System Guard 2009
System Guard 2009 Description
System Guard 2009, SystemGuard2009, SystemGuard 2009 or System Guard2009, is a rogue anti-spyware program usually installed on the user’s computer system by a Trojan or through other dubious mechanisms. System Guard 2009 infects users without their knowledge and permission and will attempt to trick the user into buying the full System Guard 2009 version of the program. System Guard 2009’s common tactics to persuade the user may be bogus system notifications or fake security alerts stating that the computer is infected with a large amount of spyware. System Guard 2009 will state that in order to remove the supposed threats the user should purchase the commercial version.
System Guard 2009 may also emulate a computer system scan and list supposed spyware infections as a result. However, these resulting entries are created by System Guard 2009 itself to make the user believe System Guard 2009’s scanner has detected actual threats.
System Guard 2009’s popup messages and scan results may redirect you to System Guard 2009’s website (SystemGuard2009.net) to further purchase System Guard 2009’s commercial version. System Guard 2009 may also cause various programs, such as Word and Excel, to suddenly interrupt their run without saving data. System Guard 2009 is a threat to the user’s personal and financial data. System Guard 2009 is a threat and should be removed without hesitation.
Type: Rogue AntiSpyware Programs
How Can You Detect System Guard 2009?
System Guard 2009 Technical Report
As new System Guard 2009 details are reported by our customers and findings from our Threat Research Center, we will update this section.
The following System Guard 2009 files with its MD5s were created in the system:
| File Name | File Size | MD5 |
|---|
| systemguard.exe | 1006592 | d65a283cc6c563efc1815fbdeeb205e6 |
| systemguard.exe | 1006592 | 886528a68935cce57034ab113e7d185f |
| systemguard.exe | 1006592 | d3733c00cef081f4db299597f7c47d3d |
| systemguard.exe | 1006592 | 9bf439220b581bc9c4385e71a2b5395d |
| winscenter.exe | 381440 | d21e188f8afcd375d1ffb3695bd4047b |
| winscenter.exe | 392192 | b78e438d52d7c9be51fd75d1bcaa1a7d |
| iemodule.dll | 2348032 | f05bb624e0a770a840485b0c455b5370 |
| uqmgwcdcve.dll | 763904 | 127c63040952f0530f24d8b1c2645e7a |
| iemodule.dll | 2348032 | ffad703f93f946f612205bc61480393b |
| mqhkcnqxvg.dll | 763904 | e4b358eeef77957286c92cf600521962 |
| moduleie.dll | 38912 | ff014e28addba6715b22f0522359fe0f |
| iemodule.dll | 2999808 | 217103fa5ffeb38312925db10bedb601 |
| undeiimrfx.dll | 825856 | 264a407a86ecbf2fb9b3b5b59d64c14e |
| moduleie.dll | 36864 | abbb1c99471aed20005724d9c89ef046 |
| systemguard.exe | 1007104 | ed04e3e9aa4682e5a1944988aa8bbc77 |
| systemguard.exe | 1006080 | a1d3429e6e0f1234f83b961887560030 |
| SystemGuard2009.exe | 69637 | 886900b6bfbee8813c6ceac25e54222d |
| winlogon.exe | 69637 | 886900b6bfbee8813c6ceac25e54222d |
| iemodule.dll | 2348032 | 684fa6418663b8da7ea7a23c592da5c5 |
| ndamqohbzv.dll | 763904 | d0ffcbae7c0cb027431a89eb8b6f0bd6 |
| moduleie.dll | 38912 | ad357a02c243b5de76d30157cdc050a1 |
| winscenter.exe | 381952 | bacdfbca9cf60854a56b6743cfa04384 |
| iemodule.dll | 2347520 | 440b302e2f52fd5d8d4d688bedc47356 |
| zdbwchlcag.dll | 763392 | 7680d5bc9542acb094ca053950d4b6c1 |
| winscenter.exe | 380928 | 1c12dc3646b5738a8a2b35e36cdeb759 |
| iemodule.dll | 2351104 | 6b63d534d5fb92859ca7fb211f3b75de |
| hafjrwkdjg.dll | 763904 | 97bc7db33723bf64cc8c8179c2d43b64 |
| systemguard.exe | 1007104 | 825dd57138d7f0b46811a4716c7a21f5 |
| iemodule.dll | 2348544 | 677e195e0c340aaec474467e7ca510b6 |
| jxwwldgtxf.dll | 762368 | 45a52c3757c80f49cbbf930dc50ffaa3 |
| systemguard.exe | 1007104 | c1303e4ebd30d00339dbce7c0bffc5d0 |
| systemguard.exe | 1007104 | 1670f60175b88c9e47678f49ba8d5594 |
| iemodule.dll | 2348544 | 5de23475eaf4fc311c1f63b4d2d84767 |
| hditohpcyc.dll | 762880 | 238655549488b3d4d475c138e1389204 |
| iemodule.dll | 2348544 | 7943fdd87cc5466958f02ebcfaee95b3 |
| pheauarqzb.dll | 762880 | 6da5aa3c1ad0c8a0a02b21e0cf592c81 |
| winscenter.exe | 380416 | 9c5302f8973d2d8d4b34de6aae623503 |
| winscenter.exe | 380416 | 40cadd08cdfd6bd80af0a6a50b5f9ff8 |
| systemguard.exe | 1007104 | 01e01e6a77ab3625437b95d0a40e83c3 |
| iemodule.dll | 2349568 | 8ac0a75ef6d00e2b72e57972d47ea0c9 |
| ikpxrsbnnq.dll | 763392 | 8e6c0dbf4be45cad3bcf4927408bfca8 |
| systemguard.exe | 1007616 | 73ddedb038ea6d0671dc4bccf2e2d737 |
| systemguard.exe | 1007104 | e6f9c89e79a6a7ef081d255609b13952 |
| systemguard.exe | 1007616 | 3e7181004265c860ad5e685b0ac9e189 |
| iemodule.dll | 2349056 | b4900d9968f4a225688e1ceb109066ad |
| zhqbmeuqai.dll | 762880 | c58ae410cd5fdb824b433a507d6af9c0 |
| iemodule.dll | 2348032 | 0f9f56fbcbf2913caa5e8e992b8deddb |
| qxpvjgihuv.dll | 762368 | 3d601467d10eca12bb80fc9d7d4f7050 |
| fnypjxnzek.dll | 762880 | e2f613784945490e917e3eda0684fbb5 |
| iemodule.dll | 2348544 | 7688d49911b13d9763ba55eb4505a0e9 |
| winscenter.exe | 380928 | f9d9ee7b5c304f83e7a968a96abe9375 |
| winscenter.exe | 380928 | 80bc482b04dd2d7919fa6942af3d4f3d |
| winscenter.exe | 380928 | 4709a54057ef980e6b59d00837296a1a |
| systemguard.exe | 1007104 | f0f0a9b1499a091faf55e329d3ed85e2 |
| systemguard.exe | 1007104 | 0df73978a93e51e12e19b59eda4c9b7d |
| systemguard.exe | 1007104 | 3a196c3f2038295d292a7103282184a2 |
| systemguard.exe | 1007616 | f32136c0c7273c971f7eb02c9bab3cf6 |
| systemguard.exe | 1007616 | 33577e0dffdd8928bc0cf3defeb9e462 |
| winscenter.exe | 380928 | 5e6ddf41d6f45d2cc68507e32a5f8f5a |
| systemguard.exe | 1007616 | 9e0691cfe697ca1308508ff0fdaf2bc6 |
| qvovoghiyx.dll | 763392 | 274aa4e91eec5a741da079187cfe812d |
| iemodule.dll | 2351104 | 2d80a94b3e2e31f0cfe5542e3cd1af51 |
| fejopjgulu.dll | 763904 | c9db60539aee6aab3593ed57fb2c45b7 |
| winscenter.exe | 380928 | 2434b3693da2c6e086cbf1a32b89c6ad |
| systemguard.exe | 1007616 | 2299e0d0650791d2a570c441fbd620d9 |
| systemguard.exe | 1007616 | 0ed9db153315ac61863614c1c9f05113 |
| winscenter.exe | 380928 | 613944a13093daf07ceed9749103b566 |
| iemodule.dll | 2351104 | e902b820b1d52ac980f57db36398daa4 |
| udunjexmim.dll | 763392 | ffbf52155ae0e48dc4356fa6aade8211 |
| iemodule.dll | 2352128 | 32fb463b356ce87c93efe1286b0f87cd |
| jykgxumxkk.dll | 764416 | 8d996de581fbf9c8ef52401135319f16 |
| iemodule.dll | 2351616 | 4ef9fe6499f2fe96409d29dab99f63bf |
| czltvtkkox.dll | 763904 | a11260b6e6dc0e507c6812e5493114da |
| winscenter.exe | 380928 | 8c636f73d5e258e800597a6f98586677 |
| winscenter.exe | 380928 | e2d6395a080f9a3b8107ff1b0669af52 |
| iemodule.dll | 2351104 | fe4414ce71d3c3fab9fc430b65c04292 |
| iemodule.dll | 2351104 | 70c4204696e4579a091ca33e5b2689ac |
| nqhjazmauc.dll | 763392 | 0ced7f9816708681bb57b9342dc60a12 |
| iemodule.dll | 2348544 | d3bf27c8565c546d725fc2ae1af1191a |
| waqqhmkjpz.dll | 762880 | 6818d9c4e88a9371d36e2492449113cf |
| iemodule.dll | 2347008 | 2952ff510b5a60a0b27075eee5e71a74 |
| wqfsnodfub.dll | 762368 | 9a549ce669543f8d663ba54a69a25008 |
| winscenter.exe | 380928 | f883625a227b9048f183889f3330fdbf |
| systemguard.exe | 1007616 | 2acc72d3d2a5edff0dca2281ce37d24a |
| SystemGuard2009[1].exe | 69637 | be9585f1d193145db7f6576dc4166b4f |
| winlogon.exe | 69637 | be9585f1d193145db7f6576dc4166b4f |
| systemguard.exe | 1008640 | 3f815d03c8ecbe990f332c25f9e3db89 |
| systemguard.exe | 1007616 | 2ffeac68b376283104314d058f2442a5 |
| winscenter.exe | 380928 | 35fb0a7304384ce16956580571b716f0 |
| winscenter.exe | 380928 | 42d0b52a5b36a4f87b9a7df89bb7caad |
| iemodule.dll | 2345984 | e3653a2099a71ffdbe4192ac20c29553 |
| mmriunwlaw.dll | 761856 | 729a4aba39312d704220e61c18a24138 |
| winscenter.exe | 380928 | ec35349b8820e4778ea130e2d8b8f78e |
| iemodule.dll | 2347520 | c8e19948f24217d9329056b6a3e34880 |
| pvlhlemfts.dll | 761856 | 373464b0e849e3c04eb77d7e8edbe89b |
| iemodule.dll | 2676736 | 3a588d29996fc9f2b9af6c65f8bf29ee |
| winscenter.exe | 381952 | 9cf3c48cbb665efd4718d60535d3151d |
| iemodule.dll | 2676736 | 161956306982bf176b9afd58ea7cd25a |
| iemodule.dll | 2689536 | d2d42139584a0977087f56194464421f |
| winscenter.exe | 384512 | 1dd01cde73be415ba123b0823d362753 |
| iemodule.dll | 2689536 | 7b658814aff5b93a699dd6abf1801f2c |
| winscenter.exe | 384000 | d457269012bdccaa2902316f4a334f3d |
| iemodule.dll | 2689024 | 58497d983d92f5964e8f68d33366c5ef |
| winscenter.exe | 384512 | d42ba8990c711d8d58384df5d11ef678 |
| iemodule.dll | 2689536 | a75d65ad9cb0b6b49595ce3c54df1543 |
| winscenter.exe | 384000 | 8568fe08d37eeb008319653d3167355f |
| winscenter.exe | 383488 | feaf6f0bae82cf060f7705cbf778a6a0 |
| iemodule.dll | 2687488 | 7e2234232f18c94cf2684e280e6dc612 |
| iemodule.dll | 2688000 | 3fc708f19f2b30769800fbe2f7013098 |
| winscenter.exe | 384000 | e1d385298cdfd983bd23bcdcd6df39f3 |
System Guard 2009 has typically the following processes in memory:
- c:\Documents and Settings\All Users\Application Data\winlogon.exe
- c:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs\moduleie.dll
- c:\WINDOWS\system32\winscenter.exe
- c:\WINDOWS\reged.exe
- c:\WINDOWS\vmreg.dll
- %ALLUSERSPROFILE%\application data\microsoft\network\dlls\iemodule.dll
- %ALLUSERSPROFILE%\application data\microsoft\network\dlls\moduleie.dll
- %ALLUSERSPROFILE%\application data\microsoft\internet explorer\dlls\moduleie.dll
- %ALLUSERSPROFILE%\application data\microsoft\network\dlls\ndamqohbzv.dll
- %ALLUSERSPROFILE%\application data\microsoft\network\dlls\pheauarqzb.dll
- %ALLUSERSPROFILE%\application data\microsoft\network\dlls\zhqbmeuqai.dll
- %ALLUSERSPROFILE%\application data\microsoft\network\dlls\qvovoghiyx.dll
- %ALLUSERSPROFILE%\application data\microsoft\network\dlls\czltvtkkox.dll
- %ALLUSERSPROFILE%\application data\microsoft\network\dlls\nqhjazmauc.dll
- %ALLUSERSPROFILE%\application data\microsoft\network\dlls\mmriunwlaw.dll
- c:\Program Files\System Guard 2009\uninstall.exe
- c:\Documents and Settings\All Users\Application Data\Microsoft\Network\track.sys
- c:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs\ieModule.dll
- c:\WINDOWS\syscert.exe
- c:\WINDOWS\sysexplorer.exe
- %SYSTEMROOT%\system32\winscenter.exe
- %ALLUSERSPROFILE%\application data\microsoft\network\dlls\mqhkcnqxvg.dll
- %ALLUSERSPROFILE%\application data\microsoft\internet explorer\dlls\undeiimrfx.dll
- %ALLUSERSPROFILE%\application data\microsoft\network\dlls\zdbwchlcag.dll
- %ALLUSERSPROFILE%\application data\microsoft\network\dlls\hditohpcyc.dll
- %ALLUSERSPROFILE%\application data\microsoft\network\dlls\jxwwldgtxf.dll
- %ALLUSERSPROFILE%\application data\microsoft\network\dlls\fnypjxnzek.dll
- %ALLUSERSPROFILE%\application data\microsoft\network\dlls\jykgxumxkk.dll
- %ALLUSERSPROFILE%\application data\microsoft\network\dlls\waqqhmkjpz.dll
- %ALLUSERSPROFILE%\application data\microsoft\network\dlls\wqfsnodfub.dll
- c:\Program Files\System Guard 2009\systemguard.exe
- c:\Documents and Settings\All Users\Application Data\Microsoft\Network\svchost.exe
- c:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs\eewhptdpyl.dll
- c:\WINDOWS\sys.com
- c:\WINDOWS\spoolsystem.exe
- %PROGRAMFILES%\System Guard 2009\systemguard.exe
- %ALLUSERSPROFILE%\application data\microsoft\network\dlls\uqmgwcdcve.dll
- %ALLUSERSPROFILE%\application data\microsoft\internet explorer\dlls\iemodule.dll
- SystemGuard2009.exe
- %ALLUSERSPROFILE%\application data\microsoft\network\dlls\ikpxrsbnnq.dll
- %ALLUSERSPROFILE%\application data\microsoft\network\dlls\hafjrwkdjg.dll
- %ALLUSERSPROFILE%\application data\microsoft\network\dlls\qxpvjgihuv.dll
- %ALLUSERSPROFILE%\application data\microsoft\network\dlls\fejopjgulu.dll
- %ALLUSERSPROFILE%\application data\microsoft\network\dlls\udunjexmim.dll
- SystemGuard2009[1].exe
- %ALLUSERSPROFILE%\application data\microsoft\network\dlls\pvlhlemfts.dll
System Guard 2009 created the following directories, files, paths:
- %ProgramFiles%\System Guard 2009
System Guard 2009 creates the following registry entries:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\System Guard 2009
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad “ieModule”
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad “InternetConnection”
- HKEY_CLASSES_ROOT\CLSID\{AB6DAA8C-F726-4FDD-8B06-9537C5878612}
- HKEY_LOCAL_MACHINE\SOFTWARE\System Guard 2009
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “systemguard”
- HKEY_CLASSES_ROOT\CLSID\{77C96E10-FDA7-4AA7-B318-0631C0D27DBB}
Important Article Disclaimer

English 
Deutsch
Español
Français
Portuguese
System Guard 2009 











