Associated Malware Groups
The filename is associated with the malware group:
File Behavior
PHWASYSGUARD.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Adds products to the system registry
- Writes to another Process's Virtual Memory (Process Hijacking)
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Executes a Process
- Can communicate with other computer systems using HTTP protocols
- Modifies the Windows Host File which could be used to stop you visiting specific web sites by redirecting you to alternative addresses without you knowing
- This Process Deletes Other Processes From Disk
- This process creates other processes on disk
- Creates new folders on the system
- Copies files
- Injects code into other processes
PHWASYSGUARD.EXE has been the subject of the following behavior:
- Added as a Registry auto start to load Program on Boot up
- Executed as a Process
- Created as a process on disk
- Has code inserted into its Virtual Memory space by other programs
- Terminated as a Process
- Copied to multiple locations on the system
Country Of Origin
The filename PHWASYSGUARD.EXE was first seen on Nov 17 2009 in the following geographical regions of the Prevx community:
- The United States on Nov 17 2009
- Canada on Nov 17 2009
File Name Aliases
PHWASYSGUARD.EXE can also use the following file names:
- CFXASYSGUARD .EXE
- UCFTSYSGUARD .EXE
- JLIGSYSGUARD.EXE
- RRIFSYSGUARD.EXE
- JLIGSYSGUARD .EXE
- SJKTSYSGUARD.EXE
- SIGTSYSGUARD.EXE
- GXPVSYSGUARD.EXE
- 7086B0D3.EXE
Filesizes
This file has been seen with the following file size:
File Type
The filename PHWASYSGUARD.EXE refers to an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.