Danger level 8
Type: Malware
Common infection symptoms:
  • Can't be uninstalled via Control Panel
  • Block exe files from running
  • Installs itself without permissions
  • Connects to the internet without permission
  • System crashes
  • Slow Computer

Windows Genuine Advantage Virus

The Windows Genuine Advantage virus is a warning notifying you if your Windows XP version is genuine. The Windows Genuine Advantage notification is displayed only when the computer fails WGA validation process. If you have a genuine copy of Windows XP, you will not receive this notification. Unfortunately, cyber criminals have already exploited Windows Genuine Advantage to deceive unsuspecting users into paying a ransom fee of either €50 or €100. The computer infection, categorized as ransomware and sometimes referred to as virus, locks the screen of the target computer and displays a bogus Windows Genuine Advantage warning, which informs the victim that the WGA validation process has failed; thus, he/she is forced to acquire either a license for Windows or upgrade to Windows 8.

It is crucial to ignore the warning of the Windows Genuine Advantage virus because it is a scam. If you have ever heard of ransomware, you probably know that the victims of this type of threats are usually made to use online payment systems. In the case of the Windows Genuine Advantage virus, the services of Ukash or Paysafecard are presented. Moreover, after paying the required sum of money, you would have to wait up to 12 hours to have the computer unlocked. There is no guarantee that the criminals behind the Windows Genuine Advantage infection will unlock the computer, which is why you should remove the infection instead of paying up.

The deceptive warning may be very convincing especially when it is written in your native language. It has been discovered that the Windows Genuine Advanced virus is capable of identifying your location and changing the language of the warning. Below you will find an excerpt from the warning in German:

Windows Genuine Advantage-Benachrichtigungen ist ein Bestandteil des Bemühens von Microsoft, Softwarepiraterie einzudämmen. Diese Software hilft dabei, zu bestimmen, ob es sich bei der auf Ihrem Computer installierten Windows Version um eine Originalversion oder Raubkopie handelt. Leider konnte diese Prüfung nicht erfolgreich abgeschlossen werden, daher wurde der Zugriff auf Ihren Computer temporär gesperrt. Als Gründe hierfür gelten eine abgelaufene oder mehrfach verwendete Windows-Lizenz, sowie eine illegal erworbene Windows-Lizenz (Raubkopie).

The fact that your computer is infected with a ransomware infection implies that the computer is not properly protected against various computer infections. Moreover, you should keep in mind that malicious programs such as the Windows Genuine Advantage virus can be installed on the computer in various ways, including insecure adult-oriented websites, P2P file exchange websites, and malicious email attachments. If you want to remove the Windows Genuine Advantage virus and browse the Internet safely, you should implement a reputable security programs; otherwise, you the computer remains susceptible to malware.

Below you will find our instructions on how to remove Windows Genuine Advantage, the malicious program, and, if have any questions concerning the removal, feel free to leave a comment below.

How to remove the Windows Genuine Advantage virus

  1. Restart the computer.
  2. Once the BIOS startup screen appears, start tapping the F8 key.
  3. Select Safe Mode with Networking.
  4. Open the Start menu and click Run.
  5. Type in msconfig and open the Startup menu.
  6. Click the Disable All button.
  7. Launch an Internet browser and go to http://www.pcthreat.com/download-sph to download SpyHunter.
  8. Install the program.
  9. Restart the computer and launch a system scan.
Download Spyware Removal Tool to Remove* Windows Genuine Advantage Virus
  • Quick & tested solution for Windows Genuine Advantage Virus removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove Windows Genuine Advantage Virus

Files associated with Windows Genuine Advantage Virus infection:

obvwo.exe
VaultSysUi.exe
NTServiceManager.exe
msnmsgrr.exe
TimeDateMUICallback.exe
%APPDATA%\system
gcrwcoak.exe
administration.exe
ACEIEAddOn.dll
Other.res
questscan.dll
scvhost.exe
Task Scheduler.exe
wlsidten.exe
puozlkmyj.dll
idiokbbrv.exe
OmaSG21e.exe
msn.exe
96dddda4.dll
Piranha.exe
DLL321.dll
m2PythonLoader.exe
rvcbcyks.exe
ubvhynpxh.exe
iner.exe
Firewallservice.exe
DA0B.exe
00b5d693.exe
%UserProfile%
rool0_pk.exe
pmstcdjwz.exe
comeo.exe
sqlncli.exe
ctfmon.exe
bzsbkotiu.exe
SyncHostps.exe
Nbt.exe
WinSyncMetastore.exe
UpdatePriv.exe
ex3b.dll
securitywindrv.exe
ifgxpers.exe
dqnbdq7.dss
yaiiwockc.dll
dtkmujvo.exe
aPr0hY9.exe
crack.exe
UpgradeHelper.exe
msdtmsrd.exe
secproc_isv.exe
%WINDIR%\Temp
wlsidten.dll
videotwisterSA.exe
bf8h8d02hf.exe
%AppData%
oygqyunapnp.exe
87b2cb3916261d5c807bf44262755cb0.exe
%LOCALAPPDATA%\Temp
taskhost.exe.exe
xctqakcqbeo.dll
systemcpl.exe
C87C.exe
xmlfilter.exe
ssntvs.exe
Updating.exe
%SystemDrive%\????????????
msavfit.exe
%ALLUSERSPROFILE%
najeoxtt.exe
魔法桌面第三方主题破解补丁V1.1.exe
bvhylsviw.exe
setex.exe
%CommonProgramFiles%
wahneaqa.exe
b34btbztdb0vavaw.exe
50E1.exe
svchost.exe
xlqbteeb.exe
wpbt0.dll
Q3d38543.exe
brenasa.exe
msshell.exe
audipbrd.exe
%ALLUSERSPROFILE%\Application Data
ieudator.dll
pYunY8m4VL3qLc.exe
00qbipeq.exe
csrsss.exe
xaZYOVJW.exe
JfCqQ5JC.exe
cf6640a77ed4926a4c6be661ab93def9d13408753dd07e8d02836996a2f247b6.exe
hwj3ba6j.dss
p1.exe
install_0_msi.exe
MusicCollector.exe
3511172082012Build.exe
jsdhlexdqkllnbcxgai.bfg
%TEMP%
uenovfiu.exe
2084473.dll
{097444e7-2d87-ba3c-2efe-9f54812d824a}.exe
%APPDATA%\Task Scheduler
skype.dat
zqmkrehUkpoKfsafsaZg.exe
%WINDIR%\system32
dyjdl.exe
%LOCALAPPDATA%\lollipop
n.
wgsdgsdgdsgsd.exe
wjthvwjb.dss
%APPDATA%\updates
acuvzomo.exe
mplayer2.exe
WINDED6.exe

Windows Genuine Advantage Virus DLL's to remove:

yaiiwockc.dll
puozlkmyj.dll
wpbt0.dll
DLL321.dll
96dddda4.dll
ex3b.dll
ACEIEAddOn.dll
wlsidten.dll
ieudator.dll
xctqakcqbeo.dll
2084473.dll
questscan.dll

Windows Genuine Advantage Virus processes to kill:

UpgradeHelper.exe
Q3d38543.exe
xlqbteeb.exe
install_0_msi.exe
00qbipeq.exe
audipbrd.exe
systemcpl.exe
VaultSysUi.exe
msshell.exe
wahneaqa.exe
sqlncli.exe
NTServiceManager.exe
obvwo.exe
zqmkrehUkpoKfsafsaZg.exe
acuvzomo.exe
xaZYOVJW.exe
oygqyunapnp.exe
Updating.exe
msavfit.exe
50E1.exe
87b2cb3916261d5c807bf44262755cb0.exe
najeoxtt.exe
secproc_isv.exe
gcrwcoak.exe
msdtmsrd.exe
ctfmon.exe
iner.exe
msnmsgrr.exe
aPr0hY9.exe
m2PythonLoader.exe
pmstcdjwz.exe
wlsidten.exe
JfCqQ5JC.exe
OmaSG21e.exe
ifgxpers.exe
administration.exe
pYunY8m4VL3qLc.exe
scvhost.exe
csrsss.exe
ubvhynpxh.exe
setex.exe
mplayer2.exe
videotwisterSA.exe
wgsdgsdgdsgsd.exe
Piranha.exe
b34btbztdb0vavaw.exe
UpdatePriv.exe
taskhost.exe.exe
bf8h8d02hf.exe
00b5d693.exe
魔法桌面第三方主题破解补丁V1.1.exe
bvhylsviw.exe
Firewallservice.exe
crack.exe
idiokbbrv.exe
C87C.exe
xmlfilter.exe
rool0_pk.exe
{097444e7-2d87-ba3c-2efe-9f54812d824a}.exe
DA0B.exe
cf6640a77ed4926a4c6be661ab93def9d13408753dd07e8d02836996a2f247b6.exe
Nbt.exe
brenasa.exe
3511172082012Build.exe
dtkmujvo.exe
Task Scheduler.exe
WinSyncMetastore.exe
MusicCollector.exe
dyjdl.exe
p1.exe
msn.exe
rvcbcyks.exe
uenovfiu.exe
WINDED6.exe
TimeDateMUICallback.exe
bzsbkotiu.exe
ssntvs.exe
comeo.exe
svchost.exe
SyncHostps.exe
securitywindrv.exe
Disclaimer

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.