Help removing Home Search Assistant

Discussion in 'Malware Help (A Specialist Will Reply)' started by tcm278, Jul 25, 2004.

  1. tcm278

    tcm278 Private E-2

    I have been reading the various threads about removving home search assistant and have tried most everything and it still keeps coming back. I have run the HSA remover and it removes it but it comes right back. I followed the directions and ran it in safe mode. When I look in services I do not find Network Security Service so I have not been able to disable it since it is not there. I think I also deleted something I shouldn't have, IE will not open now if I click on it but it will open if another program calls for it or if it needs to open another window. HELP HELP I have been plagued by this for days now!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You never mentioned your OS! And have you done anything other than HSremove. Have you run Ad-aware, SpyBot S&D, CWShredder, etc?

    I'll need to see your HijackThis log. But before doing that you need to read the new rules: http://forums.majorgeeks.com/showthread.php?t=35407

    It's okay to post your log because I'm asking you to do so. But make sure you post it as a text attachment as explained in that thread.

    When you save the log in HijackThis a save dialog window comes up. Change the Save as type to "all files" and change the Filename from hijackthis.log to hijackthis.txt. Then upload that file.
    After doing this and to have the easiest time (even though it will still be difficult) removing the HSA problem, please do not shutdown, reboot, or change anything (i.e., try to fix anything). Otherwise the problem can mutate making what I tell you ineffective. It is okay if you need to disconnect from the internet to be safe (you can unplug your ethernet connection from an ADSL or Cable modem or physically drop an analog dial-up modem connections). You can even shut off your monitor to save power. Just leave your computer running until I give you a procedure to follow.

    Sorry I did not answer sooner. I had a load of items in progress today and just saw your request now.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    tcm,

    Give the new About:Buster a try first. You get it here. Follow the instructions on the link.

    If still having a problem after that, post the log I asked for in my previous post.
     
  4. David Moon

    David Moon Private E-2

    I've tried both HSRemove and About:Buster, and the instructions aren't very clear - specifically, why do you "write down the name and path of the file in the 'Path to Executable' section"? What do you do with it once you've written it down?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The directions for about:Buster have changed see the newest version: http://www.majorgeeks.com/download4289.html

    And for HSremove the idea behind writing down the path to the Network Security Service executable is so that the file can be manually deleted if necessary. Sometimes the programs have a problem deleting certain files. If we write down the name, we can always go back and remove the file by hand later.

    Please do not post your questions in multiple threads and if you have questions and or problems you should start your own thread.
     
  6. tcm278

    tcm278 Private E-2

    Thanks for the help I am running XP home Edition I had tried running Adaware with the plug in and Spy-Bot Hs remover and About Buster before my first post. After reading your post I downloaded the new About Buster and ran that. Just like each time before it removed it and as soon as I rebooted out of safe mode it was right back. I also followed all the instructions in the link you posted about spy ware and again nothing. I was unable to run CCleaner as it would not install. Also windows installer is constantly opening and trying to re-install Front page. Anyway here is my log, maybe after we hopefully fix this I could get some help as to what I probabbly accidently deleted wrong so that my IE will no longer open by double clicking on it. I was so frustrated I deleted some registry items...oops!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I also want you to download ProcessExplorer from here: http://www.sysinternals.com/files/procexpnt.zip
    Then run it and kill these processes:
    mfcko32.exe
    ieow.exe

    Then enable viewing of hidden files and folders: http://forums.majorgeeks.com/showthread.php?t=37650
    Find and delete those two files:
    C:\WINDOWS\mfcko32.exe
    C:\WINDOWS\system32\ieow.exe

    Now quickly reboot in safe mode: http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406?OpenDocument&src=sec_doc_nam
    Run HSremove. Save log.
    Run About:Buster twice. Save each log.

    Reboot normal mode and post HSremove log, both AboutBuster logs, and a new HJT log (put them in one attachment file).
     
  8. tcm278

    tcm278 Private E-2

    I downloaded the procexpnt and shut off and then deleted the files you said to. I ran HSremover and About Buster, but I don't see an option to save a log and I can not find a saved log from these applications.

    Am I missing something?

    It also did not get rid of the plague on my computer. When I checked the home page in safe mode it was reset to google but as soon as I rebooted and open control panel internet options it is again reset to the HSA page.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What versions do you have for
    - HSremove
    - About:Buster
    - Ad-aware
    - Ad-Aware reference file
     
  10. tcm278

    tcm278 Private E-2

    HSremover is v2.39
    AboutBuster V1.32
    Adaware 6.0
    Reference file 0R 150 05 07 2003

    It seems that the reference file is old but when I click to update Adaware it tells me there are no updates available.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    about:Buster is now on 1.5 (today)
    Your Ad-aware is not even close to being the correct version. You need to download both the main program and then do the update. Get Ad-aware 6.181here.
    Ad-aware referencefile 01R334 24.07.2004 here. Or you could just update it online after getting the proper version. Read how to do a full scan with Ad-aware here.
    Also download and install the VX2 Cleaner Plugin for Ad-ware here. Read how to install it and run it on that link too.

    After updating both of them boot to safe mode.
    Run about:Buster twice (two full times - that will show a total of four scans). Save the logs by highlighting the text in the screen and copy and paste to a text file. Then run Ad-aware in fullscan mode (let me know if it finds any thing). Now run the VX2 Cleaner Plugin for Ad-aware.

    Now boot normal mode. Send me that info from about:Buster scans and Ad-aware. Also give a new HijackThis log. (post as attachments please).
     
  12. tcm278

    tcm278 Private E-2

    Ok updated all the tools and ran adaware about buster and HS Remove. I have attached the logs from adaware, About Buster and hijack this. Adaware found and removed things as did About Buster but again as soon as I reboot the plague has re-hijacked my IE. Thanks for all your continuing help!
     

    Attached Files:

  13. tcm278

    tcm278 Private E-2

    I forgot to mention I am using Propel Accelerator, I figured you probably saw this in the logs, don't know if that could have anything to do with it and I have deleted the temp files in this trying to rid the HS.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Guess what! about:Buster (let's call it AB for short) is now version 2.0. Get the new one here and follow the directions exactly as written on the download page. In particular note this part:

    "The program should start scanning. Then hit exit and reboot.
    Once rebooted run About Buster once more to make sure everything is ok."

    Make sure you do not run ANYTHING before running AB again after reboot. Also I want to add some other important item.
    - Shutdown all applications ESPECIALLY Internet Explorer before running about:Buster and DO NOT RUN Internet Explorer again until noted below.
    - make sure you have done both runs
    - after running AB the second time (after reboot), run HijackThis and clean up any left over info from the problem (which could be from your log):
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\diqer.dll/sp.html#26512
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://diqer.dll/index.html#26512
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://diqer.dll/index.html#26512
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\diqer.dll/sp.html#26512
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://diqer.dll/index.html#26512
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\diqer.dll/sp.html#26512
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8081
    O2 - BHO: (no name) - {92785D9A-20BA-33B7-8258-1F1AF4B27CD0} - C:\WINDOWS\javapk.dll
    O4 - HKLM\..\Run: [ieow.exe] C:\WINDOWS\system32\ieow.exe

    Delete these file too if found (enable view of hidden files: http://forums.majorgeeks.com/showthread.php?t=37650)
    C:\WINDOWS\javapk.dll
    C:\WINDOWS\system32\diqer.dll
    C:\WINDOWS\system32\ieow.exe

    - now you can try Internet Explorer and post your results

    Note: you did not follow directions. I told you to run Ad-aware FULLSCAN and VX2 cleaner AFTER RUNNING about:Buster. You will find quite often it is very important to follow steps exactly without skipping or leaving anything out. Will it always make a difference....who knows. But it can. And the things I have been telling you to do have work for everyone else. There is no reason why they should not be working for you unless there is a procedural type problem.

    Do you have multiple accounts on this PC? If yes, all accounts must be cleaned.
    Have you disabled system restore and left it disabled? Are you sure Network Security Service is disabled (or non-existent)?
     
    Last edited: Jul 29, 2004
  15. tcm278

    tcm278 Private E-2

    Sorry about running things in the wrong order. What do you mean by multiple accounts? There are multiple users setup. If you mean users how would I clean each user? System restore has been off the whole time and Network Security is non-existant.
     
  16. tcm278

    tcm278 Private E-2

    Also should AB be run in safe mode then when rebooting should I reboot into safe mode again? Trying to make sure its done right.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes by multiple accounts I meant multiple user logins. You need to login to each user account and veryify that each one is clean. Same methods would be used to clean each one.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not according to new write up. Run it in normal, do immediate reboot, then immediately run it again. Then look for the stuff I show from you HijackThis log and fix it if still there. Delete the files too. All this needs to be done before you open Internet Explorer again.

    By the way are you using a Proxy Server? See this line in your HJT log:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8081
     
    Last edited: Jul 30, 2004
  19. tcm278

    tcm278 Private E-2

    Deleted all user accounts accept two and deleted files whit them. Cleaned both accounts. Although when I run hijack it only shows problems on one account (which is the main account). Ran the new AB deleted the files you said to and it helped. IE will now open. When I reboot and check IE options in the control panel the page is set to google instead of the other. When I first open IE it goes to google but when I open a second window it goes back to HS page and pop ups start. I attached the hijack log and the only thing that seems to show up is the HKCU .....localhost 8081. No matter how many times I tell hijack to fix this item as soon as I reboot it is back again. The other problem is when I open the second IE window, windows installer pops up wanting to install front page. Log is attached.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! For some reason I had not noticed you are not using the current version of HijackThis. Please get the proper version from here.

    Please run ProcessExplorer and save a copy of the running processes and give me a new HijackThis log too. Put them together in one attachment. DO NOT REBOOT AFTER THIS.
     
  21. tcm278

    tcm278 Private E-2

    Download latest ver of HT here are the requested log files.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Use ProcessExplorer to kill this process:

    C:\WINDOWS\sysvy.exe

    Then try to delete this file:
    C:\WINDOWS\sysvy.exe

    Tell me the results from above.

    Now run HijackThis and fix these lines:
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {A7717956-9A67-0F8E-761C-A65492DB585D} - C:\WINDOWS\mfcmt.dll
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
     
  23. tcm278

    tcm278 Private E-2

    Ok after kill process it let me delete the file. Then fixed the items in hijack this. Should I reboot now? When loged back on to the Internet default page was google. Although I still have windows installer keep poping open. Havent had any pop ups yet. Maybe fixed:)
     
  24. tcm278

    tcm278 Private E-2

    Been surfing and no pop ups and no redirects:). But I have not yet re-booted.
    Any idea why windows installer keeps comming up? :rolleyes:
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First, see if you can find this file and delete it
    C:\WINDOWS\mfcmt.dll

    If you cannot delete it now, reboot to safe mode and delete it.
    If you boot to safe mode, run About:Buster one more time in safe mode.

    If you do not need to boot to safe mode to delete the above DLL then just reboot and when you come back up. Do not run anything until running About:Buster? Then try doing some opening and closing of browser sessions and lets see what happens. The problem with Windows Installer opening is something that has happen in many cases where people have had HSA problems. I do not know of a fix yet. What happens if you let try to re-install FrontPage?
     
  26. tcm278

    tcm278 Private E-2

    The plague has been eradicated!!!! :) Thank you very much for your help! Computer is now running much better and I can surf the web again. Only left over is the windows installer problem. I will try and re install front page (cd is at my office) later and see if that solves the problem. Would it work if I turned installer service on manual? Again... Thanks for the Help!!!!!!
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your welcome.

    Not sure about turning the installer service on manual. Give it a try. I don't think anyone understands how this HSA hijacker and the use of the HSremove and About:Buster tools to aid in its removal causes this type of problem but I have seen multiple complaints in this area. Most frequently it was an MS Office trying to install problem.

    Make sure you get your system protected from reoccurrence of issues like this.
    Here are some simple steps you can take to reduce the chance of infection in the future.
    I strongly encourage you to do them all.
    1. Visit Windows Update:
    Make sure that you have all the Critical Updates recommended for your operating system and IE. The first defense against infection is a properly patched OS.
    a. Windows Update: http://v4.windowsupdate.microsoft.com/en/default.asp
    Do this at least once a month.
    b. Never add any site to your Trusted Sites Zone.

    2) Anti Virus: make sure you have one and keep it updated. Here are some good free ones:
    http://majorgeeks.com/download1968.html Avast
    http://majorgeeks.com/download886.html AVG
    The top two hands down. Better than Norton or McAfee!
    Only run ONE AV!

    3) Firewall: if you don't have one get one of these below. The last two are free versions:
    Don't care if your on dial up or High Speed....you must have a firewall
    http://majorgeeks.com/download738.html Kerio Personal Firewall http://majorgeeks.com/download3356.html Sygate Personal Firewall Free http://www.majorgeeks.com/download388.html ZoneAlarmFree

    4) Get a Temp File/Cookies/index.dat cleaner
    http://majorgeeks.com/download4191.html CCleaner (Crap Cleaner)

    5) SpyWare Prevention (These prevent, they are not scanners. Scanners are listed later.)
    http://majorgeeks.com/download2859.html SpyWare Blaster
    http://majorgeeks.com/download3045.html SpyWare Guard

    6) SpyWare Scanners/Removers
    http://majorgeeks.com/download2471.html SpyBot (Use the Immunize feature. I don't activate the TeaTimer)
    http://majorgeeks.com/download506.html Ad-aware http://www.majorgeeks.com/download4283.html VX2 Cleaner Plug-In for Ad-Aware
     
  28. tcm278

    tcm278 Private E-2

    My kids also use this computer and I am sure that is how they downloaded the HSA ( I assume it was downloaded when they downloaded a compt game or something). Is there a program out that will block any downloads without having a password? Is the HSA one of those downloads that pop up asking if it is ok or connected to a game or is it something that downloads in the background without your knowledge? I am going to add all the recomendations you have made. Windows firewall is not sufficient I take it?
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HSA can come from many different places. I don't think it would be a download. I think it just sneaks in. But it could be that it is embedded in some application that your kids have downloaded and installed (without reading or understanding the find print).

    I think the other firewalls recommended would be a better choice than the WinXP firewall.

    You can go into Internet Explorer's Tools, Internet Options, Security aread and block what you want for each of you kids. It will probably cause them some grief sometimes but that is a method by which you can block downloads and Active X stuff. Take a look at the options there.
     
  30. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    In addition to what Chaslang said install SpywareBlaster. It wont stop everything, but a lot of it.

    Better surfing habits. I doubt its any games they downloaded, but making typos or installing programs or hitting enter when a window opens at a website asking to install whatever. One typo and your hijacked, use bookmarks when you can.

    Forget Internet Explorer and get Mozilla FireFox, again, not perfect, but much better.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's in my list Major. See number 5.
     
  32. dodgybeaver

    dodgybeaver Private E-2

    hey im suffering from the same problem except not from sysvy.exe or mfcmt.dll, its from a program from sdkuf32.exe. I have searched for this prog many times and deleted it many times, however the thing keeps comin back so i have attempted to delte it maunally from the registry, but guess what it keeps comin back, i have also used all manner of removal tools, for example SpySweeper,Spybot,hijack this,ABOUT:BUSTER AND EVEN HSREMOVER yet none of them seem to get rid of it< whenever i end the process in the memory it reloads again within seconds and its startin to affect my business as i am spendin more time tryin to get rid of it than doing work, so does anyone have n e tips on gettin rid of the little critter or shud i wiped my hard drive and start again?
     
  33. dodgybeaver

    dodgybeaver Private E-2

    hey i found a way to solve the problem......system restore. With any luck system restore will take u back to a point before u downloaded HSA and therefore it will be gone, ive tried it and it has worked fine for me. So i suggest backing up what u want to keep them use system restore, let me know if it works for anyone else out there
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please start your own thread when you have problems.

    Yes, system restore has worked in some cases. In many others it did not because the users may not have had any valid restore points prior to the HSA problem. Or they already disabled it while trying to fix the HSA problem prior to having tried to use it. Note, that this may bring back other problems that may have been fixed after that system restore point was made too.

    Do not answer my post here! If you need to discuss this any further, start your own thread. If the problem comes back, see this thead: http://forums.majorgeeks.com/showthread.php?t=38772
     
  35. dodgybeaver

    dodgybeaver Private E-2

    I apoligise i only registered with the forum here today!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds