Home Malware Programs Rogue Anti-Spyware Programs Warning! Win32/Adware.Virtumonde

Warning! Win32/Adware.Virtumonde

Posted: August 26, 2008

"Warning! Win32/Adware.Virtumonde" is a fake warning message displayed by rogue anti-spyware program XP-Guard. "Warning! Win32/Adware.Virtumonde" is a message designed to make you believe you are infected with spyware. "Warning! Win32/Adware.Virtumonde" will try to trick you and push you into purchasing XP-Guard. "Warning! Win32/Adware.Virtumonde"'s entire message may read:

"WARNING! Spyware detected on your computer! Install an antivirus or spyware remover to clean your computer.
Warning! Win32/Adware.Virtumonde
Warning! Win32/privacyremover.M64"

If you click on the message, you will most likely be redirected to XP-Guard's website or other rogue websites that promotes XP-Guard as a legitimate software. Blocking the "Warning! Win32/Adware.Virtumonde" popup is not a solution. You need to remove the Trojan that is generating this fake warning message.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Desktop\XP-Guard.lnk
    2 %UserProfile%\Start Menu\Programs\XPGuard\XP-Guard Web Site.lnk
    3 %UserProfile%\Start Menu\Programs\XPGuard\XP-Guard.lnk
    4 c:\Program Files\XPGuard\INSTALL.LOG
    5 c:\Program Files\XPGuard\XP-Guard Web Site.url
    6 unwise.exe
    7 XP-Guard.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\XPGuardHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}XP-Guard
Loading...