Help with OTB Pop Ups and HSA Please!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Sandi04, Jul 31, 2004.

  1. Sandi04

    Sandi04 Private E-2

    Hi..

    I am new here but have been reading for about a week trying to figure out how to get rid of this annoying Home Search Assistent and the Only the Best Pop-Ups, it's been on my computer for a little over a month. I have followed all the instructions posted by Major Attitude..

    Getting prepared...
    1. Windows Update
    2. Disable System Restore
    3. Disabled the NSS
    4. Enabled viewing of hidden files and folder
    5. Booted my computer into Safe Mode

    I then did the scanning and cleaning steps....
    1. I scanned with Nortons
    2. I cleaned the hard drive (removed temp files, etc..)
    3. I scanned with Ad-Aware with the VX2 plug-in and also scanned with Spybot
    4. I did this two times.. The first time I just ran the about:buster and the HSRemove. It seemed to have gotten rid of it but as soon as I opened IE again the Pops-Ups were back and HSA showed in my control panel in add and remove programs again. So I then repeated all the steps and also ran the CWShredder and the Kill2me.

    Everything said my computer was clean, it was all gone again until I opened IE and it's back.

    I have not d/l Hijack This yet as I see it is for advanced users and the last step, so I thought I would finally just ask for some help on what I should do next.

    Please help me get this nasty thing off my computer!

    Thanks! Sandi
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    I think HSremove has new steps, requiring you run it twice, you should run Hijack This and remove the lines. If your not sure which lines, post your log file and I, or one of us, will look at it.
     
  3. Sandi04

    Sandi04 Private E-2

    Ok thanks, I just ran HS Remove again and it removed 9 items, then I ran it again and it was clean. HSA is back though.

    I'll Download Hijack This now and then close all running programs and run it. I'll attach the log file because I have no idea what I'm looking for.

    Do I run Hijack This in Safe Mode or doesn't it matter?
     
  4. Sandi04

    Sandi04 Private E-2

    I ran Hijack This. Attached is the log.

    Thanks for your help! :)
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    http://majorgeeks.com/download4289.htmlWhen you first started following the steps, did you actually find the NSS running? If so, did you write down the Path to Executable? And what was it?

    Check right now to make sure it has not enabled itself again? If it has then disable it again.

    Download about:Buster and read the directions on using it on the download page. Do not run it yet.

    Download ProcessExplorer and run it. Have it kill the following processes (if found). Tell me which ones you find running:
    ntxc32.exe
    ippa32.exe
    addpj32.exe
    apidu.exe
    winit.exe
    mscx.exe
    sdkpx32.exe
    msxp.exe
    ntis32.exe
    ipnn.exe

    Now shut down all applications (especially Internet Explorer) and disconnect your analog modem or ethernet cable (for ADSL or Cable modems) from your PC to physically remove connectivity to the internet. Do not run Internet Explorer again until told to.

    Now run about:Buster, Hit start and then Ok. The program should start scanning. Copy and Paste the results of the scan into a file. Then hit exit and reboot.
    Once rebooted run about:Buster once more to make sure everything is ok. Again copy & paste the results of the scan into a file. Run HijackThis right and if you see any lines indicating the presence of the hijacker in your log file, have HijackThis fix them. I have attached copies of the lines from your previous log that were related to the hijack.

    Reconnect your physical connection to the internet and post the results of the two about:Buster scans back here. Also post a new HijackThis log. You can combine all these logs into one text file attachment.

    If you are still having a problem with the hijacker do not shut your PC down or reboot at this point. Just wait for a response from me. You can shutoff your monitor and drop your connection to the internet but do not reboot. This hijacker mutates when you reboot and when you start Internet Explorer.

    You have some other problems we will need to clean up too (later). WeatherBug and msopt.dll (msopt.dll is from the Winshow Trojan).



    Edit: I forgot the attachment.
     

    Attached Files:

    • hsa.txt
      File size:
      1.4 KB
      Views:
      2
    Last edited: Jul 31, 2004
  6. Sandi04

    Sandi04 Private E-2

    Yes, I did find NSS running and stopped and disabled it, it didn't say to write down the Path to the Executable so I didn't, was that something I needed?

    I just checked and it's not running now.

    I have about:Buster already, but not the ProcessExplorer, so I will d/l that and follow the rest of your instructions..

    Thanks, I'll be back with the new logs in a bit.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes, it is useful to know the path to executable. When you just checked now. You said it was not running but was it still there?
     
  8. Sandi04

    Sandi04 Private E-2

    No, I didn't even see NSS there at all. Is it supposed to be there?

    I did everything you said...

    I ran ProcessExplorer and the only thing I saw was ippa32.exe, so I killed that.

    I disconnected and I then ran Buster, rebooted and ran Buster again. Then I ran HiJackThis and copied all the logs. I saw the lines you posted (they were all there except for the 04 one with the apidu.exe in it) and had them fixed, I copied the before and after logs.

    When I came on this site just now, I got an Only the Best Pop-Up, so it's still there. :(
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Before starting make sure you know how to view hidden and system files: http://forums.majorgeeks.com/showthread.php?t=37650
    Run ProcessExplorer again and kill any of the below if found (look for multiple occurrences too):
    apidu.exe
    addpj32.exe
    ntxc32.exe
    ippa32.exe
    winit.exe
    mscx.exe
    sdkpx32.exe
    msxp.exe
    ntis32.exe
    ipnn.exe


    Then disconnect from the internet (physically) and boot into safe mode.
    Now run About:Buster twice (that should result in 4 scans. Save the results.

    Now while still in safe mode fix the following lines with HijackThis if still there:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\rgczx.dll/sp.html#37049
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://rgczx.dll/index.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://rgczx.dll/index.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\rgczx.dll/sp.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\rgczx.dll/sp.html#37049
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://rgczx.dll/index.html#37049
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {58A9849D-12E0-4CBB-4B4C-84249CEA038D} - C:\WINDOWS\mskj32.dll
    O4 - HKLM\..\Run: [ntxc32.exe] C:\WINDOWS\system32\ntxc32.exe
    O4 - HKLM\..\Run: [ippa32.exe] C:\WINDOWS\system32\ippa32.exe
    O4 - HKLM\..\Run: [addpj32.exe] C:\WINDOWS\system32\addpj32.exe
    O4 - HKLM\..\RunOnce: [winit.exe] C:\WINDOWS\winit.exe
    O4 - HKLM\..\RunOnce: [mscx.exe] C:\WINDOWS\system32\mscx.exe
    O4 - HKLM\..\RunOnce: [sdkpx32.exe] C:\WINDOWS\sdkpx32.exe
    O4 - HKLM\..\RunOnce: [msxp.exe] C:\WINDOWS\msxp.exe
    O4 - HKLM\..\RunOnce: [ntis32.exe] C:\WINDOWS\system32\ntis32.exe
    O4 - HKLM\..\RunOnce: [ipnn.exe] C:\WINDOWS\system32\ipnn.exe

    Now make sure you can view hidden and system files and delete the following. Let me know which ones you find and if you have any problems deleting any of the ones you do find:

    C:\WINDOWS\system32\rgczx.dll
    C:\WINDOWS\mskj32.dll
    C:\WINDOWS\system32\ntxc32.exe
    C:\WINDOWS\system32\ippa32.exe
    C:\WINDOWS\system32\apidu.exe
    C:\WINDOWS\system32\addpj32.exe
    C:\WINDOWS\winit.exe
    C:\WINDOWS\system32\mscx.exe
    C:\WINDOWS\sdkpx32.exe
    C:\WINDOWS\msxp.exe
    C:\WINDOWS\system32\ntis32.exe
    C:\WINDOWS\system32\ipnn.exe

    Now reboot in normal mode and still while disconnect from the Internet run About:Buster one more time (save this log too).
    Check you HijackThis log again and delete any of the above items if they reappeared.

    Now connect to internet again and send me your AB logs also attach a new HJT log after connecting to the internet.
     
  10. Sandi04

    Sandi04 Private E-2

    I have checked the box that says show hidden files. Now how do I view the ones you want me to look for and delete after I do all this? I don't see where it says how to find them? I'm sure it's easy and I probably know it, but I'm drawing a blank here, sorry!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You just use Windows Explorer (not Internet Explorer) and navigate your way thru the directory structure to located them. The left pane shows you the directory tree and the right pane the files and directories within each directory. Just click on a plus sign to expand the view. Experiment a little with it before you start. I'm sure you will see it is pretty easy.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you do not know how to bring up Windows Explorer, click Start, All Programs, Accessories, and Windows Explorer.
     
  13. Sandi04

    Sandi04 Private E-2

    I'm using XP Pro and I don't see Windows Explorer? Do I go into My Computer and click on drive C and then under system tasks go to search for files and folders?
     
  14. Sandi04

    Sandi04 Private E-2

    Ahh! Ok - gotcha, thanks!

    OK - I hope this works.. I'll be back to post the logs in a bit.
     
  15. Sandi04

    Sandi04 Private E-2

    OK..

    I ran ProcessExplorer, both apidu.exe and addpj32.exe were there so I killed them. (Do I kill process or kill process tree?)

    Safe mode, ran Buster twice (4).

    Ran HijackThis, fixed the addpj32.exe, sdkpx32.exe, and the apidu.exe

    The only hidden file I saw was the C:\WINDOWS\system32\ntxc32.exe and I could not delete it.

    Rebooted in normal mode, ran Buster and then HijackThis again, saw the ntxc32.exe and fixed it.

    Reconnected to the internet and ran HijackThis again and kept the log.

    Now I keep getting a window popup that says:
    ntxc32.exe Bad Image
    The DLL C:\WINDOWS\javaqi.dll is not a valid windows image. Please check this against your installation disk.

    What does that mean? :confused:

    Attached are the Buster logs and new Hijackthis log
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First question: why didn't you download About:Buster from the link I gave you a while back. You are not using the proper version of About:Buster. The current version is 2.0. You know we put information in our messages for a reason and we have to assume that the directions we give are followed. If they are not followed properly you waste my time and yours.

    With all the spyware scanners and virus scanners etc. that are out there, it never hurts to double check to make sure you have the current version. Some of these programs change quite freqently.
     
  17. Sandi04

    Sandi04 Private E-2

    That is where I d/l it from 2 days ago, when I went and looked at the link you posted, it had the same date on it as the day I got it so I assumed it was the one I just d/l, I'm sorry, I didn't mean to waste your time.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to get those two exe files deleted when in safe mode. You cannot just say, it will not delete and go on. That will just allow it to come back. While in safe mode you may need to run ProcessExplorer again and kill any of these unknown 5 to 8 character random processes and then try to delete the file. If it still does not delete you need to try to take ownership of the files by right clicking on it select Properties. Then click the Security tab and take ownership.
    Change the 'everyone special' to 'you > with Admin rights-> FULL control

    These two had to be killed and deleted:
    C:\WINDOWS\SYSTEM32\ntxc32.exe
    C:\WINDOWS\javasf32.exe

    And now there is a new DLL to fix and delete (I would assume your hijack has now returned)
    O2 - BHO: (no name) - {33AFF50D-3DBF-7B1A-9ED9-47706F9F1C8D} - C:\WINDOWS\system32\atlll.dll
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Version 2.0 came out 2 days ago (look at the link, the date is 7/29/04)

    Did you download the correct version now?

    You may have to click refresh in your browser to clear out old cache data.
     
  20. Sandi04

    Sandi04 Private E-2

    Yes, The new one is downloaded now.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay, did you see my message below about killing those new processes and trying to delete those files.

    Has your problem actually come back yet?
     
  22. Sandi04

    Sandi04 Private E-2

    Yes, I just saw the other reply. I'll go do that now.

    And yes the problem is still here.

    And I keep getting that other window now about the
    ntxc32.exe bad image, and then it lists a dll c:\WINDOWS\ and then different letters/numbers each time. Like sdkm32.dll, and sdklo.dll, and syslj.dll.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those are all files from the hijacker. Something is trying to run them. And that is what we are trying to kill.

    Please run ProcessExplorer and click File and then Save As. And save the process list. Post it back here as an attachment along with a current HijackThis log (attachment).
     
  24. Sandi04

    Sandi04 Private E-2

    ok - here is the process list and the Hijack log from right now.
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Select these processes (one at a time) and kill them. Tell me what happens:

    javasf32.exe
    NTXC32.EXE
     
  26. Sandi04

    Sandi04 Private E-2

    OK- killed them, and am getting the Only the Best Pop up now, but so far not that other new window that was popping up.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Two things:
    1) see if you can delete those two files now:
    C:\WINDOWS\javasf32.exe
    C:\WINDOWS\SYSTEM32\ntxc32.exe
    Tell me exactly what happens when trying to delete these.
    2) check the ProcessExplorer list again and see if anything new has popped up.
     
  28. Sandi04

    Sandi04 Private E-2

    I tried to delete the ntxc32.exe and I get a message that says
    Cannot delete ntxc32: access denied.
    Make sure the disk is not full or write protected and that the file is not currently in use.

    I tried to right click on it to properties to get ownership of it but there is no security tab.

    Here is the new processexplorer log, the only difference I see is the Javesf32 isn't there, and I forgot to close explorer and outlook so those are there now too.
     

    Attached Files:

  29. Sandi04

    Sandi04 Private E-2

    Oops, I was wrong, the javasf32 is still there, it's just moved.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Shutdown all Internet Explorer and Windows Explorer sessions and save a a ProcessExplorer list.

    The open a Command Prompt window by click Start, All Programs, Accessories, Command Prompt. The type into that window,
    cd c:\windows
    then type
    delete javasf32.exe
    then type
    cd system32
    now type
    delete ntxc32.exe

    Now reopen Internet Explorer and give me that ProcessList and tell me what happens at each step from above.
     
  31. Sandi04

    Sandi04 Private E-2

    Will just closing my browser shutdown internet explorer, that's the only thing I have open right now. Or do I need to go somewhere else to shut the processes down?
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Your browser is Internet Explorer.
     
  33. Sandi04

    Sandi04 Private E-2

    I thought so, I just wanted to make sure.

    Ok - When I did the command prompt and entered all that it told me
    delete is not recognized as an internal or external command, operable program, or batch file
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ooop! I typed what the command does not what the command is.

    Use 'del' not 'delete'

    Sorry.
     
  35. Sandi04

    Sandi04 Private E-2

    Oh ok :)

    This time it said
    could not find javasf32.exe
    and
    Access is denied to the ntxc32.exe
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! the javasf32.exe file was delete previously as we wanted.

    Now at that command prompt in the c:\windows\system32 directory type this:

    attrib -r -h -s ntxc32.exe

    tell me what happens.
     
  37. Sandi04

    Sandi04 Private E-2

    Nothing happened, it just said c:\windows\system32>
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now type:
    attrib ntxc32.exe

    and tell me what you get. Then try:
    del ntxc32.exe

    and tell me what you get.
     
  39. Sandi04

    Sandi04 Private E-2

    ok, when I typed attrib ntxc32.exe it came back with
    A C:\windows\system32\ntxc32.exe

    then when I typed the del ntxc32.exe it came back with
    access is denied
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run About:Buster and show copy its output back here.
    Then run HSremove and copy the output from it back here.

    Then try to delete the file in the command prompt window again (unless the outputs from AB or HSremove show them deleting it).
     
  41. Sandi04

    Sandi04 Private E-2

    OK! Should I run them in Safe Mode?
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! Do them right now!
     
  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Next do this:

    1) First, go here and download Registrar Lite and install it: http://www.resplendence.com/reglite
    2) Run it, copy and paste this line to reglite's address bar:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
    3) Click the "go" tab
    4) Find: "AppInit_Dlls" value on the right side panel.
    5) DoubleClick on AppInit_Dlls tell me exactly what you see in the Value field.
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also try this:

    Go to Start->Run and type Regedit then click Ok. Navigate to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
    and highlight Services in the left pane. In the right pane, look for any of these entries:

    __NS_Service
    __NS_Service_2
    __NS_Service_3

    If any are listed, right-click that entry in the right pane and choose Delete.

    Again in Regedit, navigate to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root and highlight Root in the Left Pane. In the right pane, look for these entries (the number at the end should correspond to the first one you deleted above):

    LEGACY___NS_Service
    LEGACY___NS_Service_2
    LEGACY___NS_Service_3

    If you find it, right-click it in the right-pane and choose delete.

    If you have trouble deleting a key. Then click once on the key name (LEGACY__NS_SERVICE_ or some other name that starts with LEGACY__NS_SERVICE) to highlight it and click on the Permission menu option under Security or Edit. Then Uncheck "Allow inheritible permissions" and press copy. Then click on everyone and put a checkmark in "full control". Then press apply and ok and attempt to delete the key again.

    Tell me if any of those were found and if so did you get them delete okay?
     
  45. Sandi04

    Sandi04 Private E-2

    I ran Buster and here is the log. The HSRemove said there were no files removed. I tried to delete again in Command Prompt but it still said access is denied.

    I see you posted some other things to do, I'll go do them now, thanks!
     

    Attached Files:

  46. Sandi04

    Sandi04 Private E-2

    I don't see "AppInit_Dlls" listed there?
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! As you can see AB keeps finding more problems each time we run it.

    Do as I asked in my other two messages.
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you mean you cannot even find AppInit_DLLs or do you mean the value was blank?
     
  49. Sandi04

    Sandi04 Private E-2

    I Didn't find any _NS_Service or any LEGACY_NS_Service at all.
     
  50. Sandi04

    Sandi04 Private E-2

    I couldn't even find anything that said AppInit_DLLs.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds