SpyGuarder
SpyGuarder
        Found: 
    
                    2008-04-28        
        Known system changes: 
    Created Files
- %ApplicationData%redir.dll
 
Created Folders
- %ApplicationData%SpyGuarder
 - %ApplicationData%SpyGuarder
 
Registry Entries
- Key: HKEY_LOCAL_MACHINE\software\antispyware
 - Value:
 - Data:
 - Key: HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
 - Value: spyguarder
 - Data:
 - Key: HKEY_CLASSES_ROOT\clsid\{49300144-b971-4a4a-aaaf-97881cc7b06a}
 - Value:
 - Data:
 - Key: HKEY_CLASSES_ROOT\clsid\{a04b5994-572e-4bee-a96c-9ba9ea79d19c}
 - Value:
 - Data:
 - Key: HKEY_CLASSES_ROOT\interface\{733c568e-d16f-4e43-83e8-8539a5af4b0a}
 - Value:
 - Data:
 - Key: HKEY_CLASSES_ROOT\interface\{cb6e4bbd-3e6d-414f-b47c-8a43d1cf1eae}
 - Value:
 - Data:
 - Key: HKEY_CLASSES_ROOT\typelib\{18897803-0789-44aa-9ded-b3371718112f}
 - Value:
 - Data:
 - Key: HKEY_CLASSES_ROOT\typelib\{df9cf57d-d78f-4553-a74d-cfd573c725e9}
 - Value:
 - Data:
 - Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{49300144-b971-4a4a-aaaf-97881cc7b06a}
 - Value:
 - Data:
 - Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\spyguard
 - Value:
 - Data:
 - Key: HKEY_LOCAL_MACHINE\software\spyguard
 - Value:
 - Data:
 - Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
 - Value: spyguard
 - Data:
 - Key: HKEY_CLASSES_ROOT\CLSID\{C40624B4-CCDB-4F00-8888-7896032D234A}
 - Value:
 - Data:
 - Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C40624B4-CCDB-4F00-8888-7896032D234A}
 - Value:
 - Data:
 - Key: HKEY_CLASSES_ROOT\CLSID\{784CE1EA-4109-4D9E-BAD0-6E022808EEAE}
 - Value:
 - Data:
 - Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{784CE1EA-4109-4D9E-BAD0-6E022808EEAE}
 - Value:
 - Data:
 - Key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
 - Value: SpyGuarder
 - Data: C:\Program Files\SpyGuarder\SpyGuarder.exe