This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hsa, Search Extender, Shopping Wizard...

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Well, I'm stuck. I'd like to say I'm knowledgeable with computers, but I know I'm not. I can usually track down a good bit of the reminants of spyware with the help of Ad-Aware, but these 3 are impossible. Here's the log:

Logfile of HijackThis v1.98.2
Scan saved at 7:17:31 PM, on 12/6/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\javaeo32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\apirq.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\documents and settings\ross llewallyn\local settings\temp\B.exe
C:\WINDOWS\System32\tibs3.exe
C:\documents and settings\ross llewallyn\local settings\temp\BavyZkRI.exe
C:\Documents and Settings\Ross Llewallyn\Application Data\osoa.exe
C:\WINDOWS\System32\l?ass.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Ross Llewallyn\My Documents\downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\pghju.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\pghju.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\pghju.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\pghju.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\pghju.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\pghju.dll/sp.html#29126
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\pghju.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=488
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {C1A41FA6-75A9-208D-8DC5-1020AE6270B6} - C:\WINDOWS\d3fr.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [xrovnc] C:\WINDOWS\System32\xrovnc.exe
O4 - HKLM\..\Run: [apirq.exe] C:\WINDOWS\system32\apirq.exe
O4 - HKLM\..\Run: C:\documents and settings\ross llewallyn\local settings\temp\B.exe
O4 - HKLM\..\Run: [tibs3] C:\WINDOWS\System32\tibs3.exe
O4 - HKLM\..\Run: [BavyZkRI] C:\documents and settings\ross llewallyn\local settings\temp\BavyZkRI.exe
O4 - HKLM\..\Run: [Windows AdService] C:\Program Files\Windows AdService\WinAdServ.exe
O4 - HKLM\..\Run: [ckkppgoyfuehu] C:\WINDOWS\System32\xesogfms.exe
O4 - HKCU\..\Run: [WhatPulse] C:\MYMINI~1\WHATPU~1\WHATPU~1.EXE
O4 - HKCU\..\Run: [pgtaff] C:\WINDOWS\pgtaff.exe
O4 - HKCU\..\Run: [Ncao] C:\Documents and Settings\Ross Llewallyn\Application Data\osoa.exe
O4 - HKCU\..\Run: [Yyb] C:\WINDOWS\System32\l?ass.exe
O4 - HKCU\..\Run: [eww5RfHpO] zliin.exe
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\My Mini-Programs\AOL\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: (no name) - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.frame.crazywinnings.com
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comned.com/signuptemplates/ActiveSecurity.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://rtc3.webresponse.one.microsoft.com/…p/TLIEFlash.CAB

First off, I am aware that I don't have SP2 yet. It wouldn't download properly, and I had to go through a whole ordeal to get my computer back to normal. Even then, things are still buggy. Hopefully it's a spyware problem. :)

I've heard that these 3 (Home Search Assistent, Search Extender, and Shopping Wizard) are hard to remove. I've tried a program reccomended by another website without success. I've also heard that these programs, or at least HSA, change their names on Startup/Shutdown. I just need some help getting rid of all of the files, because I always seem to miss one or two.

Thanks in advance for any help you give me…

:D

Hi,
Sorry you have been delayed but the forum is very busy and you have one of the severe infections that we see nowadays.

Step#1:

If you still are having computer problems please scan again with HijackThis and post a new log file here in this thread using Add Reply so that we can see any changes that have taken place. Please note that fixing this type of infection takes a number of steps to complete.


Step#2:

Then:

1. Please download Service Filter
2. Extract it to it's own folder.
3. Click on ServiceFilter.vbs
4. A text file called POST_THIS will be in the same folder
5. Please use Edit>Select all then Edit>Copy to obtain the contents
6. Please Post the contents into this thread using 'Add Reply'
It’s fine about the delayed response; I realize how bad this thing is. Here’s the new HiJackthis log:

Logfile of HijackThis v1.98.2
Scan saved at 5:44:55 PM, on 12/12/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\javaeo32.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\MYMINI~1\WHATPU~1\WHATPU~2.EXE
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\wincm32.exe
C:\Program Files\Common Files\GMT\GMT.exe
C:\Program Files\Common Files\CMEII\CMESys.exe
C:\Program Files\ISTsvc\istsvc.exe
C:\Program Files\Internet Optimizer\optimize.exe
C:\Program Files\Internet Optimizer\actalert.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Documents and Settings\Ross Llewallyn\My Documents\downloads\Hijackthis\HijackThis.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\WINDOWS\explorer.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\kkbkm.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\kkbkm.dll/sp.html#29126
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\kkbkm.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\kkbkm.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\kkbkm.dll/sp.html#29126
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\kkbkm.dll/sp.html#29126
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\kkbkm.dll/sp.html#29126
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {59411F8E-CF6C-7B7A-F0C0-DB33873458BD} - C:\WINDOWS\winvy32.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [apirq.exe] C:\WINDOWS\system32\apirq.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [wincm32.exe] C:\WINDOWS\wincm32.exe
O4 - HKLM\..\Run: [SysIdle] C:\WINDOWS\System32\26143.exe
O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe"
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\RunOnce: [AAW] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe" "+b1"
O4 - HKCU\..\Run: [WhatPulse] C:\MYMINI~1\WHATPU~1\WHATPU~2.EXE
O4 - HKCU\..\Run: [Usove] C:\WINDOWS\System32\??plorer.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O15 - Trusted Zone: *.frame.crazywinnings.com
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB


Here’s the Service Filter thingy:

########################################

ServiceFilter 1.1
by rand1038

Microsoft Windows XP Professional
Version: 5.1.2600 Service Pack 1
Dec 12, 2004 5:46:34 PM


—> Begin Service Listing <—

Unknown Service # 1
Service Name: Autocomplete
Display Name: AutoComplete Service
Start Mode: Manual
Start Name: LocalSystem
Description: …
Service Type: Own Process
Path: c:\progra~1\intern~2\autocomp.exe
State: Stopped
Process ID: 0
Started: False
Exit Code: 1077
Accept Pause: False
Accept Stop: False

Unknown Service #2
Service Name: SwPrv
Display Name: MS Software Shadow Copy Provider
Start Mode: Manual
Start Name: LocalSystem
Description: Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this …
Service Type: Own Process
Path: c:\windows\system32\dllhost.exe /processid:{261ff5d6-55b3-4d28-8348-7dbc93e219f0}
State: Stopped
Process ID: 0
Started: False
Exit Code: 1077
Accept Pause: False
Accept Stop: False

Unknown Service # 3
Service Name:  %AFå  ¤À¨
Display Name: Workstation NetLogon Service
Start Mode: Auto
Start Name: LocalSystem
Description: …
Service Type: Share Process
Path: c:\windows\system32\javaeo32.exe /s
State: Running
Process ID: 1348
Started: True
Exit Code: 0
Accept Pause: False
Accept Stop: True

Unknown Service # 4
Service Name: sysidleserv
Display Name: System Idle Service
Start Mode: Auto
Start Name: LocalSystem
Description: …
Service Type: Own Process
Path: c:\windows\system32\adprot.exe
State: Stopped
Process ID: 0
Started: False
Exit Code: 1077
Accept Pause: False
Accept Stop: False

—> End Service Listing <—

There are 82 Win32 services on this machine.
4 were unrecognized.

Script Execution Time: 4.808594 seconds.


Well, there you have it. You might notice my HiJackthis log is different, mostly because I gave it a shot myself a few times. Alas, it came back… many times. :(

On a side note: Is my AIM not supposed to work, my Notepad to close occasionally, and my Add/Remove Progams to close when I try to open it? …because that's what's happening. :D

:huh:
Hi Boss1000
I am not going to be able to give you the start of the fix until tomorrow unfortunately. However, in the meantime, you have the variant that deletes system files, and that is what is causing notepad, AIM and add./remove programs not to work. SInce we will need those items during the fix I will as you to repair them prior to my posting with the first stage of the fix Unfortunately the infection will delete more files before we get rid of it so you will have to do this again once you are cleaned and may even have to do it before then to get notepad working again.

Step#1:

The first thing you should do is:
.Please download and open the following zip file. Double-click on the file inside the zip and when it asks you if you would like to merge the file into your registry, please answer yes. This will make sure all files are visible on your computer.
http://www.davehigham.zen.co.uk/downloads/xphidden.zip



Step#2:

In Windows XP notepad.exe is in two locations and both locations need to have the legitimate file in them:

1. Please navigate to C:\Windows\System32\dllcache and find notepad.exe (65k)

2. Copy notepad.exe

3. Navigate to C:\Windows\System32 and paste notepad.exe there

4. Go back to C:\Windows\System32\dllcache and find notepad.exe and copy it again

5. Navigate to C:\Windows and paste notepad.exe in this folder as well.


Step#3:

If you are unable to get notepad.exe from the dllcache folder then you should go to the following location and download and install the Windows Files that are available there. I suspect you are missing notepad.exe and shell.dll as those are the commonest ones that are deleted by the infection.

If you are having any difficulty with Notepad, please go to
Merijn's Files and choose 'Windows Files' from the menu on the left hand side of the page. Then choose 'Notepad' from the list and download it to C:\Windows and C:\Windows\System32
Hi boss1000
you have a very severe infection that will take several steps to remove. Using Internet Explorer or contacting the internet during the removal steps causes the infection to reinstall, so I will be asking you to disconnect from the internet and keep IE closed. I will tell you when this is necessary.

There is also a problem with an entry in your trusted zone of Internet Explorer which allows this website access to your entire computer. Removing it is necessary. Please go to Start>Control Panel>Internet Options and open the general tab. Highlight the Trusted Zone at the top and then choose Sites. In the window that opens please remove all entries from the lower box. Click Apply. Then Click Close.


Step#1:

The following programs are either not recommended or are malware. You can
find replacements for them and read about the Safe Programs

Please go to Start > Control Panel > Add Remove Programs and uninstall each of the following:
istservice
WhatPulse <— is a keylogger keeping track of your activity - you may want this
Internet Optimizer
Gator


Step#2:

1. Please download Service Filter
2. Extract it to it's own folder.
3. Click on ServiceFilter.vbs
4. A text file called POST_THIS will be in the same folder
5. Please use Edit>Select all then Edit>Copy to obtain the contents
6. Please Post the contents into this thread using 'Add Reply'



Step#3:

Please save these instructions to WordPad so that you have them accessible while following the steps. You also may want to print out these directions as the Internet will not be available. You must disconnect from the internet totally, as staying connected while fixing will prevent the fix from working. Also please keep Internet Explorer closed throughout as opening it will reinstall the infection. Read through all the instructions so that you can ask any questions now, before you disconnect from the Internet.

Please continue with the next step and if you run into any problems with the current one, just keep going through the list step by step. Just be sure to let us know what the problem was when you finally reply.


Step#4:

1. Please download About:Buster from here: http://tools.zerosrealm.com/AboutBuster.zip.

2. Once it is downloaded extract it to c:\aboutbuster. Do NOT use it yet



Step#5:

Another program to download is Registrar Lite for use later: Please download Registrar Lite and install it to C:\Program Files\RegLite\ . This is a registry editor that is very easy to use.



Step#6:

Now Please disconnect from the Internet and unplug your modem for the duration of this fix

1. Reboot your computer into Safe Mode by tapping F8 while booting up and continue for the rest of the fix in SAFE MODE

2. Click on start > control panel > administrative programs > services. Look for a service called Workstation NetLogon Service. Double click on that service and click stop and then set the startup to disabled. Also write down the name and path of the file listed in the Path to executable field. This filename must be deleted below.



Step#7:

Press control-alt-delete to get into the task manager and end the following processes if they exist:

C:\MYMINI~1\WHATPULSE\WHATPULSE.EXE <– you may want this keylogger
C:\Program Files\ISTsvc\istsvc.exe
C:\Program Files\Internet Optimizer\optimize.exe
C:\Program Files\Internet Optimizer\actalert.exe
C:\Program Files\Common Files\CMEII\CMESys.exe
C:\WINDOWS\system32\javaeo32.exe
C:\WINDOWS\wincm32.exe
C:\Program Files\Common Files\GMT\GMT.exe


Step#8:

I now need you to delete the following files:

C:\Program Files\Common Files\GMT\GMT.exe
C:\Program Files\Common Files\CMEII\CMESys.exe
C:\WINDOWS\system32\javaeo32.exe
C:\WINDOWS\system32\apirq.exe
C:\WINDOWS\wincm32.exe
C:\WINDOWS\system32\kkbkm.dll
C:\WINDOWS\winvy32.dll
C:\WINDOWS\system32\apirq.exe
C:\WINDOWS\System32\26143.exe
C:\WINDOWS\System32\??plorer.exe



If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. if it is uncheck it and try again.



Step#8:

Then close all programs and windows and run hijackthis. Put a checkmark next to each of these entries and click 'fix checked' button when ready (some may be gone after uninstalling some programs):



R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\kkbkm.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\kkbkm.dll/sp.html#29126
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\kkbkm.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\kkbkm.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\kkbkm.dll/sp.html#29126
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\kkbkm.dll/sp.html#29126
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\kkbkm.dll/sp.html#29126
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {59411F8E-CF6C-7B7A-F0C0-DB33873458BD} - C:\WINDOWS\winvy32.dll
O4 - HKLM\..\Run: [apirq.exe] C:\WINDOWS\system32\apirq.exe
O4 - HKLM\..\Run: [wincm32.exe] C:\WINDOWS\wincm32.exe
O4 - HKLM\..\Run: [SysIdle] C:\WINDOWS\System32\26143.exe
O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe"
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKCU\..\Run: [WhatPulse] C:\MYMINI~1\WHATPU~1\WHATPU~2.EXE
O4 - HKCU\..\Run: [Usove] C:\WINDOWS\System32\??plorer.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O15 - Trusted Zone: *.frame.crazywinnings.com




Step#9:

In the next step we are going to remove a service that gets installed by this malware.

1. Open Registrar Lite and run it.

2. Copy and paste the bold text below into the address bar of Registrar Lite:(this is making a Registry backup for safety in case of error)

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\

Go to File> Export and and save as (in the C:\Program Files\Registrar Lite (Reglite) folder):

1.) Winkey.reg (Save as type: regedit4 .reg type)
2.) Winkey.hiv (Save as type: Scroll to select-regetd32/WinAPI *hiv *dat files)


3. Copy and paste the bold text below into the address bar of Reglite:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\%AFå ¤À¨


4. Click Go

5. If %AFå ¤À¨
exists it will be highlighted in the left pane , right click on it and choose delete from the menu.


6. Copy and Paste the bold text below into the address bar of Registrar Lite:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ %AFå ¤À¨


7. Click Go

8. If LEGACY_ %AFå ¤À¨ exists then right click on it and choose delete from the menu.

9. If you have trouble deleting a key. Then click once on the key name to highlight it and on the top menu choose Security, then Edit Permissions. Then make sure you are an Administrator and give yourself Full Control of that key. Then click on everyone and put a checkmark in "full control". Then press apply and ok and attempt to delete the key again.

10. If you have had to change the permissions on the keys in Registrar Lite then they will have to be returned to the way they were . To do this please navigate to C:\ProgramFiles\Registrar Lite (Reglite) and double-click on Winkey.reg. It will ask if you want to merge this file with the registry, say Yes. Then double-click on Winkey.hiv and merge this file with the Registry. You have now returned the permissions to the way they were.


Step#10:

This is the step where we will use About:Buster that you had downloaded previously.

Navigate to the c:\aboutbuster directory and double-click on aboutbuster.exe When the tool is open press the OK button, then the Start button, then the OK button, and then finally the Yes button. It will start scanning your computer for files. If it asks if you would like to do a second pass, allow it to do so. Post the log file in your next reply

Step#11:

Copy the contents of the Quote Box below to Notepad.
Name the file as fix.reg
Change the Save as Type to All Files
and Save it on the desktop

REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HSA]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SE]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SW]


Then double-click on the fix.reg file, and when it prompts to merge say yes, and this will clear some registry entries left behind by the process.


Step#12:

1.Reboot your computer back to normal mode and Scan again with HijackThis. We still have a few steps to complete but a log file at this time would be helpful.

2. Post both your log from About Buster and your HijackThis log here in this thread with any questions or problems that you have run into. There are still some steps that are necessary to clear out all of the malware. There will be necessary files that it has deleted that will need to be replaced.

Good Luck!
I had some problems, but I don’t think it matters anymore. My dad just re-did the whole computer, losing everything, and here I am. Everything is back to normal, of course, but I’m missing a lot. I’d like to say that what you told me did help and got rid of HSA and all that. I still had a few problems, but it seemed much better than before. Thanks for all your help. Don’t worry, it’s not in vain; I’ll tell others with this problem about this and try to help them myself. (Of course, I won’t go so far as to possibly destroy their computers.) Thanks again. :)
This topic is now closed.


If you need this topic reopened because of continued malware problems, please request this by sending an email to the following link
(Click for address)

Please make the subject of the Email: "Reopen" and provide a valid link to this post in the body. Your username and your reason for requesting a reopen should also be included.



Any emails which do not include all of the above will be deleted without being looked at.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI