SpyGuardPro
|
Description:
|
Rogue Security Program
|
|
Risk Level:
|
High
|
|
Date of First Occurence:
|
Monday, April 21, 2008
|
|
Software Developer:
|
(unknown)
|
|
Brief Info:
|
Rogue/Suspect Anti-Spyware Product
"Rogue/Suspect" means that these products are of unknown, questionable, or dubious value as anti-spyware protection.
|
|
Removal:
|
This threat can be removed using "Spyware
Terminator"
|
REMOVER SPYWARE »
Geographical Distribution of Threat "SpyGuardPro"
Threat Info
View All
Detected Items
- Detected Files:
%COMMONFILES%\SpyGuardPro\bm.exe
MD5: 03BA45DE56A75B310AD03889362688FF Size:990720
%PROGRAMFILES%\SpyGuardPro\Up\gup.exe
MD5: 586D833478111A1F6D5492F2FDF1F4F4 Size:716800
%WINDIR%\Temp\~uga6psetup.exe
MD5: A38632291C0E24C1941CD215FED71A1E Size:15130717
MD5: E6F3A0AC5172B2067244E02C6FBFE1D4 Size:6949603
- Detected Files with variable Filenames:
MD5: B352C9979A87569004567750CF5F57C4 Size: 712704
%PROGRAMFILES%\BarreraIntegral\Up\gup.exe
%PROGRAMFILES%\SpyGuardPro\Up\gup.exe
%PROGRAMFILES%\TrojanerFilter\Up\gup.exe
%PROGRAMFILES%\AntiSpionagePro\Up\gup.exe
%PROGRAMFILES%\AllertaMinacce\Up\gup.exe
%SystemDiskRoot%\System Volume Information\_restore{772A566A-8788-4CD6-B41B-259BA7F4033D}\RP956\A0860055.exe
%SystemDiskRoot%\System Volume Information\_restore{772A566A-8788-4CD6-B41B-259BA7F4033D}\RP952\A0858788.exe
%PROGRAMFILES%\AntivirusPCSuite\Up\gup.exe
%SystemDiskRoot%\System Volume Information\_restore{E92F476D-2609-425C-AF11-34EBED91AE66}\RP564\A0134008.exe
MD5: 97D2D7C47F5F4C495B850AF38CC55911 Size: 15268896
%TEMP%\NI.UGA6P_0001_N122M2210\setup.exe
%TEMP%\NI.UGA6P_0001_N120M1710\setup.exe
%SystemDiskRoot%\Documents and Settings\User\Local Settings\Temp\NI.UGA6P_0001_N122M2210\setup.exe
%SystemDiskRoot%\Documents and Settings\alessio\Impostazioni locali\Temp\NI.UGA6P_0001_N122M2210\setup.exe
%SystemDiskRoot%\Documents and Settings\ne1\Local Settings\Temp\NI.UGA6P_0001_N122M2210\setup.exe
e:\Temp\NI.UGA6P_0001_N122M2210\setup.exe
Local Settings\Temp\NI.UGA6P_0001_N122M2210\setup.exe
%SYSDIR%\config\systemprofile\Local Settings\Temp\NI.UGA6P_0001_N122M2210\setup.exe
%SystemDiskRoot%\Documents and Settings\Owner.YOUR-XHTR8HVC4P.005\Local Settings\Temp\NI.UGA6P_0001_N122M2210\setup.exe
%SystemDiskRoot%\Documents and Settings\Owner.YOUR-XHTR8HVC4P.004\Local Settings\Temp\NI.UGA6P_0001_N122M2210\setup.exe
%SystemDiskRoot%\Documents and Settings\Owner.YOUR-XHTR8HVC4P.003\Local Settings\Temp\NI.UGA6P_0001_N122M2210\setup.exe
and next 9 variations.
MD5: EF48D6B19BB583DEDB03CBA17915CD9F Size: 15219883
%TEMP%\~uga6psetup.exe
%SystemDiskRoot%\Documents and Settings\ne1\Local Settings\Temp\~uga6psetup.exe
e:\Temp\~uga6psetup.exe
%SystemDiskRoot%\Documents and Settings\Penerbitan1\Local Settings\Temp\~uga6psetup.exe
%SystemDiskRoot%\Documents and Settings\Administrator\Local Settings\Temp\~uga6psetup.exe
F:\Users\Consuelo Becerra Cab\AppData\Local\Temp\~uga6psetup.exe
%SYSDIR%\config\systemprofile\Local Settings\Temp\~uga6psetup.exe
%SystemDiskRoot%\Documents and Settings\Owner.YOUR-XHTR8HVC4P.005\Local Settings\Temp\~uga6psetup.exe
%SystemDiskRoot%\Documents and Settings\Owner.YOUR-XHTR8HVC4P.004\Local Settings\Temp\~uga6psetup.exe
%SystemDiskRoot%\Documents and Settings\Owner.YOUR-XHTR8HVC4P.003\Local Settings\Temp\~uga6psetup.exe
%SystemDiskRoot%\Documents and Settings\Owner.YOUR-XHTR8HVC4P.002\Local Settings\Temp\~uga6psetup.exe
and next 10 variations.
MD5: A508AD884614A1262E876DBE0D7B8EA9 Size: 163840
%PROGRAMFILES%\SpyGuardPro\rpt.dll
%PROGRAMFILES%\AntivirusPCSuite\rpt.dll
%PROGRAMFILES%\TrustedAntivirus\rpt.dll
%PROGRAMFILES%\WinSpyControl\rpt.dll
%SystemDiskRoot%\System Volume Information\_restore{78114D33-B5E7-4685-AEE5-929BAE61477B}\RP328\A0499816.dll
MD5: 683567B2280A672E0CB92E4998EBC1BC Size: 57344
%PROGRAMFILES%\SpyGuardPro\fopnl.dll
%PROGRAMFILES%\AVSYSTEMCARE\fopnl.dll
%PROGRAMFILES%\1\FOPNL.dll
%PROGRAMFILES%\AntivirusPCSuite\fopnl.dll
%PROGRAMFILES%\PCSecureSystem\fopnl.dll
%PROGRAMFILES%\TrustedAntivirus\FOPNL.dll
%PROGRAMFILES%\WinSpyControl\fopnl.dll
MD5: DB4B729141B7604A1071F720A31C26FC Size: 593920
%COMMONFILES%\SpyGuardPro\bm.exe
%COMMONFILES%\1\bm.exe
%SystemDiskRoot%\RECYCLER\S-1-5-21-1220945662-1343024091-1060284298-500\Dc32.tmp
%COMMONFILES%\WinSpyControl\bm.exe
%COMMONFILES%\AVSystemCare\bm.exe
%COMMONFILES%\BestsellerAntivirus\bm.exe
%COMMONFILES%\SpyGuardPro\bm .exe
%COMMONFILES%\SpyGuardPro\bm .exe
%COMMONFILES%\AntivirusPCSuite\bm.exe
%SystemDiskRoot%\Documents and Settings\Owner.YOUR-XHTR8HVC4P.001\Local Settings\Temp\TMP70.tmp
MD5: EB2D3F772AB4207295341C2EE5F79ADC Size: 139264
%PROGRAMFILES%\1\Tools\pg.dll
%PROGRAMFILES%\SpyGuardPro\Tools\pg.dll
%PROGRAMFILES%\AntivirusPCSuite\Tools\pg.dll
%PROGRAMFILES%\WinSecureAv\Tools\pg.dll
Detecting items list:
- Files by Name
%COMMONFILES%\SpyGuardPro\bm.exe
%PROGRAMFILES%\SpyGuardPro\fopnl.dll
%PROGRAMFILES%\SpyGuardPro\rpt.dll
%PROGRAMFILES%\SpyGuardPro\Tools\pg.dll
%PROGRAMFILES%\SpyGuardPro\Up\gup.exe
%WINDIR%\Temp\~uga6psetup.exe
%WINDIR%\Temp\NI.UGA6P_0001_N122M2210\setup.exe
- Files by MD5
MD5: DB4B729141B7604A1071F720A31C26FC Size: 593920
MD5: 683567B2280A672E0CB92E4998EBC1BC Size: 57344
MD5: A508AD884614A1262E876DBE0D7B8EA9 Size: 163840
MD5: EB2D3F772AB4207295341C2EE5F79ADC Size: 139264
MD5: B352C9979A87569004567750CF5F57C4 Size: 712704
- Registry Keys
HKLM\SOFTWARE\Classes\AVIEBHO.IEFW
HKLM\SOFTWARE\Classes\AVIEBHO.IEFW.2
HKU\.DEFAULT\Software\SpyGuardPro
HKCU\Software\SpyGuardPro
HKLM\SOFTWARE\SpyGuardPro
- Registry Values
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ValueName=SpyGuardPro Value=%PROGRAMFILES%\SpyGuardPro\pgs.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ValueName=ugcw Value=?%SystemDiskRoot%\PROGRA~1\COMMON~1\SPYGUA~1\ugcw.exe? -start
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ValueName=Salestart(1) Value=?%COMMONFILES%\SpyGuardPro\bm.exe? dm=http://spyguardpro.com; ad=http://spyguardpro.com
«
Go to Software Database