Results 1 to 9 of 9

Thread: PSGuard, intel32.exe, and desktop hijacking?

  1. #1
    zword_of_zeal's Avatar

    Fromage du Canadien

    Join Date
    May 2005
    Location
    Vancouver BC CANADA
    Posts
    34

    Question PSGuard, intel32.exe, and desktop hijacking?

    Hi guys, my desktop was recently hijacked, though I'm not sure, but I think it has to do with the PSGuard virus. A filed named "intel32.exe" was installed WINDOS/system32 directory, and when double clicked, it leads to the registration and purchase page on a rougue software called PSGuard, AND my internet browser homepage was hijacked, but I'm not sure if it has to do with the intel32 file. Further more, my desktop was hijacked with a dark blue screen, stating the following in white:

    Security warning
    A fatal error in IE has occured at 0028:C0011E36 in VXD VMM<01> +
    00010E36. Error was caused by a Trojan-Spy.HTML.Smitfraud.c
    * System can not function in normal mode.
    Please check you security settings.
    * Scan your PC with any avaliable antivirus/spyware remover program to fix the problem.

    Ok, first of all, its definitely a desktop-hijacker screen because the two words I purposely displayed in bold were typos, and an official source would never make mistakes like that (and those were pretty stupid, too).

    Now, back to the intel32 file, it displays as a red button with a white "!" in the middle, on the minimized tray, and like I said, leads to the PSGuard registration page when clicked.

    I tried several anti-spy/adwares such as SpywareDoctor, HijackThis, Yahoo Anti-spy and Avast! Anti-virus. The file only showed up in the result lists of SpywareDoctor and HijackThis. So I removed it, and even manually removed it from my system32 folder. But a while later it keeps on returning! I did all that in savemode, and when I boot back to normal, intel32 was still there, on my system tray AND still in my system32 dir, and my desktop has not returned to normal. I'm sure if I delete it, it will come back again on the next boot.

    By the way, the page that hijacked my browser was something called "abcsearch", if I remembered correctly. I kept setting my homepage to blank, but it comes back on the next boot. Does anyone think this BHO is related to intel32.exe as well?

    Anyways, if anybody have any programs or methods to remove this PSGuard annoyance or maybe even get rid of the abcsearch, I would really, really, appreciated it.

    EDIT: that brower hijacker was called abcsearch4u, I just confirmed it.
    "Yes, male prostitutes. The kind that wears Nike and Kappa."

  2. #2
    ferrarimodena360's Avatar

    Yada Yada Yada

    Join Date
    Mar 2003
    Location
    India
    Posts
    1,556
    system restore ?

  3. #3
    -0-BACKLASH-0-'s Avatar

    weeeee

    Join Date
    Aug 2003
    Location
    somewhere...
    Posts
    606
    hey! I'm glad I'm not the only one that had this issue. Though mine was a little different. I found a file on emule and when I checked it out (after scanning with norton it was clean) a file wanted to access the internet. mine was install32m.exe. It was in the system32 folder also. Windows looked for this file on startup and shutdown (I deleted it and that's how I found windows looking for it. It would come up with the message "windows cannot find....")

    I used adaware SE pro to get rid of the registry entry it made and so far so good. I also checked all the running processes. All was fine after that, but I don't know what would've happened if it had accessed the internet! I couldn't find anything on this file on google or symantec.com.

    I'd check your hosts file also as well as all programs running at startup. regcleaner is great for that and download procexp.exe from here

  4. #4

    Still learning.........!

    Join Date
    Jun 2002
    Location
    Cyberspace
    Posts
    2,686

  5. #5
    zword_of_zeal's Avatar

    Fromage du Canadien

    Join Date
    May 2005
    Location
    Vancouver BC CANADA
    Posts
    34
    SE Adaware and RegCleaner? I'll try that sometime, thanks.

    ferrari, what do you mean by system restore?

    DigitalJunkie, smitfraud was not the problem, PSGuard is. That smitfraud screen was probably made up by the desktop hijackers to make users believe that their computer is infected and buy their rogue anti-spy programs.

    EDIT: No, sorry about that, it probably is smitfraud's doing, but I couldn't seem to detect the file anywhere though.
    "Yes, male prostitutes. The kind that wears Nike and Kappa."

  6. #6

    Zeropaid Noob

    Join Date
    Jul 2005
    Posts
    1

    Exclamation

    Hello I had the same problem. I went to the link that DigitalJunkie posted, deleted all the files that were stated there, but couldn't get rid of intel32. I then downloaded the Panda Platinum Antivirus (my Norton couldn't clean anything for some reason), and it deleted the intel32. So the homepage, the tabs in the taskbar, and all the popups saying how my system is infected disappeared, but I still can't get my desktop back to normal (the text disappered, but when I right-click and try to change the settings in the "Display Properties", there is no "desktop" tab there, just the "screensaver" tab. Come to think of it, I am not even sure the rest is clean, maybe the virus is still tracking my web surfing.

    Can anyone recommend any free software (evaluation versions perhaps?) that will DEFINITELY clean this?
    Or if it is already clean, how do I get my desktop back to normal?

    Thanks in advance

  7. #7

    Zeropaid Noob

    Join Date
    Jul 2005
    Posts
    1
    The HKEY entries have been modified, I have the same problem. I don't know yet which HKEY registry entry has been affected.

  8. #8
    Lehk's Avatar

    Old and Ornery

    Join Date
    Jul 2003
    Posts
    843
    are your important files backed up? if they are FFR might be the easiest solution.

    *edit*

    oops should mention FFR= fdisk, format, reinstall
    DILLIGAF

  9. #9
    napho's Avatar

    Antisocial Bastard

    Join Date
    Dec 2002
    Location
    The Great White North
    Posts
    1,165
    It isn't that difficult to get rid of these kinds of spyware. Once you know the names to get rid of (HijackThis is a great tool) you can delete everything in safe mode that can't be deleted right away.

Similar Threads

  1. Using Laptop as wifi card for desktop
    By Bhangra Knight in forum General Computing
    Replies: 2
    Last Post: July 10th, 2005, 06:13 PM
  2. Kazaa Media Desktop 2.6.4 RELEASED
    By GATORIAN in forum General Discussion
    Replies: 4
    Last Post: July 14th, 2004, 11:36 AM
  3. Can't connect to Bluster on laptop but can with desktop
    By Legalaid5 in forum Networks / Clients
    Replies: 2
    Last Post: January 1st, 2004, 01:27 PM
  4. Redhat phasing out desktop support
    By fernandez in forum Linux
    Replies: 7
    Last Post: November 6th, 2003, 09:13 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •