BehaviorThe program must be manually installed.
The program reports false or exaggerated system security threats on the computer.

The user is then prompted to pay for a full license of the application in order to remove the threats.
InstallationWhen the program is executed, it creates the following files:
- %UserProfile%\Desktop\Spyware Guard 2008.lnk
- %UserProfile%\Start Menu\Programs\Spyware Guard 2008\Spyware Guard 2008.lnk
- %UserProfile%\Start Menu\Programs\Spyware Guard 2008\Uninstall.lnk
- %ProgramFiles%\Spyware Guard 2008\conf.cfg
- %ProgramFiles%\Spyware Guard 2008\mbase.vdb
- %ProgramFiles%\Spyware Guard 2008\quarantine.vdb
- %ProgramFiles%\Spyware Guard 2008\queue.vdb
- %ProgramFiles%\Spyware Guard 2008\spywareguard.exe
- %ProgramFiles%\Spyware Guard 2008\uninstall.exe
- %ProgramFiles%\Spyware Guard 2008\vbase.vdb
- %UserProfile%\Application Data\Microsoft\Internet Explorer\olesys.dll
- %Windìr%\reged.exe
- %Windìr%\spoolsystem.exe
- %Windìr%\sys.com
- %Windìr%\syscert.exe
- %Windìr%\sysexplorer.exe
- %Windìr%\vmreg.dll
Next, the program creates the following registry entry so that it executes whenever Windows starts:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"spywareguard" = "C:\Program Files\Spyware Guard 2008\spywareguard.exe"
It also creates the following registry subkeys:
- HKEY_CURRENT_USER\Software\Spyware Guard
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spyware Guard 2008
Similar Security RisksMalwareDefender2009