Home Malware Programs Fake Warning Messages Trojan.Wincod - Trojan Found! Popup

Trojan.Wincod - Trojan Found! Popup

Posted: September 2, 2009

"Trojan.Wincod - Trojan Found!" Popup is a fake security alert generated by the fake spyware remover Personal Antivirus. "Trojan.Wincod - Trojan Found!" pop-up reads as follows:

"Trojan.Wincod - Trojan Found!
Trojan.Wincod is a Trojan horse that displays message boxes and modifies settings on the compromised computer."

"Trojan.Wincod - Trojan Found!" seeks to trick you into believing your PC is infected or has been compromised, prompting you to purchase and download Personal Antivirus in order to combat these threats. Do not be fooled, and remove Personal Antivirus as soon as possible.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Application Data\Personal Antivirus
    2 %UserProfile%\Application Data\Personal Antivirus\db
    3 c:\Documents and Settings\All Users\Start Menu\Programs\Personal Antivirus
    4 c:\Program Files\Personal Antivirus
    5 c:\Program Files\Personal Antivirus\db
    6 c:\Program Files\Personal Antivirus\Languages

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "PrS"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Personal Antivirus"HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ITGRDENGINEHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ITGrdEngineHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Personal Antivirus_is1
Loading...