O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dllO12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dllO16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/...s/msnchat45.cabO16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://download.winf...nnerInstall.cab

HijackThis needs to be moved to its own permanent folder off of the desktop. Create a folder on the root drive, (Usually C:\), called C:\HJT

Detect and remove the following PSGuard files: Processes intell32.exepsguard.exe psguardinstall.exe uninstiu.exe DLLs core.dlllocalization.dlloleext.dlloleext32.dllwndsystem.dll Other Files wppp.html Registry Keys HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunintell32.exeHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunPSGuard15DC7116-E58E-4395-A45A-A1C99B17C03017E02586-A91D-4A9D-A74E-187B05DFFE6F1BD98DFD-2DA9-4C54-85D7-BE03A0F9C4871C94EA51-3800-4F08-B5DC-A5B67823FFEA20F8B70D-9F16-4DCB-8788-90A0498E46B928FEDB90-53C7-4928-994A-CEE7826065072C462D06-3BA0-48BB-9282-BB6519FE86E93A350193-C7F7-4E10-B347-02FF4C3CC4E94723879B-8F52-4BE7-9994-626AFA5393667B6A3434-8625-4ABF-B79D-09D98C2498C48B6C0168-BAAC-4C7C-911E-0132590F56618EC33B7D-9953-4EDB-ACE2-D4C105968601A00E2305-7001-4200-BA00-5779F9A3E7D3A20F5672-7486-4D27-BD2B-E555E4692C5FA917B2F3-A9BF-477C-A0E3-0382D0376159B26B5883-F15F-4283-B3D5-A1728077DE47B803D266-A08D-4A4C-9604-6D35689ABE09C6E2A22C-B3A8-43A4-B5EC-A5BB671AB3F7CB9385AB-8541-4B2F-A363-48F64C612993CF1674CC-EC9A-4AEE-996E-65A8F7C0B0E4D5D6E9B5-30D5-4457-AC8B-399205F50411D6A7D177-0B2F-4283-B2E8-B6310A45E606E0D6C30A-B9A3-4181-8099-3B0D5A2B98AFF100A342-3AC5-47FF-B5B3-FCDB6FC9F016F4364EEC-31F5-4B8B-A7E0-3B6394C9D23F982392F9-9C65-48B4-B667-3459C46630D1F61D1CE1-5199-4B57-B59E-C6819EA92F3BHKEY_CURRENT_USERControlPanelDesktopWallpaperStyle=0HKEY_CURRENT_USERControlPanelDesktopWallpaper=%System%wppp.htmlHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoActiveDesktopChanges=1HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystemNoDispAppearancePage=1HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystemNoDispBackgroundPage=1HKEY_LOCAL_MACHINESOFTWAREShudderLTDPSGuardHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallInternetUpdate External links If you believe your computer is infected with spyware, Wiki-Security It is no longer on the list, but I still have the black background, and red exclaimation point telling me that my computer is infected with spyware.Below is my latest highjackthis Check out the forums and get free advice from the experts. The system window will display.

If you get any kind of warning message about scripts, please choose to allow the script to run. If you have expertise in working with smartphones, we urge you to contact an administrator about the possibility of becoming part of the staff after we review your credentials. Check out the forums and get free advice from the experts. I would like to start off by apologizing in the delay in our response time.

Please re-enable javascript to access full functionality. Please delete this copy and replace it with the new version (which you also have), v1.99.1. This website does not advocate the actions or behavior of PSGuard and its creators. Find PSGuard popup from the list.

Restart your computer in Safe Mode with Networking.
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dllO12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dllO16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cabO16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://download.winf...nnerInstall.cab
Restart your computer After

SpywareBlaster - Great prevention tool to keep nasties from installing on your system.
Incident Status Location Virus:W32/Smitfraud.E Disinfected Operating system Adware:adware/mediatickets No disinfected Windows Registry Virus:W32/Smitfraud.E Disinfected C:\WINDOWS\SYSTEM\WININET.DLL Virus:W32/Smitfraud.E Disinfected C:\WINDOWS\Desktop\WININET.DLL Adware:Adware/PurityScan No disinfected C:\My Documents\backups\backup-20050805-180244-815.dll Adware:Adware/PurityScan No disinfected
Another method of distributing PSGuard involves tricking you by displaying deceptive pop-up ads that may appear as regular Windows notifications with links which look like buttons reading Yes and No.
On the left side of the System window, click System protection.

Go to "My Computer" (Windows key+e), or by double-clicking on the "My Computer" icon on your desktop.

Contents 1 Detection of PSGuard (Recommended) 2 Method of Infection 3 Symptoms 4 Remedies and Preventions 4.1 Install a good anti-spyware software 4.2 Remove PSGuard manually 6 External links
Step 4.Uninstall PSGuard via System Restore.
Go to Start > Settings > Control Panel.Double-click the System icon.

C:\WINDOWS\SYSTEM\WININET.DLL - 574976 Bytes
Select the first option, to run Windows in Safe Mode. When it's finished it will reboot your machine to finish the cleaning process.

Like other threats, PSGuard releases plenty of unwanted warning error notifications and fake adverts on the browser screen. Register now to gain access to all of our features, it's FREE and only takes one minute. Click the "Custom Level" button.

This website should be used for informational purposes only. This program is very highly regarded and you can choose either the free or paid version. Step 3: Uninstall PSGuard popup programs from the Control Panel.

If the tab is missing, you are logged in under a limited account.(Windows XP)