Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win


pe386-msguard-lzx32 & some spywares

Posted on 2006-10-26
Medium Priority
Last Modified: 2012-06-21
im down to the last 3 items which is really hard to delete even in hijack this or commandprompt.

1. rootkit? pe386-msguard-lzx32 - i have no idea how to remove this. i think this one is opening & listening the port and send sentivite information to the hacker's computer.

2. dll's which are loaded even on startup safemode command prompt only.

i could not delete these dlls because these are loaded already even on command prompt only?
this is the deskbar spyware i think. cause i could still see it on the windows explorer's toolbar.
i have deleted all deskbar.dll related files except for the last 2.
xxyxtt.dll & pmkh.dll

is there another way to prevent them from loading? which files to check?
or is there a way to disable an already running dll?

im using WINXP pro btw.

last resort is to reinstall the windows.
suggestions are appreciated.
Question by:Jerry_Pang
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
  • 3
  • +1
LVL 15

Accepted Solution

venom96737 earned 800 total points
ID: 17817441
use a program called killbox located here http://www.bleepingcomputer.com/files/killbox.php

give the path to the dll files and check delete on reboot option this will get rid of it.

What kind of file is the pe thing and where is it located? you can romove the file using the same method if you wanted.
LVL 15

Expert Comment

ID: 17817454
there appers to be really a few things you want to do to get rid of this rootkit.  

here is a great post where they deleted it I figured there was a service and a few things to it but I didn't know 100 percent here you go.


Author Comment

ID: 17817668
this nasty rootkit - pe386 hides itself.
i just learned about this on wiki

i do not know how to delete it. it's not even detected on hijackthis.
It was detected by a smitfraudfix.cmd
while im trying to fix the spywares - smitfraud and astakiller

it says i need to download a rootkit software.

but i dont trust any of the sites that i found.

thanx for the killbox.
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

LVL 15

Assisted Solution

venom96737 earned 800 total points
ID: 17817901
rootkit revealer will help but it will only give you the text file it is writing to. Use avenger found here: http://swandog46.geekstogo.com\avenger.zip and do you have the log from smithfraudfix?  If I could get some locations I could help you out more.

Author Comment

ID: 17817933
>  If I could get some locations I could help you out more.

it says evrything is clean
at the end of the raport.txt

it just says
rootkit detected use rootkit tools to fix it.

no other locations.

i just found out it starts to delete all the exe file that i run
in "start/run" after reboot.

gonna backup now. brb on monday

Assisted Solution

Mnf earned 400 total points
ID: 17818796
First install this free utility
it will help you to identify the files that loaded when boot
try it in "safe mode command prompt only" – this is very important so the spayware will not be working there-
you may put it in the root of the D:\  
then you can use the command prompt to run it (use the autoruns.exe)
then seek all the taps there to seek your files and disabling it.

And also you can use this free utility to reveal the RootKit

and the other one from AVG

and finally this is more details about "Anti-Rootkit Software - Detection, Removal & Protection"
LVL 47

Expert Comment

ID: 17825577
Smitfraudfix does detect drivers from those 3 rootkits mentioned, but it also has false positives, I had a couple of false positives reported with the smitfraudfix scan.

What you should do is to check for rootkits and  run Gmer:
Download GMER from here:

Unzip it and start GMER.exe
Click the rootkit-tab and click scan.

Once done, click the Copy button.
This will copy the results to clipboard.
Paste the results in your next reply.

If you're having problems with running GMER.exe, try it in safe mode.

If Gmer doesn't find any rootkit then that is halfway clear.
Next is to unload the driver pe386 using avenger or just stopping the service, if there are no drivers to unload then it is false positive.

LVL 47

Assisted Solution

rpggamergirl earned 800 total points
ID: 17825611
deskbar.dll<-- is a variant of Alcan worm/P2PNetwork worm

xxyxtt.dll <-- looks like haxdoor

pmkh.dll<-- looks like qoologic file, could also be vundo

Can we look at your hijackthis log please? hijackthis log can tell us what infections those files belong to by looking at what lines in hijackthis they are running from.

Please download HijackThis 1.99.1
Open Hijackthis, click "Do a system scan and save a logfile" don't fix anything yet.

Then upload the logs to any hosting sites,
or go to the below link and login using your Experts-Exchange username and password.
Click on "Expert Area" tab
type or paste the link to your Question
"Browse" your pc to the location of your Hijackthis log and click "Upload"
Copy the resulting "url" and post it back here.

OR: paste the log to either of these sites:
1. http://www.rafb.net/paste/
then at the bottom left corner click "paste"
Copy the address/url and post it here.

2. or at --> http://www.hijackthis.de/ 
and click "Analyse", click "Save".  Then post the link to the saved list here.

Author Comment

ID: 17838765
finally reformating it.  
gona split now. im giving up fixing it.

LVL 47

Expert Comment

ID: 17838903
Ooops!!! too late!
malware expert just created a tool for this little buggers --> pe386-msguard-lzx32

Sorry to hear you had to reformat, maybe it's for the best, at least now you have a squeaky-clean system.

Thanks for the points!

Author Comment

ID: 17854649
i started to backup it and just when i was about to format it,
i gave it to my friend for last try.
he said something about Defender which microsoft bought.

we installed it and it work perfectly.

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Introduction Often we come across situations wherein our batch files would be needing to reboot Windows for a variety of reasons. A few of them would be like: (1) Setup files have been updated whose changes can take effect only after a reboot …
I. Introduction There's an interesting discussion going on now in an Experts Exchange Group — Attachments with no extension (http://www.experts-exchange.com/discussions/210281/Attachments-with-no-extension.html). This reminded me of questions tha…
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…
Hi friends,  in this video  I'll show you how new windows 10 user can learn the using of windows 10. Thank you.

604 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question