Home Malware Programs Rogue Anti-Spyware Programs Windows Additional Guard

Windows Additional Guard

Posted: September 7, 2009

Windows Additional Guard is a fake spyware remover hailing from the same family as Malware Catcher, Windows Protection Suite, Ultimate Guard Pro and Windows Guard Pro. Through the use of trojan infections, Windows Additional Guard gains entry to your PC and from there, begins issuing dozens of annoying security alerts and bogus system scans that turn up nothing but fabricated infection results. These tactics are there to scare you into purchasing the rogue spyware remover Windows Additional Guard. Do not be fooled. Remove Windows Additional Guard as soon as it is detected.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\All Users\Application Data\345d567
    2 %Documents and Settings%\All Users\Application Data\345d567\578.mof
    3 %Documents and Settings%\All Users\Application Data\345d567\mozcrt19.dll
    4 %Documents and Settings%\All Users\Application Data\345d567\sqlite3.dll
    5 %Documents and Settings%\All Users\Application Data\345d567\WI345d.exe
    6 %Documents and Settings%\All Users\Application Data\345d567\WINAGSys
    7 %Documents and Settings%\All Users\Application Data\345d567\WINAGSys\vd952342.bd
    8 %Documents and Settings%\All Users\Application Data\WINAGSys
    9 %Documents and Settings%\All Users\Application Data\WINAGSys\winag.cfg
    10 %Program Files%\Mozilla Firefox\searchplugins\search.xml
    11 %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Additional Guard.lnk
    12 %UserProfile%\Application Data\Windows Additional Guard
    13 %UserProfile%\Application Data\Windows Additional Guard\cookies.sqlite
    14 %UserProfile%\Desktop\Windows Additional Guard.lnk
    15 %UserProfile%\Recent\ANTIGEN.tmp
    16 %UserProfile%\Recent\cb.exe
    17 %UserProfile%\Recent\CLSV.tmp
    18 %UserProfile%\Recent\ddv.dll
    19 %UserProfile%\Recent\dudl.drv
    20 %UserProfile%\Recent\energy.dll
    21 %UserProfile%\Recent\energy.sys
    22 %UserProfile%\Recent\exec.exe
    23 %UserProfile%\Recent\fan.drv
    24 %UserProfile%\Recent\FS.dll
    25 %UserProfile%\Recent\PE.drv
    26 %UserProfile%\Recent\ppal.exe
    27 %UserProfile%\Recent\SICKBOY.tmp
    28 %UserProfile%\Recent\tjd.sys
    29 %UserProfile%\Start Menu\Programs\Windows Additional Guard.lnk
    30 %UserProfile%\Start Menu\Windows Additional Guard.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "967907703"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Windows Additional Guard"HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes "URL" => http://search-gala.com/?&uid=7&q={searchTerms}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}HKEY_CLASSES_ROOT\WI345d.DocHostUIHandler

Related Posts

Loading...