Help with HSA

Discussion in 'Malware Help (A Specialist Will Reply)' started by mschultz116, Jul 26, 2004.

  1. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Print these or save them locally to a notepad file. We are adding one more step this time. And here it is:
    Disconnect physically from the internet (unplug your cable)
    Now these two processes need to be killed with process explorer (watch the window and make sure no other processes like these pop up).
    sdkzk32.exe
    ipqh32.exe

    Then have HijackThis fix these two lines:
    O4 - HKLM\..\RunOnce: [sdkzk32.exe] C:\WINNT\system32\sdkzk32.exe
    O4 - HKLM\..\RunOnce: [d3nv32.exe] C:\WINNT\d3nv32.exe

    Then look for these files and delete them (if you see the same filenames but with a .dat or .dll extension delete them too).
    C:\WINNT\system32\sdkzk32.exe
    C:\WINNT\d3nv32.exe
    C:\WINNT\ipqh32.exe or C:\WINNT\system32\ipqh32.exe

    Then reboot to safe and do the stuff with HSremove and AboutBuster. You know the drill. And report back.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. mschultz116

    mschultz116 Private E-2

    oh boy, here goes, back in a lil bit...
     
  4. mschultz116

    mschultz116 Private E-2

    oh yeah, before i go...there is a netyw.exe file that was created and modified yesterday...9.54kb

    in C:\WINNT...hidden

    delete?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! If you search around you will find loads of crap like this in C:\winnt,
    c:\winnt\system, and c:\winnt\system32. Lots of bad .DLL, .DAT, and .EXE but you need to be careful what you remove here. Some are system files. Sometimes you can tell by just looking at the file modification dates.
     
  6. mschultz116

    mschultz116 Private E-2

    so generally if it was modified/created in the last day or so i can delete it?

    crapload of .dat files with random letters
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Most likely especially with random letter and numbers for the filenames and if they are hidden that also makes them likely canidates (but not defintely we still need to be careful here). If you delete the wrong things, you can make your PC unbootable.

    The longer you wait to continue this process the more likely another crapware process will be kicked off spawning more crap.
     
  8. mschultz116

    mschultz116 Private E-2

    ok...i'm going to crack under this pressure, I'm terrified of the results...BUT..it looks like so far so good...here's the logs...no problems booting

    found some extra .exe files that I got rid of too, but I also saw some that looked like the would be random letters but it was like a disk check thing, so i definitely no what you mean by being careful...definitely won't be spending much time in the winnt folder
     

    Attached Files:

  9. mschultz116

    mschultz116 Private E-2

    oooohhh Chaslang!? Where are yooouuu? I think it was you who said "Wake up!" :D
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Only one item left. Have HijackThis fix this:
    O2 - BHO: (no name) - {D223E4C5-1B9A-1963-16C9-6F7292E5F3EA} - C:\WINNT\netcf.dll

    Hopefully it has not already spawned from this.

    See if you can located that DLL and also look for netcf.exe and remove them.

    Let me know the results. Try a few reboots. Gotta sleep now! Good luck.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Working on other peoples threads! But now I'm leaving! BYE!
     
  12. mschultz116

    mschultz116 Private E-2

    Thank you sooooooooooooooo much...you're my hero. Will let you know how the rest goes, bedtime for me too soon.
     
  13. mschultz116

    mschultz116 Private E-2

    Alright, had to clean up that last one you mentioned...went through "the drill". Came out fine. Did a couple of reboots and there have been no problems. Attatched the logs...HijackThis log has been the same with each reboot. Thank you a ton for all your help, much appreciated.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your welcome! Log looks good. The only other thing I would say to do is:

    Bring up Internet Explorer, select Tools, Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    We may have done some of this already but I did not see a start page in your HJT log so I wanted to be sure.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds