PSGuard Problem (I think)

Discussion in 'Malware Help (A Specialist Will Reply)' started by ctsw2001, Jul 21, 2005.

  1. ctsw2001

    ctsw2001 Private E-2

    Right here we go.........

    Last night when I switched my computer on (XP sp2) my active desktop which normally has a photograph on it had a message saying that my machine was infected with a virus. On the taskbar on the bottom right I had a red exclamation mark saying the same thing. I clicked on it and it took me to a web page for a program called psguard which I downloaded and ran as a trial version.

    Since then when my machine loads up I select the user from the welcome screen it just stays on that screen.

    I can only loadup on safe mode, but can't access anything. It's just a black screen where i can move the mouse around. If I press control-alt-delete i get the task manager up but that's it.

    I've booted in safe mode to command prompt and ran HijackThis and msconfig.exe to remove the PSguard files - but still no joy.

    Any ideas........
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Never ever do something like this! This is how dozens of forms of malware infest PC's every day.

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below exactly as written:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. ctsw2001

    ctsw2001 Private E-2

    I had to manually type this up as the desktop that is infected doesn't allow me internet access. So i'm using a Laptop with no floppy drive. Anyway here's my log file.
    =========================================================


    Inline log attached
     

    Attached Files:

    Last edited by a moderator: Jul 24, 2005
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I understand you are having a problem with Internet Access but you must remember to attach logs and not post them inline.

    - Also you installed HijackThis improperly.
    - It also looks like the log was from safe mode and we need them from normal boot mode.
    - And also, you must not use msconfig to control startups from loading. We need to see everything that could load. It is the only way to properly and completely know what you have .

    All that said let's start with a fix anyway:

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.

    C:\Windows\System32\cmd.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 – HKLM\..\RunOnce: [Srv32 spool service] C:\Windows\System32\spoolsrv32.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Windows\System32\spoolsrv32.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  5. ctsw2001

    ctsw2001 Private E-2

    I can only bootup in Safe Mode and don't have access to anything unless I go through the command prompt setup.

    Does this effect you you told me to do in the previous post ? And does that mean that by not being able to run HijackThis from the Normal startup I'm not getting an accurate log report ?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Do not have HJT kill the cmd.exe process then.

    Yes it does mean the report may not be accurate. However, you can still fix the item given and you can still run msconfig from the command prompt and then select normal startup.

    What is the problem with booting in normal mode? Any error messages? Try after fixing what I gave you.
     
  7. ctsw2001

    ctsw2001 Private E-2

    Still no joy I’m afraid.

    I booted up to the command prompt in safe mode and ran HijackThis as advised. The only process I could kill was cmd.exe, the rest it said was either in use or protected.

    Came back out and booted up to safe mode again and deleted spoolsrv32.exe from the command prompt and it seemed to do it fine.

    Booted up in normal mode this time and got the same problem which is, when you get to the welcome screen and select the user it just seems to sit on the screen trying to load up the users preferences. The system isn’t hanging as I can still move the mouse around the screen. I’ve tried all three users on the system and waited up to an hour for something to happen without any success.

    So I booted up to safe mode again and ran HijackThis. The log file is exactly the same as the one below with the spoolsrv32.exe still on there.

    HELP….
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to have HijackThis fix the below line:
    O4 – HKLM\..\RunOnce: [Srv32 spool service] C:\Windows\System32\spoolsrv32.exe

    Then reboot into safe mode again and from the command prompt or explorer (run explorer.exe if it runs) delete the C:\Windows\System32\spoolsrv32.exe file.

    You need to make sure that you can actual see the file and that the response to the delete of the file is positive. Otherwise you may need to use the attrib -r -h -s command on the file first.
     
  9. ctsw2001

    ctsw2001 Private E-2

    You were right in saying I should check to see if the file was there first. Hijacked the spoolsrv32.exe file. Booted back into safe mode, explorer won’t work so used the command prompt and went into the system32 folder and can’t see the file. Used the –r –h –s attribs but still can’t see it.

    And like I say I can’t get normal mode up or explorer in safe mode………… What a mess, can’t believe I ran that bl**dy file.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Post a current HJT log.

    Also look at your c:\boot.ini file and tell me what is in it. This is a hidden file system file so to be able to see it from the command prompt you will need to use the attrib -r -h -s boot.ini command first. Then you can use type boot.ini to see what is in it.
     
  11. ctsw2001

    ctsw2001 Private E-2

    Thanks for bearing with me on this one, it's appreciated.
    boot.ini content;

    [boot loader]
    timeout=30
    default=multi<0>rdisk<0>partition<1>\WINDOWS=”Microsoft Windows XP Professional”/fastdetect / NoExecute=OptInb
     
  12. ctsw2001

    ctsw2001 Private E-2

    Oh Log is as same as post #3
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure about the boot.ini being what you posted? Or was it really like below:

    [boot loader]
    timeout=30
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
     
  14. ctsw2001

    ctsw2001 Private E-2

    Yip you're right, my mistake.

    Exactly as you've typed it.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is the below something you installed?

    O4 – HKLM\..\Run: [AppHunter] C:\Program Files\SystemTracker\SystemTracker.exe /init

    Please look at your current HJT log and fix the below two lines if they still appear:
    O4 – HKLM\..\Run: [MSConfig] C:\Windows\ServicePackFiles\i386\msconfig.exe /auto
    O4 – HKLM\..\RunOnce: [Srv32 spool service] C:\Windows\System32\spoolsrv32.exe

    Then reboot (into normal boot mode if possible) and post a new HJT log.
     
  16. ctsw2001

    ctsw2001 Private E-2

    Hi there, yes AppHunter is an install program. Here's my latest Logfile with the 2 changes made, but still can't bootup in normal mode yet ! Typed up again - sorry !!


    Inline log attached
     

    Attached Files:

    Last edited by a moderator: Jul 24, 2005
  17. ctsw2001

    ctsw2001 Private E-2

    bump

    just incase you'g forgotton about me
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Bumping is a bad idea. It only delays you in getting a response. We go from oldest threads to newest when answering. Since bumping makes your thread newer. It moves you to a point where you will basically be answered later.

    Your log from safe mode shows no further problems. You may be better off working this problem that prevents you from booting to normal boot mode in the Software Forum.

    Tell them if you get any error messages.
     
  19. ctsw2001

    ctsw2001 Private E-2

    Thanks for that, I appreciate you're help - transferred to Software Forum as suggested.

    Thanks again
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds