Threat Search: 

ThreatExpert's Statistics for SpywareGuard2008 [Symantec]:

SpywareGuard2008 [Symantec] is also known as:
Threat AliasNumber of Incidents
RogueAntiSpyware.Sysguard [PC Tools]627
Trojan:Win32/FakeSpyguard [Microsoft]42
Rootkit.Win32.TDSS [Ikarus]33
RogueAntiSpyware.SpywareGuard2008 [PC Tools]28
Trojan.Win32.FakeSpyguard [Ikarus]21
Mal/Generic-A [Sophos]17
Mal/FakeVirPk-A [Sophos]16
Troj/FakeAV-ABN [Sophos]14
Trojan.Generic [Ikarus]12
Win-Trojan/Xema.variant [AhnLab]12
Generic.Win32.Malware.FakeSpyguard [Ikarus]11
Trojan.Fakeavalert [Symantec]10
FakeAlert-SpywareGuard [McAfee]9
Generic PUP.z [McAfee]9
Generic.dx [McAfee]9
not-a-virus:FraudTool.Win32.SpywareGuard2008.ab [Kaspersky Lab]9
Virus.Win32.Fasec [Ikarus]9
DNSChanger.r [McAfee]8
Packed.Win32.Tdss.c [Kaspersky Lab]8
Troj/FakeAV-AIA [Sophos]8
DNSChanger.f.gen.a [McAfee]7
Generic.Win32.Malware [Ikarus]7
Mal/EncPk-CZ [Sophos]6
Generic PWS.y [McAfee]5
Packed.Win32.Tdss.f [Kaspersky Lab]5
Mal/EncPk-HT, Mal/FakeVirPk-A, Mal/TDSS-A [Sophos]4
not-a-virus:FraudTool.Win32.SpywareGuard2008.x [Kaspersky Lab]4
not-a-virus:FraudTool.Win32.SpywareGuard2008.z [Kaspersky Lab]4
Troj/FakeVir-KG [Sophos]4
Trojan.Win32.Tdss.arvy [Kaspersky Lab]4
Mal/TDSS-A, Mal/FakeVirPk-A [Sophos]3
Rootkit.Win32.TDSS.dbo [Kaspersky Lab]3
Trojan.Crypt [Ikarus]3
FakeAlert-SpywareGuard.gen.b [McAfee]2
Generic FakeAlert.c [McAfee]2
Mal/EncPk-GR, Mal/EncPk-GR [Sophos]2
Mal/FakeVirPk-A, Mal/EncPk-CZ [Sophos]2
Mal/TDSSPack-E [Sophos]2
Mal/TibsPk-A [Sophos]2
not-a-virus:FraudTool.Win32.SpywareGuard2008.ax [Kaspersky Lab]2
not-a-virus:FraudTool.Win32.SpywareGuard2008.bf [Kaspersky Lab]2
Program:Win32/FakeSpyguard [Microsoft]2
Trojan.FraudPack!sd6 [PC Tools]2
Trojan.Win32.FraudPack [Ikarus]2
Trojan.Win32.FraudPack.amm [Kaspersky Lab]2
Trojan:Win32/Alureon.BJ [Microsoft]2
Trojan:Win32/FakePowav.B [Microsoft]2
Trojan:Win32/FakeSpypro [Microsoft]2
Worm.Win32.AutoTDSS [Ikarus]2
BehavesLike.Win32.Malware [Ikarus]1
DNSChanger!h [McAfee]1
FakeAlert-AB [McAfee]1
FakeAlert-BM [McAfee]1
FakeAlert-DB [McAfee]1
FakeAlert-EA [McAfee]1
FakeAlert-KU [McAfee]1
FakeAlert-SpyPro.gen.a [McAfee]1
FakeAlert-SpyPro.gen.dr [McAfee]1
Generic Downloader.x!yv [McAfee]1
Generic FakeAlert!bo [McAfee]1
Generic FakeAlert!ee [McAfee]1
Generic PUP.x [McAfee]1
Mal/Alureon-C, Mal/FakeVirPk-A [Sophos]1
Mal/Basine-C [Sophos]1
Mal/FakeAV-AD [Sophos]1
Mal/FakeAV-AD, Mal/Alureon-C, Mal/FakeVirPk-A, Troj/Virtum-Gen [Sophos]1
Mal/FakeAV-BX, Mal/EncPk-MC, Mal/EncPk-MA [Sophos]1
Mal/FakeAV-CF [Sophos]1
Mal/FakeVirPk-A, Mal/TDSS-A [Sophos]1
Mal/TDSS-A [Sophos]1
Mal/TDSSPack-J, Mal/TDSSPack-E [Sophos]1
Mal/TDSSPack-Q, Mal/EncPk-HT, Mal/FakeVirPk-A, Mal/TDSS-A [Sophos]1
Malware-Cryptor.Win32.Rp [Ikarus]1
New Malware.ix [McAfee]1
not-a-virus:FraudTool.Win32.PrivacyCenter.dt [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.PrivacyCenter.du [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.SpywareGuard2008.aa [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.SpywareGuard2008.b [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.SpywareGuard2008.d [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.SpywareGuard2008.s [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.SpywareGuard2008.y [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.WinSpywareProtect.bfc [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.XPAntivirus.gj [Kaspersky Lab]1
Packed.Win32.Krap [Ikarus]1
Packed.Win32.Krap.ah [Kaspersky Lab]1
Packed.Win32.Tdss.a [Kaspersky Lab]1
Packed.Win32.TDSS.aa [Kaspersky Lab]1
RogueAntiSpyware.WindowsSecuritySuite [PC Tools]1
Rootkit.Win32.TDSS.dgl [Kaspersky Lab]1
Troj/FakeAV-AHF [Sophos]1
Troj/FakeAV-AUU [Sophos]1
Troj/FakeVir-IV [Sophos]1
Troj/FakeVir-NX [Sophos]1
Troj/FakeVir-PU [Sophos]1
TROJ_FAKEALRT.CG [Trend Micro]1
Trojan.Fakealert [Ikarus]1
Trojan.Fakealert.AHX [Ikarus]1
Trojan.TDSS!sd6 [PC Tools]1
Trojan.Win32.FakeIA [Ikarus]1
Trojan.Win32.FakeXPA [Ikarus]1

SpywareGuard2008 [Symantec] has the following possible country of origin:
OriginNumber of Incidents
Russian Federation46

SpywareGuard2008 [Symantec] is known to be created as:
%AppData%\cdhmdm\gafcsysguard.exe
%AppData%\hskdfm\einhsysguard.exe
%AppData%\hxqlqq\ufhssysguard.exe
%AppData%\kpljha\xhvssysguard.exe
%AppData%\nmpcue\evbesysguard.exe
%AppData%\pceafd\mbxmsysguard.exe
%AppData%\qgcanl\kxamsftav.exe
%AppData%\ubbrhs\sypwsysguard.exe
%AppData%\ugbsxq\xkelsftav.exe
%AppData%\uhxevr\jfppsysguard.exe
%AppData%\vmdspi\syudsysguard.exe
%AppData%\vncvfj\xtnvsysguard.exe
%CommonAppData%\svhost.exe
%ProgramFiles%\advanced defender\advanceddefender.exe
%ProgramFiles%\malware defender 2009\malwaredef.exe
%ProgramFiles%\malware defender 2009\uninstall.exe
%ProgramFiles%\malwareremoval\malwareremoval.exe
%ProgramFiles%\personal guard 2009\personalguard.exe
%ProgramFiles%\privacy components\agent.exe
%ProgramFiles%\privacy components\pc.exe
%ProgramFiles%\rhc75dj0erc1\rhc75dj0erc1.exe
%ProgramFiles%\spyware guard 2008\spywareguard.exe
%ProgramFiles%\spyware guard 2008\uninstall.exe
%ProgramFiles%\system guard 2009\systemguard.exe
%System%\setupmalwareremoval.exe
%System%\winscenter.exe
%Temp%\personalguard.exe
%Temp%\qdmr.exe
%Temp%\virus\malwaredefender2009.exe
%Windir%\1.exe
%Windir%\temp\svchost.exe
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %CommonAppData% is a variable that refers to the file system directory containing application data for all users. A typical path is C:\Documents and Settings\All Users\Application Data.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.