Home Malware Programs Rogue Anti-Spyware Programs SafeGuard 2009

SafeGuard 2009

Posted: February 5, 2009

SafeGuard 2009, also known as SafeGuard2009, is a rogue anti-spyware program usually installed by the Trojan Zlob or Vundo. Once infected by SafeGuard 2009, you'll receive numerous fake security alerts and system scan results stating that your computer is infected with spyware. To remove the supposed spyware infections, SafeGuard 2009 will then urge you to purchase SafeGuard 2009's full program from its website for $79.95 or $49.95. All links provided by SafeGuard 2009 will most likely redirect you to malicious websites that sell SafeGuard 2009 as a legitimate spyware remover. SafeGuard 2009 may have the ability to recreate itself after reboot. It is strongly recommended to remove SafeGuard 2009 from your system upon detection.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Start Menu\Programs\Safeguard 2009
    2 %UserProfile%\Start Menu\Programs\Safeguard 2009\Safeguard 2009.lnk
    3 c:\Documents and Settings\All Users\Application Data\SafeguardSoft Ltd
    4 c:\Documents and Settings\All Users\Application Data\SafeguardSoft Ltd\Safeguard 2009
    5 c:\Documents and Settings\All Users\Application Data\SafeguardSoft Ltd\Safeguard 2009\BASE
    6 c:\Documents and Settings\All Users\Application Data\SafeguardSoft Ltd\Safeguard 2009\DELETED
    7 c:\Documents and Settings\All Users\Application Data\SafeguardSoft Ltd\Safeguard 2009\LOG
    8 c:\Documents and Settings\All Users\Application Data\SafeguardSoft Ltd\Safeguard 2009\LOG\20090204155256795.log
    9 c:\Documents and Settings\All Users\Application Data\SafeguardSoft Ltd\Safeguard 2009\SAVED
    10 c:\Documents and Settings\All Users\Application Data\SafeguardSoft Ltd\Safeguard 2009\sf2009.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Safeguard 2009"HKEY_CURRENT_USER\Software\SafeguardSoft LtdHKEY_CURRENT_USER\Software\SafeguardSoft\Safeguard 2009HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Safeguard 2009
Loading...