|
|
|
Antivirus Pro Fake iehelper.dll ssxrsysguard.exe
Showing all messages in thread #1257475165 Windows XP Annoyances Discussion Forum
The following are all of the messages in this thread (4 in all), shown in chronological order. Click any message subject to view that message by itself or to view the thread hierarchy.
|
Antivirus Pro Fake iehelper.dll ssxrsysguard.exe
Thursday, November 5, 2009 at 6:39 pm Posted by Thordis
(4 messages posted)
Hello, I am running XP Pro on a Pentium IV 2.8 GHZ with 1 Gig of RAM. The other day
when I got home, my son had been surfing and he clicked on a pop up and yep, you
got it, instant infection. Sooo, while battling with an array of fake warnings and
pop ups about wanting me to install this program I did a search using Foxfire and
found advice to use Malwarebytes' Anti-Malware which I did. Installed it and after
having to stop the process which caused the "program can't be started" routine did
the scan and had it fix what it found.
Got a message that it couldn't fix several files until a reboot, so I agreed to that.
Came back up STILL getting the pop ups and fake warnings. Wash, rinse, repeat. My
feeling is that despite the update, my version of Antivirus Pro Fake hasn't caught
up with a new file naming criteria to eliminate everything. So far, so not so good.
Installed HiJackThis and ran it. It found the iehelper.dll entry and the ssxrsysguard.exe
entry, but by this point I am loath to try any sort of manual removal without instructions.
I'll show the entries from HJT which are relevant below.
O1 - Hosts: ::1 localhost
O1 - Hosts: 193.169.12.50 winguard2009.microsoft.com
O1 - Hosts: 193.169.12.50 winguard-2009.com
O1 - Hosts: 193.169.12.50 www.winguard-2009.com
O2 - BHO: BHO - {B6D223F6-C185-49a2-BA7E-A03E84744702} - C:\WINDOWS\system32\iehelper.dll
O4 - HKCU\..\Run: [qcpukuir] C:\Documents and Settings\Julia Boyles\Local Settings\Application
Data\pokfju\ssxrsysguard.exe
O4 - HKCU\..\Run: [qcpukuir] C:\Documents and Settings\Julia Boyles\Local Settings\Application
Data\pokfju\ssxrsysguard.exe
I had just erased the entries from the HOSTS file manually when I thought that it
may be wasted effort if I haven't gotten the other parts of the infection cleaned
up and decided to come here after all.
[Reply or follow-up to this message]
| |
re: Antivirus Pro Fake iehelper.dll ssxrsysguard.exe
Thursday, November 5, 2009 at 7:26 pm Posted by Thordis
(4 messages posted)
Ugh, the line:
My feeling is that despite the update, my version of Antivirus Pro Fake hasn't caught
up with a new file naming criteria to eliminate everything.
Should read:
My feeling is that despite the update, my version of Malwarebytes' Anti-Malware hasn't
caught up with a new file naming criteria to eliminate everything.
[Reply or follow-up to this message]
|
re: Antivirus Pro Fake iehelper.dll ssxrsysguard.exe
Friday, November 6, 2009 at 6:06 am Posted by Johnb33
(2283 messages posted)
Although Malwarebytes is a great program it will not catch everything. Please download
combofix and run. Follow the instructions on this page.
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
Please post the log file that it displays at the end along with a new hijackthis
log.
On Thursday, November 5, 2009 at 7:26 pm, Thordis wrote:
>Ugh, the line:
>My feeling is that despite the update, my version of Antivirus Pro Fake hasn't caught
>up with a new file naming criteria to eliminate everything.
>
>Should read:
>My feeling is that despite the update, my version of Malwarebytes' Anti-Malware
hasn't
>caught up with a new file naming criteria to eliminate everything.
[Reply or follow-up to this message]
|
re: Antivirus Pro Fake iehelper.dll ssxrsysguard.exe
Tuesday, November 10, 2009 at 1:59 pm Posted by Mozark
(255 messages posted)
Do format & reinstall of OS after backing up your data-after malware your system
security is compromised
[Reply or follow-up to this message]
| |
| |
Tip: Use one of the [Reply or follow-up to this message] links above to add a message to this thread
| |
Return to the Windows XP Discussion Forum
|
|
|
|