Same problem: HSA tried it all

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by tea_ny, Aug 5, 2004.

  1. tea_ny

    tea_ny Private E-2

    Hi,
    i have the same problem like everybody else here, so i read through all the posts, learned all about HijackThis and have just completed full_When all else fails - try Generic Solution to HSA (Only the Best) hijack_ procedure. one problem: i couldn't find my xxxxx.dll files anywhere in the path displayed (windows or system32). anyway, after first reboot everything looked fine, and then Home Search came back.and all R1 and R0 are back (no 04s tho)too. HSA and SW are still in my add/remove programs, and can't remove them.

    what should i try next?
    tnx
    t_
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like you did not follow the steps correctly.
    Were you able to identify the R0 & R1 lines and the associated DLL file?
    Were you able to locate your O2 BHO DLL?
    Were you able to identify the running EXE files (the O4 lines and also the ones in the running process list)? I don't think so! You just said no O4's above. There is always at least one O4 line and usually more.
    Did you have any problems whatsoever along the way running any steps as requested? Any error messages?
    What OS do you have?
     
  3. tea_ny

    tea_ny Private E-2

    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Before I found tutorial, I already run HT for the first time.I had several R1 & R0s, and even more 04 when i ran HT for the first time.I identified them and fix them with HT. Couldn't find any of them in their path. I also indetified 02 BHO, but couldn't find it.Then I started agian with tutorial, second HT had one bad 02 HBO again, several R1 & RO which i deleted in notepad, via 'run notepad' but couldn't find it to turn it into read only. All 04 were "good ones" except for one C:\WINDOWS\system32\winxg.exe that keeps coming back and again can't find it.
    Question: step 13 b, c, d, says search registry, and then 13 e, f, search computer: how do i search registry?
    ok, i did't run ccCleaner and about:Buster at the end, only Adaware full scan and HT again before connecting back.
    I am going to redo the whole thing one more time. Can i send you logs?
    tnx
    tea
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure you did the following:

    2) Make sure you have enabled viewing of Hidden Files and Folders with
    Windows Explorer
    . While doing this, also verify that you do NOT have a check on the option to Hide extensions for known file types.

    The registry is search using regedit which is part of Windows. You can use other 3rd party tools to do this to. You can bring up regedit by click Start, Run, and then enter regedit in the dialog box and click OK.

    You are not supposed to fixing anything with HijackThis other than in steps 9 & 12. The procedure must be followed exactly as written. Before beginning the procedure you obviously need a copy of the HijackThis scan but you must not fix anything using HijackThis until told to do so. Follow the steps one by one. If you have a problem at a particular point completing a step, you should be asking for help. Also, while doing this procedure you must not be connected to the Internet and you must not run Internet Explorer at any point (unless told to). If you do connect or do run Internet Explorer, you can cause the problem to spread and or mutate causing anything your tried to fix to fail.

    I think you should attach a current unmodified HijackThis log for me to look at.
     
  5. tea_ny

    tea_ny Private E-2

    Hi,
    before i start again, jsut want to thank you very much for your help, this is really driving me crazy. so i ran the whole tutorial once again with all pre-steps done.
    so steps 1,2,3,4 all ok.
    step 5 first problem: deleted and saved blank *.dll in notepad, but can't find it and change it into read only.
    step 6: Network Security Service is not running
    step 7: found 1 BHO (yellow in log attachment)
    step 8: found 1 04 (yellow in log attachment)
    step 9: ran HT (log saved), fixed 7&8
    step 10: now in safe mode, can't find and delete dll and exe from 7&8
    step 11: found exe from step 8 in Windows/Prefech and deleted
    step 12: ran HT (log saved), fixed all R0 & R1
    step 13: A:done, BCD: didn't know how, EF:nothing found, G:done, H:not found, IJK:done, LM: nothing found
    step 14: done
    step 15:nothing found today, but yesterday when did tutorial 1st time, have removed HSA,SE and SW foledres
    step: 16: done
    step 17: done (log saved)
    step 18: first reboot everything was ok, with good home page etc, but then after second rebood, HSA is back.

    Also, i noticed that winxg.exe runs in my processes in the task bar, and every time after i end the proces it comes back.
    I have logs for step 9,12 and 17 saved if you'd need to have a look.
    I am attaching a current log which is again full of crap! I highlited in yellow the stuff that i consider my 'bad' things as i go through tutorial.
    tnx again
    tea
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Could you please follow directions and answer my questions too. See my previous message.

    Stop trying to continue thru the procedure and figure out why you cannot do the earlier steps. If steps 5 and 10 are not done correctly (in fact if 5 cannot be done) you should not be continuing.

    An for steps 13 BCD I already told you how to do that using regedit. Do you need more info than what I already gave? How did you do steps 13L and 13 M if you could not figure out 13 B,C, &D?

    But the biggest problem I see is that you are not doing what step 8 tells you to do. It states that you must find "all the executable (EXE) files". It goes on to tell you, only some are show in the O4 list, some are only shown in the Process list, and some are in the Process list and the O4 list. You are ignoring one of the main problems:

    C:\WINDOWS\netuw.exe

    You must also delete this file. You need to find these files from steps 5 & 10 and do what the steps indicate. How are you trying to locate them?
    And if you try to delete the file and it does not allow you to delete it, try ending the process using Task Manager first. For example both netuw.exe and winxg.exe most likely show in Task Manager (at least in normal boot, you will have to check in safe mode).

    There are more than likely many more similarly named files that are located in you directories. Some will be .DAT, .DLL, or .EXE . Finding the bad ones is what steps 7, 8, and the last paragraph of the up front information told you would be difficult (or at least be time consuming).


    You should try to fix this line using HijackThis before continuing with the HSA problem:
    O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - C:\WINDOWS\msopt.dll (file missing)

    IMPORTANT: YOU MUST NOT HAVE INTERNET EXPLORER RUNNING WHEN CREATING A HIJACK THIS LOG AND EVEN MORE IMPORTANT NEVER HAVE IT RUNNING WHEN FIXING LINES WITH HIJACKTHIS.
     
    Last edited: Aug 5, 2004
  7. taxximom

    taxximom Private E-2

    I also had the same problem. I deleted everything in the notepad file and saved it. When I did a search for the file, nothing was found. Although I knew it was there. I went back to folder options to make sure I had checked show hidden file and uncheck the box mentioned. Right below was a box that said "Hide Protected Operating System Files (Recommended)". I unchecked that. Then I could find the file to mark it read only. I hope this helps.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That information is already given in the Generic Solution in the links and info provided in step 2. If directions are being followed properly, there should be no problem locating these files.
     
  9. taxximom

    taxximom Private E-2

    I had the same problem as the poster. I couldn't find the file after I deleted the contents to mark it as read only. The generic instructions said this which is what I did.

    2) Make sure you have enabled viewing of Hidden Files and Folders with
    Windows Explorer. While doing this, also verify that you do NOT have a check on the option to Hide extensions for known file types.

    I enabled viewing of hidden files and folders.
    I also removed the check from Hide Extension for known file types as the instructions state.

    Underneath both of those was a third one. "Hide Protected Operatin System Files (Recommended).

    I had to uncheck that as well in order to find the folder to mark it as read only. Otherwise my folder search came up with no files found. I think this is what is happening with the poster. There is actually three things you need to check in folder options. It worked for me. I was able to get rid of it then. Thanks for your great instructions. They saved me and my sanity.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So I repeat the information is already provided in step 2. Please read the information in the links provided. That is why they are given. Are you ignoring the fact that the following words " enabled viewing of Hidden Files and Folders with
    Windows Explorer
    ."

    given there is a link? Click on it and you will see all the correct information for each OS.
    Again I repeat! The directions are already there and must be followed correctly.
     
  11. taxximom

    taxximom Private E-2

    I read the instructions you had. I thought they were great, but at first I missed that step and went back to fix it. I didn't realize at the beginning it was a link with instructions for each operating system. I know the information was there. I was trying to say that I believe the original poster did not uncheck that one extra box which is why he could not find the file to mark it read only. I thought that is where he is probably going wrong. He also didn't click the link you provided. He just read what the link said. I was only sharing my own experience in hopes that the original poster would read it and solve his problem. I have never seen such complete instructions like you had. You saved the day. Sorry to post any misunderstanding. In fact, you guys have sold me on this being the best site for advice. I want to send a donation. You guys are great and very thorough.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It may well be that the link was not clicked but I even asked the question "Are you sure you did the following" and posted the info again right in this thread. I did not get any answer. You know we try to spell things out in quite a bit of detail but you have to assume a user has some basic knowledge at some point. But to add a little more help for everyone, I will add a statement that tells the users that the underlined items in the steps are links that must be clicked on. (In fact, I just completed that now.)

    By the way did the Generic Solution fix your problem?
     
  13. taxximom

    taxximom Private E-2

    Like a charm. Like I said the instructions saved the day. I had tried an easier solution posted here and it didn't work. However, that post said if you had the newest version of it, go to this thread. Which lead me to your thread. I must admit when I first read your instructions I struggled. I read them several times before I completely understood what I needed to do. I did have trouble at first determining some of the files that were related on the HiJack this report. When HiJack this analyzed it, I was able to determine the correct files. I printed your instructions as well as their report. It took some time, but the mission was a success. What I really wanted to know was what I should I have on my computer to prevent this from happening again. I have a mirage of software and am trying to shuffle which is the best protection. I take it that ad-aware from lavasoft is different then ad-aware 6.0. I want to have the right tools and one that is enabled to detect these things while I am on the web or especially when my teenagers are there. They are the ones that clicked on this 'HSA' in the first place. What do you recommend?

    Ad-aware by lavasoft.
    Spybot Search and Destroy

    Should I ad Spyware Blaster to the list as well.

    I have Norton Antivirus as well.

    I trust your advice. Your advice is beyond reproach. Thanks so much for helping me. My computer works like a champ now.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  15. tea_ny

    tea_ny Private E-2

    Re: Same problem: HSA tried it all--> happy end

    Ok, so i left computer alone for couple of days, went through b'day party, and now older and wiser read again the whole thing. and yes, i didn't unchecked "hide protected operating system files", which was the reason i couldn't find anything. plus, HT would only show 'flavor of the day' dlls and exes, and actually my windows/system32 folder were loaded with exe files that were sitting there since i first got HSA. after i have cleaned them all (now that i am super expert in recognizing them), ran the tutorial one more time, and here i am, all clean and happy writing you this thank you note.
    so thank you very much for your help and time,
    tea
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Same problem: HSA tried it all--> happy end

    That's great news Tea! And Happy Birthday! I new something had to be getting missed. Now that you are so much wiser we will no longer have these kind of problems....Right?
     
  17. tea_ny

    tea_ny Private E-2

    he he right...never again.....but hey, i am going to keep this url in my bookmarks ;) !!!
    tnx
    tea
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't just keep it in your bookmarks, come back often and keep up with what's going on!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds