PS Guard wont go from registry?

Discussion in 'Malware Help (A Specialist Will Reply)' started by babylon5gr, Feb 6, 2006.

  1. babylon5gr

    babylon5gr Private E-2

    Hi.
    I am a computer tech and encounter PS Guard in a PC I support for a law firm.
    I have done all the procedures and some of my own in the way but one problem still cant figure out.
    In the registry in HKLM\Software there is a Key named PS GUARD. It contains another key named P.S. Guard and this contains another named PS.Guard which contains a Licenses (key??) in which I have no access whatsoever.
    I tried both REGEDIT and REGEDT32 (the OS is WINDOWS 2000 PRO SP4)
    in both NORMAL and SAFE mode and still cant delete rename move these keys. The problem seems to be the Licenses key. I tried taking the ownership of the keys and change the security settings with no result. I also tried booting from a utility cd and delete from there the registry entries but still no access. ADAWARE-SPYBOT-MICROSOFT ANTISPYWARE run fine in safe mode but in NORMAL mode ADAWARE-SPYBOT stuck in the scanning proccess and MICROSOFT ANTISPYWARE scans ok detects PS GUARD and says that it is removed but the registry entries are still there. I have also run CWShredder.
    Please help anybody
    BB
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  3. babylon5gr

    babylon5gr Private E-2

    Thanks
    I have already done all these that you mention in your post.
    The problem is a single point in the registry that I have no access at all in order to wipe out the last remaining entry of this pest.
    If you have read my whole post you could see that I even tried booting from a custom made boot utility cd that should be able to delete anything in the registry since it doesnt load anything from the OS.
    Anyway now my hope is to contact microsoft in order to find out if theres is an other way to delete these registry entries.
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    You can delete any registry entry if you take control over it from Windows. What key are you talking about and how do you know it's bad?

    I wouldn't be deleting registry keys unless I was very comfortable with the registry.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Start attaching the logs so we can see what is going on. You did not attach the requested logs from the SpywareStrike, Smitfraud, SpySheriff, SpyAxe & PSGuard Removal link that BJ gave to you. You should be attaching the smitfiles.txt log and then a PandaActiveScan log too.

    And as this link indicates, if you still have problems after running the above, it specifies that you should run this Sticky thread READ & RUN ME FIRST Before Asking for Support and attach the logs requested in it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds