Home Malware Programs Rogue Anti-Spyware Programs Windows Additional Guard

Windows Additional Guard

Posted: September 7, 2009

Windows Additional Guard is a fake spyware remover hailing from the same family as Malware Catcher, Windows Protection Suite, Ultimate Guard Pro and Windows Guard Pro. Through the use of trojan infections, Windows Additional Guard gains entry to your PC and from there, begins issuing dozens of annoying security alerts and bogus system scans that turn up nothing but fabricated infection results. These tactics are there to scare you into purchasing the rogue spyware remover Windows Additional Guard. Do not be fooled. Remove Windows Additional Guard as soon as it is detected.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\All Users\Application Data\345d567
    2 %Documents and Settings%\All Users\Application Data\345d567\578.mof
    3 %Documents and Settings%\All Users\Application Data\345d567\mozcrt19.dll
    4 %Documents and Settings%\All Users\Application Data\345d567\sqlite3.dll
    5 %Documents and Settings%\All Users\Application Data\345d567\WI345d.exe
    6 %Documents and Settings%\All Users\Application Data\345d567\WINAGSys
    7 %Documents and Settings%\All Users\Application Data\345d567\WINAGSys\vd952342.bd
    8 %Documents and Settings%\All Users\Application Data\WINAGSys
    9 %Documents and Settings%\All Users\Application Data\WINAGSys\winag.cfg
    10 %Program Files%\Mozilla Firefox\searchplugins\search.xml
    11 %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Additional Guard.lnk
    12 %UserProfile%\Application Data\Windows Additional Guard
    13 %UserProfile%\Application Data\Windows Additional Guard\cookies.sqlite
    14 %UserProfile%\Desktop\Windows Additional Guard.lnk
    15 %UserProfile%\Recent\ANTIGEN.tmp
    16 %UserProfile%\Recent\cb.exe
    17 %UserProfile%\Recent\CLSV.tmp
    18 %UserProfile%\Recent\ddv.dll
    19 %UserProfile%\Recent\dudl.drv
    20 %UserProfile%\Recent\energy.dll
    21 %UserProfile%\Recent\energy.sys
    22 %UserProfile%\Recent\exec.exe
    23 %UserProfile%\Recent\fan.drv
    24 %UserProfile%\Recent\FS.dll
    25 %UserProfile%\Recent\PE.drv
    26 %UserProfile%\Recent\ppal.exe
    27 %UserProfile%\Recent\SICKBOY.tmp
    28 %UserProfile%\Recent\tjd.sys
    29 %UserProfile%\Start Menu\Programs\Windows Additional Guard.lnk
    30 %UserProfile%\Start Menu\Windows Additional Guard.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "967907703"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Windows Additional Guard"HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes "URL" => http://search-gala.com/?&uid=7&q={searchTerms}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}HKEY_CLASSES_ROOT\WI345d.DocHostUIHandler

Use SpyHunter to Detect and Remove PC Threats

If you are concerned that malware or PC threats similar to Windows Additional Guard may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.

* See Free Trial offer below. EULA and Privacy/Cookie Policy.

Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.

Related Posts

Loading...
Spywareremove.com uses cookies to provide you with a better browsing experience and analyze how users navigate and utilize the Site. By using this Site or clicking on "OK", you consent to the use of cookies. Learn more.