Options

stuck on step 4 of hsa removal

I've been following the hsa removal guide, and I've already run adaware and spybot, but I can't seem to find Network Security Service,
Workstation NetLogon Service, or Remote Procedure Call (RPC) Helper in either safe or normal mode. I've also run Active.txt but can't find them there either. I'm not sure what to do now. Should I post my hjt and active.txt reports? Any help would be greatly appreciated.

Comments

  • edited April 2005
    ffisearch.exe is the one I can't get rid of it just keeps coming back (and I still can't find the 3 things in my post above....)


    Logfile of HijackThis v1.99.1
    Scan saved at 5:09:20 PM, on 20/04/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
    c:\windows\system32\yxfvpa.exe
    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\BRMFRSMG.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\unzipped\hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
    O4 - HKLM\..\Run: [Msbb.exe] Msbb.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
    O4 - HKLM\..\RunServices: [Microsoft DirectX] PDSched.exe
    O4 - HKLM\..\RunServices: [Msbb.exe] Msbb.exe
    O4 - HKCU\..\Run: [Microsoft DirectX] PDSched.exe
    O4 - HKCU\..\Run: [Msbb.exe] Msbb.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: ppctlcab - http://ppupdates.ca.com/downloads/scanner/ppctlcab.cab
    O16 - DPF: {01FE8D0A-51AD-459B-B62B-85E135128B32} (DD_v4.DDv4) - http://www.drivershq.com/DD_v4.CAB
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
    O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://www.pcpitstop.com/internet/pcpConnCheck.cab
    O16 - DPF: {405BBF5B-2FD8-4614-AC51-D8566F635B94} (SafeWallet Class) - http://idsm.citadelprocessing.com/SafeCommon/downloads/WalletCab.CAB
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/05b83ffe38657e634922/netzip/RdxIE601.cab
    O16 - DPF: {63BAECA2-9E3C-45DE-B2B1-BBC5FA99958E} (MCCWrapperObj Class) - ftp://download.sympatico.ca/OnlineNA/BellCanadaPortalAX.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1099545634191
    O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/24/install/gtdownls.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab32846.cab
    O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
    O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
    O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
    O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - C:\WINDOWS\isrvs\mfiltis.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
    O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe

    active.txt file:

    These are the Current Active Services:

    avast! iAVS4 Control Service: aswUpdSv
    "C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"

    Windows Audio: AudioSrv
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Cryptographic Services: CryptSvc
    C:\WINDOWS\system32\svchost.exe -k netsvcs

    DHCP Client: Dhcp
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Error Reporting Service: ERSvc
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    COM+ Event System: EventSystem
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Fast User Switching Compatibility: FastUserSwitchingCompatibility
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Help and Support: helpsvc
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Server: lanmanserver
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Workstation: lanmanworkstation
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Network Connections: Netman
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Network Location Awareness (NLA): Nla
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Remote Access Connection Manager: RasMan
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Task Scheduler: Schedule
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Secondary Logon: seclogon
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    System Event Notification: SENS
    C:\WINDOWS\system32\svchost.exe -k netsvcs

    Shell Hardware Detection: ShellHWDetection
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Telephony: TapiSrv
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Themes: Themes
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Distributed Link Tracking Client: TrkWks
    C:\WINDOWS\system32\svchost.exe -k netsvcs

    Windows Time: W32Time
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Windows Management Instrumentation: winmgmt
    C:\WINDOWS\system32\svchost.exe -k netsvcs

    Security Center: wscsvc
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Automatic Updates: wuauserv
    C:\WINDOWS\system32\svchost.exe -k netsvcs

    Wireless Zero Configuration: WZCSVC
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    avast! Antivirus: avast! Antivirus
    "C:\Program Files\Alwil Software\Avast4\ashServ.exe"

    DCOM Server Process Launcher: DcomLaunch
    C:\WINDOWS\system32\svchost -k DcomLaunch

    Terminal Services: TermService
    C:\WINDOWS\System32\svchost -k DComLaunch

    DNS Client: Dnscache
    C:\WINDOWS\System32\svchost.exe -k NetworkService

    Event Log: Eventlog
    C:\WINDOWS\system32\services.exe

    Plug and Play: PlugPlay
    C:\WINDOWS\system32\services.exe

    HTTP SSL: HTTPFilter
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter

    TCP/IP NetBIOS Helper: LmHosts
    C:\WINDOWS\System32\svchost.exe -k LocalService

    SSDP Discovery Service: SSDPSRV
    C:\WINDOWS\System32\svchost.exe -k LocalService

    WebClient: WebClient
    C:\WINDOWS\System32\svchost.exe -k LocalService

    IPSEC Services: PolicyAgent
    C:\WINDOWS\System32\lsass.exe

    Protected Storage: ProtectedStorage
    C:\WINDOWS\system32\lsass.exe

    Security Accounts Manager: SamSs
    C:\WINDOWS\system32\lsass.exe

    Remote Procedure Call (RPC): RpcSs
    C:\WINDOWS\system32\svchost -k rpcss

    Print Spooler: Spooler
    C:\WINDOWS\system32\spoolsv.exe

    Windows Image Acquisition (WIA): stisvc
    C:\WINDOWS\System32\svchost.exe -k imgsvc

    Windows User Mode Driver Framework: UMWdf
    C:\WINDOWS\System32\wdfmgr.exe


    :confused:
  • edited April 2005
    please if anybody has any idea of what I should do I will be so grateful....I've been at this all day and I'm sure I'm missing something easy...

    thanks to anyone with help
  • Buckeye_SamBuckeye_Sam Columbus, Ohio
    edited April 2005
    Download the attached file and extract it to your desktop. Don't do anything with it yet, we will use it later.

    Place a checkmark next to these entries, close all browsers and windows, and have HijackThis fix them by clicking Fix Checked:

    O4 - HKLM\..\Run: [Msbb.exe] Msbb.exe
    O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
    O4 - HKLM\..\RunServices: [Microsoft DirectX] PDSched.exe
    O4 - HKLM\..\RunServices: [Msbb.exe] Msbb.exe
    O4 - HKCU\..\Run: [Microsoft DirectX] PDSched.exe
    O4 - HKCU\..\Run: [Msbb.exe] Msbb.exe
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/05b83ff...ip/RdxIE601.cab
    O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - C:\WINDOWS\isrvs\mfiltis.dll


    Close HijackThis and open Task Manager (Ctrl-Alt-Del)
    Highlight each of the following and select: End Task

    desktop.exe
    ffisearch.exe
    yxfvpa.exe

    Then reboot, on restart, restart in Safe Mode


    Start | Run (type and click Ok for each of the following: (if exists)

    regsvr32 /u C:\WINDOWS\isrvs\sysupd.dll
    regsvr32 /u C:\WINDOWS\isrvs\mfiltis.dll
    regsvr32 /u C:\WINDOWS\isrvs\msdbhk.dll


    Next:

    Locate fixdesktopsearch.reg right-click and select: Merge (Ok the prompt)

    Start | Run (type) "%temp%" (no quotes) [required step]
    Completely delete the entire contents of that "temp" folder.

    Open Windows Explorer to your Windows\Temp folder [required step]
    Completely delete the entire contents of that "temp" folder.

    Open Windows Explorer locate and delete the following: (if exists)

    C:\WINDOWS\isrvs\desktop.exe
    C:\WINDOWS\isrvs\ffisearch.exe
    C:\WINDOWS\isrvs\sysupd.dll
    C:\WINDOWS\isrvs\mfiltis.dll
    C:\WINDOWS\isrvs\msdbhk.dll
    C:\WINDOWS\delprot.sys
    C:\WINDOWS\delprot.ini
    C:\WINDOWS\delprot.log
    C:\WINDOWS\isrvs <--this folder
    c:\windows\system32\yxfvpa.exe
    Msbb.exe
    PDSched.exe

    After the above, reboot, rescan with HijackThis and post a new hijackthis log.
Sign In or Register to comment.