Ultimate System Guard

Ultimate System Guard is another threat from the rogue program group who also popularized Personal Deluxe Guard, Windows Additional Guard and Windows Guard Pro. This counterfeit program can bypass legit security software and  virus scanners on the computer by using a Trojan that conceals it process, files and other components on the system. Users may only detect presence of this potentially unwanted program when an Ultimate System Guard virus scan starts to scrutinize the computer and present dozens of detected viruses.

There is nothing to worry. All detected threats do not really reside on the system. Detection was comparable to other computers even clean ones; this clearly indicates that rogue program’s virus scanning engine is non-operational. The malware author created these false threats to delude people about the valid security status of their PC. So beware of this hazardous program masquerading as genuine system guardian.

To remove Ultimate System Guard, users must not rely on Add/Remove Programs of Windows. The fraud software does not contain any uninstall information which makes the instant removal function impossible. To perform automatic removal, you must use a trusted anti-malware program.

Screen Shot Images:

Ultimate System Guard image

Technical Details and Additional Information:

Damage Level: Medium

Systems Affected: Windows 9x, 2000, XP, Vista, Windows 7

Characteristics (Analysis)

Malware Behavior
Similar to other malware from the same group, Ultimate System Guard displays many fake warnings as a tactics to scare users and force them to obtain the registration key. Internet browser redirection, disables antivirus program and non-responding desktop are other damages it causes to the compromised PC.

Added Registry Entries:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run "Ultimate System Guard" 
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes "URL" => "http://search-gala.com/?&uid=7&q={searchTerms}"
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "78890603"
Associated Files and Folders:
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Ultimate System Guard.lnk
%UserProfile%\Application Data\Ultimate System Guard
%UserProfile%\Application Data\Ultimate System Guard\cookies.sqlite
%UserProfile%\Desktop\Ultimate System Guard.lnk
%UserProfile%\Start Menu\Ultimate System Guard.lnk
%UserProfile%\Start Menu\Programs\Ultimate System Guard.lnk
C:\Documents and Settings\All Users\Application Data\42e3
C:\Documents and Settings\All Users\Application Data\42e3\5228.mof
C:\Documents and Settings\All Users\Application Data\42e3\MainFAVProj.exe
C:\Documents and Settings\All Users\Application Data\42e3\mozcrt19.dll
C:\Documents and Settings\All Users\Application Data\42e3\sqlite3.dll
C:\Documents and Settings\All Users\Application Data\42e3\unins000.dat
C:\Documents and Settings\All Users\Application Data\42e3\USYSG.ico
C:\Documents and Settings\All Users\Application Data\42e3\ULTGSys
C:\Documents and Settings\All Users\Application Data\42e3\ULTGSys\vd952342.bd
C:\Documents and Settings\All Users\Application Data\ULTGSys
C:\Documents and Settings\All Users\Application Data\ULTGSys\ultg.cfg
C:\Program Files\Mozilla Firefox\searchplugins\search.xml 

How to Remove Ultimate System Guard

1. Reboot your computer in Safe Mode with Networking.
- Continue tapping F8 on your keyboard after turning on the computer.
- From the selections menu, select Safe Mode with Networking.

2. Connect to Internet and download SuperAntiSpyware here.
3. Install SAS with default configuration. It will prompt for update when installation has completed.
4. After installation and update, SuperAntiSpyware will open.
5. On main window, select Scan Type, choose Complete Scan.
6. Click on Scan your Computer…, this will give you options on which drive to scan.
7. On Scan Location, select c:\Fixed Drive.
8. Click on Start Complete Scan. This will begin the scanning process.
9. Scanning will take some time. Please be patient.8. When scanning is done it will display the Scan Summary.
10. On scanning Window, items detected are marked in check.
11. Click Next to remove infected items.
12. It will prompt you to reboot your computer. Click Yes to reboot.
13. After reboot. Open SuperAntiSpyware again. Go to the Main Menu and click Manage Quarantine.
14. Select all items that were quarantined and click Remove. This will completely remove all detected items on your computer.
15. Close the Window to exit SuperAntiSpyware.

What to do next...