIATH says:

    I have followed all the steps, my computer could not detect the win32 virus. however this big red warning is still stuck on my screen!

  • Jeff Swope says:

    Best way I found to remove it was blow out my partition with fdisk, recreate it and then created a new NTFS partition and used my factory ghost images to restore.

Loading...