Dmitry Sokolov recommends UnHackMe!
UnHackMe is a powerful tool against malware.UnHackMe quickly removes rootkits/malware/adware/browser hijack issues!
Adware.CloudGuard also known as Riskware.Win32.DnsChange.eayqrh, Gen:Variant.Adware.DNSUnlocker.1, AdWare.MSIL.rca.
Malware Analysis of Adware.CloudGuard – DNSWILLISTON.EXE
Created files:
%Program Files%\DNS Unlocker\DnsMonitoring.dll
%Program Files%\DNS Unlocker\DNSWILLISTON.cer
%Program Files%\DNS Unlocker\dnswilliston.exe
%Program Files%\DNS Unlocker\Info.rtf
%Program Files%\DNS Unlocker\License.rtf
Autostart registry keys:
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\DNSUnlocker.ns\DisplayName: “DNS Unlocker”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\DNSUnlocker.ns\UninstallString: “”%Program Files%\DNS Unlocker\unins.exe””
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{E1527582-8509-4011-B922-29E3FB548882}_is1\UninstallString: “”%Program Files%\DNS Unlocker\unins000.exe””
HKLM\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}\StubPath: “”%Program Files%\Google\Chrome\Application\51.0.2704.84\Installer\chrmstp.exe” –configure-user-settings –verbose-logging –system-level –multi-install –chrome”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome\UninstallString: “”%Program Files%\Google\Chrome\Application\51.0.2704.84\Installer\setup.exe” –uninstall –multi-install –chrome –system-level”
Detected by UnHackMe:
DNSWILLISTON.EXE
Default location: %PROGRAM FILES%\DNS UNLOCKER\DNSWILLISTON.EXE
Dropper hash(md5): d025d2209801a76d274759bab96f398e
UnHackMe
removes malware invisible for your antivirus!
UnHackMe is 100% CLEAN, which means it does not contain any form of malware, including adware, spyware, viruses, trojans and backdoors. VirusTotal (0/56).
System Requirements: Windows 2000-Windows 8.1/10. UnHackMe uses minimum of computer resources.