
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\wdgtzayd (Rogue.SecurityShield) -> Value: wdgtzayd
Files Infected:
c:\Users\daniel robinson\AppData\Local\wdgtzayd.exe (Rogue.SecurityShield)
c:\Users\daniel robinson\local settings\wdgtzayd.exe (Rogue.SecurityShield)
c:\Users\daniel robinson\local settings\application data\wdgtzayd.exe (Rogue.SecurityShield)
c:\Users\daniel robinson\AppData\Roaming\microsoft\Windows\start menu\Programs\security shield.lnk (Rogue.SecurityShield)