Home Search Assistant/Windows ME

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by srl, Jul 26, 2004.

  1. srl

    srl Private E-2

    Is there any help out there for those of us who have Windows ME? I cannot get Home Search Assistant off of my computer!!! Please help!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! I have worked a few people thru it. But it is not going to be easy. The first suggestion though would be to see if you can go back to a System Restore point pre-dating where the infection occurred. If you have already disabled system restore, the look process is the only option other than re-installing you WinME system.

    Please see the guidelines and things to do first here. And then post (as a text attachment) your HijackThis log.

    *****IMPORTANT*****: Do not try to fix anything after posting and do not reboot your PC or shutdown. Otherwise what is in your log will not be useful to me because it will mutate upon reboot. You can disconnect from the internet but do not reboot. That way your HijackThis log will still be the same as what I will be referring to.
     
  3. srl

    srl Private E-2

    Well my system restore will not let me restore any earlier than the current date. I ran hijackthis but I'm not sure how to save it for you to view. sorry i'm so computer illiterate!
     
  4. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Hi,
    Once you view the log file, you can choose file, save as. Save it somewhere you can easily find, like on your desktop. In a new post, look below the typing area for a button that says "manage attachments". You can use that to browse to where you saved it, then click upload :)
     
  5. srl

    srl Private E-2

    it only gives me the option to save as "all file types" or "log file". then, when i try to upload it, it says invalid file type. what am i doing wrong??? :(
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HijackThis defaults to saving the file with a .LOG extension. All you have to do is use Windows Explore and find the file you saved and right click on it. Then choose rename and change the extension from .LOG to .TXT

    So for example, if you have hijackthis.log, rename it to hijackthis.txt.

    You could have done that right in HijackThis when you first saved your log.
    All you have to do is change it to All File Types and then change the file name to hijackthis.txt and save it.

    You cannot upload .log files here.
     
  7. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's good new Major!

    srl, give about:buster a run. See the instructions on the above link. While it is geared towards about:blank problems, it is also useful for HSA problems. If you still have problems after that. Then post the HJT log I asked for.
     
  9. srl

    srl Private E-2

    Thanks for the help. I'll try this after I get home from work and let you know the outcome!
     
  10. srl

    srl Private E-2

    O.K. about:buster seems to have worked. No more home page changes or only the best pop ups. the only thing is that i can still see home search assistant when i go to add/remove programs in my control panel. doesn't that mean that it is still hiding somewhere???? I will post my hijackthis log for you to check out. thanks for all the help so far!
     

    Attached Files:

  11. NeoNemesis

    NeoNemesis Moutharrhea

    also, you may want to pay a visit to www.windowsupdate.com and update windows internet explorer. 5.5 was like the worst one ever made. Also check out some updates for your ME. This should help prevent some future attacks.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are still infected with HSA. Even though the R0 & R1 lines do not show in your log right now. They will come back. You still have some executables related to it running. And there is another bad DLL (msopt.dll - a different issue but it appears on a lot of PC infected with HSA).

    If you can kill these two processes first:
    C:\WINDOWS\SDKFO32.EXE
    C:\WINDOWS\WINPK32.EXE

    you may be able to get rid of this problem. I doubt Task Manager will kill them. Get Process Explorer here and use it two kill those to processes and then do the below.

    Try booting to safe mode and running about:Buster at least two more times and then reboot to normal mode and send another HJT log attachment.
     
    Last edited: Jul 27, 2004

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds