The Network Security. Org

RSS Feed

How to dump Windows piracy spyware

April 28th, 2006 · No Comments


Man, I couldn’t believe it was Microsoft who finally got my system infested with spyware! An Spywareunkillable process? Popup windows? A prompt you have to click at logon? My GOD!!! But it’s ok. You CAN get rid of it:

There are 2 parts to this spyware popup: WGAtray.exe and wgalogon.dll. Killing the WGAtray.exe process causes it to reappear in 1 second. With it present, WGAlogon cannot be deleted. And you can’t delete it while it’s running. Seem impossible? Nah.

First, you need to have an Explorer window open and pointing to the C:\windows\system32 folder, where the spyware resides (interestingly, doing a hard drive search for "wgatray" turns up nothing- clever spyware, this is!). And you have to have Task Manager open, right beside the Explorer window. This is tricky, and must be done fast- you kill the process in Task Manager, and before the spyware can reopen itself, you must delete WGAtray.exe in the Explorer window. You only have a split second, but it is possible. Once the spyware .exe is gone, you must reboot your computer. How to dump Windows’ piracy ’spyware’

From around the Web

0 comments for this entry ↓

  • There are no comments yet for this entry.

You must log in to post a comment.

  • Advertisments