Help with HSA, SE, & SW removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by tejano78, Aug 21, 2004.

  1. tejano78

    tejano78 Private E-2

    I tried the generic solution to removing HSA but found the dll file I am trying to remove seems to mutate. I am not comfortable with identifying the bad items in hijackthis log such as the BHO line or 04 lines. I only have one BHO line listed. Can someone analyze my log? I know that by only removing the R1 & R0 lines that the hijacker added is not enough and end up changing. I did not see the services listed in step 13l or 13m. I was allowed to delete HSA, SE, and SW. After returning to the internet, my homepage is still redirected. HSA, SE, and SW are listed again.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't attempt partial fixes!!!! If you skip around and keep making changed like that, you will spread the problem all over the place. Also, the more you reboot the more it can mutate (especially if you start trying to delete one or to file or line here and there. The procedure must be followed step by step in the order it was written in a continuous fashion. That is, don't stop in the middle and come back later, especially rebooting at any point when you were not told to. If you stop or reboot at a point not specified you will have to start over again at the beginning.

    Are you absolutely positive you have this hijacker? If so, post me a HijackThis log (as a .txt file attachment) and I'll try to point you in the right direction. If not positive, you should run the procedures here first: http://forums.majorgeeks.com/showthread.php?t=35407
     
  3. tejano78

    tejano78 Private E-2

    I've attached my hijackthis log. Home Search Assistant, Search Extender, and Shopping W are all on my computer. Thank you for your help. I have been reading up on this topic for a few days now.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your Windows 2000 is out of date with proper service packs. This can be a security problem. The same is true for your Internet Explorer version.

    Questions: These next three line from your log (related to two programs) are not part of the HSA hijack, but I do not like the looks of them. Have you run a full virus scan and or trojan scan lately? Unless you know what they are?
    C:\WINNT\System32\vrmw.exe
    O4 - HKCU\..\Run: [Supe] C:\Documents and Settings\Dora Lopez\Application Data\siwt.exe
    O4 - HKCU\..\Run: [Voffxvx] C:\WINNT\System32\vrmw.exe


    Okay here are your processes related to HSA:
    C:\WINNT\system32\apijt32.exe
    C:\WINNT\mfcqi32.exe


    Here are your R0 & R1 lines:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\dgqcn.dll/sp.html#96676
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\dgqcn.dll/sp.html#96676
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://dgqcn.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://dgqcn.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\dgqcn.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\dgqcn.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\dgqcn.dll/sp.html#96676
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://dgqcn.dll/index.html#96676
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\dgqcn.dll/sp.html#96676
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\dgqcn.dll/sp.html#96676


    Here is your BHO line:
    O2 - BHO: (no name) - {2337E364-64B1-714C-A6EE-D6016C7DA801} - C:\WINNT\d3ki32.dll

    And here is the only line shown right now in the O4 startup section:
    O4 - HKLM\..\Run: [mfcqi32.exe] C:\WINNT\mfcqi32.exe

    Don't forget to add in any info (if found) from the Network Security Service
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is that enough info to get you on your way or do you have other questions about other steps?
     
  6. tejano78

    tejano78 Private E-2

    I have a burned copy of Microsoft Office 2000 installed. Can I download an update from Microsoft's website?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't understand your question!
    And what does this have to do with the HSA hijack?
     
  8. tejano78

    tejano78 Private E-2

    You stated that I don't have an up to date service pack. If I need to install updates on my computer and the copy I have is burned, will I get somebody in trouble by visiting Microsoft's update page? By the way, I was able to get rid of HSA. Thank you.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now I understand what you meant. Well we don't deal with any questions here related to illegally copied software.

    Happy to hear your HSA issue is resolved though!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds