Home Malware Programs Fake Warning Messages CoreGuard Antivirus 2009 Popup

CoreGuard Antivirus 2009 Popup

Posted: May 1, 2009

"CoreGuard Antivirus 2009" Popup is another fake popup message that comes from the CoreGuard Antivirus 2009 rogue anti-spyware application. The message below is used to scam computer users and force them into purchasing the CoreGuard Antivirus 2009 program. The "CoreGuard Antivirus 2009" Popup reads like the following:

"There is unauthorized antivirus software detected on your computer. It is recommended to you to remove it, otherwise it could conflict with CoreGusard Antivirus 2009."

It is recommended that you take the necessary precautions to detect and remove the "CoreGuard Antivirus 2009" Popup infection or CoreGuard Antivirus 2009 rogue anti-spyware program. This can be done successfully with a spyware scan and removal tool.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Coreguard 2009.lnk
    2 %UserProfile%\Desktop\Coreguard 2009.lnk
    3 %UserProfile%\Start Menu\Programs\Coreguard Antivirus 2009\Coreguard 2009.lnk
    4 %UserProfile%\Start Menu\Programs\Coreguard Antivirus 2009\Uninstall Coreguard Antivirus 2009.lnk
    5 c:\Program Files\Coreguard Antivirus 2009\Help\images\buttons\offline.gif
    6 c:\Program Files\Coreguard Antivirus 2009\Help\images\buttons\online.gif
    7 c:\Program Files\Coreguard Antivirus 2009\Help\images\buttons\voice.gif
    8 c:\Program Files\Coreguard Antivirus 2009\Help\images\delete.png
    9 c:\Program Files\Coreguard Antivirus 2009\Help\images\info.png
    10 c:\Program Files\Coreguard Antivirus 2009\Help\images\plus_circle.png
    11 c:\Program Files\Coreguard Antivirus 2009\Help\images\tick.png
    12 c:\Program Files\Coreguard Antivirus 2009\Help\images\warn.png
    13 c:\Program Files\Coreguard Antivirus 2009\Help\reg.html
    14 c:\Program Files\Coreguard Antivirus 2009\Help\support.png
    15 c:\Program Files\Coreguard Antivirus 2009\Help\unreg.html

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\CoreGuardHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Coreguard Antivirus 2009"HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Coreguard Antivirus 2009

One Comment

  • Dale Baker says:

    In order to protect myself against computer viruses I use Cyberdefender. It has worked great. It is easy to use and keeps my computer running extremely fast.

Loading...