Help with HSA

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mschultz116, Jul 26, 2004.

  1. mschultz116

    mschultz116 Private E-2

    I have been trying to get rid of HSA for a little while now. I ran AdAware and Spybot, then followed the directions for HSRemove. Each time I ran HSRemove it seemed to have worked but the problem was still there on restart out of safe mode. In the Network Security Service, the Path to Executable read "C:\WINNT\System32\apiad.exe/s" I am running on Windows 2000 on this computer. I don't know how to do the system restore on windows 2000 so I haven't tried that. If you have any suggestions please let me know. Thanks a lot.
     
  2. aLLiKZar

    aLLiKZar It's not too late to back out!

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is no system restore on Win2K. Try my original Generic Solution to fix this. I have been using it again lately with a few additional steps added and it has worked. Note it is written "generically" so you have to subsitute in your info from your HijackThis log in the correct places. Here is the link: http://forums.majorgeeks.com/showthread.php?t=35917
    Note: where ever it states c:\windows you will most likely have c:\winnt since you are using Win2k.

    Before starting make sure you download and install CCleaner from here:
    http://www.majorgeeks.com/download4191.html

    Don't run CCleaner yet.

    Also before starting make sure you have the current versions of:
    HijackThis (you have an old version): http://www.majorgeeks.com/download3155.html
    HSremove : http://www.majorgeeks.com/download4286.html
    About:Buster: http://www.majorgeeks.com/download4289.html
    Ad-aware: http://www.majorgeeks.com/download506.html
    make sure Ad-aware reference file is updated.
    Also first read about how to set Ad-aware for a fullscan: http://www.lavahelp.com/howto/fullscan/index.html


    If you can follow how to substitute all of you info into the Generic Solution Thread, do it but when you get to step 13, add the steps below in and then after these continue on with step 14 and above:


    13A. Search the registry for every instance of xxxxx.dll (the file from step 5). Change the values for your home and search pages to what you want (www.majorgeeks.com will do).
    13B. Search the registry for every instance of the suspicious exe files found by Hijack This from step 8. Delete every instance.
    13C. Run CCleaner and on the Windows tab (you'll see when you run it) leave the defaults and click Run Cleaner.
    13D. Search your computer for xxxxx.dll. Delete each instance.
    13E. Search your computer for the suspicious exe files. Delete each instance.
    13F. If WinXP, Delete the Prefetch folder in C:\WINDOWS.
    13G. Delete Memory.dmp in C:\WINDOWS or was it C:\WINDOWS\System32
    13H. Run HSRemover. (save the log)
    13I. Run about:Buster (save the log)
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  5. mschultz116

    mschultz116 Private E-2

    Thanks...I don't have time to do this now, but I'm going to try it when I get home from work. Thanks a lot though, if I have further problems I will post again.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Let me know when you get finished or if you need help understanding all this.
     
  7. mschultz116

    mschultz116 Private E-2

    Alright, I'm having a little problem getting started here. First 4 steps are going just fine...the easy ones. :) Anyway...in my HijackThis log I don't have any .dll files like in your example. Here is the R0&R1 lines of the log.

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://youriskalka.com/sp.htm
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://youriskalka.com/sp.htm
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://youriskalka.com/index.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://youriskalka.com/index.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://youriskalka.com/sp.htm
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://youriskalka.com/index.htm
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://youriskalka.com/sp.htm
    R3 - Default URLSearchHook is missing

    I'm thinking maybge the youriskalka part, but I don't want to...screw with things I know nothing about. Thanks for any help offered.
     
  8. mschultz116

    mschultz116 Private E-2

    Also don't know if it matters that the desktop, folders, etc. is set up as a browser.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This does not show the typical lines seen when having the HSA hijack problem. That is, unless this is a new strain of the problem. I see you already ran HSremove. Perhaps you need to reboot a few times and open & close Internet Explorer a couple of times to see if these lines change. If they do not change, the first thing I would do is download the latest About:Buster (it just updated so make sure your download this version) and run it and save its log. Then let me know where things stand. If still having problems, post the About:Buster log and a HijackThis log. Remember to post them as a text attachment (see this thread for new rules on this: http://forums.majorgeeks.com/showthread.php?t=35407)
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You mean you have Active Desktop enabled and you have it set to Show Web Content?
     
  11. mschultz116

    mschultz116 Private E-2

    I mean...like to open a desktop shortcut or a folder I only click once...like a link on a website.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay just tell me something. If you run HijackThis right now, does it still give the same log. Or are there other R0 & R1 lines now.
     
  13. mschultz116

    mschultz116 Private E-2

    yeah, same log...just ran it

    I started a new thread with the attatched log you asked for if you'd want to resume over there. And I can't tell you how much I appreciate you helping me out...seriously, thanks.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Wrong approach! Do not start a new thread! Stay in the same thread until your problem is resolved. If you have different problem then start a new thread.
     
  15. mschultz116

    mschultz116 Private E-2

    Here's the post...sorry, in my naiveity I thought I had to start a new thread to attatch...

    I tried running about:Buster as told and from the log it looks as if it removed all the same stuff twice, but I don't really know how it works, that's your guys' department. Let's see...I didn't mention that along with the start page being reset it also repeatedly adds 4 shortcuts in my favorites menu. Didn't think it a big deal, but I guess it doesn't hurt to include.

    As far as the log file, I just combined the two logs into one text file, hoping it's easier for you guys. The about:Buster log is pasted toward the end of the file after the HijackThis log.

    I'm getting pretty lost with all this, seems like a million things to try to keep track of. Though I'm looking forward to when I get to use all these programs you've told me to download.

    If all else fails I'm just going to reformat the stupid thing, probably should just put WinXP on this thing anyway. But again, I appreciate any advice you can offer.
     

    Attached Files:

    Last edited by a moderator: Jul 27, 2004
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have multiple issues in here we have to take care of. They may be fighting each other. Let's try to work one at a time:

    Bring up Task Manager using CTRL-ALT-DEL and select Processes. Find the winlgn.exe process (be careful!!!! I said winlgn.exe NOT winlogon.exe), when you find it, select it then click End process.
    The have HijackThis fix the lines below:
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://youriskalka.com/sp.htm
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://youriskalka.com/sp.htm
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://youriskalka.com/index.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://youriskalka.com/index.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://youriskalka.com/sp.htm
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://youriskalka.com/index.htm
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://youriskalka.com/sp.htm
    O4 - Global Startup: winlgn.exe

    Now reboot in safe mode: http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406?OpenDocument&src=sec_doc_nam
    and delete the below file:
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\winlgn.exe
    While in safe mode we may as well run About:Buster. Save its log.
    Now reboot in normal mode and post you About:Buster log and a new HijackThis log (as an attachment).
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I just noticed you have HijackThis running from your Desktop. You need to get it into its own directory where it can save backup files. Do not put it on the desktop or in a temp directory that is prone to cleanups (this could erase its backup files). You could make a c:\spyware-tools directory and put items like HijackThis, CWShredder, etc in it. None of these require installation. They just run.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yo! Shultzie! Wake up! Where did you go!
     
  20. mschultz116

    mschultz116 Private E-2

    Hey hey, go easy on me...having a few difficulties here... Alright, here's where I'm at. When I went into safe mode I didn't find winlgn.exe, so I searched for it and found some backup files related to it. Said they had been created in the last like 10 minutes, so I deleted them. Otherwise as far as I know no such winlgn.exe exists. Also just checked task manager and it's not running. I ran About:Buster...log attatched. Looks like it went better this time, didn't have to remove same stuff with second scan.

    I also noticed this, the other day there was a folder named FOUND.000 in Documents and Settings...so I deleted it. Well, I just deleted it again, don't know where it came from, whatever. Just dled and unzipped that program, too long to type it, ready to go.

    Oh, one of my restarts had some crazy problems. Nothing was coming up so I checked task manager and apiad.exe and another one (obviously should've written it down, my bad), can't remember the name, newcf.exe or something, bunch of those kept popping up in processes and disappearing. I ended up just shutting it off and turning it back on, started fine. That's all I can think of right now. Let me know what's up next.

    Sidenote...I was going to ask how you knew my name was Schultz...then I looked at my login name...yeah, I'm a genius sometimes... :rolleyes:
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I was just trying to wake you up. ;) I thought maybe you fell asleep at the wheel (well the keyboard that is).

    If you run Process Explorer, do you see any of these:
    winlgn.exe
    apiad.exe
    apikh32.exe
    msw3prt.exe
    WEATHER.EXE
     
  22. mschultz116

    mschultz116 Private E-2

    OH! I forgot to mention that my homepage has now been set to Google...as oppossed to youris...blah blah .com or whatever.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's normal after running About:Blank and when it sucessfully completes.
    Check my request below.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also, check Add/Remove programs for anything that looks like WeatherCast and let me know if you find it. We have to get rid of WeatherCast.
     
  25. mschultz116

    mschultz116 Private E-2

    ok...of those I see...

    apiad.exe
    WEATHER.EXE
    msw3prt.exe

    I also saw netyt.exe as a sub section of iexplore.exe...that might've been one of the crazy things popping up in the task manager that I mentioned...not sure though
     
  26. mschultz116

    mschultz116 Private E-2

    No WeatherCast...I do have WeatherBug though...the WEATHER.EXE in the process explorer program had the weatherbug symbol next to it...so I assume it was from weather bug...I have it open...closed now...opens at window startup. Oh, and it's 65 degrees here if you care to know. :)
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay run windows explorer and navigate to these files (one at a time). Right click on them and select Properties and then version. I want to see if there is any version info and who the company could be if any. Also tell me the file sizes and Modification dates.

    C:\WINNT\system32\apikh32.exe
    C:\WINNT\System32\msw3prt.exe
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Both WeatherBug and WeatherCast are not programs that you want to use. Both are Ad-aware (WeatherCast is even considered a Trojan: see this http://www.inet-mates.com/articles/3_rm_weathercast.html). Uninstall WeatherBug.

    Where is "here"?
     
  29. mschultz116

    mschultz116 Private E-2

    Ok, weatherbug uninstalled per your request. "Here" would be southeast wisconsin...

    Anyhoo...
    msw3prt.exe
    Lists no version nor a modification date. Only the last accessed date, being right now. The file size is 51.3 kb.

    I see no apikh32.exe file, nor a apiad.exe file for that matter.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  31. mschultz116

    mschultz116 Private E-2

    ah yes, there's the s.o.b.

    apiad.exe
    size 9.91kb
    modified July 26th at 12:45am

    here's the other one so you don't need to scroll down
    msw3prt.exe
    Lists no version nor a modification date. Only the last accessed date, being right now. The file size is 51.3 kb.
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But no apikh32.exe ?

    Any version info on apiad.exe ?
     
  33. mschultz116

    mschultz116 Private E-2

    no version info and no apikh32.exe, but that wasn't one of the ones shown running by processor explorer
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All three were shown running in your HijackThis log. So use process explorer to kill these (if found):
    apiad.exe
    apikh32.exe
    msw3prt.exe

    The use windows explore to delete (if found! Tell me which ones you find too. And if you have any problems deleting them, I need to know before you continue.)
    C:\WINNT\system32\apiad.exe
    C:\WINNT\system32\apikh32.exe
    C:\WINNT\System32\msw3prt.exe

    Reboot to safe mode and run HSremove save log, run About:Buster twice and save each log. Reboot normal mode post those three logs along with a new HJT log. Put them all in one attachment.)
     
  35. mschultz116

    mschultz116 Private E-2

    kill the process or the process tree

    oh, and the netyt.exe is no longer running as a sub process of iexplore
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Kill the process. But tell me....do you see things running under those processes? If so, what?
     
  37. mschultz116

    mschultz116 Private E-2

    nevermind that one...no problems deleting...doing the safe mode thing, back in a bit barring no problems...

    the netyt.exe is running alone though
     
  38. mschultz116

    mschultz116 Private E-2

    nothing was running under those processes as far as i saw
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you kill those processes make sure to have all Internet Explorer sessions and any other applications closed. Then run Win Explorer to delete the files. Then quickly reboot in safe mode to continue the steps.
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay go for it! Execute the rest of the steps! It's getting late! And I'm what an hour later then you (or is it two hours - 1:56 am here).
     
  41. mschultz116

    mschultz116 Private E-2

    1 hour later...1 am here...quick question, when you said run about:buster twice...it runs the scan twice, so do you mean 4 scans or just the 2
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Physically run it twice! So yes, you will see 4 scans. These problems are persistent and sometimes restart themselves very quickly. So we are just trying to stop them.
     
  43. mschultz116

    mschultz116 Private E-2

    oh, and the netyt.exe was running as it's own process I meant, not that it wasn't running at all anymore...back in...a bit
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to kill and delete netyt.exe too..
     
  45. mschultz116

    mschultz116 Private E-2

    I don't know how you guys feel about swearing...but I am well aware it is unnescessary to type out my words...so here...beeeeeeeeeeeeeeeeeeeppppppppppppppppppp...

    <sigh>..that's better. Ok, Ran it, everything seemed to go fine. Then i restarted and it went crazy again. Only this time I wrote down the crazy process that was going on. sdkz32.exe, like 6 instances of it running. So I shut down and restarted. However, I did not see the last message to kill netyt.exe and delete it before I did all that...so should I do those and do all this again.

    logs attatched.
     

    Attached Files:

  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well now you have other processes running. One as you mentioned is sdkz32.exe. There is also d3nv32.exe. And I still see this in your HJT log, msw3prt.exe. Were you able to find msw3prt.exe and delete it?
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The only one I see in the current log running is: C:\WINNT\system32\sdkzk32.exe
     
  48. mschultz116

    mschultz116 Private E-2

    yeah, i deleted msw3 one
     
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then right now have HijackThis fix this line:
    O4 - HKCU\..\Run: [msw3prt] C:\WINNT\System32\msw3prt.exe

    Do another quick scan and make sure it goes away.

    The run Process Explorer and click File, Save As, and save the process list. Post it back here so I can see what is running.
     
  50. mschultz116

    mschultz116 Private E-2

    Alright, here's the list.

    And just so you now, I'm battling these little flies buzzing around me and it's not helping the situation... :mad:

    haha, that's a great face
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds