HSA vs Jason vs Michael Myers

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by melomano, Sep 15, 2004.

  1. melomano

    melomano Private E-2

    HSA vs Jason vs Michael Myers

    Hi there!


    Well, last two days I've methodically followed, read, done, dowloaded,
    updated, etc. everything said on these three tutorials...

    1. READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
    2. When all else fails - Generic Solution to HSA
    (BTW, I've feedback & some suggestions related to this document).
    2. Hijack This Tutorial And How To Post Your Log File

    ...And cannot completly remove the freakin' HSA (aka About:Blank, Windows
    Help Center, etc.)!.


    I think HSA is kind of a movie monster-bad-serial-killer (like Michael
    Myers). You cannot never be sure if you kill the mothertrucker!


    Please guys help me out and together we can get rid off this f.cking
    character flix!

    PS I'm ready to send you the new logs from About:Buster & Hijack This;
    and other interesting feedback.


    Melomano
    WinXP
     
  2. melomano

    melomano Private E-2

    Sorry guys, forgot to tell you that -after all the scanning and cleaning
    things- NOW I have the following symptoms:

    1. I've put majorgeeks.com as the IE startpage, but now isn't.
    Instead a www.google.com address appears...
    2. If a run Hijack_This everytinhg looks normal there's nothing wrong in
    the R1 or R2 lines. BUT in the O2 there's this little archive *.dll.
    2. Anyway, IE doesn't responde. Actualy there's no activity in
    the status bar. I cannot even go through to the Internet Options.
    3. Cuz IE is dead, I started to used Mozilla Firefox but is funky
    time here. When you try to open www.google.com the browser
    sends you to a windows update page with the Google logo (?). If
    you then click stop, and put another page like www.hotmail.com, the
    browser sends you to google.com (!).

    So if you put www.mail.com the browsers responds with
    hotmail.com or with a Error Page (not the 404) or a page with a URL
    ending with .../en/default.asp. So f.cking strange because if I close
    Firefox and open it again, things go normal but in seconds
    weird pages open up like a Windows Update page with a left
    pane with the world google (hahahah! funny as hell!!!!!)

    - So if a do a Hijack_This scan, I can see that HSA is back
    in the R1 and R0 lines (AAAAARGGGGH!!!)

    I think this a case for the experts.
    Calling Major Attitude or Chaslang: Need help!
     
  3. melomano

    melomano Private E-2

    Today I should add other symptom and a placebo effect:
    4. All my icons disappear from the toolbar.
    5. I installed Opera and browsing the Web without problems so far. If I encounter problems I'll repost.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please post a HijackThis log as a .txt file attachment.

    And note you said:

    "1. I've put majorgeeks.com as the IE startpage, but now isn't.
    Instead a www.google.com address appears... "

    This is due to About:Buster. It changes you to google.com.
     
  5. melomano

    melomano Private E-2

    Thanks Chaslang, This is the new (after doing everyting by the book) Hijack This post.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis and put checks on the following items BUT DO NOT CLICK FIX until you exit all browers sessions including the one you are reading in right now (this include IE, Mozilla, Firefox etc):
    O2 - BHO: (no name) - {E363C209-E213-B037-FBC0-927E7138A3AF} - C:\WINDOWS\system32\crpf32.dll
    O16 - DPF: Win32 Classes -
    O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} -
    O21 - SSODL: System - {805F800B-D927-47A5-9123-287A6B469C55} - C:\WINDOWS\system32\system32.dll (file missing)

    After fixing, make sure you still have viewing of hidden files enable per the tutorial.
    Also, system restore should still be disabled.

    Reboot in safe mode and delete the below:
    C:\WINDOWS\system32\crpf32.dll

    Reboot normal and tell me how things are looking.
    By the way you need to get to Windows Update. You're way out of date.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Another line that I wonder about is this:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.1:1111

    I don't believe you need this but I don't know for sure. Are you using a proxy server?
     
  8. melomano

    melomano Private E-2

    Thanx Chasland

    First, I run the Hijack This and this window pop up appeared saying this:

    An unexpected error has occurred at procedure: modBackup_MakeBackup(sItem=O21 - SSODL: System - {805F800B-D927-47A5-9123-287A6B469C55} - C:\WINDOWS\system32\system32.dll (file missing))
    Error #62 - Input past end of file

    Please email me at merijn@spywareinfo.com, reporting the following:
    * What you were doing when the error occurred
    * How you can reproduce the error
    * A complete HijackThis scan log, if possible

    Windows version: Windows NT 5.01.2600
    MSIE version: 6.0.2600.0000
    HijackThis version: 1.98.2

    This message has been copied to your clipboard.


    Secondly, I reboot in Safe Mode and look after the .dll file. Couldn't found it and that's was probably because I'd previously deleted it yesterday with about:Buster (yes, the Hijack This log you read it was from yesterday and it wasn't updated) .

    Third, I run Mozilla Fire Fox and isn't working properly (when I do a google search I get the results but can't open any: I'm still getting a "Server Database Error" page).

    Finally, I'm posting this message in IE !!! It's working good so far! aleluya! Thanks Chaslang for the help, you're so damn good !!!

    PS.
    Chaslang,
    I'm going to update my Windows version, doing all over again the process of cleaning and scanning , reboot few more times, navigate, etc. If a encounter something bad or good I'll post more feedback.
     
  9. melomano

    melomano Private E-2


    Sorry, forgot to tell you. Yes, I'm using a proxy server and that line for me looks normal.

    Cheers
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Post me a new HJT this log. I want to see where we are at.

    You said,

    "Secondly, I reboot in Safe Mode and look after the .dll file. Couldn't found it and that's was probably because I'd previously deleted it yesterday with about:Buster (yes, the Hijack This log you read it was from yesterday and it wasn't updated) . "

    If it has been deleted, HJT would have said (missing). It is still probably there.
    How did you look for it? What did you use to try to find it.
     
  11. melomano

    melomano Private E-2

    I look for it (the .dll file) with the search for File or Folders (+ subfolders, hidden files, etc.) option from the Windows Start . And also look after the xxx.exe and xxx.dat, but none found. I don't know but maybe yesterday when I did some hijjack fixs and about:Buster scans, the file could be eliminated. I don't remember well but I think I also run & clean with AdAware SE.

    Here's my most recent Hijack This log:


    (CANNOT UPLOAD hijackthis.txt NEITHER IE OR OPERA, WHY?)
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have uploaded a file called hijackthis.txt before, the system will not let you upload it again. Try calling it something different, like hjtlog.txt
     
  13. melomano

    melomano Private E-2

    Here's it:
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! You look clean now.

    For your problem with FireFix, you may want to bring that up in the Software Forum. All I could suggest right now is to uninstall it. Reboot. And then reinstall. But I not sure that is why you get that error when going to google search. Can you do the same search using IE?
     
  15. melomano

    melomano Private E-2

    Thank you so much Chaslang for helping me. Last four days I've been normaly
    navigating the Internet with Opera & IE, and I gotta tell you:
    I finally killed the "HSA", aka "About:Blank"!. Of course, with so
    much of your help.

    And about my case, forgot to tell you that I didn't deleted these
    services because didn't found them:

    "Network Security Service"
    "Workstation Netlogon Service"

    Instead, I deleted this service named: "Remote Procedure Call (RPC) Helper"

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Remote Procedure Call (RPC) Helper
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_Remote Procedure Call (RPC) Helper


    I found that service suspicious. Check for yourself at http://www.d-a-l.com/help/archive/index.php/t-1637.html

    PS. I uninstalled and installed Firefox but that didn't work. Guess I don't need it anymore (ahem, I hope so).


    ¡MUCHAS GRACIAS COMPA!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks for the feedback.

    Yes, the "Remote Procedure Call (RPC) Helper" service is another place this hijacker has been found to hide. I need to update my procedure again to include this one. Everyone must be careful not to confuse this with "Remote Procedure Call (RPC)" or "Remote Procedure Call (RPC) Locator" which are valid services.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds