Options

kindly help with Search Assistant Removal (hijackthis log presented)

Dear Community Members,

I have been infected with the Search Assistant spyware and have tried following multiple strategies to remove the spyware. Before, I go into some details, I wanted to let you know that I would really appreciate if you or anyone you know could help me remove this spyware.

I tried deleting suspicious .dll and .exe files created in the last month in c:\windows and c:\windows\system32

This worked and my Internet Explorer went back to my home page - google! However, next time I turned it back on, I got the same spyware home page.

I have also run hrsremove.exe and aboutbuster multiple times. It seems like the spyware recreates itself very fast and everytime I go to c:\windows and c:\windows\system32 I find new shady files created.

Here is a copy of my hijackthis log.

Logfile of HijackThis v1.99.1
Scan saved at 5:51:31 PM, on 4/2/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\carpserv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\program files\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\ntdj.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\802.11 Wireless LAN\802.11b Wireless CardBus & PCI Adapter HW.11 V1.10\WlanCU.exe
C:\WINDOWS\system32\ntnt.exe
C:\WINDOWS\system32\cisvc.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\wfdxc.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\wfdxc.dll/sp.html#93256
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\wfdxc.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {FF52FC75-302C-5DED-C090-F77905337D75} - C:\WINDOWS\winfb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\program files\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ntdj.exe] C:\WINDOWS\ntdj.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Wireless Configuration Utility.lnk = C:\Program Files\802.11 Wireless LAN\802.11b Wireless CardBus & PCI Adapter HW.11 V1.10\WlanCU.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.ofoto.com/downloads/BUM/BUM_WIN_IE_1/axofupld.cab
O16 - DPF: {C4847596-972C-11D0-9567-00A0C9273C2A} (Crystal Report Viewer Control) - http://www.cars.csom.umn.edu/viewer/activeXViewer/activexviewer.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by1fd.bay1.hotmail.msn.com/activex/HMAtchmt.ocx
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\ntnt.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe


Could you or anyone tell me which of these I should delete and how I can overcome the issye of this spware recreating itself?

I have already turned system restore off as recommended by a website/forum.
I have also tried cancelling Remote Procedure Call (RPC helper)

Thank you for your time. Any help would be appreciated.

-Khosa

Comments

  • A2IA2I
    edited April 2005
    Hi khosa

    I have some other option b4 you try it with hijackthis.

    go to start run msconfig [disable all startups] follow the prompt

    download the following programms and do update their definition files first before you scan.

    This is just to clean your system afterwards you can deside if you keep them or not.

    First [ http://download.microsoft.com/download/8/1/5/815d2d60-49b5-44dc-ae35-fca2f2c6f0cc/MicrosoftAntiSpywareInstall.exe ]

    Second Try with Webroot Spy Sweeper 3.5 update definition files first b4 scan

    [ http://www.download.com/Webroot-Spy-Sweeper/3000-8022_4-10373771.html ]

    u should update ur xp ; ) a little [ http://www.microsoft.com/downloads/details.aspx?FamilyId=049C9DBE-3B8E-4F30-8245-9E368D3CDB5A&displaylang=en ] 272Mb install

    Download sp2 install activate Windows updates.

    run http://housecall.trendmicro.com/housecall/start_corp.asp as a double check too see if ur system is clean of vir_items.

    if all done incl ur scans, updates, go to msconfig [enable all startups]
    reboot.

    If the problem still persists plz post.

    ty.
  • edited April 2005
    A2I wrote:
    Hi khosa

    I have some other option b4 you try it with hijackthis.

    go to start run msconfig [disable all startups] follow the prompt

    download the following programms and do update their definition files first before you scan.

    This is just to clean your system afterwards you can deside if you keep them or not.

    First [ http://download.microsoft.com/download/8/1/5/815d2d60-49b5-44dc-ae35-fca2f2c6f0cc/MicrosoftAntiSpywareInstall.exe ]

    Second Try with Webroot Spy Sweeper 3.5 update definition files first b4 scan

    [ http://www.download.com/Webroot-Spy-Sweeper/3000-8022_4-10373771.html ]

    u should update ur xp ; ) a little [ http://www.microsoft.com/downloads/details.aspx?FamilyId=049C9DBE-3B8E-4F30-8245-9E368D3CDB5A&displaylang=en ] 272Mb install

    Download sp2 install activate Windows updates.

    run http://housecall.trendmicro.com/housecall/start_corp.asp as a double check too see if ur system is clean of vir_items.

    if all done incl ur scans, updates, go to msconfig [enable all startups]
    reboot.

    If the problem still persists plz post.

    ty.
    Thanks. I am going to do this now. After I disabled all the startups, I got a prompt to restart - should I restart the machine and then download, update and run the programs you have suggested?

    -Khosa
  • A2IA2I
    edited April 2005
    Yes just run fullscans on your root drive normally thats a full c:\> only.

    In what order you place it doesnt really matter as long as they all are fully completed and any items found removed.

    On ur virusscan its good to keep the logg usefull if you wanna know what the file technically did or triggers for payloads good to know were you dealing with.

    may any problems occur plz post.

    ty.
  • A2IA2I
    edited April 2005
    Important is when you install Microsoft antispyware that you restore all home page settings to the default Microsoft puts it on and your homepage on ur own.

    Tools\Advanced Tools\Browser Hijack Settings Restore [Arm those settings right plz]

    Make sure its right on were the program wants the default on.

    Then its set correct.

    Save that as default.

    Let the files make the first move you get the blue warning alert Internet Explorer Start Page URL CHange Requires Approval see what it tries to change, if you dont allow it press block. Right bottum.

    After everything you have blocked is done you can send the log if you want for comparison to spynet or looked into.

    they will fix it and not only you will be helped but all the people afterwards can autofix this aswell.

    Second thing you can do with the programm go to Tools\Advanced Tools and go to System Explorers see if anything is drawn with yellow Explainationmarks Yellow Stars are certified goodies those others are unknown and most of the time not needed, just look into them see if you can make some scum removals.

    Its important that you manage your allowed and blocked stuff correctly, otherwise the program is kinda worthless in ur case :banghead: .

    keep posting if you meet any other problems.

    ty.
  • edited April 2005
    Hi,

    Since my last post to you, I was unable to work on my laptop to remove the Search Assistant. I was out of town on work (training) and now I am back. Let me read your posts again and do as you instruct.

    Thank you again for your time.
    I will write to you with an update.
    -Khosa
  • Buckeye_SamBuckeye_Sam Columbus, Ohio
    edited April 2005
    khosa - I wanted to let you know that A2i's advice, while not necessarily harmful, may not be the best way to proceed with your problem. In fact, it's very unlikely that the steps he outlined will solve your problem.

    If you are still in need of help, please post a new hijackthis log and I will post instructions for you that will help resolve your problem.
Sign In or Register to comment.