Remove Adware Spyware and Malware

You are here: HOME > COMPUTER > ANTI SPYWARE

WinHound

Updated: 04- January-2006

Description:

WinHound silently installs itself to infected vulnerable computers. It can also be dropped by some parasites.

 

WinHound installs several other dangerous threats, changes the Internet Explorer default home page and the desktop wallpaper once execurted.

 

The new wallpaper warns the user that the system is infected with spyware and asks to download and install WinHound, which is a corrupt illegally distributed anti-spyware program.

 

It has the files:

Winhound.exe

WinhoundInstaller.exe

Technical Name:

WinHound

Threat Level:

Low

Type:

Adware

Systems Affected:

Windows All

 

Winhound removal procedures requires technical know-how on  computer troubleshooting. It is better to consult your LAN Administrator or Technical Persons to avoid additional damage on your computer if modifications on Services and Registry have to be done.
 

MANUAL REMOVAL:

1. Update your Antivirus definitions and run a full system scan.

2. Reboot the computer in "SafeMode"
3. Uninstall the security risk.

On the Windows taskbar:
- Click Start > Control Panel.
- In the Control Panel window, double-click Add or Remove Programs.
- Click Winhound Spyware Remover.

 

4. Delete any values added to the registry.

Navigate to the subkey and delete value:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value: "WinHound" = "%ProgramFiles%\Winhound\Winhound.exe"

Navigate to and delete the following subkeys:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0878F045-B52E-46B3-9724-D3AE69D50067}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0EA04667-E53B-4E81-8E7C-DE2CA114CBD6}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{265C2AF8-C94C-4AFF-B2B6-340D3982562C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3946A33D-BBC6-4792-A383-D855E0F76D91}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41D7BB0A-64E0-4AB2-BD0B-69EA78E462E8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4AA55E8C-2C19-4F3A-91EC-43B6DF937C4F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4F93062D-7BDA-48BE-AEB6-88AF2B1FE2D4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5206DF89-97FC-41AD-BAE3-993E87053A99}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{58E68548-42E2-479D-A9E0-86D9F2EAF02E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5E5A79A6-C67B-444E-BE58-BD0ACEFCDA07}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67196B3E-55A0-49DE-BA11-66F07DF804DB}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7198F8DA-012C-4DB4-ABD8-923A54C87900}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{82847700-FE61-46A3-B3EE-761A1E312ACA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C2A05C5-780F-4A2E-AE1C-FB8181F860E4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DCA6B3D-1FCA-4500-B210-76119BB5C69E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ACC647EE-991A-4811-B420-F063F50CDDC1}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C5B70256-5B08-4056-B84E-C6CE084967F5}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CBE4B748-08F9-44DB-8FB1-9AD25979DA35}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CDD964C2-FB78-4A74-BB1E-1CB1FCB72018}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D25F7446-4D36-4203-9EA5-5422B26FA9D0}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E12AAACF-8AF2-4C31-BA94-E3787B44F90E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E479197F-49E5-4E60-9FA2-A71D4C7C2BBC}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F880B4F2-75BF-44EC-B7AA-45EC37448027}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0BACA3C1-F734-4A5F-970A-15DBF7D3C09C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0D4385DF-F78A-4264-A32C-7DD4A72DE539}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{19A0B5C9-65FE-4D3B-8BDD-EFB7FE553C58}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{19C99256-D011-47E2-BC64-6322096E20A5}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2871B7AF-2D4C-478F-BE89-881881C272AB}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2B94CDFD-4A45-4B08-B105-54C709D07B28}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2C354A9B-A5DF-41A3-BF40-2D72FEAC14D3}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2C797AA0-978C-4AC2-BBB4-F89D410B614E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{54007809-0689-4A40-9D8F-94C79D87D931}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{557C3787-D066-496E-8CAF-BA47DA7365C1}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5C083B7E-A083-4B20-A7AD-7C8E29085494}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{649D371E-D3E3-4FC0-AC82-E91F73D8E79E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{655980F1-13D5-4DA2-9E80-AA56C36876CB}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AF126A9-B07A-4DE4-883E-28D3ECCD75D8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B436BDD-8B8B-4A1F-ADD5-E67B30C8F7DD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{71BF80FD-7E91-4730-B6E8-8F3E81F5C38B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{81723C8C-918F-4456-B7E8-A68CF7A10C6D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{82A10659-A1E5-4732-A839-C910D955C88B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{84844B27-0D53-4C71-AB24-0151B33AB02F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A8BCF2B9-ED19-4637-AC77-BF59F131FA1F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A9A73A66-B0E0-4FFB-828F-3A55E1FA4271}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B6049D5D-718F-44C0-B965-06840D27E206}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B817D284-1B82-4793-B1F3-58A06DAB03A1}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BC077DD0-42B5-451C-B78C-4AC97E4B116B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C123DBA0-52DF-4272-BBAA-BFD092D07C2E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CB9DD914-68B6-4710-A04E-4745470706CE}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DE1E317F-716A-4784-BA90-FDA6D6A8FAD5}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E36DCDBC-57AD-4A1C-B9C6-1161441B51CA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E51AC62C-E82E-4E60-97AB-C66C4969AF39}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EF5750B1-0ABA-45C5-BF12-FB4D1D1150D2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F1D9585E-20A6-4689-84C7-C19FE21C9A71}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F1E1A6B0-6CAC-471B-99C4-4DBADA883BE8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F8C9D1A9-B7B7-47CA-8B93-27C5B64D3A47}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{31E956BF-8CA9-4D75-B534-7EBC79770002}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6E9E448E-B195-4627-953C-5377FA9BBA36}
HKEY_LOCAL_MACHINE\Software\WinHound.com
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\WinHound spyware remover

Navigate to the subkey and delete value:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MSSYCLM
Value: "Start" = "0x15D6510B"

Navigate to the subkey and reset values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
Values:
"1200" = "3"
"1201" = "3"
"1400" = "1"

Navigate to the subkey and reset value:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
Value: "1201" = "1"

 

5. Exit registry editor and restart the computer.
 

6. In order to make sure that winhound is completely eliminated from your computer, carry out a full scan of your computer using AntiVirus and Antispyware Software. Another way to delete the virus using various Antivirus Program without the need to install can be done with Online Virus Scanner.

 

7. Winhound removal tools is also provided on this site. See below..

  FREE ON-LINE VIRUS SCANNER:   

Click here to proceed

 

  SPYWARE REMOVAL TOOLS:

Download and run any of these Anti-Spyware