I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:
Free DownloadFully Functional 30-day Trial. No credit card is required.
Reviews. EULA. Privacy Policy. Uninstall.
WINSEARCHAGDL.EXE – Backdoor Maximus removal
File | MD5 | Virus Alias |
---|---|---|
WINSEARCHAGDL.EXE | 9f0a71f4cc34e1e65ae6796039f1f180 | Backdoor Maximus |
WINSEARCHAGDL.EXE size: 36864 bytes
Created files:
%Program Files%\Winsearchag\cleversearchag.dll
%Program Files%\Winsearchag\installwin.exe
%Program Files%\Winsearchag\Uninstall.exe
%Program Files%\Winsearchag\winsearchag.dll
%Program Files%\Winsearchag\winsearchagdl.exe
%SysDir%\INETKO.DLL
%SysDir%\winsearchaginst.exe
Autostart registry keys:
HKLM\Software\Classes\CLSID\{121AF540-2C98-4E1B-8816-4AEEAEE2F8A0}\InprocServer32 : %Program Files%\Winsearchag\cleversearchag.dll
HKLM\Software\Classes\CLSID\{3E64D91A-EE39-4D25-BA7B-5CCE22E8CF42}\InprocServer32 : %Program Files%\Winsearchag\winsearchag.dll
HKLM\Software\Classes\CLSID\{48E59293-9880-11CF-9754-00AA00C00908}\InprocServer32 : %WinDir%\System32\MSINET.OCX
HKLM\Software\Classes\CLSID\{48E59294-9880-11CF-9754-00AA00C00908}\InprocServer32 : %WinDir%\System32\MSINET.OCX
HKLM\Software\Classes\CLSID\{48E59295-9880-11CF-9754-00AA00C00908}\InprocServer32 : %WinDir%\System32\MSINET.OCX
Detected by UnHackMe:
WINSEARCHAGDL.EXE
Default location: %PROGRAM FILES%\WINSEARCHAG\WINSEARCHAGDL.EXE