1. Quinndrew5

    Quinndrew5 Corporal

    I am definetly one of the unluckiest around these days, my other computer has come down wtih what seems to be a new version of HSA. I run fixes and then it seems to work, but about 20 minutes later it comes back. IT also corrupts AIM. Any ideas?
     
  2. Bear_Nunya

    Bear_Nunya Private E-2

    Give this a try, please click HERE
     
  3. PhilliePhan

    PhilliePhan Guest

    Hey Bear - For future reference, please note that Chaslang has addressed HSA in his own Generic Solution. He likes to keep these "In House" to avoid confusion. If Quinndrew wants to take his problem to S-M, that's his choice.

    When all else fails - Generic Solution to HSA (Only the Best) & About:Blank hijack

    Thanks :)
    PP

    Hey QuinnDrew,

    Did you try the tools in the Cleanup Tutorial? About:Buster/HSRemove?

    Why don't you go ahead and attach a log for Chas to take a peek at to see where you stand.
     
  4. Bear_Nunya

    Bear_Nunya Private E-2

    Sorry PhilliePhan, I was just trying to help :eek:
     
  5. PhilliePhan

    PhilliePhan Guest

    That's Cool :) Not too big a deal! - Just wanted to let you know Chas had a workthrough. Any good help and advice is welcome here!

    PP :)
     
  6. Bear_Nunya

    Bear_Nunya Private E-2

  7. Quinndrew5

    Quinndrew5 Corporal

    I would like to say i am not trying to affend anyone but,

    First, i have tried the SM version of the fix and found it works just as well as chaslangs and is much faster to use.
    Second, i know what im doing (thanks to this site) and i dont mean to step on anyones ground but im pretty sure what i have is not the traditional HSA, it hides the r1's and you cannot find them when you are asked
    Third, i tried chaslangs today to try to fix my problem and i couldnt do have of the things because the files were being hidden

    Hope anyone can help, im sure you dont have much to go on so ill post my log.

    it just looks like any other HSA infected log but it when you try to fix it that you see the problem
     
  8. Quinndrew5

    Quinndrew5 Corporal

    Sry, here it is
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I thought you said the SM version works! So why are you still infected?

    I'm not offended by any of the comments about the SM version working and being faster. Mine is longer for a reason. There were many different variations of the HSA & about:blank hijackers and I was trying to cover all of them and for ALL OS types.

    If you want to fix this problem, you have to remember (this has been mentioned many many times) that NO browsers should be running when using HijackThis. You had IE running:
    C:\Program Files\Internet Explorer\iexplore.exe

    And you have HijackThis installed where we specifically request that it not be installed.
    C:\Documents and Settings\Andrew\Desktop\Virus Stuff\HijackThis.exe
     
    Last edited: Jan 11, 2005
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Use the Generic Procedure here are your problem files (one of which - DeskAd Service - is not HSA related).

    Here are the processes:
    C:\WINDOWS\sdkqx.exe
    C:\WINDOWS\system32\sdksz.exe <--- this is the Network Security Service

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\wupvq.dll/sp.html#10001
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\wupvq.dll/sp.html#10001
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\wupvq.dll/sp.html#10001
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\wupvq.dll/sp.html#10001
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\wupvq.dll/sp.html#10001
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\wupvq.dll/sp.html#10001
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\wupvq.dll/sp.html#10001
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {B043489C-6BF0-01EB-E5BD-CE306F545707} - C:\WINDOWS\system32\iehe.dll
    O2 - BHO: (no name) - {EF1C5F19-D800-F30A-ADD5-7E618D29C88F} - C:\WINDOWS\d3gk32.dll
    O4 - HKLM\..\Run: [DeskAd Service] C:\Program Files\DeskAd Service\DeskAdServ.exe
    O4 - HKLM\..\Run: [sdkqx.exe] C:\WINDOWS\sdkqx.exe
    O23 - Service: Network Security Service - Unknown - C:\WINDOWS\system32\sdksz.exe
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you want to try a brute force procedure that sometimes works and is fast. Make sure you have both HSremove and About:Buster and that About:Buster is version 4 and the database has been updated. Try this:
    - You MUST be physically disconnected (unplug cables) from the internet
    - You MUST exit ALL applications especially browsers like IE
    - stop and then disable the Network Sercurity Service per the Read ME or Generic Solution step
    - Kill these two processes (if still running)
    C:\WINDOWS\sdkqx.exe
    C:\WINDOWS\system32\sdksz.exe
    - Run HijackThis and have if fix
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\wupvq.dll/sp.html#10001
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\wupvq.dll/sp.html#10001
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\wupvq.dll/sp.html#10001
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\wupvq.dll/sp.html#10001
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\wupvq.dll/sp.html#10001
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\wupvq.dll/sp.html#10001
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\wupvq.dll/sp.html#10001
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {B043489C-6BF0-01EB-E5BD-CE306F545707} - C:\WINDOWS\system32\iehe.dll
    O2 - BHO: (no name) - {EF1C5F19-D800-F30A-ADD5-7E618D29C88F} - C:\WINDOWS\d3gk32.dll
    O4 - HKLM\..\Run: [DeskAd Service] C:\Program Files\DeskAd Service\DeskAdServ.exe
    O4 - HKLM\..\Run: [sdkqx.exe] C:\WINDOWS\sdkqx.exe
    O23 - Service: Network Security Service - Unknown - C:\WINDOWS\system32\sdksz.exe

    - Pull the power plug (or shut off the power if on a power strip) to your computer. The key here is that you do not want a graceful shutdown of Windows where the malware can respawn itself.
    - Wait a minute and reboot with no internet connection yet and no browsers open
    - run HSremove and then About:Buster after About:Buster completes, immediately reboot
    - no reconnect your internet connection and open and then close a single IE browser session.
    - get a HJT log. If clean, we are doing good (and we are lucky). If not clean, start the Generic Procedure .
     
  12. Quinndrew5

    Quinndrew5 Corporal

    Ok, will do, the only thing is, both your version and the SM fix ask at one point or another to do what seem to be double-checks to make sure the files are gone. The problem seems to be that no matter how i aproach that, the files to do not exist in my C drive when I go to look. They are not where they are supposed to be at all and upon a search they are not there either. Im going to go ahead with the listed procedures.... but i dont i will not be able to completethe generic fix correcly.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The best thing to do in cases like that is to continue. In some cases the files do not exist (they may have renamed themselves). In other cases they do exist but something blocks you from seeing them. That is one reason we want to make sure you have the following set (always double check - malware can change it on you). So check all of these again right now:
    Click Start and then Explore
    Select the Tools menu and click Folder Options.
    Select the View Tab.
    Under the Hidden files and folders heading select Show hidden files and folders.
    Uncheck the Hide extensions for known file types option.
    Uncheck the Hide protected operating system files (recommended) option.
    Click Apply.
    Click OK.

    The above options are for using Windows Explorer. If you are going to use Windows XP's search capability, you must also configure it to properly search for all files as follows:

    Click Search and the Select "All files and folders"
    Enter the filename in the "All or part of the file name:" box, so enter res.dll
    Now select "More advanced options"
    Make sure the following check boxes are checked:
    - Search system folders
    - Search hidden files and folders
    - Search subfolders
    Then click the Search button.

    There are many cases of files that cannot be seen with Windows Explorer but they do exist. They are sometimes referred to as "Super Hidden". A good example is the c:\Windows\Downloaded Program Files folder. If you look at it with Win Explorer, is will only show a few items, but there can be many more files there. Malware sometimes hides itself there too. You can see the files in Downloaded Program Files by going to the command prompt or use a program like ExplorerXP
     
    Last edited: Jan 12, 2005
  14. Quinndrew5

    Quinndrew5 Corporal

    Ok, not gonna jink myself, but at this point things are working. I forgot to save alog with about buster while in safe mode (i remember it said it removed 2 keys) sry about that, but i have posted the hijack this log and the second buster log from regular mode.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is this after opening and closing your IE? How does it look now after coming here?

    Note: You still have HJT installed where we ask not to put it.
    C:\Documents and Settings\Andrew\Desktop\Virus Stuff\HijackThis.exe

    Also you must exit all browsers and have HJT fix the below line.
    O2 - BHO: (no name) - {24C88EC4-0FC2-9C0F-A5FD-F3DA397E615C} - C:\WINDOWS\mfcdj32.dll (file missing)

    FInal note: You need to update About:Buster as I requested in that procedure. You are only using Reference list 19.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Oh by the way, go look for some of those files now and tell what you find.
     
  17. Quinndrew5

    Quinndrew5 Corporal

    OK, yes that was after a little surfing and then i just fixed that 02 line figuring that would be next. Things still seem to be fine. Also, i totally forgot about the location of hijack this, I have it right on my other computer. About About Buster, i downloaded the new version from the spyware tools section at majorgeeks.com, so i dont no what i did wrong.
     
  18. Quinndrew5

    Quinndrew5 Corporal

    I think the key to my success was the hints on how to set the search settings and then XPexplorer, that really helped thanks!
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you downloaded version 4 but you did not update. You need to click the Update button everytime you go to use it. Many programs work like this now. For example Ad-Aware SE still says 1.05 but the reference file is always changing. You should ALWAYS check for updates with ALL programs like this before running. With programs that don't use these database references you have to periodically check to make sure you have the correct version. That is why we ask in the READ ME that you click on the links to veryify against what you have. Things can change quickly.
     
  20. Quinndrew5

    Quinndrew5 Corporal

    OK, ill keep that in mind.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you check for an update with About:Buster? Do it now. You don't need to scan just do the update. What do you get?

    Have you checked around for more of those files? Which ones had you found using the methods I told you?
     
  22. Quinndrew5

    Quinndrew5 Corporal

    I cant do the update quite this second, but using the search settings and XPexplorer i was able to find and delete the R0, R1, 02 and 04 files with ease.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Get the update for AB later.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds