System Guard 2009 manual removal:
Kill processes:
systemguard.exe uninstall.exe reged.exe spoolsystem.exe syscert.exe sysexplorer.exe winscenter.exe winlogon.exe svchost.exe
Delete registry values:HKEY_CLASSES_ROOT\CLSID\{77C96E10-FDA7-4AA7-B318-0631C0D27DBB}
HKEY_CLASSES_ROOT\CLSID\{AB6DAA8C-F726-4FDD-8B06-9537C5878612}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\System Guard 2009
HKEY_LOCAL_MACHINE\SOFTWARE\System Guard 2009
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "systemguard"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad "ieModule"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad "InternetConnection"
Unregister DLLs:vmreg.dll eewhptdpyl.dll ieModule.dll moduleie.dll
Delete files:c:\\Program Files\\System Guard 2009 c:\\Program Files\\System Guard 2009\\conf.cfg c:\\Program Files\\System Guard 2009\\mbase.vdb c:\\Program Files\\System Guard 2009\\quarantine.vdb c:\\Program Files\\System Guard 2009\\queue.vdb c:\\Program Files\\System Guard 2009\\systemguard.exe c:\\Program Files\\System Guard 2009\\uninstall.exe c:\\Program Files\\System Guard 2009\\vbase.vdb c:\\Program Files\\System Guard 2009\\quarantine c:\\WINDOWS\\reged.exe c:\\WINDOWS\\spoolsystem.exe c:\\WINDOWS\\sys.com c:\\WINDOWS\\syscert.exe c:\\WINDOWS\\sysexplorer.exe c:\\WINDOWS\\vmreg.dll c:\\WINDOWS\\system32\\winscenter.exe c:\\Documents and Settings\\Bleeping\\Desktop\\System Guard 2009.lnk c:\\Documents and Settings\\Bleeping\\Start Menu\\Programs\\System Guard 2009 c:\\Documents and Settings\\Bleeping\\Start Menu\\Programs\\System Guard 2009\\System Guard 2009.lnk c:\\Documents and Settings\\Bleeping\\Start Menu\\Programs\\System Guard 2009\\Uninstall.lnk c:\\Documents and Settings\\All Users\\Application Data\\winlogon.exe c:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Network\\svchost.exe c:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Network\\track.sys c:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Network\\DLLs c:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Network\\DLLs\\c.cgm c:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Network\\DLLs\\eewhptdpyl.dll c:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Network\\DLLs\\ieModule.dll c:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Network\\DLLs\\moduleie.dll
Symptoms were pops ups (antiviralscanner14.com and various bogus scanning windows), slow performance
Downloaded MS Windows Defender and it identified and removed Trojan:Win32/Vundo.BR first time
Post Comment: