Hi, I just found this forum and it looks good. A lot of helpful people here.

Here's my problem right now. Yesterday I was trying to clean up my computer a little bit after I noticed it slowing down a bit. I went through msconfig and disabled several programs that I didn't want runing on startup. Then after reboot this thing appeared. I don't know how to get rid of it. Its not in the add/remove programs. I ran ad-aware twice and it didn't get rid of it. See pic below:

[IMG][/IMG]

Thanks.

Dani AI

Generated

A concise expert note tying the thread together and giving a safe cleanup path.

This is a classic “Search Assistant” adware case: the toolbar in the taskbar is usually installed by a component (commonly shown as C:\Program Files\WindowsSA\omniscient.exe) and is treated as adware/PUP by removal databases. ’s discovery of an Add/Remove entry called WindowsSA matches the common footprint for this family. (auditmypc.com)

Behavior to watch for and a key warning: the infection often alters the Winlogon/Userinit settings so a bogus program (wsaupdater.exe) runs at login. Removing files blindly (or letting a scanner quarantine wsaupdater.exe) before restoring the Userinit value can leave a system that won’t let a user log on. Restoring or copying a clean userinit.exe from the installation media or ServicePackFiles\i386 is the usual recovery step. (wilderssecurity.com)

Safe cleanup workflow (order matters):

  1. Run an up‑to‑date on‑demand anti‑adware scanner (example: Malwarebytes) to detect PUP components and leftovers.
  2. Capture a current HijackThis/Autoruns listing and fix the obvious Run/UserInit/IE-Search entries that point at WindowsSA/omniscient/wsaupdater (record changes).
  3. Reboot to Safe Mode, verify a legit C:\Windows\System32\userinit.exe exists, then delete C:\Program Files\WindowsSA and any omni*/wsaupdater files. Unregister related DLLs (regsvr32 /u) if present.
  4. If the system will not log on, boot Recovery Console (or recovery media) and copy a clean userinit.exe into System32 before fixing the registry.
  5. After manual cleanup, run a thorough offline scan (Microsoft Defender Offline or equivalent) and then reboot. (malwarebytes.com)

Final notes: always back up the registry/create a restore point before editing, keep anti‑malware tools current, and avoid bundled freeware that can install toolbars silently. These steps explain why SpyBot/Ad‑Aware sometimes miss items and why manual registry+file cleanup is often required for this variant.

Recommended Answers

All 3 Replies

In addition to running Ad-Aware, try running SpyBot. Sometimes one catches something the other doesn't. Let us know what happens after that.

What exactly does the search bar say? I tried clicking your link, and it came up dead.

I'm not sure why the link is not working for you. I uploaded it here as an attachment. It doesn't seem like its doing any harm, just very annoying. I'll try spybot when I get home. Thanks.

I fixed the problem myself after doing some more research. Ended up there's a program hiding in the add/remove programs called WindowsSA.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.