is this a result of PSGUARD?!

Discussion in 'Malware Help (A Specialist Will Reply)' started by justblaze, Jul 23, 2005.

  1. justblaze

    justblaze Private E-2

    its been about 3 weeks where my computer went AWOL, and i finally had gotten it formatted yesterday. And what do you know, today i already have spyware? How?! Displaying on my Desktop is "WARNING! Your computer might be infected with....." and contains a link to PSGUARD. (someone should hack this company or something for sending out their own spywares in order for you to buy their product). Anyway, i have no access to changing the background image anymore in my display properties and i can't stand staring at this warning screen. So

    Anyway, i've deleted the c:\windows\system32\isolat32.exe file and psguard files in my Program Files directory but still no luck.

    I found that the html file that's being displayed on my desktop is c:\windows\system32\wppp.html and i've deleted it so many times now, but it just comes back like 2 seconds later.

    In my registry, i locate where it sets wppp as the desktop background so i change it, and once again, 2 seconds later it's back to directing it to wppp.html

    also, the HKEY_....\...\....\System\ i change the NoDispBackgroundPage from 1 to 0, and then of course what do you know, it changes back to 1 by itself again.

    Anyway, i need some help. this is brutal.
    thanks for any input
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. justblaze

    justblaze Private E-2

    Okay, i've went through all the steps and some scanners claimed to have found infected files and then deleted them. But the problem is still there.
    The "Warning! Your computer might be infected....." desktop background still shows and still i have no access to changing the background in the display settings.
    Also, i still can't delete the wppp.html file (which is the source code for the desktop background) located in my C:\Windows\System32\ folder. (like, i can delete it, but it creates itself a few seconds later)

    So i did the hijackthis scan (attached file) and i hope you can help me out.
    Thanks again
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should use Add/Remove programs to uninstall MessengerPlus! 3. It can add all kinds of bad stuff to your PC including a LOP infection.

    Other than that, there are no real problems showing in your HJT log.

    You should also look in Add/Remove programs for PSGuard and uninstall if found.

    The goto this thread: SpySheriff (aka SpywareNo) Removal
    and run step # 8. Let me know if that helps with your Desktop problems.
     
    Last edited: Jul 25, 2005
  5. justblaze

    justblaze Private E-2

    k, i've uninstalled msn plus 3 and i can't find anymore psguard on my computer left to delete, but still no luck.
    I did that "step 8" thing, and added it to my registry, but i think that just made it worse. Because the isolate32.exe file popped up again.
    I've ran another hijack file, so maybe it's different this time. and i've deleted the iisolate32 file again.

    Anyway, hope you are still willin to help. see attached for new hijack log


    also, if you have a moment on the side, what exactly do you look for when your see the logs?

    thanks again
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not fix anything on your own. I need to see what is going on. If you make changes before I see what process are running or what items appear in a HijackThis log, I do not know what is really happening on your PC.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [intell32.exe] C:\WINDOWS\system32\intell32.exe
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\intell32.exe

    Also look for and delete any of the below if found (you may or may not find these but look for them anyway):
    C:\WINDOWS\svcproc.exe
    C:\WINDOWS\system32\msmsgs.exe
    C:\WINDOWS\system32\shnlog.exe
    C:\WINDOWS\system32\intmonp.exe
    C:\WINDOWS\System32\intmon.exe
    C:\Windows\System32\helper.exe
    C:\Windows\System32\ole32vbs.exe
    C:\Windows\system32\msole32.exe
    c:\windows\system32\wppp.html
    C:\wp.exe
    C:\wp.bmp
    C:\bsw.exe
    C:\Windows\sites.ini
    C:\Windows\popuper.exe
    C:\Program Files\Search Maid<--- the whole folder
    C:\Program Files\Security IGuard<--- the whole folder
    C:\Program Files\Virtual Maid<--- the whole folder
    C:\Program Files\PSGuard<--- the whole folder
    C:\Windows\System32\Log Files <--- the whole folder
    C:\Program Files\AntivirusGold <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  7. justblaze

    justblaze Private E-2

    still no luck.
    even with all hidden files shown and system restore disabled, i couldn't find any of those files you've mentioned to delete except the wppp.html which i delete and it re-creates itselft again 2 seconds later.

    am i lookin at formating again? or having to cave and purchase psguards damn program?

    i know for sure somethings up with the wppp.html file...cause even when i don't try deleting it, i can see it flickering cause the directory keeps refreshing itself.

    so anything else i can try?

    here's my updated log.

    thanks again
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well you log is clean now. The O4 line with C:\WINDOWS\system32\intell32.exe is gone.

    Did you reboot before getting this log?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download getsys32.zip

    Then extract it someplace you can locate it. Then use windows explorer to locate the getsys32.bat and double click on it to run the bat file. This will create a file named c:\sys32hs.txt

    Post the c:\sys32hs.txt file back here as an attachment.
     
  10. justblaze

    justblaze Private E-2

    k, here's the file
     

    Attached Files:

  11. justblaze

    justblaze Private E-2

    in addition to the sys32hs.txt file (message below), i decided to post a picture of what the task managers says i'm running. Since the wppp.html keeps restoring itself, i was thinking maybe there was some program that's running that checks to make sure this keeps popping up. I've deleted the wppp.html from safemode and it still re-creates itself 2 seconds later.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well that did not show me anything useful.

    Let's try the below.

    Download this: Find It NT/2000/XP


    Unzip this file to a folder of its own (like c:\findit ) and run "find.bat" - Allow it as much time as it needs to run. You may get an error message of "File Not Found," but just let it go.

    The tool should generate a long text file. Attach this log as an attachment to your next post.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Task Manager is not useful as it does not show all processes that run and it does not give the full path. HijackThis's process manager is much better. Or you could also use Process Explorer
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please look for the below files right now and tell me if you find them

    C:\windows\system32\intell32.exe
    C:\windows\system32\oleext.dll
    C:\windows\system32\oleext32.dll
    C:\windows\system32\wppp.html
    C:\windows\uninstIU.exe
     
  15. justblaze

    justblaze Private E-2

    here is the output.txt file from Find It

    Thanks again for your help
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you see what I asked in message # 14?
     
  17. justblaze

    justblaze Private E-2

    as for the files.

    i found oleext.dll

    wppp.html is there too, but everytime i delete it it re-creates itself
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Rename the oleext.dll file to oleext.ddd then immediately reboot your PC.

    After reboot make sure that the oleext.dll file did not come back!
    Now delete the wppp.html file. Does it say deleted.
     
  19. justblaze

    justblaze Private E-2

    sweet! it worked!


    thanks for your help and patience.

    just curious though, what exactly is the oleext.dll for?
    and are there any ways to prevent this from happening again?


    thanks again, you're awesome
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    That file was one of the items that can be part of the infection you had. Since the problem is now gone you should also delete the file we renamed. For more info on what you had here is one example from Symantec:

    http://www.symantec.com/avcenter/venc/data/trojan.desktophijack.c.html

    You will see the files I was asking about listed.

    To help protect your PC, complete the steps in the below thread:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds