PersonalGuard2009

PersonalGuard2009

Found: 
2009-09-10
Known system changes: 

Created Files

  • %Desktop%Personal Guard 2009.lnk
  • %Desktop%Personal Guard 2009..lnk
  • %Desktop%Personal Protector.lnk
  • %Windir%tempfile2.bat
  • %Desktop%Smart Protector.lnk

Created Folders

  • %ProgramFiles%Personal Guard 2009
  • %CommonPrograms%Personal Guard 2009
  • %StartMenu%Programs\Personal Guard 2009
  • %ProgramFiles%Personal Protector
  • %CommonPrograms%Personal Protector
  • %ProgramFiles%Smart Protector
  • %CommonPrograms%Smart Protector

Registry Entries

  • Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Smart Protector
  • Value:
  • Data:
  • Key: HKEY_LOCAL_MACHINE\SOFTWARE\Smart Protector
  • Value:
  • Data:
  • Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Personal Guard 2009
  • Value:
  • Data:
  • Key: HKEY_LOCAL_MACHINE\SOFTWARE\Personal Guard 2009
  • Value:
  • Data:
  • Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
  • Value: personalguard
  • Data: C:\Program Files\Personal Guard 2009\personalguard.exe
  • Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
  • Value: SysNet
  • Data: {D51506B3-B8AB-48ED-84D3-E9CB892D4F59}
  • Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Personal Protector
  • Value:
  • Data:
  • Key: HKEY_LOCAL_MACHINE\SOFTWARE\Personal Protector
  • Value:
  • Data:
  • Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
  • Value: personalprotector
  • Data: C:\Program Files\Personal Protector\personalprotector.exe
  • Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
  • Value: suicide
  • Data: C:\WINDOWS\tempfile2.bat
  • Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
  • Value: smrtprt
  • Data: C:\Program Files\Smart Protector\smrtprt.exe
  • Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
  • Value: selfdel
  • Data: C:\WINDOWS\tempfile2.bat