Re: Can't remove spyware registry entries for PSGuard Spyware?

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



What happened was I accidently clicked an advertisement link and browser
popups filled my memory up so I couldn't respond, in the background PSGuard
was installed, took over the desktop, it's designed to fool you by showing a
believable spyware scan in which you are actually seeing your own files and
directory structures being collected in front of you, after completed it's
designed to make your system appear abused then it installs multiple trojans,
viruses, keyloggers, you name it and updates itself. After awhile it's
designed to make hundreds of international 1-900 calls then destroy your
machine when finished to make it harder to track back, luckily I caught it in
time. I used sysinternals connection monitor and took a snapshot of the
remote connection to where it phoned home too.

Anyways, it's pretty cleaned up except for that entry which you're right
about it shows exactly what you said I ran that scanner and it shows
"embedded null's", so what do I do now to get rid of it?


--
Knight Technologies (http://knight-technologies.us)
E4 Chat (http://e4chat.com)


"Mark V" wrote:

> In microsoft.public.win2000.registry
> =?Utf-8?B?S25pZ2h0IFRlY2hub2xvZ2llcw==?= wrote:
>
> > On Windows Server 2003 R2 I'm unable to remove PSGuard registry
> > entries using regedit, even after doing an OS repair the entries
> > still remain.
>
> And PSGuard has provide no help in removing/uninstalling their
> software?
>
> > The registry entry is:
> > HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTD\PSGuard\PSGuard\License
> >
> > System produces error on key deletion attempt that says I cannot
> > the delete key.
> >
> > I can't delete the root for the entire branch either:
> > HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTD
> >
> > I've ran some several spyware scanners and on Spybot S & D it
> > comes up and requests reboot to remove, once the system reboots
> > the entry remains.
>
> Often this is a permissions issue on the key or sub-key. Have you
> taken ownership and set new ACLS (or tried to)?
>
> Since this is a licence key one possibility is that the key was
> created in such a way as to be unremovable. Possibly by embedding
> null characters that make the key invalid for access by the Win32
> APIs used in regedit and most Windows registry tools. In practice
> this key may be un-removable.
>
> You might want to run Sysinternals RootkitRevealer to see what can
> be seen about it.
> http://www.sysinternals.com/utilities/rootkitrevealer.html
>
>
.



Relevant Pages

  • Re: Cant remove spyware registry entries for PSGuard Spyware?
    ... > browser popups filled my memory up so I couldn't respond, ... > background PSGuard was installed, took over the desktop, it's ... > designed to make your system appear abused then it installs ... I used sysinternals connection monitor and took a snapshot ...
    (microsoft.public.win2000.registry)
  • Re: SuSE 9.0: Alsamodular synthesizer missing?
    ... >>I have installed the alsa modular synthesizer from the SuSE 9.0 DVD. ... >>shows, that it installs the package, and there is an entry in the ... >>Buggy package from SuSE? ... that's right - the entry in the KDE menu was wrong. ...
    (alt.os.linux.suse)
  • Re: Best installation tool?
    ... I've already checked out your entry. ... I created a CD version of The Replicator that installs with Jaws. ... JVM on the CD to use if necessary. ...
    (comp.lang.java.programmer)
  • where can I find the back button in WORD?
    ... installs have included a green coloured back button allowing me to return to ... a hyperlink of table of contents entry after following a link. ... navigation tool is very useful and I cannot find it on any of the toolbars. ...
    (microsoft.public.word.docmanagement)
  • Re: InstallAware... anyone know this?
    ... so basically all installs seem to have a function at the end of the install that doesnt work. ... Make sure that "Finish Dialog" is selected under "Run Timing", ... You should now have the entry for your app in the Run Programs view, and it will use this on the Finish dialog. ... David Ridgway ...
    (borland.public.delphi.non-technical)