Questions about Generic Solution To HSA (Only the Best)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by melomano, Sep 16, 2004.

  1. melomano

    melomano Private E-2

    Hi,

    I've some questions related with the document called "Generic Solution to HSA (Only the Best) & About: Blank hijack"


    I think steps 11) and 13g) are very similar, why don't delete everything in step 11 and skip step 13g)?

    11) This step is for WinXP only. Now also look in c:\windows\Prefetch for all of the above files deleted in steps 7 to 10. If found, delete them too. After deleting all of the items from the steps above, empty your Recycle bin

    13g) For WinXP, delete everything in the Prefetch folder in C:\WINDOWS\Prefetch



    Should we always scan twice with the About: Buster program? I mean, Is it safer?


    At the last part of the document, you say that we should send to you the new logs of Hijack This & About: Buster. Is it useful to keep the old log from the about:Buster?


    13k) Run about:Buster (copy the output to a file)
    16) Now reboot normal mode. And run about:Buster one more time saving the output again.

    18) Reconnect your internet connection, run your browser, and connect here to MG's and post the new HijackThis and about:Buster logs as attachments FOLLOWING THE RULES OF THE FORUM. Then continue running and let's see how everything is working.



    Thank you guys for creating a very useful document and (disclaimer) sorry if my questions are so stupid, I'm here trying to learn something.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No, your questions are not stupid.

    The reason for multiple cleanups is to get rid of anything sitting in the Prefetch folder (and for that matter the Recycle bin) at various points to prevent the hijackers from spawning more processes from things we thought we deleted. If anything, I should add clearing the Recycle bin again at step 13g. Repetition is the name of the game in defeating these hijackers.

    Yes, you need to scan twice with About:Buster. One is perform in safe mode and one is performed in normal boot mode right after rebooting to catch anything that the hijacker may have restarted at boot. Save both logs of About:Buster to different file names so you can post them later. Avoid overwriting the 1st with the 2nd.

    Once you post the logs here (as attachments) you do not need to keep them. They will be here until the time frame of forum and message cleanups.
     
  3. melomano

    melomano Private E-2


    Sorry, didn't explain myself too clear. I was trying to ask "Should we scan twice as the program about.Buster ? You know, about: Buster ask you if you want to do a second or third scan just to check everything is cleaned.

    Thanx so far!
     
    Last edited: Sep 16, 2004
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm still not sure I follow you. About:Buster runs twice automatically when you run it.
    Do you mean after if finishes, run it again? If the 2nd phase of the scan finds nothing, you don't need to rescan until the point where I have you restart in normal mode and then we scan again for saftey.
     
  5. melomano

    melomano Private E-2

    As for the version 3.0 it doesn't runs twice automatically. The program ask you if you want to do a second scan. It's weird because it starts all over again -like trying to verify if everything is oK.

    So I guess I should do a second scan everytime I run about:Buster.

    Chaslang, sorry if I'm not making good & clear questions, english is not my first language.
    VIVA MEXICO (Today i'ts Independence Day! -but no for my PC)
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds