SpyGuardPro

Description: Rogue Security Program
Risk Level: High
Date of First Occurence: Monday, April 21, 2008
Software Developer: (unknown)
Brief Info: Rogue/Suspect Anti-Spyware Product "Rogue/Suspect" means that these products are of unknown, questionable, or dubious value as anti-spyware protection.
Removal: This threat can be removed using "Spyware Terminator"

SUPPRIMER SPYWARE »

Geographical Distribution of Threat "SpyGuardPro"

Threat Info

View All

Detected Items

  1. Detected Files: %COMMONFILES%\SpyGuardPro\bm.exe MD5: 03BA45DE56A75B310AD03889362688FF Size:990720 %PROGRAMFILES%\SpyGuardPro\Up\gup.exe MD5: 586D833478111A1F6D5492F2FDF1F4F4 Size:716800 %WINDIR%\Temp\~uga6psetup.exe MD5: A38632291C0E24C1941CD215FED71A1E Size:15130717 MD5: E6F3A0AC5172B2067244E02C6FBFE1D4 Size:6949603
  2. Detected Files with variable Filenames: MD5: B352C9979A87569004567750CF5F57C4 Size: 712704 %PROGRAMFILES%\BarreraIntegral\Up\gup.exe %PROGRAMFILES%\SpyGuardPro\Up\gup.exe %PROGRAMFILES%\TrojanerFilter\Up\gup.exe %PROGRAMFILES%\AntiSpionagePro\Up\gup.exe %PROGRAMFILES%\AllertaMinacce\Up\gup.exe %SystemDiskRoot%\System Volume Information\_restore{772A566A-8788-4CD6-B41B-259BA7F4033D}\RP956\A0860055.exe %SystemDiskRoot%\System Volume Information\_restore{772A566A-8788-4CD6-B41B-259BA7F4033D}\RP952\A0858788.exe %PROGRAMFILES%\AntivirusPCSuite\Up\gup.exe %SystemDiskRoot%\System Volume Information\_restore{E92F476D-2609-425C-AF11-34EBED91AE66}\RP564\A0134008.exe MD5: 97D2D7C47F5F4C495B850AF38CC55911 Size: 15268896 %TEMP%\NI.UGA6P_0001_N122M2210\setup.exe %TEMP%\NI.UGA6P_0001_N120M1710\setup.exe %SystemDiskRoot%\Documents and Settings\User\Local Settings\Temp\NI.UGA6P_0001_N122M2210\setup.exe %SystemDiskRoot%\Documents and Settings\alessio\Impostazioni locali\Temp\NI.UGA6P_0001_N122M2210\setup.exe %SystemDiskRoot%\Documents and Settings\ne1\Local Settings\Temp\NI.UGA6P_0001_N122M2210\setup.exe e:\Temp\NI.UGA6P_0001_N122M2210\setup.exe Local Settings\Temp\NI.UGA6P_0001_N122M2210\setup.exe %SYSDIR%\config\systemprofile\Local Settings\Temp\NI.UGA6P_0001_N122M2210\setup.exe %SystemDiskRoot%\Documents and Settings\Owner.YOUR-XHTR8HVC4P.005\Local Settings\Temp\NI.UGA6P_0001_N122M2210\setup.exe %SystemDiskRoot%\Documents and Settings\Owner.YOUR-XHTR8HVC4P.004\Local Settings\Temp\NI.UGA6P_0001_N122M2210\setup.exe %SystemDiskRoot%\Documents and Settings\Owner.YOUR-XHTR8HVC4P.003\Local Settings\Temp\NI.UGA6P_0001_N122M2210\setup.exe and next 9 variations. MD5: EF48D6B19BB583DEDB03CBA17915CD9F Size: 15219883 %TEMP%\~uga6psetup.exe %SystemDiskRoot%\Documents and Settings\ne1\Local Settings\Temp\~uga6psetup.exe e:\Temp\~uga6psetup.exe %SystemDiskRoot%\Documents and Settings\Penerbitan1\Local Settings\Temp\~uga6psetup.exe %SystemDiskRoot%\Documents and Settings\Administrator\Local Settings\Temp\~uga6psetup.exe F:\Users\Consuelo Becerra Cab\AppData\Local\Temp\~uga6psetup.exe %SYSDIR%\config\systemprofile\Local Settings\Temp\~uga6psetup.exe %SystemDiskRoot%\Documents and Settings\Owner.YOUR-XHTR8HVC4P.005\Local Settings\Temp\~uga6psetup.exe %SystemDiskRoot%\Documents and Settings\Owner.YOUR-XHTR8HVC4P.004\Local Settings\Temp\~uga6psetup.exe %SystemDiskRoot%\Documents and Settings\Owner.YOUR-XHTR8HVC4P.003\Local Settings\Temp\~uga6psetup.exe %SystemDiskRoot%\Documents and Settings\Owner.YOUR-XHTR8HVC4P.002\Local Settings\Temp\~uga6psetup.exe and next 10 variations. MD5: A508AD884614A1262E876DBE0D7B8EA9 Size: 163840 %PROGRAMFILES%\SpyGuardPro\rpt.dll %PROGRAMFILES%\AntivirusPCSuite\rpt.dll %PROGRAMFILES%\TrustedAntivirus\rpt.dll %PROGRAMFILES%\WinSpyControl\rpt.dll %SystemDiskRoot%\System Volume Information\_restore{78114D33-B5E7-4685-AEE5-929BAE61477B}\RP328\A0499816.dll MD5: 683567B2280A672E0CB92E4998EBC1BC Size: 57344 %PROGRAMFILES%\SpyGuardPro\fopnl.dll %PROGRAMFILES%\AVSYSTEMCARE\fopnl.dll %PROGRAMFILES%\1\FOPNL.dll %PROGRAMFILES%\AntivirusPCSuite\fopnl.dll %PROGRAMFILES%\PCSecureSystem\fopnl.dll %PROGRAMFILES%\TrustedAntivirus\FOPNL.dll %PROGRAMFILES%\WinSpyControl\fopnl.dll MD5: DB4B729141B7604A1071F720A31C26FC Size: 593920 %COMMONFILES%\SpyGuardPro\bm.exe %COMMONFILES%\1\bm.exe %SystemDiskRoot%\RECYCLER\S-1-5-21-1220945662-1343024091-1060284298-500\Dc32.tmp %COMMONFILES%\WinSpyControl\bm.exe %COMMONFILES%\AVSystemCare\bm.exe %COMMONFILES%\BestsellerAntivirus\bm.exe %COMMONFILES%\SpyGuardPro\bm .exe %COMMONFILES%\SpyGuardPro\bm .exe %COMMONFILES%\AntivirusPCSuite\bm.exe %SystemDiskRoot%\Documents and Settings\Owner.YOUR-XHTR8HVC4P.001\Local Settings\Temp\TMP70.tmp MD5: EB2D3F772AB4207295341C2EE5F79ADC Size: 139264 %PROGRAMFILES%\1\Tools\pg.dll %PROGRAMFILES%\SpyGuardPro\Tools\pg.dll %PROGRAMFILES%\AntivirusPCSuite\Tools\pg.dll %PROGRAMFILES%\WinSecureAv\Tools\pg.dll

Detecting items list:

  1. Files by Name %COMMONFILES%\SpyGuardPro\bm.exe %PROGRAMFILES%\SpyGuardPro\fopnl.dll %PROGRAMFILES%\SpyGuardPro\rpt.dll %PROGRAMFILES%\SpyGuardPro\Tools\pg.dll %PROGRAMFILES%\SpyGuardPro\Up\gup.exe %WINDIR%\Temp\~uga6psetup.exe %WINDIR%\Temp\NI.UGA6P_0001_N122M2210\setup.exe
  2. Files by MD5 MD5: DB4B729141B7604A1071F720A31C26FC Size: 593920 MD5: 683567B2280A672E0CB92E4998EBC1BC Size: 57344 MD5: A508AD884614A1262E876DBE0D7B8EA9 Size: 163840 MD5: EB2D3F772AB4207295341C2EE5F79ADC Size: 139264 MD5: B352C9979A87569004567750CF5F57C4 Size: 712704
  3. Registry Keys HKLM\SOFTWARE\Classes\AVIEBHO.IEFW HKLM\SOFTWARE\Classes\AVIEBHO.IEFW.2 HKU\.DEFAULT\Software\SpyGuardPro HKCU\Software\SpyGuardPro HKLM\SOFTWARE\SpyGuardPro
  4. Registry Values HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ValueName=SpyGuardPro Value=%PROGRAMFILES%\SpyGuardPro\pgs.exe HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ValueName=ugcw Value=?%SystemDiskRoot%\PROGRA~1\COMMON~1\SPYGUA~1\ugcw.exe? -start HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ValueName=Salestart(1) Value=?%COMMONFILES%\SpyGuardPro\bm.exe? dm=http://spyguardpro.com; ad=http://spyguardpro.com

« Go to Software Database