zword_of_zeal
July 5th, 2005, 11:54 AM
Hi guys, my desktop was recently hijacked, though I'm not sure, but I think it has to do with the PSGuard virus. A filed named "intel32.exe" was installed WINDOS/system32 directory, and when double clicked, it leads to the registration and purchase page on a rougue software called PSGuard, AND my internet browser homepage was hijacked, but I'm not sure if it has to do with the intel32 file. Further more, my desktop was hijacked with a dark blue screen, stating the following in white:
Security warning
A fatal error in IE has occured at 0028:C0011E36 in VXD VMM<01> +
00010E36. Error was caused by a Trojan-Spy.HTML.Smitfraud.c
* System can not function in normal mode.
Please check you security settings.
* Scan your PC with any avaliable antivirus/spyware remover program to fix the problem.
Ok, first of all, its definitely a desktop-hijacker screen because the two words I purposely displayed in bold were typos, and an official source would never make mistakes like that (and those were pretty stupid, too).
Now, back to the intel32 file, it displays as a red button with a white "!" in the middle, on the minimized tray, and like I said, leads to the PSGuard registration page when clicked.
I tried several anti-spy/adwares such as SpywareDoctor, HijackThis, Yahoo Anti-spy and Avast! Anti-virus. The file only showed up in the result lists of SpywareDoctor and HijackThis. So I removed it, and even manually removed it from my system32 folder. But a while later it keeps on returning! I did all that in savemode, and when I boot back to normal, intel32 was still there, on my system tray AND still in my system32 dir, and my desktop has not returned to normal. I'm sure if I delete it, it will come back again on the next boot.
By the way, the page that hijacked my browser was something called "abcsearch", if I remembered correctly. I kept setting my homepage to blank, but it comes back on the next boot. Does anyone think this BHO is related to intel32.exe as well?
Anyways, if anybody have any programs or methods to remove this PSGuard annoyance or maybe even get rid of the abcsearch, I would really, really, appreciated it.
EDIT: that brower hijacker was called abcsearch4u, I just confirmed it.
Security warning
A fatal error in IE has occured at 0028:C0011E36 in VXD VMM<01> +
00010E36. Error was caused by a Trojan-Spy.HTML.Smitfraud.c
* System can not function in normal mode.
Please check you security settings.
* Scan your PC with any avaliable antivirus/spyware remover program to fix the problem.
Ok, first of all, its definitely a desktop-hijacker screen because the two words I purposely displayed in bold were typos, and an official source would never make mistakes like that (and those were pretty stupid, too).
Now, back to the intel32 file, it displays as a red button with a white "!" in the middle, on the minimized tray, and like I said, leads to the PSGuard registration page when clicked.
I tried several anti-spy/adwares such as SpywareDoctor, HijackThis, Yahoo Anti-spy and Avast! Anti-virus. The file only showed up in the result lists of SpywareDoctor and HijackThis. So I removed it, and even manually removed it from my system32 folder. But a while later it keeps on returning! I did all that in savemode, and when I boot back to normal, intel32 was still there, on my system tray AND still in my system32 dir, and my desktop has not returned to normal. I'm sure if I delete it, it will come back again on the next boot.
By the way, the page that hijacked my browser was something called "abcsearch", if I remembered correctly. I kept setting my homepage to blank, but it comes back on the next boot. Does anyone think this BHO is related to intel32.exe as well?
Anyways, if anybody have any programs or methods to remove this PSGuard annoyance or maybe even get rid of the abcsearch, I would really, really, appreciated it.
EDIT: that brower hijacker was called abcsearch4u, I just confirmed it.