Houzz Logo Print
gram999

Uninstall Spyware Guard 2008

17 years ago

How do I uninstall this? The uninstall icon doesn't work. I can't delete anything anywhere. I tell it to exit & it doesn't. It keeps popping up wanting to do a scan. It's so annoying. In the middle of the installation, I decided I didn't want it & stopped the download. Obviously, that didn't work either.

I would sure appreciate any help.

Comments (13)

  • 17 years ago
    last modified: 11 years ago

    Hi,
    gramm999, best to run the program below please follow all instructions.

    Please download Malwarebytes' Anti-Malware to your desktop. Click here
    Double Click mbam-setup.exe to install the application.
    Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    Â If an update is found, it will download and install the latest version.
    Â Once the program has loaded, select "Perform Full Scan", then click Scan.
    Â The scan may take some time to finish,so please be patient.
    Â When the scan is complete, click OK, then Show Results to view the results.
    Â Make sure that everything is checked, and click Remove Selected.
    Â When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    Â The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    Â Copy&Paste the entire report in your next reply.
    Extra Note:
    If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.

  • 17 years ago
    last modified: 11 years ago

    Here's what it is.

    Spyware Guard 2008 is a rogue anti-spyware program that uses deceptive advertising methods. This program is promoted through the use of fake online anti-malware scanners that state your computer is infected and that you should download and install Spyware Guard 2008 to protect it. These online scanners, though, are just advertisements and have no way of knowing what is running on your computer. They are only stating that you are infected in order to scare you into installing the program.

    If you decide to install the software, Spyware Guard 2008 will configure itself to run automatically on your computer when it starts. Then it will create seven fake malware files that it will detect as malware on your computer in order to further scare you into thinking you are infected. These fake malware files are:

    c:\WINDOWS\reged.exe
    c:\WINDOWS\spoolsystem.exe
    c:\WINDOWS\sys.com
    c:\WINDOWS\syscert.exe
    c:\WINDOWS\sysexplorer.exe
    c:\WINDOWS\vmreg.dll
    %UserProfile%\Application Data\Microsoft\Internet Explorer\olesys.dll

    When Spyware Guard 2008 starts, it automatically scans your computer and lists the seven files above, as well as numerous legitimate files, as malware and does not allow you to remove them unless you first purchase the software. These fake malware files, and all of the legitimate files it flags as infections, are only being used to scare you into purchasing the software. In fact, the files found are all harmless. While this software is installed, you may also find that your computer starts to operate slower. This is because the program is constantly running in the background using up your computer's resources.

  • Related Discussions

    System restore & software install

    Q

    Comments (3)
    When you use the link Bob provided be cool and follow along carefully, if you get flustered simply walk away for a while and return with a clear head and it will work great. You really need to have confidence in the anti virus installed on a computer, in this case McAfee. As long as it is up to date and allowed to scan daily you should be safe from a virus attack. Why would you click to download a second program? Does this Lenovo have any other protection besides McAfee? You might consider installing Superantispyware for protection from Trojans and the like. Be sure to click on the free version. Once installed look immediately for updates and run a full scan. This may take 45 minutes or more. Repeat that every one or 2 weeks to stay clean. Here is a link that might be useful: Superantispyware free
    ...See More

    HELP Help Help !!

    Q

    Comments (14)
    if it is a specific program that is causing the issue and you know that then it is actually better to go to add remove and choose to remove it, then you can do some searches on the pc for any thing left with the program name and delete those items. If something goes wacky or suddenly your settings are changed then using system restore is a good thing to try and often will bring things back to normal. If you had created a restore point right before you installed something, you could also go back in time to that specific restore point if you knew that program was the culprit. I always do create a new restore point prior to any type of install it is just something I have trained my self to do, just in case LOL. Usually other wise you might have to guess as to when you should go back to.
    ...See More

    Never, Ever Heard Of This Problem Before! Help!!!

    Q

    Comments (40)
    can you run this, see link Then this http://www.bleepingcomputer.com/download/junkware-removal-tool/ Anyway you can run Malwarebytes http://www.bleepingcomputer.com/download/malwarebytes-anti-malware/ Here is a link that might be useful: adwcleaner
    ...See More

    Spyware found

    Q

    Comments (34)
    Yes, I do feel better about my computer security, but truthfully will feel a lot better when I get it all sorted out. Is it just me, or do you have to be a rocket scientist to understand SpywareBlaster? lol First of all, under Protection Status, Internet Explorer Protection, I ticked off both Active X Protection and Cookie Protection not being sure if I should do that. ie. Do I want to protect my PC from ALL Active X and ALL cookies? I just left the 'Block List' alone since SpywareBlaster has 355 items selected, and since I don't know what I want to block or not block. After doing this, Internet Explorer Protection is 'partially enabled'. I don't know if that's what I should have. I have protection enabled for Restricted Sites - that, I think I understand. Do I want to do a System Snapshot? And with the Secunia, when I downloaded it I set it to automatically update out-of-date programs. Should I have selected that option, or should I manually update out-of-date programs that it finds? To respond to your recommendations (and thank you for making them), near: 1. I do have Windows set to automatically update, so I'm good on that. I checked up update history, and the only updates it recommends at this time are 7 optional ones. I never done the optional updates. 2. I'm seeing more and more recommendations for the MSE. So it only updates and runs once a week and not daily. I guess this is sufficient? I'm not sure if I'm going to switch over my AVG for something else, but MSE is in the running. 3. Check, on the MalwareBytes. Do you usually run a full scan or a Quick Scan? I've been running the full scan mostly. 4.Check, on the SpywareBlaster (but I have the above questions on it). I still haven't downloaded the SuperAntispyware. 5. I downloaded the Secunia. 6. I haven't downloaded the WinPatrol yet. I have been wondering if AVG will have a problem with it, or vice versa. But we'll see.
    ...See More
  • 17 years ago
    last modified: 11 years ago

    Thanks so much Zep for your help & speedy reply. I did what you recommended. I do notice some things run faster. What a blessing.

    Last summer someone came out to fix some problems on my computer. He installed Spyware Guard, Spybot, Spyware Blaster & Ad-Aware SE Personal on my system. Should I delete these too? I have McAfee through AOL.

    I'm going to have to do some reading on this forum. There are probably other fixes I need.

    Here's the report for Malaware. Oh, should I purchase it?

    Malwarebytes' Anti-Malware 1.33
    Database version: 1665
    Windows 5.1.2600 Service Pack 2

    1/18/2009 12:30:15 PM
    mbam-log-2009-01-18 (12-30-00).txt

    Scan type: Full Scan (C:\:D:\:J:\:)
    Objects scanned: 139689
    Time elapsed: 1 hour(s), 38 minute(s), 26 second(s)

    Memory Processes Infected: 1
    Memory Modules Infected: 3
    Registry Keys Infected: 5
    Registry Values Infected: 3
    Registry Data Items Infected: 0
    Folders Infected: 4
    Files Infected: 27

    Memory Processes Infected:
    C:\Program Files\Spyware Guard 2008\spywareguard.exe (Rogue.SpywareGuard) -> No action taken.

    Memory Modules Infected:
    C:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\dpqmhychnu.dll (Trojan.FakeAlert) -> No action taken.
    C:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\ieModule.dll (Trojan.FakeAlert) -> No action taken.
    C:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\moduleie.dll (Trojan.FakeAlert) -> No action taken.

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\spyware guard 2008 (Rogue.SpywareGuard) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Spyware Guard 2008 (Rogue.SpywareGuard) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\spyware guard (Rogue.SpywareGuard) -> No action taken.
    HKEY_CLASSES_ROOT\CLSID\(55937e13-0442-41ea-a026-2604ff356d05) (Trojan.FakeAlert) -> No action taken.
    HKEY_CLASSES_ROOT\CLSID\(88796e8d-2186-47d8-978f-af18aa0965f8) (Trojan.FakeAlert) -> No action taken.

    Registry Values Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\spywareguard (Rogue.SpywareGuard) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\internetconnection (Trojan.FakeAlert) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\iemodule (Trojan.FakeAlert) -> No action taken.

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    C:\Program Files\Antivirus 2009 (Rogue.Antivirus 2009) -> No action taken.
    C:\Program Files\Spyware Guard 2008 (Rogue.SpywareGuard) -> No action taken.
    C:\Program Files\Spyware Guard 2008\quarantine (Rogue.SpywareGuard) -> No action taken.
    C:\Documents and Settings\Owner\Start Menu\Programs\Spyware Guard 2008 (Rogue.SpywareGuard) -> No action taken.

    Files Infected:
    C:\Documents and Settings\All Users\Application Data\winlogon.exe (Rogue.Installer) -> No action taken.
    C:\Documents and Settings\All Users\Application Data\Microsoft\Protect\svhost.exe (Rogue.Installer) -> No action taken.
    C:\System Volume Information\_restore(F845E3DB-F751-4BE4-A620-64F2CA1BFB5F)\RP470\A0112617.exe (Rogue.Installer) -> No action taken.
    C:\System Volume Information\_restore(F845E3DB-F751-4BE4-A620-64F2CA1BFB5F)\RP470\A0112618.exe (Rogue.Installer) -> No action taken.
    C:\Program Files\Antivirus 2009\av2009.exe (Rogue.Antivirus 2009) -> No action taken.
    C:\Program Files\Spyware Guard 2008\conf.cfg (Rogue.SpywareGuard) -> No action taken.
    C:\Program Files\Spyware Guard 2008\mbase.vdb (Rogue.SpywareGuard) -> No action taken.
    C:\Program Files\Spyware Guard 2008\quarantine.vdb (Rogue.SpywareGuard) -> No action taken.
    C:\Program Files\Spyware Guard 2008\queue.vdb (Rogue.SpywareGuard) -> No action taken.
    C:\Program Files\Spyware Guard 2008\spywareguard.exe (Rogue.SpywareGuard) -> No action taken.
    C:\Program Files\Spyware Guard 2008\uninstall.exe (Rogue.SpywareGuard) -> No action taken.
    C:\Program Files\Spyware Guard 2008\vbase.vdb (Rogue.SpywareGuard) -> No action taken.
    C:\Documents and Settings\Owner\Start Menu\Programs\Spyware Guard 2008\Spyware Guard 2008.lnk (Rogue.SpywareGuard) -> No action taken.
    C:\Documents and Settings\Owner\Start Menu\Programs\Spyware Guard 2008\Uninstall.lnk (Rogue.SpywareGuard) -> No action taken.
    C:\Documents and Settings\All Users\Application Data\Microsoft\Protect\svhost2.exe (Trojan.FakeAlert) -> No action taken.
    C:\Documents and Settings\All Users\Application Data\Microsoft\Protect\track.sys (Trojan.FakeAlert) -> No action taken.
    C:\WINDOWS\sysexplorer.exe (Trojan.FakeAlert) -> No action taken.
    C:\WINDOWS\system32\winscenter.exe (Trojan.FakeAlert) -> No action taken.
    C:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\dpqmhychnu.dll (Trojan.FakeAlert) -> No action taken.
    C:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\ieModule.dll (Trojan.FakeAlert) -> No action taken.
    C:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\moduleie.dll (Trojan.FakeAlert) -> No action taken.
    C:\WINDOWS\reged.exe (Rogue.SpywareGuard) -> No action taken.
    C:\WINDOWS\spoolsystem.exe (Rogue.SpywareGuard) -> No action taken.
    C:\WINDOWS\sys.com (Rogue.SpywareGuard) -> No action taken.
    C:\WINDOWS\syscert.exe (Rogue.SpywareGuard) -> No action taken.
    C:\WINDOWS\vmreg.dll (Rogue.SpywareGuard) -> No action taken.
    C:\Documents and Settings\Owner\Desktop\Spyware Guard 2008.lnk (Rogue.SpywareGuard) -> No action taken.

  • 17 years ago
    last modified: 11 years ago

    No action taken,

    Please let Malwarebytes remove everything it finds,

    When the scan is complete, click OK, then Show Results to view the results.
    Make sure that everything is checked, and click Remove Selected.

  • 17 years ago
    last modified: 11 years ago

    Need to see another log after, you're doing good just missed a step.

    zep516

  • 17 years ago
    last modified: 11 years ago

    Thanks again. I misunderstood. I did remove everything. I thought you wanted to see that log.

    Do you think I should delete Spyware Guard (an earlier version), Spybot, Ad-Adaware Personal SE & SpywareBlaster? Someone installed them on my machine without asking when he worked on it. I have McAfee through AOL. I've heard it's not good to have 2 virus programs.

    Here's the log you want -

    Malwarebytes' Anti-Malware 1.33
    Database version: 1665
    Windows 5.1.2600 Service Pack 2

    1/18/2009 12:32:01 PM
    mbam-log-2009-01-18 (12-32-01).txt

    Scan type: Full Scan (C:\:D:\:J:\:)
    Objects scanned: 139689
    Time elapsed: 1 hour(s), 38 minute(s), 26 second(s)

    Memory Processes Infected: 1
    Memory Modules Infected: 3
    Registry Keys Infected: 5
    Registry Values Infected: 3
    Registry Data Items Infected: 0
    Folders Infected: 4
    Files Infected: 27

    Memory Processes Infected:
    C:\Program Files\Spyware Guard 2008\spywareguard.exe (Rogue.SpywareGuard) -> Unloaded process successfully.

    Memory Modules Infected:
    C:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\dpqmhychnu.dll (Trojan.FakeAlert) -> Delete on reboot.
    C:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\ieModule.dll (Trojan.FakeAlert) -> Delete on reboot.
    C:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\moduleie.dll (Trojan.FakeAlert) -> Delete on reboot.

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\spyware guard 2008 (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Spyware Guard 2008 (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\spyware guard (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\(55937e13-0442-41ea-a026-2604ff356d05) (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\(88796e8d-2186-47d8-978f-af18aa0965f8) (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\spywareguard (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\internetconnection (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\iemodule (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    C:\Program Files\Antivirus 2009 (Rogue.Antivirus 2009) -> Delete on reboot.
    C:\Program Files\Spyware Guard 2008 (Rogue.SpywareGuard) -> Delete on reboot.
    C:\Program Files\Spyware Guard 2008\quarantine (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Owner\Start Menu\Programs\Spyware Guard 2008 (Rogue.SpywareGuard) -> Quarantined and deleted successfully.

    Files Infected:
    C:\Documents and Settings\All Users\Application Data\winlogon.exe (Rogue.Installer) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Microsoft\Protect\svhost.exe (Rogue.Installer) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore(F845E3DB-F751-4BE4-A620-64F2CA1BFB5F)\RP470\A0112617.exe (Rogue.Installer) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore(F845E3DB-F751-4BE4-A620-64F2CA1BFB5F)\RP470\A0112618.exe (Rogue.Installer) -> Quarantined and deleted successfully.
    C:\Program Files\Antivirus 2009\av2009.exe (Rogue.Antivirus 2009) -> Quarantined and deleted successfully.
    C:\Program Files\Spyware Guard 2008\conf.cfg (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
    C:\Program Files\Spyware Guard 2008\mbase.vdb (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
    C:\Program Files\Spyware Guard 2008\quarantine.vdb (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
    C:\Program Files\Spyware Guard 2008\queue.vdb (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
    C:\Program Files\Spyware Guard 2008\spywareguard.exe (Rogue.SpywareGuard) -> Delete on reboot.
    C:\Program Files\Spyware Guard 2008\uninstall.exe (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
    C:\Program Files\Spyware Guard 2008\vbase.vdb (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Owner\Start Menu\Programs\Spyware Guard 2008\Spyware Guard 2008.lnk (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Owner\Start Menu\Programs\Spyware Guard 2008\Uninstall.lnk (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Microsoft\Protect\svhost2.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Microsoft\Protect\track.sys (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\WINDOWS\sysexplorer.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\winscenter.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\dpqmhychnu.dll (Trojan.FakeAlert) -> Delete on reboot.
    C:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\ieModule.dll (Trojan.FakeAlert) -> Delete on reboot.
    C:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\moduleie.dll (Trojan.FakeAlert) -> Delete on reboot.
    C:\WINDOWS\reged.exe (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
    C:\WINDOWS\spoolsystem.exe (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
    C:\WINDOWS\sys.com (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
    C:\WINDOWS\syscert.exe (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
    C:\WINDOWS\vmreg.dll (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Owner\Desktop\Spyware Guard 2008.lnk (Rogue.SpywareGuard) -> Quarantined and deleted successfully.

  • 17 years ago
    last modified: 11 years ago

    I will answer questions at end.

    Please do this next,

    Download ATF Cleaner by Atribune to your Desktop.


    Note: Vista users must use Run As Administrator
    Under Main: Select Files to Delete choose: Select All.
    Click the Empty Selected button.
    If you use Firefox browser click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    If you would like to keep your saved passwords click No at the prompt.
    If you use Opera browser click Opera at the top and choose: Select All
    Click the Empty Selected button.
    If you would like to keep your saved passwords click No at the prompt.
    Click Exit on the Main menu to close the program.

    No log to post, make sure you run this, post back telling me you ran it then I will answer questions you have.

    zep

  • 17 years ago
    last modified: 11 years ago

    On that link you will see ATF cleaner in RED, that's the download.

  • 17 years ago
    last modified: 11 years ago

    the spyware guard your tech put on is NOT this same rogue spwyare guard2008 they named it that to make people think it was the good program and they would fall for it.

    the real spywareguard and sypwareblaster are by javacool and are good excellent programs so you can keep those.
    ' you can not have 2 antivirus programs running but you can have more than one antispywareprogram so you are ok since the ones you have are antispyware.
    Keep that malwarebytes for sure it is excellent.

    zep will help you out!

  • 17 years ago
    last modified: 11 years ago

    Raven,

    Thanks

    Rogue.Antivirus 2009

    Raven I don't trust this one above, malwarebytes misses 2 files on this and I think a follow up is in order to LLDDzz, after she posts back would you do the referral to there.

    The user needs to have hijackthis ran ect, & combofix.

  • 17 years ago
    last modified: 11 years ago

    I agree totally zep she has some some other stuff going on there. I will let Corrine know.

    Gram999 will you please go to this help forum and register I will start a thread there with your name on it in the Hijackthis area, you need a bit more work done and it will be better to do it there. We will take care of you over there.
    HijackThis Logs

    Just go there and register to the forum then go to the area I linked to Hijackthis logs and look for the the thread I am going to start with your name. I will post your log there for you.

  • 17 years ago
    last modified: 11 years ago

    OK. Thanks very much.

  • 17 years ago
    last modified: 11 years ago

    ok gram999 your thread is up and posted there, just go ahead and post there if you have done any other logs , and please provide the info on your pc, which windows version you are using for example etc, over there. The team there is from all over the world so it may take a little time to get you taken care of so just be patient.
    You do have some pretty serious infections on your pc so be sure you do follow through.

0
Sponsored