System Guard 2009

GoldSparrow By GoldSparrow in Rogue Anti-Spyware Program | 146 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...

System Guard 2009 Description

System Guard 2009, SystemGuard2009, SystemGuard 2009 or System Guard2009, is a rogue anti-spyware program usually installed on the user’s computer system by a Trojan or through other dubious mechanisms. System Guard 2009 infects users without their knowledge and permission and will attempt to trick the user into buying the full System Guard 2009 version of the program. System Guard 2009’s common tactics to persuade the user may be bogus system notifications or fake security alerts stating that the computer is infected with a large amount of spyware. System Guard 2009 will state that in order to remove the supposed threats the user should purchase the commercial version.

System Guard 2009 may also emulate a computer system scan and list supposed spyware infections as a result. However, these resulting entries are created by System Guard 2009 itself to make the user believe System Guard 2009’s scanner has detected actual threats.

System Guard 2009’s popup messages and scan results may redirect you to System Guard 2009’s website (SystemGuard2009.net) to further purchase System Guard 2009’s commercial version. System Guard 2009 may also cause various programs, such as Word and Excel, to suddenly interrupt their run without saving data. System Guard 2009 is a threat to the user’s personal and financial data. System Guard 2009 is a threat and should be removed without hesitation.

Type: Rogue AntiSpyware Programs

How Can You Detect System Guard 2009?

 
 

Download SpyHunter’s Detection Scanner
to Detect System Guard 2009.

 
 

System Guard 2009 Technical Report

As new System Guard 2009 details are reported by our customers and findings from our Threat Research Center, we will update this section.

The following System Guard 2009 files with its MD5s were created in the system:

File Name File Size MD5
systemguard.exe 1006592 d65a283cc6c563efc1815fbdeeb205e6
systemguard.exe 1006592 886528a68935cce57034ab113e7d185f
systemguard.exe 1006592 d3733c00cef081f4db299597f7c47d3d
systemguard.exe 1006592 9bf439220b581bc9c4385e71a2b5395d
winscenter.exe 381440 d21e188f8afcd375d1ffb3695bd4047b
winscenter.exe 392192 b78e438d52d7c9be51fd75d1bcaa1a7d
iemodule.dll 2348032 f05bb624e0a770a840485b0c455b5370
uqmgwcdcve.dll 763904 127c63040952f0530f24d8b1c2645e7a
iemodule.dll 2348032 ffad703f93f946f612205bc61480393b
mqhkcnqxvg.dll 763904 e4b358eeef77957286c92cf600521962
moduleie.dll 38912 ff014e28addba6715b22f0522359fe0f
iemodule.dll 2999808 217103fa5ffeb38312925db10bedb601
undeiimrfx.dll 825856 264a407a86ecbf2fb9b3b5b59d64c14e
moduleie.dll 36864 abbb1c99471aed20005724d9c89ef046
systemguard.exe 1007104 ed04e3e9aa4682e5a1944988aa8bbc77
systemguard.exe 1006080 a1d3429e6e0f1234f83b961887560030
SystemGuard2009.exe 69637 886900b6bfbee8813c6ceac25e54222d
winlogon.exe 69637 886900b6bfbee8813c6ceac25e54222d
iemodule.dll 2348032 684fa6418663b8da7ea7a23c592da5c5
ndamqohbzv.dll 763904 d0ffcbae7c0cb027431a89eb8b6f0bd6
moduleie.dll 38912 ad357a02c243b5de76d30157cdc050a1
winscenter.exe 381952 bacdfbca9cf60854a56b6743cfa04384
iemodule.dll 2347520 440b302e2f52fd5d8d4d688bedc47356
zdbwchlcag.dll 763392 7680d5bc9542acb094ca053950d4b6c1
winscenter.exe 380928 1c12dc3646b5738a8a2b35e36cdeb759
iemodule.dll 2351104 6b63d534d5fb92859ca7fb211f3b75de
hafjrwkdjg.dll 763904 97bc7db33723bf64cc8c8179c2d43b64
systemguard.exe 1007104 825dd57138d7f0b46811a4716c7a21f5
iemodule.dll 2348544 677e195e0c340aaec474467e7ca510b6
jxwwldgtxf.dll 762368 45a52c3757c80f49cbbf930dc50ffaa3
systemguard.exe 1007104 c1303e4ebd30d00339dbce7c0bffc5d0
systemguard.exe 1007104 1670f60175b88c9e47678f49ba8d5594
iemodule.dll 2348544 5de23475eaf4fc311c1f63b4d2d84767
hditohpcyc.dll 762880 238655549488b3d4d475c138e1389204
iemodule.dll 2348544 7943fdd87cc5466958f02ebcfaee95b3
pheauarqzb.dll 762880 6da5aa3c1ad0c8a0a02b21e0cf592c81
winscenter.exe 380416 9c5302f8973d2d8d4b34de6aae623503
winscenter.exe 380416 40cadd08cdfd6bd80af0a6a50b5f9ff8
systemguard.exe 1007104 01e01e6a77ab3625437b95d0a40e83c3
iemodule.dll 2349568 8ac0a75ef6d00e2b72e57972d47ea0c9
ikpxrsbnnq.dll 763392 8e6c0dbf4be45cad3bcf4927408bfca8
systemguard.exe 1007616 73ddedb038ea6d0671dc4bccf2e2d737
systemguard.exe 1007104 e6f9c89e79a6a7ef081d255609b13952
systemguard.exe 1007616 3e7181004265c860ad5e685b0ac9e189
iemodule.dll 2349056 b4900d9968f4a225688e1ceb109066ad
zhqbmeuqai.dll 762880 c58ae410cd5fdb824b433a507d6af9c0
iemodule.dll 2348032 0f9f56fbcbf2913caa5e8e992b8deddb
qxpvjgihuv.dll 762368 3d601467d10eca12bb80fc9d7d4f7050
fnypjxnzek.dll 762880 e2f613784945490e917e3eda0684fbb5
iemodule.dll 2348544 7688d49911b13d9763ba55eb4505a0e9
winscenter.exe 380928 f9d9ee7b5c304f83e7a968a96abe9375
winscenter.exe 380928 80bc482b04dd2d7919fa6942af3d4f3d
winscenter.exe 380928 4709a54057ef980e6b59d00837296a1a
systemguard.exe 1007104 f0f0a9b1499a091faf55e329d3ed85e2
systemguard.exe 1007104 0df73978a93e51e12e19b59eda4c9b7d
systemguard.exe 1007104 3a196c3f2038295d292a7103282184a2
systemguard.exe 1007616 f32136c0c7273c971f7eb02c9bab3cf6
systemguard.exe 1007616 33577e0dffdd8928bc0cf3defeb9e462
winscenter.exe 380928 5e6ddf41d6f45d2cc68507e32a5f8f5a
systemguard.exe 1007616 9e0691cfe697ca1308508ff0fdaf2bc6
qvovoghiyx.dll 763392 274aa4e91eec5a741da079187cfe812d
iemodule.dll 2351104 2d80a94b3e2e31f0cfe5542e3cd1af51
fejopjgulu.dll 763904 c9db60539aee6aab3593ed57fb2c45b7
winscenter.exe 380928 2434b3693da2c6e086cbf1a32b89c6ad
systemguard.exe 1007616 2299e0d0650791d2a570c441fbd620d9
systemguard.exe 1007616 0ed9db153315ac61863614c1c9f05113
winscenter.exe 380928 613944a13093daf07ceed9749103b566
iemodule.dll 2351104 e902b820b1d52ac980f57db36398daa4
udunjexmim.dll 763392 ffbf52155ae0e48dc4356fa6aade8211
iemodule.dll 2352128 32fb463b356ce87c93efe1286b0f87cd
jykgxumxkk.dll 764416 8d996de581fbf9c8ef52401135319f16
iemodule.dll 2351616 4ef9fe6499f2fe96409d29dab99f63bf
czltvtkkox.dll 763904 a11260b6e6dc0e507c6812e5493114da
winscenter.exe 380928 8c636f73d5e258e800597a6f98586677
winscenter.exe 380928 e2d6395a080f9a3b8107ff1b0669af52
iemodule.dll 2351104 fe4414ce71d3c3fab9fc430b65c04292
iemodule.dll 2351104 70c4204696e4579a091ca33e5b2689ac
nqhjazmauc.dll 763392 0ced7f9816708681bb57b9342dc60a12
iemodule.dll 2348544 d3bf27c8565c546d725fc2ae1af1191a
waqqhmkjpz.dll 762880 6818d9c4e88a9371d36e2492449113cf
iemodule.dll 2347008 2952ff510b5a60a0b27075eee5e71a74
wqfsnodfub.dll 762368 9a549ce669543f8d663ba54a69a25008
winscenter.exe 380928 f883625a227b9048f183889f3330fdbf
systemguard.exe 1007616 2acc72d3d2a5edff0dca2281ce37d24a
SystemGuard2009[1].exe 69637 be9585f1d193145db7f6576dc4166b4f
winlogon.exe 69637 be9585f1d193145db7f6576dc4166b4f
systemguard.exe 1008640 3f815d03c8ecbe990f332c25f9e3db89
systemguard.exe 1007616 2ffeac68b376283104314d058f2442a5
winscenter.exe 380928 35fb0a7304384ce16956580571b716f0
winscenter.exe 380928 42d0b52a5b36a4f87b9a7df89bb7caad
iemodule.dll 2345984 e3653a2099a71ffdbe4192ac20c29553
mmriunwlaw.dll 761856 729a4aba39312d704220e61c18a24138
winscenter.exe 380928 ec35349b8820e4778ea130e2d8b8f78e
iemodule.dll 2347520 c8e19948f24217d9329056b6a3e34880
pvlhlemfts.dll 761856 373464b0e849e3c04eb77d7e8edbe89b
iemodule.dll 2676736 3a588d29996fc9f2b9af6c65f8bf29ee
winscenter.exe 381952 9cf3c48cbb665efd4718d60535d3151d
iemodule.dll 2676736 161956306982bf176b9afd58ea7cd25a
iemodule.dll 2689536 d2d42139584a0977087f56194464421f
winscenter.exe 384512 1dd01cde73be415ba123b0823d362753
iemodule.dll 2689536 7b658814aff5b93a699dd6abf1801f2c
winscenter.exe 384000 d457269012bdccaa2902316f4a334f3d
iemodule.dll 2689024 58497d983d92f5964e8f68d33366c5ef
winscenter.exe 384512 d42ba8990c711d8d58384df5d11ef678
iemodule.dll 2689536 a75d65ad9cb0b6b49595ce3c54df1543
winscenter.exe 384000 8568fe08d37eeb008319653d3167355f
winscenter.exe 383488 feaf6f0bae82cf060f7705cbf778a6a0
iemodule.dll 2687488 7e2234232f18c94cf2684e280e6dc612
iemodule.dll 2688000 3fc708f19f2b30769800fbe2f7013098
winscenter.exe 384000 e1d385298cdfd983bd23bcdcd6df39f3

System Guard 2009 has typically the following processes in memory:

  • c:\Documents and Settings\All Users\Application Data\winlogon.exe
  • c:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs\moduleie.dll
  • c:\WINDOWS\system32\winscenter.exe
  • c:\WINDOWS\reged.exe
  • c:\WINDOWS\vmreg.dll
  • %ALLUSERSPROFILE%\application data\microsoft\network\dlls\iemodule.dll
  • %ALLUSERSPROFILE%\application data\microsoft\network\dlls\moduleie.dll
  • %ALLUSERSPROFILE%\application data\microsoft\internet explorer\dlls\moduleie.dll
  • %ALLUSERSPROFILE%\application data\microsoft\network\dlls\ndamqohbzv.dll
  • %ALLUSERSPROFILE%\application data\microsoft\network\dlls\pheauarqzb.dll
  • %ALLUSERSPROFILE%\application data\microsoft\network\dlls\zhqbmeuqai.dll
  • %ALLUSERSPROFILE%\application data\microsoft\network\dlls\qvovoghiyx.dll
  • %ALLUSERSPROFILE%\application data\microsoft\network\dlls\czltvtkkox.dll
  • %ALLUSERSPROFILE%\application data\microsoft\network\dlls\nqhjazmauc.dll
  • %ALLUSERSPROFILE%\application data\microsoft\network\dlls\mmriunwlaw.dll
  • c:\Program Files\System Guard 2009\uninstall.exe
  • c:\Documents and Settings\All Users\Application Data\Microsoft\Network\track.sys
  • c:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs\ieModule.dll
  • c:\WINDOWS\syscert.exe
  • c:\WINDOWS\sysexplorer.exe
  • %SYSTEMROOT%\system32\winscenter.exe
  • %ALLUSERSPROFILE%\application data\microsoft\network\dlls\mqhkcnqxvg.dll
  • %ALLUSERSPROFILE%\application data\microsoft\internet explorer\dlls\undeiimrfx.dll
  • %ALLUSERSPROFILE%\application data\microsoft\network\dlls\zdbwchlcag.dll
  • %ALLUSERSPROFILE%\application data\microsoft\network\dlls\hditohpcyc.dll
  • %ALLUSERSPROFILE%\application data\microsoft\network\dlls\jxwwldgtxf.dll
  • %ALLUSERSPROFILE%\application data\microsoft\network\dlls\fnypjxnzek.dll
  • %ALLUSERSPROFILE%\application data\microsoft\network\dlls\jykgxumxkk.dll
  • %ALLUSERSPROFILE%\application data\microsoft\network\dlls\waqqhmkjpz.dll
  • %ALLUSERSPROFILE%\application data\microsoft\network\dlls\wqfsnodfub.dll
  • c:\Program Files\System Guard 2009\systemguard.exe
  • c:\Documents and Settings\All Users\Application Data\Microsoft\Network\svchost.exe
  • c:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs\eewhptdpyl.dll
  • c:\WINDOWS\sys.com
  • c:\WINDOWS\spoolsystem.exe
  • %PROGRAMFILES%\System Guard 2009\systemguard.exe
  • %ALLUSERSPROFILE%\application data\microsoft\network\dlls\uqmgwcdcve.dll
  • %ALLUSERSPROFILE%\application data\microsoft\internet explorer\dlls\iemodule.dll
  • SystemGuard2009.exe
  • %ALLUSERSPROFILE%\application data\microsoft\network\dlls\ikpxrsbnnq.dll
  • %ALLUSERSPROFILE%\application data\microsoft\network\dlls\hafjrwkdjg.dll
  • %ALLUSERSPROFILE%\application data\microsoft\network\dlls\qxpvjgihuv.dll
  • %ALLUSERSPROFILE%\application data\microsoft\network\dlls\fejopjgulu.dll
  • %ALLUSERSPROFILE%\application data\microsoft\network\dlls\udunjexmim.dll
  • SystemGuard2009[1].exe
  • %ALLUSERSPROFILE%\application data\microsoft\network\dlls\pvlhlemfts.dll

System Guard 2009 created the following directories, files, paths:

  • %ProgramFiles%\System Guard 2009

System Guard 2009 creates the following registry entries:

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\System Guard 2009
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad “ieModule”
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad “InternetConnection”
  • HKEY_CLASSES_ROOT\CLSID\{AB6DAA8C-F726-4FDD-8B06-9537C5878612}
  • HKEY_LOCAL_MACHINE\SOFTWARE\System Guard 2009
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “systemguard”
  • HKEY_CLASSES_ROOT\CLSID\{77C96E10-FDA7-4AA7-B318-0631C0D27DBB}

Important Article Disclaimer

ESG Support Center

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Furl
  • StumbleUpon
  • Technorati
  • YahooMyWeb
This entry was posted on 02/10/09 and is filed under Rogue Anti-Spyware Program. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Poll

How much money have you spent trying to rid your PC of spyware?
View Results
Follow Us on Twitter

Archives

Home Sitemap RSS Feed Privacy Policy End User License Agreement Copyright 2003-2010. Enigma Software Group USA, LLC. All Rights Reserved.