How is PSGuard malware deleted from windows 98?

Discussion in 'Malware Help (A Specialist Will Reply)' started by hansenbrh, Sep 22, 2005.

  1. hansenbrh

    hansenbrh Private E-2

    I have run all the applicable steps from the "READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware..." article and am still stuck with the PSGuard malware. I have also run and saved a hijack this list which is attached. Any suggestions?
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note: HJT logs must always be posted from normal boot mode unless otherwise requested. But do the below before posting a new one.

    Download smitRem.exe and save the file to your desktop.

    Double click on the file to extract it to it's own folder on the desktop.

    Reboot into safe mode.

    Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen. Wait for the tool to complete and disk cleanup to finish.

    The tool will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating system is installed. Please attach this log to your next reply.

    Also attach a new HJT log. Let me know if there is any improvement.
     
  3. hansenbrh

    hansenbrh Private E-2

    Here is the HJT log. Also smitrem indicated that wininet.dll is infected.

    Edit by chaslang: Inline log attached
     

    Attached Files:

    Last edited by a moderator: Sep 24, 2005
  4. hansenbrh

    hansenbrh Private E-2

    Here is what smitrem came up with run in safe mode:
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run Smitrem while you were booted in safe mode? If not, please do so.

    Do you have your Win 98 CD?

    Please do not post HJT logs inline. They must be attachments.

    Do you know what C:\Program Files\TrueAssistant\TrueAssistant.exe is for?


    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\SYSTEM\SPOOLSRV32.EXE

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\RunServices: [Srv32 spool service] C:\WINDOWS\System\spoolsrv32.exe
    O4 - HKCU\..\Run: [NETZIP SMARTDOWNLOADER] C:\WINDOWS\SYSTEM\npnzdad.exe /t
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file
    missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\SYSTEM\SPOOLSRV32.EXE
    C:\WINDOWS\SYSTEM\npnzdad.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
    Last edited: Sep 24, 2005
  6. hansenbrh

    hansenbrh Private E-2

    Thanks for the help so far. You guys do a great service. Here is the reply to your last post.

    Smitrem was run in safe mode.

    I do have my WIN98 CD.

    HJT is attached.

    C:\Program File\TrueAssistant\TrueAssistant.exe I believe is a program that SBC uses to help customers make all the transfers from their previous internet provider to SBC. I am not positive about this.

    Viewing of hidden files is enabled.

    Killed spoolsrv32.exe

    Fixed the four items from the HJT scan.

    When I went to restart, so I could reboot in safe mode, the screen locked up on a blue screen with a horizontal green line on top of the screen. At this point I hit Ctrl/Alt/Delete which brought up the normal start up screens, and I was then able to F8 my way into safe mode.

    In safe mode I deleted C:\WINDOWS\SYSTEM\SPOOLSRV32.EXE and C:\WINDOWS\SYSTEM\npnzdad.exe with no problems.

    Ran Ccleaner

    Rebooted in normal mode, and am posting new HJT log.

    Notes: There is still a generic folder on my desktop for PSGuard.

    For some reason, The SBC execute icon disappeared from my desktop.
    however, there is still an Icon on my lower tool bar.

    Is there some reason why my cursur quickly flashes three times with a
    quick pause, over and over again, while I am typing this?

    Thanks again.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If this is true (and you should check with them), then why is it necessary to still have it running if you have already done this.

    Try deleting the PSGuard folder on your Desktop. Also look for on in c:\program files\psguard and delete it.

    I don't know about this one.

    Let's see if we can fix the rest of your problems with the Desktop hijacker first. Some of the items in the steps below may not be found. That's okay. Just ignore them and continue. This is a somewhat generic process and sometimes they do exist.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Open Control Panel and select Add/Remove Programs look for the below programs and uninstall them if found:
    Search Maid
    Security IGuard
    Virtual Maid

    Now exit Add/Remove Programs.


    Some of the items mentioned in the below steps may or may not be there. If not found just ignore them and continue. These problems come in a variety of forms and different filenames can be used each time.

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\System32\msole32.exe
    C:\WINDOWS\system32\msmsgs.exe
    C:\WINDOWS\system32\shnlog.exe
    C:\WINDOWS\system32\intmonp.exe
    C:\WINDOWS\System32\intmon.exe
    C:\Windows\System32\helper.exe
    C:\Windows\System32\ole32vbs.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [intell32.exe] C:\WINDOWS\SYSTEM\intell32.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:


    C:\WINDOWS\System32\popcorn64.exe
    C:\WINDOWS\system32\wppp.html
    C:\WINDOWS\system32\oleext32.dll
    C:\WINDOWS\system32\oleext.dll
    C:\WINDOWS\system32\intell32.exe
    C:\WINDOWS\uninstIU.exe
    C:\WINDOWS\system32\msmsgs.exe
    C:\WINDOWS\system32\shnlog.exe
    C:\WINDOWS\system32\intmonp.exe
    C:\WINDOWS\System32\intmon.exe
    C:\Windows\System32\helper.exe
    C:\Windows\System32\ole32vbs.exe
    C:\Windows\system32\msole32.exe
    C:\WINDOWS\system32\hp9980.tmp
    C:\wp.exe
    C:\wp.bmp
    C:\bsw.exe
    C:\Windows\sites.ini
    C:\Windows\popuper.exe
    C:\Program Files\Search Maid<--- the whole folder
    C:\Program Files\Security IGuard<--- the whole folder
    C:\Program Files\Virtual Maid<--- the whole folder
    C:\Windows\System32\Log Files <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and continue with the below.

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixsmit.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Double-click on the fixsmit.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to add to the registry say yes.
    Now please download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program.
    Now post a new HJT log. And tell me how things are working.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also look on your original Win98 CD in the Win98 folder for a file names WIN98_44.CAB. Inside this CAB file (which is a compress archive containing a bunch of Windows files) there should be a wininet.dll file. We may need to extract this files from the CAB file to replace your infected file later. You will need a utility like WinZip to do this.

    You will have to extract the wininet.dll file to a different folder (a temp folder) and then we may need to boot your PC to an MS-DOS prompt to overwrite the infected one with a copy of the clean one.
     
  9. hansenbrh

    hansenbrh Private E-2

    Hello Chasling,

    I found no Search Maid, Security IGuard or Virtual Maid.

    Did not find any of the listed processes listed in the HJT Open process manager.

    In safe mode, and after the HJT scan, did not find any of the listed lines.

    Ran Ccleaner which removed 31.3 mb.

    In normal mode, copied and ran fixsmit.reg.

    Ran Hoster.

    Ran and posted new HJT log.

    Notes: deleted PSGuard folder from destktop and program files earlier, but it seems to have returned after last reboot.

    After applying directions from previous post, I ran AD-Aware SE and it came up with: MALWARE, PSGuard (100 objects total) and MRU list (7 objects total). Ouch.

    hansenbrh
     

    Attached Files:

  10. hansenbrh

    hansenbrh Private E-2

    Also, rebooted after this message. Desktop came with white background and Active Desktop Recovery note in background behind the desktop icons. Also, and as usually happens with this malware, the PSGuard program automatically starts a "spyware scan" of my system. I do not push any of the PSGuard program buttons, I simply do an end task to get rid of it.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You said that you did not find any of the process I listed but two items are clearly shown in your HJT log which means they do exist.

    O4 - HKLM\..\Run: [intell32.exe] C:\WINDOWS\SYSTEM\intell32.exe
    O4 - HKLM\..\Run: [PSGuard] C:\Program Files\PSGuard\PSGuard.exe

    Boot into safe mode to do the below and do not run any browsers while in safe mode.

    Open Control Panel and select Add/Remove Programs look for the below programs and uninstall them if found:
    PSGuard

    Now exit Add/Remove Programs.

    Run HijackThis and select the below lines but and click Fix:
    O4 - HKLM\..\Run: [intell32.exe] C:\WINDOWS\SYSTEM\intell32.exe
    O4 - HKLM\..\Run: [PSGuard] C:\Program Files\PSGuard\PSGuard.exe

    After clicking Fix, exit HJT.
    Use Windows Explorer to delete:
    C:\WINDOWS\system32\intell32.exe
    C:\Program Files\PSGuard <--- the whole folder


    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Run SmitRem and post the log from it.

    Now run Ccleaner (installed while running the READ ME FIRST).

    Add the registry patch you download from my previous message into the registry again.

    Now reboot into normal mode and post a new HJT log. And tell me how things are working.

    Did you look for the file I indicated on you Win98 CD? You may need to get the Wininet.dll file from your CD, otherwise you may just keep getting reinfected.
     
  12. hansenbrh

    hansenbrh Private E-2

    Hello Chaslang,

    Booted in Safe mode.

    Removed PSGuard using Add/Remove and uninstalled.

    Ran hijackthis and fixed intell32.exe. PSGuard was not there.

    I couldn't find C:\WINDOWS\system32\intell32.exe in windows explorer, so I did a Start/find/files or folders search, found it there and deleted it. Did find C:\Program Files\PSGuard in windows explorer and deleted it.

    Ran SmitRem and it noted that WININET.dll is infected. I'm not sure how to post a log from SmitRem.

    Ccleaned

    Added previous messages registry patch.

    Rebooted into normal and ran HJT and posted log.

    It looks like intell32.exe comes back every time I reboot in normal.

    Should I go ahead and try to replace the wininet.dll now from my Windows98 CD?
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like you may not have viewing of hidden and system files enabled per the READ ME.

    Just upload the smitfiles.txt log just like you did with your HJT log.

    Yes! This is why intell32.exe keeps coming back. You will need to boot to MS-DOS mode to replace the infected wininet.dll. Although it may be possible in Windows for you to rename the infected one to wininet.bad and then copy in the new one from your CD.

    If you had a firewall installed, it may not be so easy for this to keep reinfected you.
     
  14. hansenbrh

    hansenbrh Private E-2

    Thanks again chaslang, as I am seeing progress. PSGuard is no longer showing up at reboot. Just a couple more things...

    I looked on the Windows98 disc in the Win98 folder and found WIN98_44.CAB, however could not find wininet.dll (if it makes any difference, I double checked that show hidden files and folders is still checked and hide file extensions for known types is unchecked).

    The order of files went...
    winfile.hlp
    winhelp32.hlp
    winlogo.gif
    winmodem.inf
    ...

    If these files are shown in alphabetical order, should have seen wininet.dll after winhelp32 right?

    Also, am still having problems getting a normal shut down of the PC. It usually freezes up on a blue screen with a horizontal green line going across the top of the screen.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It will probably come back since your wininet.dll file is still infected.

    Viewing of hidden files and folders only has to do with using Windows Explorer. Nothing else. Double check the CAB file again and check a few others in the range of 44_CAB. That is where it was for Win98 SE but you have a different version of Windows.


    Windows 98 shutdown issues are well know problems with Win9x & Me but this is not a topic for this forum. Try the Software Forum and also look at Microsofts Knowledgebase where there a lots of things to try.
     
  16. hansenbrh

    hansenbrh Private E-2

    Thanks again for all your support chaslang. As you predicted, PSGuard is again showing up in full force as an uninvited guest.

    I found wininet.dll file in the WIN98_40.CAB. I copied the file from the disc and put it in a desktop file named wininet.dll new.

    Would you be able to give me guidance on how to replace the infected wininet.dll

    Thanks again.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the file from your Desktop into the c:\windows\system folder. Just call it wininet.new.

    Now I would boot into safe mode and run SmitRem. Which will still show the infected wininet.dll file. When done with SmitRem. Use Windows Explorer to locate the bad c:\windows\system\wininet.dll file. Right click on it and select rename. Change the name to wininet.bad. Now find wininet.new and rename it to wininet.dll. Now reboot your PC.

    If this does not work we will need to boot your PC into MS-DOS mode to do this. Do you know how to boot to MS-DOS mode?
     
  18. hansenbrh

    hansenbrh Private E-2

    Hello chaslang,

    When I tried to rename wininet.dll, I got the message "Cannot rename Wininet: The specified file is being used by windows."

    I'm not sure how to boot to MS-DOS mode other than perhaps using the MS-DOS prompt from the programs menu.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You will need to print the below instructions so you can refer to them while offline in DOS mode. But read through them first to make sure you understand them.

    Make sure you have already copied the new uninfected file to the c:\windows\system folder and have named it wininet.new as I said in my previous message.

    Click Start and then Shutdown and in the Window that comes up choose the one that says Restart the computer in MD-DOS mode.

    When it boots you will be at the command prompt (full screen). Run the below commands each followed by the enter key. The final command will reboot to Windows.

    cd c:\windows\system
    attrib -r -h -s wininet.dll
    ren wininet.dll wininet.bad
    copy wininet.new wininet.dll

    win <--- this will reboot to Windows

    Now before doing anything else!
    Run smitrem and post another log from it.
    Then come back here and post the new log.
     
  20. hansenbrh

    hansenbrh Private E-2

    chaslang,

    I ran the commands in MS-DOS mode, ran smitrem, and attached smitfiles.txt.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! That's clean now. Post a new HJT log and also tell me how things look from your end.


    Also delete the wininet.bad file.
     
  22. hansenbrh

    hansenbrh Private E-2

    Hey chaslang, I think we may have won the battle. I booted in safe mode and removed PSGuard with the Add/Remove program.

    I ran HijackThis, found the PSGuard.exe file and clicked fix.
    I did not find the intell32.exe file.

    In windows explorer I deleted the PSGuard folder.

    Could not run CCleaner in safe or normal mode. Got message that it performed an illegal operation and would shut down.

    On normal boot, I did not get the intell32 symbol, nor did the PSGuard program start up on its own like it usually did. There was however a generic folder icon on my desktop titled PSGuard.

    My PC (or the operator of it) may have some other issues as I can't log onto SBC by clicking the little rocket icon. It starts up like its gonna work, then just freezes. I had to log into SBC via Mozilla Firefox to get here.
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you delete the Desktop icon?

    I'm not sure what happened to your connection to SBC. You may need to look at what the icon is associated to. Perhaps some where in the Properties you can figure out what it is supposed to be calling and why it does not work. Does it normally bring up IE?
     
  24. hansenbrh

    hansenbrh Private E-2

    Hello chasling,

    I'm still working on the SBC connection thing but that is trivial compared to not having malware show up every time I start my computer. PSguard now seems to be completly gone after months of problems, and I thank you for sharing your expertise and technical guidance. You perform a great service.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds