Windows Additional Guard
Windows Additional Guard is a fake spyware remover hailing from the same family as Malware Catcher, Windows Protection Suite, Ultimate Guard Pro and Windows Guard Pro. Through the use of trojan infections, Windows Additional Guard gains entry to your PC and from there, begins issuing dozens of annoying security alerts and bogus system scans that turn up nothing but fabricated infection results. These tactics are there to scare you into purchasing the rogue spyware remover Windows Additional Guard. Do not be fooled. Remove Windows Additional Guard as soon as it is detected.
File System Modifications
- The following files were created in the system:
# File Name 1 %Documents and Settings%\All Users\Application Data\345d567 2 %Documents and Settings%\All Users\Application Data\345d567\578.mof 3 %Documents and Settings%\All Users\Application Data\345d567\mozcrt19.dll 4 %Documents and Settings%\All Users\Application Data\345d567\sqlite3.dll 5 %Documents and Settings%\All Users\Application Data\345d567\WI345d.exe 6 %Documents and Settings%\All Users\Application Data\345d567\WINAGSys 7 %Documents and Settings%\All Users\Application Data\345d567\WINAGSys\vd952342.bd 8 %Documents and Settings%\All Users\Application Data\WINAGSys 9 %Documents and Settings%\All Users\Application Data\WINAGSys\winag.cfg 10 %Program Files%\Mozilla Firefox\searchplugins\search.xml 11 %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Additional Guard.lnk 12 %UserProfile%\Application Data\Windows Additional Guard 13 %UserProfile%\Application Data\Windows Additional Guard\cookies.sqlite 14 %UserProfile%\Desktop\Windows Additional Guard.lnk 15 %UserProfile%\Recent\ANTIGEN.tmp 16 %UserProfile%\Recent\cb.exe 17 %UserProfile%\Recent\CLSV.tmp 18 %UserProfile%\Recent\ddv.dll 19 %UserProfile%\Recent\dudl.drv 20 %UserProfile%\Recent\energy.dll 21 %UserProfile%\Recent\energy.sys 22 %UserProfile%\Recent\exec.exe 23 %UserProfile%\Recent\fan.drv 24 %UserProfile%\Recent\FS.dll 25 %UserProfile%\Recent\PE.drv 26 %UserProfile%\Recent\ppal.exe 27 %UserProfile%\Recent\SICKBOY.tmp 28 %UserProfile%\Recent\tjd.sys 29 %UserProfile%\Start Menu\Programs\Windows Additional Guard.lnk 30 %UserProfile%\Start Menu\Windows Additional Guard.lnk
Registry Modifications
- The following newly produced Registry Values are:
HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "967907703"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Windows Additional Guard"HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes "URL" => http://search-gala.com/?&uid=7&q={searchTerms}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}HKEY_CLASSES_ROOT\WI345d.DocHostUIHandler
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.