This guide will give you easy instructions on how to remove System Guard 2009 for free.
What is System Guard 2009? (Information)
System Guard 2009 is a fake security software which uses fraudulent strategies by displaying false or exaggerated security issues on your computer rather than any legitimate ones to coerce you into purchasing their software.
System Guard 2009 Screenshot:
Symptoms in a HijackThis Log:
O4 - HKLM\..\Run: [systemguard] C:\Program Files\System Guard 2009\systemguard.exe
O21 - SSODL: ieModule - {77C96E10-FDA7-4AA7-B318-0631C0D27DBB} - C:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs\ieModule.dll
O21 - SSODL: InternetConnection - {AB6DAA8C-F726-4FDD-8B06-9537C5878612} - C:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs\eewhptdpyl.dll
Follow these instructions to continue:
1. Please download this official version of Malwarebytes' Anti-Malware.
2. Install Malwarebytes' Anti-Malware by double clicking on mbam-setup
3. Follow the prompts. Make sure that Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware are checked. Then click finish.
4. Malwarebytes' Anti-Malware will automatically update itself after the installation, click the OK button to close that box and you will now be at the main program Window as shown below.
If you are having problems with the updater, you can use this link to manually update Malwarebytes' Anti-Malware with the latest database. Make sure that Malwarebytes' Anti-Malware is closed before installing the update.
5. Close All opened Windows, Programs, File or Folders.
6. Make sure you are on the Scanner tab. Select Perform quick scan then click the Scan button as shown below.
7. Malwarebytes' Anti-Malware will now start scanning your computer for infected files as shown below.
8. When the scan is finished a message box will appear, click OK to continue.
9. Click Show Results.
10. You will now be presented with a screen showing you the malware infections like shown below. Yours may look different depending on the infection you have.
11. Click on Remove selected.
12. When removing the files, Malwarebytes' Anti-Malware may require you to restart the computer in order to do a complete removal. If it displays a message stating that it needs to restart, click Yes.
13. After that you can close the Malwarebytes' Anti-Malware window, your computer is now cleaned from the malware infection.
To protect and prevent your computer from experiencing future threats like this, we highly recommend purchasing the FULL version of Malwarebytes' Anti-Malware with real-time protection from this link.
Malicious files associated with System Guard 2009 (click):
If you are still experiencing problems or difficulties following this guide or require any assistance removing this malware, please post your questions in our Virus, Spyware & Malware Removal forums for free help.
You have to be logged in to post questions. Registration is free. By registering you will be privileged to other resources and to ask questions.
Last edited by Doctor Inferno on 29th May 2010, 5:10 am; edited 12 times in total (Reason for editing : Information Update)
What is System Guard 2009? (Information)
System Guard 2009 is a fake security software which uses fraudulent strategies by displaying false or exaggerated security issues on your computer rather than any legitimate ones to coerce you into purchasing their software.
System Guard 2009 Screenshot:
Symptoms in a HijackThis Log:
O4 - HKLM\..\Run: [systemguard] C:\Program Files\System Guard 2009\systemguard.exe
O21 - SSODL: ieModule - {77C96E10-FDA7-4AA7-B318-0631C0D27DBB} - C:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs\ieModule.dll
O21 - SSODL: InternetConnection - {AB6DAA8C-F726-4FDD-8B06-9537C5878612} - C:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs\eewhptdpyl.dll
Follow these instructions to continue:
1. Please download this official version of Malwarebytes' Anti-Malware.
2. Install Malwarebytes' Anti-Malware by double clicking on mbam-setup
3. Follow the prompts. Make sure that Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware are checked. Then click finish.
4. Malwarebytes' Anti-Malware will automatically update itself after the installation, click the OK button to close that box and you will now be at the main program Window as shown below.
If you are having problems with the updater, you can use this link to manually update Malwarebytes' Anti-Malware with the latest database. Make sure that Malwarebytes' Anti-Malware is closed before installing the update.
5. Close All opened Windows, Programs, File or Folders.
6. Make sure you are on the Scanner tab. Select Perform quick scan then click the Scan button as shown below.
7. Malwarebytes' Anti-Malware will now start scanning your computer for infected files as shown below.
8. When the scan is finished a message box will appear, click OK to continue.
9. Click Show Results.
10. You will now be presented with a screen showing you the malware infections like shown below. Yours may look different depending on the infection you have.
11. Click on Remove selected.
12. When removing the files, Malwarebytes' Anti-Malware may require you to restart the computer in order to do a complete removal. If it displays a message stating that it needs to restart, click Yes.
13. After that you can close the Malwarebytes' Anti-Malware window, your computer is now cleaned from the malware infection.
To protect and prevent your computer from experiencing future threats like this, we highly recommend purchasing the FULL version of Malwarebytes' Anti-Malware with real-time protection from this link.
Malicious files associated with System Guard 2009 (click):
Spoiler :
c:\Program Files\System Guard 2009
c:\Program Files\System Guard 2009\conf.cfg
c:\Program Files\System Guard 2009\mbase.vdb
c:\Program Files\System Guard 2009\quarantine.vdb
c:\Program Files\System Guard 2009\queue.vdb
c:\Program Files\System Guard 2009\systemguard.exe
c:\Program Files\System Guard 2009\uninstall.exe
c:\Program Files\System Guard 2009\vbase.vdb
c:\Program Files\System Guard 2009\quarantine
c:\WINDOWS\reged.exe
c:\WINDOWS\spoolsystem.exe
c:\WINDOWS\sys.com
c:\WINDOWS\syscert.exe
c:\WINDOWS\sysexplorer.exe
c:\WINDOWS\vmreg.dll
c:\WINDOWS\system32\winscenter.exe
c:\Documents and Settings\GeekPolice\Desktop\System Guard 2009.lnk
c:\Documents and Settings\GeekPolice\Start Menu\Programs\System Guard 2009
c:\Documents and Settings\GeekPolice\Start Menu\Programs\System Guard 2009\System Guard 2009.lnk
c:\Documents and Settings\GeekPolice\Start Menu\Programs\System Guard 2009\Uninstall.lnk
c:\Documents and Settings\All Users\Application Data\winlogon.exe
c:\Documents and Settings\All Users\Application Data\Microsoft\Network\svchost.exe
c:\Documents and Settings\All Users\Application Data\Microsoft\Network\track.sys
c:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs
c:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs\c.cgm
c:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs\eewhptdpyl.dll
c:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs\ieModule.dll
c:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs\moduleie.dll
c:\Program Files\System Guard 2009\conf.cfg
c:\Program Files\System Guard 2009\mbase.vdb
c:\Program Files\System Guard 2009\quarantine.vdb
c:\Program Files\System Guard 2009\queue.vdb
c:\Program Files\System Guard 2009\systemguard.exe
c:\Program Files\System Guard 2009\uninstall.exe
c:\Program Files\System Guard 2009\vbase.vdb
c:\Program Files\System Guard 2009\quarantine
c:\WINDOWS\reged.exe
c:\WINDOWS\spoolsystem.exe
c:\WINDOWS\sys.com
c:\WINDOWS\syscert.exe
c:\WINDOWS\sysexplorer.exe
c:\WINDOWS\vmreg.dll
c:\WINDOWS\system32\winscenter.exe
c:\Documents and Settings\GeekPolice\Desktop\System Guard 2009.lnk
c:\Documents and Settings\GeekPolice\Start Menu\Programs\System Guard 2009
c:\Documents and Settings\GeekPolice\Start Menu\Programs\System Guard 2009\System Guard 2009.lnk
c:\Documents and Settings\GeekPolice\Start Menu\Programs\System Guard 2009\Uninstall.lnk
c:\Documents and Settings\All Users\Application Data\winlogon.exe
c:\Documents and Settings\All Users\Application Data\Microsoft\Network\svchost.exe
c:\Documents and Settings\All Users\Application Data\Microsoft\Network\track.sys
c:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs
c:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs\c.cgm
c:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs\eewhptdpyl.dll
c:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs\ieModule.dll
c:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs\moduleie.dll
If you are still experiencing problems or difficulties following this guide or require any assistance removing this malware, please post your questions in our Virus, Spyware & Malware Removal forums for free help.
You have to be logged in to post questions. Registration is free. By registering you will be privileged to other resources and to ask questions.
Last edited by Doctor Inferno on 29th May 2010, 5:10 am; edited 12 times in total (Reason for editing : Information Update)