I have a PC that is infected with this HOMESEARCASSISTANT crap and I cannot get rid of it. I have Microsofts AntiSpyware on the computer which is running XP pro so I came up in safe mode and it detects this thing but cannot successfully remove it. So I saw an entry here for a poor soul who had it on ME and finally got rid of it. I tried the Adaware in safe mode again it identifies and says it is getting rid of it but restart and it comes right back.
I cannot believe that anyone with any intellegence at all would write something like this! I tried to use the Hijackthis to get rid of it but I am not sure what all I should delete.
Here is the log:
Logfile of HijackThis v1.98.2
Scan saved at 5:59:16 PM, on 3/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon
.exe
C:\WINNT\system32\services
.exe
C:\WINNT\system32\lsass.ex
e
C:\WINNT\system32\svchost.
exe
C:\WINNT\System32\svchost.
exe
C:\WINNT\system32\spoolsv.
exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\ipvh32.e
xe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\wscntfy.
exe
C:\WINNT\system32\igfxtray
.exe
C:\WINNT\system32\hkcmd.ex
e
C:\WINNT\SOUNDMAN.EXE
C:\WINNT\ALCWZRD.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\j2re1.4.2_06\bi
n\jusched.
exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINNT\ieml.exe
C:\PROGRA~1\Ahead\Ahead\da
ta\Xtras\m
ssysmgr.ex
e
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\WINNT\system32\ctfmon.e
xe
C:\Program Files\Yahoo!\Messenger\ypa
ger.exe
C:\Program Files\InterVideo\Common\Bi
n\WinCinem
aMgr.exe
C:\WINNT\system32\svchost.
exe
C:\Program Files\Eyetide Media\Eyetide Viewer\EyetideController.e
xe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Microsoft ActiveSync\WCESMgr.exe
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EX
E
C:\TEMP\hijackthis\HijackT
his.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar = res://C:\WINNT\hnbwk.dll/s
p.html#447
68
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page = res://C:\WINNT\hnbwk.dll/s
p.html#447
68
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL = about:blank
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL = res://C:\WINNT\hnbwk.dll/s
p.html#447
68
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Bar = res://C:\WINNT\hnbwk.dll/s
p.html#447
68
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page = res://C:\WINNT\hnbwk.dll/s
p.html#447
68
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant = res://C:\WINNT\hnbwk.dll/s
p.html#447
68
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEH
elper.ocx
O2 - BHO: (no name) - {288E8765-988E-2CAD-E2AA-1
387368F9CE
D} - C:\WINNT\ipxg.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-F
ADC6B08487
2} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
859DF00B1D
6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - C:\PROGRA~1\Yahoo!\COMPAN~
1\Installs
\cpn\ycomp
5_5_7_0.dl
l
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray
.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.ex
e
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroChec
k.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [.mscdsr] C:\WINNT\system\lsvchost.e
xe
O4 - HKLM\..\Run: [VC5MediaPlayer] C:\WINNT\system32\csmrs.ex
e
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bi
n\jusched.
exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMo
n.exe
O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [ieml.exe] C:\WINNT\ieml.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\Ahead\da
ta\Xtras\m
ssysmgr.ex
e
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.e
xe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypa
ger.exe -quiet
O4 - Startup: Eyetide Launcher.lnk = C:\Program Files\Eyetide Media\Eyetide Viewer\EyetideController.e
xe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bi
n\WinCinem
aMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch
.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\Office10\
EXCEL.EXE/
3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict
.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict
.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - (no file)
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-0
0C04FAE2D4
F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-0
0C04FAE2D4
F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-0
0C04FAE2D4
F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-0
0010333D0A
D} - C:\Program Files\Yahoo!\Messenger\yhe
xbmes0521.
dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-0
0010333D0A
D} - C:\Program Files\Yahoo!\Messenger\yhe
xbmes0521.
dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugi
n3.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
dll
O16 - DPF: {2BCDB465-81F9-41CB-832C-8
037A406444
6} (F5 Networks VPN Manager) -
https://kubota1.clnt.virtela.net/vdesk/terminal/urxvpn.cab#version=2004,5,7,1O16 - DPF: {31E68DE2-5548-4B23-88F0-C
51E6A0F695
E} (Microsoft PID Sniffer) -
https://support.microsoft.com/OAS/ActiveX/odc.cabO16 - DPF: {6414512B-B978-451D-A0D8-F
CFDF33E833
C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1102094427921O16 - DPF: {6C275925-A1ED-4DD2-9CEE-9
823F5FDAA1
0} (F5 Networks SSLTunnel) -
https://kubota1.clnt.virtela.net/vdesk/terminal/urTermProxy.cab#version=2004,5,7,1O16 - DPF: {CC85ACDF-B277-486F-8C70-2
C9B2ED2A4E
7} (F5 Networks SuperHost Class) -
https://kubota1.clnt.virtela.net/vdesk/terminal/urxshost.cabO16 - DPF: {E0FF21FA-B857-45C5-8621-F
120A0C17FF
2} (F5 Networks Host Control) -
https://kubota1.clnt.virtela.net/vdesk/terminal/urxhost.cab#version=2004,5,11,1O17 - HKLM\System\CCS\Services\T
cpip\..\{8
85C0F3C-BE
14-4C94-A5
D6-889D26B
7DC56}: NameServer = 64.19.9.18,64.19.9.33
Your help will be gratefully appreciated.
Thanks!