Malicious Progarm - WinSpywareProtect sysguard.exe
This section provides some notes on Antivirus System PRO program sysguard.exe detected and terminated by Spybot - Search & Destroy as the WinSpywareProtect virus threat.
More notes on what Antivirus System PRO did and what I did to remove it.
10. A moment later, the "Spybot - Search & Destroy" virus protection program
displays an alert message. See the picture below:
Spybot - Search & Destroy has encountered and
terminated a process that is listed as part of a
Process ID: 1648
Found in: C:\WINDOWS\
Identified as: WinSpywareProtect
If Spybot - Search & Destroy encounters this process again...
[x] Inform me again.
[ ] Automatically kill this process.
[ ] Allow this process to run (NOT RECOMMENDED).
[X] Delete the associated file.
11. Clicking the OK button to let Spybot - Search & Destroy to delete the virus program file sysguard.exe.
12. The Antivirus System PRO task bar icon is gone.
Some quick conclusions:
- The Antivirus System PRO task bar icon is resulted from the running process, sysguard.exe.
- The antivirus program installed on the system, Spybot - Search & Destroy, did a good job to detect and remove
the sysguard.exe process as a virus threat.
- But it would be much better, if Spybot - Search & Destroy could detect and stop sysguard.exe being stored
to the hard disk or detect and stop being launched into a running process.
Last update: 2009.
Table of Contents
About This Windows Security Book
Windows 8: System Security Review
Windows 8: System Security Protection
Windows 8 System Recovery
Windows 8 Defender for Real-Time Protection
Windows 7: System Security Review
Windows 7: System Security Protection
Windows 7 System Recovery
Windows 7 Forefront Client Security
Norton Power Eraser - Anti-Virus Scan Tool
McAfee Virus and Malware Protection Tools
Spybot - Spyware Blocker, Detection and Removal
Keeping Firefox Secure
Keeping IE (Internet Explorer) Secure
Malware (Adware, Spyware, Trojan, Worm, and Virus)
HijackThis - Browser Hijacker Diagnosis Tool
IE Add-on Program Listing and Removal
"Conduit Search" - Malware Detection and Removal
"Tube Dimmer", "Scorpion Saver" or "Adpeak" Malware
Malware Manual Removal Experience
Vundo (VirtuMonde/VirtuMundo) - vtsts.dll Removal
Trojan and Malware "Puper" Description and Removal
VSToolbar (VSAdd-in.dll) - Description and Removal
PWS (Password Stealer) Trojan Infection Removal
MS08-001 Vulnerability on Windows Systems
►Antivirus System PRO
Antivirus System PRO - Fake Security Alert
Antivirus System PRO - Task Bar Icon Message
►Malicious Progarm - WinSpywareProtect sysguard.exe
Malicious Programs - pp10.exe and ld12.exe
IE BHO - iehelper.dll
Faked Host Name - 18.104.22.168
Malicious System Service - drv.dll and drv.sys
PDF Printing Version