Windows Additional Guard
Windows Additional Guard is a fake spyware remover hailing from the same family as Malware Catcher, Windows Protection Suite, Ultimate Guard Pro and Windows Guard Pro. Through the use of trojan infections, Windows Additional Guard gains entry to your PC and from there, begins issuing dozens of annoying security alerts and bogus system scans that turn up nothing but fabricated infection results. These tactics are there to scare you into purchasing the rogue spyware remover Windows Additional Guard. Do not be fooled. Remove Windows Additional Guard as soon as it is detected.
File System Modifications
- The following files were created in the system:
# File Name 1 %Documents and Settings%\All Users\Application Data\345d567 2 %Documents and Settings%\All Users\Application Data\345d567\578.mof 3 %Documents and Settings%\All Users\Application Data\345d567\mozcrt19.dll 4 %Documents and Settings%\All Users\Application Data\345d567\sqlite3.dll 5 %Documents and Settings%\All Users\Application Data\345d567\WI345d.exe 6 %Documents and Settings%\All Users\Application Data\345d567\WINAGSys 7 %Documents and Settings%\All Users\Application Data\345d567\WINAGSys\vd952342.bd 8 %Documents and Settings%\All Users\Application Data\WINAGSys 9 %Documents and Settings%\All Users\Application Data\WINAGSys\winag.cfg 10 %Program Files%\Mozilla Firefox\searchplugins\search.xml 11 %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Additional Guard.lnk 12 %UserProfile%\Application Data\Windows Additional Guard 13 %UserProfile%\Application Data\Windows Additional Guard\cookies.sqlite 14 %UserProfile%\Desktop\Windows Additional Guard.lnk 15 %UserProfile%\Recent\ANTIGEN.tmp 16 %UserProfile%\Recent\cb.exe 17 %UserProfile%\Recent\CLSV.tmp 18 %UserProfile%\Recent\ddv.dll 19 %UserProfile%\Recent\dudl.drv 20 %UserProfile%\Recent\energy.dll 21 %UserProfile%\Recent\energy.sys 22 %UserProfile%\Recent\exec.exe 23 %UserProfile%\Recent\fan.drv 24 %UserProfile%\Recent\FS.dll 25 %UserProfile%\Recent\PE.drv 26 %UserProfile%\Recent\ppal.exe 27 %UserProfile%\Recent\SICKBOY.tmp 28 %UserProfile%\Recent\tjd.sys 29 %UserProfile%\Start Menu\Programs\Windows Additional Guard.lnk 30 %UserProfile%\Start Menu\Windows Additional Guard.lnk
Registry Modifications
- The following newly produced Registry Values are:
HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "967907703"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Windows Additional Guard"HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes "URL" => http://search-gala.com/?&uid=7&q={searchTerms}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}HKEY_CLASSES_ROOT\WI345d.DocHostUIHandler
Use SpyHunter to Detect and Remove PC Threats
If you are concerned that malware or PC threats similar to Windows Additional Guard may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.
* See Free Trial offer below. EULA and Privacy/Cookie Policy.
Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.