Annoyances.org
Home » Windows XP Discussion Forum » Message 1257475165 » Entire Thread Search | Help | Home
  
Antivirus Pro Fake iehelper.dll ssxrsysguard.exe
Showing all messages in thread #1257475165
Windows XP Annoyances Discussion Forum


The following are all of the messages in this thread (4 in all), shown in chronological order. Click any message subject to view that message by itself or to view the thread hierarchy.
Antivirus Pro Fake iehelper.dll ssxrsysguard.exe
Thursday, November 5, 2009 at 6:39 pm
Posted by Thordis (4 messages posted)

Hello, I am running XP Pro on a Pentium IV 2.8 GHZ with 1 Gig of RAM. The other day 
when I got home, my son had been surfing and he clicked on a pop up and yep, you 
got it, instant infection. Sooo, while battling with an array of fake warnings and 
pop ups about wanting me to install this program I did a search using Foxfire and 
found advice to use Malwarebytes' Anti-Malware which I did. Installed it and after 
having to stop the process which caused the "program can't be started" routine did 
the scan and had it fix what it found.

Got a message that it couldn't fix several files until a reboot, so I agreed to that. 
Came back up STILL getting the pop ups and fake warnings. Wash, rinse, repeat. My 
feeling is that despite the update, my version of Antivirus Pro Fake hasn't caught 
up with a new file naming criteria to eliminate everything. So far, so not so good.

Installed HiJackThis and ran it. It found the iehelper.dll entry and the ssxrsysguard.exe 
entry, but by this point I am loath to try any sort of manual removal without instructions. 
I'll show the entries from HJT which are relevant below.

O1 - Hosts: ::1 localhost
O1 - Hosts: 193.169.12.50 winguard2009.microsoft.com
O1 - Hosts: 193.169.12.50 winguard-2009.com
O1 - Hosts: 193.169.12.50 www.winguard-2009.com

O2 - BHO: BHO - {B6D223F6-C185-49a2-BA7E-A03E84744702} - C:\WINDOWS\system32\iehelper.dll

O4 - HKCU\..\Run: [qcpukuir] C:\Documents and Settings\Julia Boyles\Local Settings\Application 
Data\pokfju\ssxrsysguard.exe

O4 - HKCU\..\Run: [qcpukuir] C:\Documents and Settings\Julia Boyles\Local Settings\Application 
Data\pokfju\ssxrsysguard.exe

I had just erased the entries from the HOSTS file manually when I thought that it 
may be wasted effort if I haven't gotten the other parts of the infection cleaned 
up and decided to come here after all.


[Reply or follow-up to this message]

Tip: Run a free scan for common Windows errors ad

re: Antivirus Pro Fake iehelper.dll ssxrsysguard.exe
Thursday, November 5, 2009 at 7:26 pm
Posted by Thordis (4 messages posted)

Ugh, the line:
My feeling is that despite the update, my version of Antivirus Pro Fake hasn't caught 
up with a new file naming criteria to eliminate everything.

Should read:
My feeling is that despite the update, my version of Malwarebytes' Anti-Malware hasn't 
caught up with a new file naming criteria to eliminate everything.

[Reply or follow-up to this message]

re: Antivirus Pro Fake iehelper.dll ssxrsysguard.exe
Friday, November 6, 2009 at 6:06 am
Posted by Johnb33 (2283 messages posted)

Although Malwarebytes is a great program it will not catch everything.  Please download 
combofix and run.  Follow the instructions on this page.

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please post the log file that it displays at the end along with a new hijackthis 
log.  






On Thursday, November 5, 2009 at 7:26 pm, Thordis wrote:
>Ugh, the line:
>My feeling is that despite the update, my version of Antivirus Pro Fake hasn't caught
>up with a new file naming criteria to eliminate everything.
>
>Should read:
>My feeling is that despite the update, my version of Malwarebytes' Anti-Malware hasn't
>caught up with a new file naming criteria to eliminate everything.

[Reply or follow-up to this message]

re: Antivirus Pro Fake iehelper.dll ssxrsysguard.exe
Tuesday, November 10, 2009 at 1:59 pm
Posted by Mozark (255 messages posted)

Do format & reinstall of OS after backing up your data-after malware  your system 
security is compromised

[Reply or follow-up to this message]

Tip: Use one of the [Reply or follow-up to this message] links above to add a message to this thread
Return to the Windows XP Discussion Forum


All content at Annoyances.org is Copyright ©1995-2012 Creative Elementtm All rights reserved.
Please do not plagiarize; redistributing these pages without permission is strictly prohibited.