I have tried "When all else fails-Generic Solution to HSA" and everthing failed

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by skd44, Oct 21, 2004.

  1. skd44

    skd44 Private First Class

    A few months back I wrote to you regarding a problem I was having with the HSA and about:blank hijackers. At the time I tried many solutions both from your site and from other things I tried and couldn't get rid of the problem. I then posted my hijackthis log file (at your request) and it was discovered that I had the HSA hicjakcer. You provided me with the Generic Solution to HSA and at the time I followed it step by step and the solution worked. Thanks to you guys I was HSA free for quite some time. Now its back and I tried the generic solution 3 times and nothing has worked. I saved both my hijackthis and aboutbuster log files but I know not to post them until asked for them. I was just curious what I should do. You guys saved me a few months back and at this time there is no way I want to use my system recovery CD's for fear of losing my emails in outlook express and all the other programs I've added over the last four months. Sorry for the long thread but I could use any help you could provide. Thanks a bunch!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay, sounds like you never put some protections into place that you should have so remember to look at How to Protect yourself from malware! when we get this fixed.

    Since you have gotten re-infected with HSA, who knows whatelse may have found its way into your PC so. Begin as usual by following all the steps here: READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Be sure you check it out and check for updates to all programs. This tutorial has most likely changed since your last problem. After that again refer to NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting and post your HijackThis log as a .txt file attachment. At this point, while waiting for a solution from me, you must not shut your PC down. The hijacker can mutate at each reboot which would make your HJT log useless to me. So leave your PC running but disconnect yourself from the internet (unplug cables if Cable or DSL modem is used) and you can shut off your monitor, that is until you are ready to come back here. Then obviously you need to plug in you cable and turn on your monitor.
     
  3. skd44

    skd44 Private First Class

    I tried running all the steps from the READ ME FIRST BEFORE ASKING FOR SUPPORT TUTORIAL and even tried to run the GENERIC SOLUTION TO HSA again but nothing worked. I am posting my hijack this log as a .txt attachment as well as the log from about:buster as a .txt attachment. I hope that this is ok and I hope that this can be fixed because it seems to be worse than the first time a few months back. Thank you very much again.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First before continuing you must put HijackThis in its own directory as indicated in the tutorial. You have it on your Desktop in C:\Documents and Settings. Do not put it on your Desktop, or in any sub-folder of C:\Documents and Settings, or in any temp folder. Try using something like C:\Program Files\HJT. Do the same for about:Buster. Next time you run HJT remember to not be running about:Buster, browsers, etc. Now hopefully you have not shut your PC down or rebooted since posting your log. I'm working on modifiyng the Generic Solution for your type of infection. I have not had a chance to do this and have been meaning to do it for a couple of weeks. So you pushed me over the edge. ;) Don't reboot until you see my next post here telling you the Generic Solution is updated and I'll point out your key files (at least the ones visible to me in your log).
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay the Generic Solution has been updated. Note another program must be downloaded. ADSSpy.zip and I added some more detail on deleting ADS infected services files in step 10b.

    Here are some tips for you:

    I'm guessing that your path to executable found in step 6 will have this:
    C:\WINDOWS\smscfg.ini:tfuqu

    Please tell me whether that is correct or not. If not, tell me what you do find in step 6. What Service(or services) and what Path to executable

    Here is your BHO for Step 7:
    O2 - BHO: (no name) - {4E08BE38-D4B4-A5CF-2262-2FA489C00DD6} - C:\WINDOWS\appsv32.dll

    Here is your EXE file for step 8:
    O4 - HKLM\..\Run: [crgk32.exe] C:\WINDOWS\system32\crgk32.exe

    Here are your lines to fix in Step 12:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\qawub.dll/sp.html#96676
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\qawub.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\qawub.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\qawub.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\qawub.dll/sp.html#96676
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\qawub.dll/sp.html#96676
    R3 - Default URLSearchHook is missing

    Hopefully this is enough to get you going.

    Don't forget to attach the TWO about:buster logs and a new HJT log when finished and tell me how the procedure went and how things are working.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds