March 6th, 2009 O4, Rogue Antispyware/Antivirus, Run
This is an harmful program.
Name: proas2009
Filename: proas2009.exe
Command: C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\proas2009.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKCU\..\Run: [Pro Antispyware 2009] “C:\Documents and Settings\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\proas2009.exe” /autorun
Description: main file of Pro Antispyware 2009
Notes: Pro Antispyware 2009 is a rogue antispyware program
How to remove: use the instructions How to remove Pro Antispyware 2009 (Antispyware Pro 2009) Delete instructions
March 6th, 2009 O4, Rogue Antispyware/Antivirus, Run
This is an harmful program.
Name: AntiSpyware Pro
Filename: AntiSpyware Pro.exe
Command: C:\Program Files\AntiSpyware Pro\AntiSpyware Pro.exe
Startup Type: HKLM->run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [AntiSpyware Pro] “C:\Program Files\AntiSpyware Pro\AntiSpyware Pro.exe” hide
Description: main file Antispyware Pro 2009
Notes: Antispyware Pro 2009 is a rogue antispyware
How to remove: use the instructions How to remove Pro Antispyware 2009 (Antispyware Pro 2009) Delete instructions
March 6th, 2009 Sound drivers, Trojan
This is an harmful program.
Name: wdmaud
Filename: wdmaud.sys
Registry key:
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“aux2″=”wdmaud.sys”
Command: C:\Windows\system32\wdmaud.sys
Startup Type: Sound drivers
Description: C:\Windows\system32\wdmaud.sys is a trojan/Google redirect also known as Rootkit.Win32.Agent.fwt. The legitimate wdmaud.sys actually exists at C:\Windows\system32\drivers\
How to remove: use the instructions How to remove Google searches redirect virus 7.7.7.0 (remove Rootkit.Win32.Agent.fwt)
March 6th, 2009 BHO, O2, Rogue Antispyware/Antivirus, Trojan
This is an harmful program.
Name: winconfig
Filename: winconfig.dll
Command: C:\Windows\System32\winconfig.dll
CLSID: {D263FA6D-84CC-48A8-9AF6-C664362B7A5B}
Startup Type: BHO
HijackThis Category: O2
HijackThis Line:
O2 – BHO: (no name) – {D263FA6D-84CC-48A8-9AF6-C664362B7A5B} – C:\Windows\System32\winconfig.dll
Description: trojan fake-alert, component of Antivirus 360
How to remove: use the instructions How to remove Antivirus 360
March 1st, 2009 Trojan
This is an harmful program.
Name: winscenter
Filename: winscenter.exe
Command: %windir%\System32\winscenter.exe
Description: Trojan FakeAlert
How to remove: Use Malwarebytes Antimalware
March 1st, 2009 Trojan
This is an harmful program.
Name: SysLoader
Filename: SysLoader.exe
Command: %programfiles%\SysLoader.exe
Description: trojan FakeAlert
How to remove: Use Malwarebytes Antimalware
March 1st, 2009 O4, Rogue Antispyware/Antivirus, RunOnce
This is an harmful program.
Name: rkgnd
Filename: rkgnd.exe
Command: C:\Program Files\Common Files\System\mgnc\rkgnd.exe
Startup Type:HKLM->RunOnce
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\RunOnce: [39173992539183281] C:\Program Files\Common Files\System\mgnc\rkgnd.exe
Description: component of ANG AntiVirus 09
How to remove: use these instructions How to remove ANG AntiVirus 09 or use HijackThis
March 1st, 2009 O4, Rogue Antispyware/Antivirus, Run
This is an harmful program.
Name: angpd
Filename: angpd.exe
Command: C:\Program Files\Common Files\System\mgnc\angpd.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [62964419826679261] C:\Program Files\Common Files\System\mgnc\angpd.exe
Description: component of ANG AntiVirus 09
How to remove: use the instructions How to remove ANG AntiVirus 09 (Delete instructions) or use HijackThis.
March 1st, 2009 O4, Rogue Antispyware/Antivirus, Run
This is an harmful program.
Name: WiniGuard
Filename: WiniGuard.exe
Command: c:\program files\winiguard software\winiguard\WiniGuard.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [WiniGuard] “c:\program files\winiguard software\winiguard\WiniGuard.exe” -min
Description: main component of WiniGuard (rogue antispyware)
How to remove: use these instructions How to remove WiniGuard (Delete instructions)
March 1st, 2009 O4, Run, Trojan
This is an harmful program.
Name: baloon
Filename: baloon.exe
Command: c:\windows\system32\baloon.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [c:\windows\system32\baloon.exe] c:\windows\system32\baloon.exe
Description: trojan FakeAlert (Found with WiniGuard)
How to remove: use these instructions How to remove WiniGuard or Use HijackThis