Spyware Protect 2009
Spyware Protect 2009 Description
Spyware Protect 2009 or SpywareProtect 2009, is a rogue anti-spyware program usually installed in the user’s computer system by a Trojan, such as Vundo. Once Spyware Protect 2009 is installed, it will emulate a computer system scan and generate bogus scan results. In addition, the user will receive rogue system alert notifications stating that Spyware Protect 2009 has detected spyware on the user’s computer. These tactics are an attempt to trick the user into purchasing the full Spyware Protect 2009 program. Spyware Protect 2009 may be configured to launch on every Windows startup. Spyware Protect 2009 may cause computer slowdowns.
Type: Rogue AntiSpyware Programs
Automatic Detection of Spyware Protect 2009
Spyware Protect 2009 Technical Report
As new Spyware Protect 2009 details are reported by our customers and findings from our Threat Research Center, we will update this section.
The following Spyware Protect 2009 files with its MD5s were created in the system:
| File Name | File Size | MD5 |
|---|
| sysguardn.exe | 262144 | eaa4d05c16c11b2b1f94b96368379300 |
| sysguard.exe | 363016 | 4fadceccec036ddd4122f1061e8534a4 |
| sysguard.exe | 364552 | 244301f0c0086e9b6b074f2b4d91f800 |
| sysguard.exe | 362504 | a1d838d86b89e15bf1f9d1e654d62911 |
| sysguard.exe | 362504 | 3f784062bed82e8004aea65692e181b2 |
| sysguard.exe | 362504 | 4733d0ac9fa3cbd8054eea5c53b8f18e |
| av.19.1[1].exe | 362504 | 4733d0ac9fa3cbd8054eea5c53b8f18e |
| sysguard.exe | 362504 | e2a13779d4680fe7de983d403ac768c6 |
| sysguard.exe | 362504 | eda6975ef6b3c284126b6cb9bf0ffc59 |
| sysguard.exe | 364040 | 597f604d0f18eff3345e67719c571f78 |
| sysguard.exe | 364040 | 311f46364ac38cbf3e5ac4bacf73b95e |
| sysguard.exe | 369160 | 97e29c2402ae0052c40b77e7624f776d |
| sysguard.exe | 394788 | b8660aa701b0b09ace6ce282355d0de7 |
| sysguard.exe | 362504 | 9ab64ec87c5ea8b46f528243df99f64c |
| sysguard.exe | 363016 | 983d5b3ef93c30cfa7f4a23998560c00 |
| sysguard.exe | 363016 | 7bab5f9fc7bb6a00fe30ac1441f59ab7 |
| sysguard.exe | 364040 | 602c06b04ef305c34c2872fe871c4827 |
| sysguard.exe | 369160 | cd071b71dbdd3d88f3a269b8e3a43b75 |
| sysguard.exe | 364040 | 9c929c157e287a7fc80f39f11c03fb7d |
| sysguard.exe | 266248 | 716add47a4eeaef9bc70e3f804afa0a7 |
| sysguard.exe | 364040 | a1a21fa3a129584157a8a83010f86c96 |
| sysguard.exe | 399364 | 48c49e9e42572ad4cbd223d4404ec89a |
| sysguard.exe | 364044 | 1630e02eebed76f932685b823fbbc794 |
| sysguard.exe | 364044 | bf50b47f4fcbe7895fcd815de738f5fc |
| sysguard.exe | 364556 | 6a4ce7dba89559ec4371bc33b8d29dd2 |
| sysguard.exe | 364556 | e1a628475fec34b18ab3f3769f487b9c |
| sysguard.exe | 364560 | 06f7490126cd069c2cead079669fe8d8 |
| sysguard.exe | 364560 | ed68509813969fdc757b3c5f993e7c58 |
| sysguard.exe | 364560 | 3c4849fa0a12aac8a31c3335caae0b7c |
| sysguard.exe | 364560 | 501636690279b5da7397a71a890b5051 |
| sysguard.exe | 364556 | 6bd414a429c21d4f73bb8c5f93374a85 |
| sysguard.exe | 364556 | 41d32d162c09c92c4eac08962f631254 |
| sysguard.exe | 364560 | d10d3f0de3be62541a5d1fbe001df38a |
| sysguard.exe | 364556 | e6bbe60752b3fe00891923bc11016679 |
| sysguard.exe | 364556 | cdabddc28678349f0fbbcd4b55f107a9 |
| sysguard.exe | 364560 | 8e26f905b63eb3713b7055b7132b962d |
| sysguard.exe | 364560 | 29b2c052618af80c9f29304e80501eda |
| sysguard.exe | 308752 | ed1a78faa64f4b8b56e95fb19300467e |
| sysguard.exe | 308752 | aaab749356132c1065ab66b14ba6c3f7 |
| sysguard.exe | 364560 | c98753775d8b2dc546d4a1d8f6079c08 |
| sysguard.exe | 364560 | b83833a2ebe334e1c146497acab6bda7 |
| sysguard.exe | 364560 | e49ef43aa287f9c8978ef3e1f8486c48 |
| sysguard.exe | 364560 | e0fb76db4affd17332f5c69ce43721e8 |
| sysguard.exe | 353808 | c86ff2acb3c466e911b51f84ddc1a306 |
| sysguard.exe | 353808 | dbed25334248338c851c7cca385c0219 |
| sysguard.exe | 353808 | 0040cbd7440f32d1756bd24cf0c82cb6 |
| sysguard.exe | 178176 | 113f4d6017c84510a0c82d0eb3620fe4 |
| sysguard.exe | 353808 | 041868707556fd9a711bef7647e6ed29 |
| sysguard.exe | 340498 | 5a4c4f5020f136aa5dc71379c758e020 |
| sysguard.exe | 353808 | 381b9781c8fd8018bd5067eb54828f02 |
| sysguard.exe | 353808 | 2eb1928e2a9e59bda88089ab81e03dfe |
| sysguard.exe | 354320 | 5aadba9ea10af94c6c4d148582304dfd |
| sysguard.exe | 354320 | 10c9757156f1890517dcf1f2f8fa4d3d |
| sysguard.exe | 354320 | 18eab5ea71b02002268d687c714d4bc9 |
| sysguard.exe | 354320 | fd97603057ac9a87c6ca466b3e4bdb86 |
| sysguard.exe | 354320 | 903215b664e5cc24361fa1a4c9d9691a |
| sysguard.exe | 354320 | 1b58bbcf6875baf79961d21ff6dec6c4 |
| sysguard.exe | 315920 | d5f85c25118c8ec0446bb0238bbcffd8 |
| sysguard.exe | 313872 | 3a0f0bdb04b882911affe975d4543630 |
| sysguard.exe | 315920 | 46fad9e966617fdaa296d11d56a763a8 |
| sysguard.exe | 304656 | a8aac51f2938d51ba1c8fd4af6c3a8b2 |
| sysguard.exe | 304656 | fca2c9506eb72cadb31a2fcd73095908 |
| sysguard.exe | 315920 | ab9f01da4e664ff735e27e0b3355da55 |
| sysguard.exe | 313872 | 5653e068d6963ec314ff2b419a89aa51 |
| sysguard.exe | 290832 | 95dafd47ea0d2fa44979447df75b58e3 |
| sysguard.exe | 290832 | c5d107c2c3f60d463d3465cc6a82d69a |
| sysguard.exe | 310800 | b2601c0fdec8817c190adf3809033a66 |
| sysguard.exe | 305680 | 0c6aa233e7c290d245cc106998beb79b |
| sysguard.exe | 290832 | edaf9fd1b166d605c03ea21bd7f3de08 |
| sysguard.exe | 290832 | ff1dd778104265475aa5960dec775a67 |
| sysguard.exe | 304656 | 3f43d1cff32bf5c174babf38b8844c49 |
| sysguard.exe | 304656 | a34411ba1347ff8982ee19037094b25f |
| sysguard.exe | 305680 | 3d3b2df8959dca870ae179d638537f0e |
| sysguard.exe | 290832 | 44bcefef29d8bcfd18c057a82607375b |
| sysguard.exe | 290832 | efb73fcf4203896b8f2a956b64a32efd |
| sysguard.exe | 290320 | bcb7b1eadf63305e2ee3bcc9d072dcd8 |
| sysguard.exe | 290320 | bdc5821a8ec258d453e595d3c661c1aa |
| sysguard.exe | 294416 | b8a528ae672edd48ca62f56780dab21e |
| sysguard.exe | 314384 | 61145807c53391f19e10de0d79cd2009 |
| sysguard.exe | 315920 | 26301d8ad11d8abfa90b1b26f4b9be40 |
| sysguard.exe | 290320 | 0a0073f6ea673f7392408aaccd77ae42 |
| sysguard.exe | 307216 | 61a5f553e6b875504ef861cbe2d9cc9e |
| sysguard.exe | 304144 | 08b09feef714fb4f5f53d8360236170b |
| sysguard.exe | 307216 | c4bee108d1e221f71d9ee02d82f48e57 |
| sysguard.exe | 304144 | 9e387fea47aa41952d46d1f012525503 |
| sysguard.exe | 292368 | 0dc0f9ccc874d0f089a486b4d947b9e2 |
| sysguard.exe | 292368 | 968c45f9066118558d68abff759eb3fe |
| sysguard.exe | 292368 | 8633542502dfd5ae609a199a94c07e93 |
| sysguard.exe | 292880 | 8f7bdfef47c9fb251be22c92ee0cc939 |
| sysguard.exe | 292368 | 5ee55b7138ee480cd87d0b5d9613199d |
| sysguard.exe | 292880 | 2303d1f8c37c95910b427cb5639bbfb7 |
| sysguard.exe | 292368 | d67f9d851a0c839db032d1ae0bf9797b |
| sysguard.exe | 291344 | ddaa8f0769576d98657c5489943c8778 |
| sysguard.exe | 291344 | 512ca75da8a8f14b00e45ae55ef209df |
| sysguard.exe | 291344 | 48370ad6a0ece0073b7bd7fcb383e4d1 |
| sysguard.exe | 292880 | 3b82256d957fc6509698333d5406f33c |
| sysguard.exe | 293392 | f5e7d13e3eda847131a33d0b7b5860de |
| sysguard.exe | 293392 | 4bc0b3d20beb4009cce1575c51bfb65f |
| install[1].exe | 291344 | 576df42eef46656e64947638afe1d5ec |
| sysguard.exe | 291344 | 576df42eef46656e64947638afe1d5ec |
| sysguard.exe | 291856 | d7ecfa5e9eaefe3d476961ce23033feb |
| sysguard.exe | 377360 | 701c1573cedf2fd6b1cd1ed00c8473d0 |
| sysguard.exe | 291856 | 70884c9898c54c0c6f62b084d2c57a5b |
| sysguard.exe | 377360 | 19f889c11b5942757b1d7d092663ae84 |
| sysguard.exe | 297488 | a0ac74d9c84c98c024170fd1e8e189bc |
| sysguard.exe | 297488 | 4a17867c94257653034b6285e5444ef2 |
| sysguard.exe | 291856 | 91feb4029d64e1b423cd69f94c404286 |
| sysguard.exe | 291856 | efcfc2c91da0d7f9cc531e2514fdc925 |
| sysguard.exe | 297488 | bc09365fc19c43b081fbf40f8208ea4d |
| sysguard.exe | 306432 | 695ce6f29b4be9091591aba2bc724dd5 |
| vvilsysguard.exe | 277248 | 01826ae8cdc8a3b08e4c152664121db8 |
| nalxsysguard.exe | 277248 | cf97283632034454cfc1ff86246a8594 |
| ntnrsysguard.exe | 276480 | 66267ef1865e6dcae8c8ad9d13ff6db6 |
Spyware Protect 2009 has typically the following processes in memory:
- %SYSTEMROOT%\sysguard.exe
- sysguardn.exe
- SpywareProtect2009.exe
- sysguard.exe
Spyware Protect 2009 creates the following registry entries:
- HKEY_CURRENT_USER\Software\Spyware Protect 2009
Important Article Disclaimer


English 

Spyware Protect 2009 










