Home Articles Spyware Research Support Scan Now Purchase F.A.Q.

Trojan/PSGuard

Alias: PSGuard

Description: Trojan/PSGuard is a fraudulent antispyware program which is related to Smitfraud trojan. Smitfraud trojan hijacks Windows Desktop and displays fake fatal error messages (example, blue screen of death) which recommend to install PSGuard antispyware. Smitfraud trojan is able to download and run PSGuard installer (file PSGUARDINSTALL.EXE) without user consent. PSGuard detects that computer has been affected by Trojan-Spy.HTML.Smitfraud.c, but the user needs to purchase PSGuard antispyware program to remove it. PSGuard communicates with suspicious servers, possibly disclosing confidential data from the infected computer. During testing, a normal uninstall of PSGUard does not completely remove all of its components.

Threat type:

Trojan - A Trojans or Trojan Horse is any programs that installs itself secretly, quite often with sinister intent. Once installed, the trojan author (hacker) can gain complete control of the infected PC. Trojans are usually designed to steal sensitive information and/or destroy the system. Trojans can be distributed as unsolicited email attachments, or bundled with freeware and shareware programs.


Advice: Remove This is a very high risk threat and should be removed immediately as to prevent harm to your computer or your privacy.

Detection:
SpyNoMore detects Trojan/PSGuard: Yes

Threat risk: High Risk
SpyNoMore AntiSpyware: Remove PSGuard, PSGuard Remover
Very dangerous malware. Can log user's keyboard activity and take snapshots of the user's screen. Uses stealth installation and removal is very difficult. Category includes spyware programs, adware programs and trojans.

Symptoms:

Trojan/PSGuard stays resident in background.

Trojan/PSGuard connects itself to the internet.

Trojan/PSGuard may cause computer errors.

Trojan/PSGuard may cause performance problems.

Trojan/PSGuard protects itself from security software.

Trojan/PSGuard may install other software.



Trojan/PSGuard Signature Details: The following information includes some of the standard signatures associated with this spyware threat. Please do not attempt to manually remove these items from your computer; Removing these items incorrectly or partially can cause your computer to experience critical errors, prevent your computer from restarting or cause loss of Internet connectivity. Should you be infected with Trojan/PSGuard, you can clean your computer by downloading SpyNoMore now.

Running Process Signatures:
N/A

File Signatures:
N/A

Registered Dll (Dynamic Link Library) Signatures:
N/A

Folder Signatures:
%DESKTOPDIRECTORY%\psguard spyware remover.lnk
%COMMON_PROGRAMS%\start menu\programs\psguard spyware remover
%PROFILE%\application data\shudder global limited
%PROGRAM_FILES%\psguard

Registry Signatures:
HKCR\interface\{d5d6e9b5-30d5-4457-ac8b-399205f50411}
HKCR\typelib\{f61d1ce1-5199-4b57-b59e-c6819ea92f3b}
HKCR\interface\{8b6c0168-baac-4c7c-911e-0132590f5661}
HKCR\clsid\{e5d78bd8-3874-4aa0-9d45-cfb79382c484}
HKCR\interface\{e0d6c30a-b9a3-4181-8099-3b0d5a2b98af}
HKCR\interface\{c6e2a22c-b3a8-43a4-b5ec-a5bb671ab3f7}
HKCR\interface\{a917b2f3-a9bf-477c-a0e3-0382d0376159}
HKCR\clsid\{20d1af34-6e19-42d8-af9f-bdfbe45c2454}
HKCR\interface\{28fedb90-53c7-4928-994a-cee782606507}
HKCR\interface\{20f8b70d-9f16-4dcb-8788-90a0498e46b9}
HKCR\interface\{09b90087-4ffa-4a44-be69-da117a710f07}
HKCR\interface\{1449f89c-ad28-427a-97ff-1d5bd812ea43}
HKCR\interface\{a20f5672-7486-4d27-bd2b-e555e4692c5f}
HKCR\clsid\{3d74d140-f780-4ae3-8d6d-f8dc39107213}
HKCR\interface\{3a350193-c7f7-4e10-b347-02ff4c3cc4e9}
HKCR\clsid\{c5a40fce-0a0f-40ca-985e-661c28b5b431}
HKCR\interface\{d6a7d177-0b2f-4283-b2e8-b6310a45e606}
HKCR\typelib\{982392f9-9c65-48b4-b667-3459c46630d1}
HKCR\interface\{b803d266-a08d-4a4c-9604-6d35689abe09}
HKCR\clsid\{15dc7116-e58e-4395-a45a-a1c99b17c030}
HKCR\interface\{1c08d3d0-1e04-4dde-ab0a-75355ea2585e}
HKCR\interface\{f4364eec-31f5-4b8b-a7e0-3b6394c9d23f}
HKCR\clsid\{e0aa0493-c410-4cbd-b1db-1723374fa8e0}
HKCR\interface\{8ec33b7d-9953-4edb-ace2-d4c105968601}
HKCR\clsid\{49443d6e-ce4e-47a9-8deb-f5774ce14984}
HKCR\interface\{cf1674cc-ec9a-4aee-996e-65a8f7c0b0e4}
HKCR\clsid\{c7f22879-7151-4c71-8c50-9557afda66c6}
HKCR\interface\{2c462d06-3ba0-48bb-9282-bb6519fe86e9}
HKCR\clsid\{2c59d5ec-6b91-4896-bd6f-5f121d87a7f8}
HKCR\clsid\{ceabf027-6cdc-4d47-adf6-ac5d065826a6}
HKCR\clsid\{52034ad2-914c-4634-b375-9299631e5525}
HKCR\clsid\{7702c521-76ae-42c0-a181-3b5a96c2eef7}
HKCR\clsid\{1bd98dfd-2da9-4c54-85d7-be03a0f9c487}
HKCR\interface\{4723879b-8f52-4be7-9994-626afa539366}
HKCR\clsid\{2f34e0e0-f0bb-477f-afb8-509262fa0ad1}
HKCR\clsid\{17e02586-a91d-4a9d-a74e-187b05dffe6f}
HKCR\interface\{f100a342-3ac5-47ff-b5b3-fcdb6fc9f016}
HKCR\interface\{b26b5883-f15f-4283-b3d5-a1728077de47}
HKCR\clsid\{7d98221e-af8f-4d29-8bb1-1dfabc288173}
HKCR\clsid\{1c94ea51-3800-4f08-b5dc-a5b67823ffea}
HKCR\clsid\{23f7ad29-f51a-4ba1-be70-143b1cb25bd1}
HKCR\clsid\{ca5e7959-60b5-47b7-80ac-1606309733f3}
HKCR\clsid\{7adda344-1d36-4446-9f4b-b2351fb19efd}
HKCR\clsid\{21e132c9-1f98-4151-bdad-7d9b49c60a8e}
HKCR\interface\{08101c3e-6c90-439e-9734-6e4dd1b53b69}
HKCR\clsid\{9746b450-6064-4ec8-9480-72a289aa2237}
HKCR\interface\{cb9385ab-8541-4b2f-a363-48f64c612993}
HKCR\interface\{a00e2305-7001-4200-ba00-5779f9a3e7d3}
HKCR\clsid\{35ed274e-3f42-4a78-bbdc-3b7d73e85578}
HKCR\interface\{7b6a3434-8625-4abf-b79d-09d98c2498c4}
HKCR\interface\{206538f7-f98c-4a46-a7d4-4a37fcdc932b}
HKCR\clsid\{f4b3e25a-33b4-4647-9a78-b627dde211a6}


SpyNoMore Collected Residual File Signatures:
N/A


See Also:
Downloader/Small.bhf
Trojan/Banker.aci
Trojan/Crypt.d
Spyware/Unclassified.103
Trojan/P2E.ai
Backdoor/BackDoor-YQ
Toolbar/Snap UltraSearch
Hijacker/JWord Plugin
Trojan/BAT.FTPDownloader
Trojan/Bambo.BS

Spyware Removal Home | Support | F.A.Q. | Contact Us | Spyware Removal Database | Privacy Policy | Site Map
Copyright © 2005-2008 Illysoft LLC