PSGUARD infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by bghkelly, Oct 16, 2005.

  1. bghkelly

    bghkelly Private E-2

    Having problems here - have read all the advice given by everyone on this site with same sort of infection incl. installing Adaware personal SE and Spybot, both of which say they have deleted PSGuard and smit etc but when I reboot, there is PSGuard again...spent all of today on this (not my idea of a relaxing Sunday!) and, as my father got this PC for me 2nd hand at a computer fair and as he was a complete expert in computer programming (he was a senior research officer at the RMCS) I know he would be able to suggest something that works! Unfortunately he passed away a month ago and now his not-so-pc-savvy daughter is tearing her hair out...PLEASE help...anyone?!! I have kept a copy of a hijackthis log as wel, if that helps...don't want to have to buy new computer as Dad got me this so it has sentimental value.
    Thanks in advance
    Bee
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. bghkelly

    bghkelly Private E-2

    Chaslang - did as you suggested (only not in safe mode as every time tried to reboot in safe mode with either ctrl key or F8 key, I got 'keyboard failure' and so extracted smitrem.exe in normal mode) PSGuard popped up when it tried to clean files although did get the text file, which reads as follows:
    (thanks, Bryony)


    smitRem log file
    version 2.7

    by noahdfear


    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    Remaining Pre-run Files
    ~~~ Program Files ~~~
    ~~~ Shortcuts ~~~
    ~~~ Favorites ~~~
    ~~~ system folder ~~~


    oleext.dll
    ~~~ Icons in system folder ~~~
    ~~~ Windows directory ~~~
    ~~~ Drive root ~~~
    ~~~ Miscellaneous Files/folders ~~~
    ~~~~ wininet.dll ~~~~

    wininet.dll Present!!


    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    Remaining Post-run Files


    ~~~ Program Files ~~~
    ~~~ Shortcuts ~~~
    ~~~ Favorites ~~~
    ~~~ system folder ~~~


    oleext.dll
    ~~~ Icons in system folder ~~~
    ~~~ Windows directory ~~~
    ~~~ Drive root ~~~
    ~~~ Miscellaneous Files/folders ~~~
    ~~~~ wininet.dll ~~~~

    wininet.dll INFECTED!! :(
     
  4. bghkelly

    bghkelly Private E-2

    PSGuard and Smit infected (10 hrs on this today!)

    Dear anyone (who are more computer knowledgable than I)
    I have a Dell Optiplex GX110 127 MB ram Win98 4.10.
    Having problems here - have read all the advice given by everyone on this site with same sort of infection incl. installing Adaware personal SE and Spybot, both of which say they have deleted PSGuard and smit etc but when I reboot, there is PSGuard again...spent all of today on this (not my idea of a relaxing Sunday!) and, as my father got this PC for me 2nd hand at a computer fair and as he was a complete expert in computer programming (he was a senior research officer at the RMCS) I know he would be able to suggest something that works! Unfortunately he passed away a month ago and now his not-so-pc-savvy daughter is tearing her hair out...PLEASE help...anyone?!! I have kept a copy of a hijackthis log as well, and Smittextfile as Chaslang suggested (unfortunately cannot reboot in safe mode to run this smit.exe prog as every time I try my PC has 'keyboard failure'), if that helps...don't want to have to buy new computer as Dad got me this so it has sentimental value. Have attached smittextfile as Chaslang told me to in hope he sees it, or someone else who knows what it means and can help. Many thanks, Bryony
     

    Attached Files:

  5. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Re: PSGuard and Smit infected (10 hrs on this today!)

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.

    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:

    Downloading, Installing, and Running HijackThis

    What is important here is we get a HijackThis log posted as an ATTACHMENT. If you can't run the scans in Safe Mode, run them in Normal Mode.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: PSGuard and Smit infected (10 hrs on this today!)

    A thread is already started for this problem! See: http://forums.majorgeeks.com/showthread.php?t=75073

    bghkelly, you must stay in one thread. I'm moving you back to your original thread. And you must get your system booted in safe mode or SmitRem will not work. See the below link and try using the Msconfig method to get you PC into safe mode.

    http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406?OpenDocument&src=sec_doc_nam


    If you still cannot boot in safe mode for any reason, or the SmitRem program still show wininet.dll is infected after running in safe mode, then you should follow the steps that were given below by Shadow. But stay in this thread!
     
    Last edited: Oct 16, 2005
  7. bghkelly

    bghkelly Private E-2

    Do apologise - never used a thread or forum before....managed to get my pc to work in safe mode and ran smit exe, adaware and spybot....PSGuard still popping up though...will keep trying
    Thank you
    Bryony
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does the current smitfiles.txt show wininet.dll is still infected?

    What OS do you have?

    Do you have your Bootable CD for your OS?

    Answer the above and them follow the steps in the message posted by Shadow_Puter_Dude. Do not run any steps on your own. Only run exactly what we ask you to run.
     
  9. bghkelly

    bghkelly Private E-2

    Hi Chaslang

    I have a Dell Optiplex GX110 127 MB ram Win98 4.10. No CD's to re-boot, as I said, my Dad got it from a computer fair 2nd hand so it's a creaky old thing! However, in 2 years, this is first time I have had such a serious infection, have had other spyware protection, Sophos antivirus and firewall Mozilla on it for quite a while and do perform updates...in answer to your question(s) yes, the wininet.dll is still there. Have uninstalled all antispyware apart from spybot now adn adaware plus hijackthis. Have been through all the steps that S_P_dude recommended and have attached hijackthis file - many thanks for your help...
    regards, Bryony
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    My question was "is wininet.dll still infected"? Look in the last smitfiles.txt that you should have after running in safe mode. wininet.dll is a valid Windows file. The problem is that your is infected.

    If you do not have the Win 98 CD, this could be difficult.

    You did not follow the directions for installing and running HijackThis. You have it installed here:
    C:\WINDOWS\TEMP\WZA0B4\HIJACKTHIS.EXE
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You also did not run all the steps in the READ & RUN ME sticky thread.
     
  12. bghkelly

    bghkelly Private E-2

    The problem is that my what is infected?!
    Should I reinstall hijack this in the right place, would that make a difference?
    And if I obtain a win98 CD, and reboot with it, does that mean I will lose info on my PC?
    Thank you
    Regards
    Bryony
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    wininet.dll - it is a file on your system and it is what Smitfraud and PSGuard infect. I'm asking what was in your last smitfiles.txt log. See the old copies you posted in this thread. You will see the last line mentions whether the wininet.dll file is infected or clean. Previous logs said it was infected but you did not run in safe mode those other times.

    Not for this problem but you are not following directions and not doing so can make it difficult for us to help you. As I stated in my last message, you never even ran all the steps in the READ & RUN ME FIRST. If you had HJT would be installed properly and there would be signs of the online scanners being run. I see no signs of the online scanners in your log.

    I did not ask you to boot from a Win98 CD. I asked if you had a bootable CD for your OS. We can get a clean copy of wininet.dll from the CD.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would like to get some more info on your copy of the c:\windows\system\wininet.dll file. Locate it by using Windows Explorer and then right click on it and select Properties. Now see if there is a Version tab in the window. If so, select the Version tab and on the next window select each of the listed Item names (one at a time) to get more info about the file. The information I want to know is the File Version number. If there is no Version tab, tell me that too.
     
  15. bghkelly

    bghkelly Private E-2

    Thanks Chaslang
    It was 2.00 am here by the time I wrote that last posting to you so called it a day and went to bed! When I get home tonight, I will do all the procedures you have asked me to (forgive me, I did miss the online scan, thought it was part of the CCleaner which I had done earlier, will repeat everything to the letter now I am slightly more awake...14 hours in front of my PC, not v healthy!)
    Speak later on
    Thanks again
    Bryony
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Make sure you install HJT properly too. Did you locate you Win98 CD?

    If not search your PC (using Windows Search) for other copies of wininet.dll.
     
  17. bghkelly

    bghkelly Private E-2

    Hi Chaslang

    Haven't been through the whole 'read me and run first' process again yet..but have obtained version number of wininet.dll: 6.00.2800.1405

    hope this helps
    thanks, Bryony
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    A copy of wininet.dll is available on the internet for download but I'm not sure what version number will work with your system. You can download it here:

    http://www.dll-files.com/dllindex/dll-files.shtml?wininet

    That was why I wanted to check your version number that is on your PC already. This download version is older that your but still may work if necessary (if you cannot find your CD. The version of you CD may be old too.) This file upgrades as patches (updates) are installed on your PC.

    You can try renaming your current file to wininet.bad and putting the new file (either downloaded or from your CD) in the folder and see what happens. You will need to boot to an MS DOS prompt to make these changes.
     
    Last edited: Oct 17, 2005
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Here is how to go about replacing the infected wininet.dll file when we get a clean copy onto your PC (either from an internet download or from your Win98 CD).

    You will need to print the below instructions so you can refer to them while offline in DOS mode. But read through them first to make sure you understand them.

    Make sure you have already downloaded and copied the new uninfected file to the c:\windows\system folder and have named it wininet.new

    - So download it and extract it (from a the zip file if necessary) somewhere else and make a copy named wininet.new
    - Then move or copy wininet.new into your c:\windows\system folder.

    Now Click Start and then Shutdown and in the Window that comes up choose the one that says Restart the computer in MD-DOS mode.

    When it boots you will be at the command prompt (full screen). Run the below commands each followed by the enter key. The final command will reboot to Windows.

    cd c:\windows\system
    attrib -r -h -s wininet.dll
    ren wininet.dll wininet.bad
    copy wininet.new wininet.dll

    win <--- this will reboot to Windows


    Now before doing anything else!
    Run smitrem and post another log from it.
    Then come back here and post the new log.
     
  20. bghkelly

    bghkelly Private E-2

    Thank you - will print this off at work tomorrow (have no printer at home) and follow...in the meantime, I did another smitrem run in safe mode (still infected :-( ) and have attached Hijack this log file (saved, extracted and run from correct place this time!)
    Thank you
    Regards, Bryony
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just write them down! They are not too long! ;) Let's see if we can fix this.

    Did you get the CD or did you download the DLL?
    Have you also tried searching the PC for another copy of wininet.dll?

    In fact just search for wininet and see what and where you find any matches.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds