Spyware Guard 2008 Malware

KnickNut3

Platinum Member
Oct 1, 2001
2,382
0
0
I'm at my wit's end, hope you can help.

Somehow my computer got infected with the malware "Spyware Guard 2008." Apparently it has to be manually installed by mistake. Don't know, I didn't do it. It's hijacking my search engine links, blocking websites, and keeps popping up to do its fake scan every 5 seconds. Oh, and Windows Security (even though I've deactivated its warnings) keeps telling me I need it when I terminate it.

So I search for it on the internet and I don't know, this version I have seems more robust in how it protects itself, and no removal methods seem to work:

(a) It blocks websites where I can download software that is known to remove it.
(b) If I try to delete every file, registry key, and reference related to it as listed on some anti-malware websites recommend, doesn't matter, it comes back and reinstalls itself.
(c) If I try to install Malwarebytes' Anit-Malware, the executable doesn't do anything (the malware blocks it from installing?)
(d) If I try to run SuperAntiSpyware, it crashes. If I use the workaround to get it started, it can't update definitions and fails. If I run it, it finds the malware, I remove it, it auto-reboots, and boom, the malware is back and still there.
(e) Avira antivirus will find it and try to delete/quarentine it, but the program laughs and reinstalls itself.
(f) None of these scans will run in safe mode if I try. I'll execute and nothing will happen.

Would really appreciate assistance.
 

bruceb

Diamond Member
Aug 20, 2004
8,874
111
106
Try running Malwarebytes in Safe Mode .. you may also need to rename it so the virus will let it install.
See link here (print it out and follow the steps)
http://www.bleepingcomputer.co...ove-spyware-guard-2008

And here: http://www.malwarehelp.org/spy...-and-removal-2008.html

And here are most of the directions (in case you can't get to those sites)

Spyware Guard 2008 Analysis and Removal

October 3, 2008 by Shanmuga
Filed under Featured, Rogue Security Software, spyware removal

Leave a comment

Spyware Guard 2008 is a new entrant to the family of rogue security software. It is not to be confused with SpywareGuard a fine freeware from Javacool software.

A rogue security software belongs to a family of software products that call themselves as antivirus, antispyware or registry cleaners and often use deceptive or high pressure sales tactics and deliberate false positives to convince users into buying a license/subscription. They are often repackaged and renamed. They do not actually remove malware instead many of them add more malware of their own.

Note: Visiting any of the malware hosting domains mentioned below may be injurious to the health of your computer system.

Analysis of Spyware Guard 2008 Installation

spyware-guard-2008-0010a Spyware Guard 2008 Analysis and Removal

This rogue anti-spyware currently lives in spywareguard2008.com. Spywareguard2008.com has the IP 67.19.176.187 hosted by bb.b0.1343.static.theplanet.com. The domain name appears to be registered by MAMBA on 26-Aug-2008 and the registrant details are protected by Protect Details, Inc out of Saint Petersburg, Russia. This IP is shared with Porn-movies-online.net, notorious for pushing fake video codecs. This IP is also used as a nameserver for pyroscanner.com.

A temporary redirect from gosg2008.com and Sg8go.com points to spywareguard2008.com.

Curiously their payment processor at innovagest2000s.com is not yet working, gives off a message ?Invalid product !?.

The executable installer file is named SpywareGuard2008.exe (1.51 MB). This file must be manually executed for the installation of the rogue anti-spyware. At this point only a couple of engines detects this as suspicious over at VirusTotal.

spyware-guard-2008-virustotal-results Spyware Guard 2008 Analysis and Removal

True to its genre, it installs a few suspicious files of its own in the Windows directory. They are reged.exe, spoolsystem.exe, sys.com, syscert.exe, sysexplorer.exe and vmreg.dll.

Spyware Guard 2008 - Associated Files and Folders

* C:\Documents and Settings\Shanmuga\Start Menu\Programs\Spyware Guard 2008
* C:\Program Files\Spyware Guard 2008
* C:\Program Files\Spyware Guard 2008\quarantine

* C:\Program Files\Spyware Guard 2008\conf.cfg
* C:\Program Files\Spyware Guard 2008\mbase.vdb
* C:\Program Files\Spyware Guard 2008\quarantine.vdb
* C:\Program Files\Spyware Guard 2008\queue.vdb
* C:\Program Files\Spyware Guard 2008\spywareguard.exe
* C:\Program Files\Spyware Guard 2008\uninstall.exe
* C:\Program Files\Spyware Guard 2008\vbase.vdb

* C:\Documents and Settings\Shanmuga\Desktop\Spyware Guard 2008.lnk
* C:\Documents and Settings\Shanmuga\Start Menu\Programs\Spyware Guard 2008\Spyware Guard 2008.lnk
* C:\Documents and Settings\Shanmuga\Start Menu\Programs\Spyware Guard 2008\Uninstall.lnk
* C:\Documents and Settings\Shanmuga\Application Data\Microsoft\Internet Explorer\olesys.dll

* C:\Windows\reged.exe
* C:\Windows\spoolsystem.exe
* C:\Windows\sys.com
* C:\Windows\syscert.exe
* C:\Windows\sysexplorer.exe
* C:\Windows\vmreg.dll

Note: File names may be randomly generated.

Spyware Guard 2008 - Associated Registry keys and values

* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\spywareguard
REG_SZ, 106 bytes, ?C:\Program Files\Spyware Guard 2008\spywareguard.exe?
* HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Program Files\Spyware Guard 2008\spywareguard.exe
REG_SZ, 26 bytes, ?spywareguard?
* HKEY_CURRENT_USER\Software\Spyware Guard\NP\NP
REG_SZ, 66 bytes, ?F620C418B59F44D289B18E1D1B5D896E?
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spyware Guard 2008\Display Name
REG_SZ, 38 bytes, ?Spyware Guard 2008?
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spyware Guard 2008\DisplayName
REG_SZ, 38 bytes, ?Spyware Guard 2008?
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spyware Guard 2008\UninstallString
REG_SZ, 100 bytes, ?C:\Program Files\Spyware Guard 2008\uninstall.exe?

Spyware Guard 2008 - Associated Domains

* spywareguard2008.com
* Porn-movies-online.net
* pyroscanner.com
* gosg2008.com
* Sg8go.com
* innovagest2000s.com

Spyware Guard 2008 - Removal (How to remove Spyware Guard 2008)

At the time of writing this none of the popular free anti-malware programs were detecting this. I tested with MalwareBytes?s Anti-Malware, SuperAntiSpyware, Ad-Aware 2008, Spybot Search & Destroy, A-squared free and PCTools SpywareDoctor starter edition. I will update this post once any of the above vendors include detection and removal for this rogue.

Update Oct 04: SUPERAntiSpyware free version detects and removes this rogue completely with the latest definitions update.

Update Nov 13: Malwarebytes? Anti-Malware free version is updated to remove this rogue.

Update: If the Internet Explorer and other IE dependent programs have lost their ability to show pictures, try the following, it seems to restore the pictures for some users:

* Open Internet Options in Control Panel
* Click on the Advanced tab.
* Look for the Multimedia section
* Place a check mark in the Show Pictures option.
* Restart Internet Explorer if running.

Advanced users may manually remove this pest by deleting the associated folders, files, registry keys and values mentioned above. I would also recommend turning off and on the System Restore to clear any infected restore points and using CCleaner to clear the temp folders and files to avoid recurrence.

If you still see symptoms associated with this rogue anti-spyware, please post your problem at one of the Recommended Online Forums for Malware Help.




 

KnickNut3

Platinum Member
Oct 1, 2001
2,382
0
0
Thanks for the links. I have tried this method before, unfortunately it didn't work.

I did just figure out that renaming the executables for the malware programs allows them to run (as you recommended), so I'm currently doing full scans in safe mode now. Thanks!
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |