Targetsaver, Isearch.sidefind, N-Case

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by pace, Jul 5, 2005.

  1. pace

    pace Private First Class

    I have ran through the tutorial and my system shows to be clean on every program except Spybot. Spybot is finding the following programs and it will not remove them with an error message saying they may be running in memory. The programs are:

    Targetsaver
    IserachTech.Sidefind
    N-Case

    It did remove Avenue A, INc and Doubleclick.

    I am running Windows XP, with Avast anti-virus, Zone Alarm and Mozilla for my browser and everything appears to be up to date. I also had an alert from Avast for
    C:\Windows\System32\rdriv.sys that it would not remove because it was running. I went into safe mode and removed the file and it appears to have worked.

    Any help on deleting the other stuff would be appreciated.

    Thanks.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have run all the steps in the READ ME FIRST, please follow the below steps exactly to properly install and use HijackThis:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. pace

    pace Private First Class

    Thanks for the quick response. I have attached the HJT log to this post.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please post a log from Spybot. Are you running the latest version 1.4?

    Have HijackThis fix the below lines (make sure no browsers are open when you click fix):
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - (no file)
    O23 - Service: Computer Browser (Browser) - Unknown owner - (no file)
    O23 - Service: Error Reporting Service (ERSvc) - Efficient Networks, Inc. - (no file)
    O23 - Service: Event Log (Eventlog) - Efficient Networks, Inc. - (no file)
    O23 - Service: COM+ Event System (EventSystem) - Efficient Networks, Inc. - (no file)
     
  5. pace

    pace Private First Class

    I was running 1.3. I downloaded 1.4 and here is the log. I will delete the items you highlighted and run another HJT log.

    Thanks
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Remember when you said
    The tutorial specifically tells you to download from our links and get updates.
     
  7. pace

    pace Private First Class


    I am sorry about that, I ran through the tutorial and checked all of my versions to make sure I was up to date and I must have skipped Spybot. I did run it again and it found 27 items, I hit fix and ran again after a reboot and it came up clean. I also ran a new HJT log and the same items that you wanted me to delete are still there after a reboot.

    Again, sorry about the oversight on Spybot. Thanks for your help.

    Here is the latest HJT log.
     

    Attached Files:

  8. pace

    pace Private First Class

    Also, I keep getting the alert from Avast of this Trojan file and even after deleting it in Safe Mode I still have it after a reboot. I can find it in the System32 folder. The file is:

    C:\Windows\System32\rdriv.sys

    Avast says it cannot delete or move the file because it is being used in other programs. I thought I got it the first time but I guess not.

    Thanks
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What about the below:

    Targetsaver
    IserachTech.Sidefind
    N-Case

    Are you sure you have done the below:

    Right Click Start.
    Select Explorer.
    Select the Tools menu and click Folder Options.
    Select the View Tab.
    Under the Hidden files and folders heading select Show hidden files and folders.
    Uncheck the Hide extensions for known file types option.
    Uncheck the Hide protected operating system files (recommended) option.
    Click Apply.
    Click OK.
     
  10. pace

    pace Private First Class

    I just double checked the settings and they were/are correct. SHould I try to delete them again with HJT, or is it going to take another path?

    Thanks.
     
  11. pace

    pace Private First Class

    Here is the latest HJT log. Spybot is coming up clean now.

    Thanks.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! That's good but what about Avast and rdriv.sys?

    You picked up a new worm called WORM_RBOT.BRQ
    See: http://ru.trendmicro-europe.com/enterprise/vinfo/encyclopedia.php?LYstr=VMAINDATA&VName=WORM_RBOT.BRQ

    Sounds like you may be missing some Windows updates.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\System32\wuamk032.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [Microsoft Update] wuamk032.exe
    O4 - HKLM\..\RunServices: [Microsoft Update] wuamk032.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\wuamk032.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  13. pace

    pace Private First Class

    I completed the steps in the last post you made but when I went into safe mode I could not find
    C:\WINDOWS\System32\wuamk032.exe

    Also, I ran Avast again after rebooting and it still shows the following virus:
    C:\Windows\System32\rdriv.sys
    and says it cannot be removed since it is being used by another program. It also found two other viruses, it had found them previously and said they had been moved to the Chest but they were there again today. They are:
    C:\RECYCLER\s-1-5-21-2882691 268-22891 49484-633614638-500\Dc1.sys
    C:\RECYCLER\s-1-5-21-2882691 268-22891 49484-633614638-500\Dc2.sys

    Both say Ifected: Win32:Trojan-gen {other}
    Avast says they were both successfully moved to the Chest.

    Here is the latest HJT log.

    Thanks.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    My last message said to run CCleaner. Did you run it? It should have emptied your recycle bin. Otherwise empty your recycle bin yourself.

    You keep picking up new problems each time. Now you have a few new ones.

    Download Pocket Killbox and save it to its own folder where you can find it.

    Read thru the below steps and make sure you understand them before starting. Ask questions if you have any before starting.

    Run Killbox by double clicking on the killbox.exe file.

    Check the following boxes:

    Standard File Kill
    End Explorer Shell While Killing file

    Copy & paste (you must use copy & paste - typing will give an error) the full path of each of the files below (one at a time - see directions after the list) into the Full Path of File to Delete box.

    C:\WINDOWS\System32\ahqvkdj.exe
    C:\Windows\System32\rdriv.sys

    With the full path to the file name in the Full Path of File to Delete textbox. The filename will appear under the box in a blue color to indicate it was found. Now Click the Red X and for the confirmation message that will appear, you will need to click Yes. If the file is successfully delete you will get a message of confirmation. Just click OK!
    If the above delete fails (because of a similar message about a process running) continue with the next steps.

    - in Killbox select the option to Delete on Reboot
    - uncheck the option to End Explorer Shell While Killing file

    Copy & paste the full path of each of the files you could not delete above into the box and then click the Red X and for the confirmation message that will appear, you will need to click Yes. A second message will ask to Reboot now? Click No if you entered the last file name otherwise click Yes

    Okay so now your PC should be reboot. If you get an error message about Pending Operations, just reboot your PC yourself.

    Is rdriv.sys gone now?

    After reboot run HJT and fix the below lines:

    O1 - Hosts: 255.255.255.255 ar.atwola.com atdmt.com avp.ch avp.com avp.ru awaps.net ca.com dispatch.mcafee.com download.mcafee.com download.microsoft.com downloads.microsoft.com engine.awaps.net f-secure.com ftp.f-secure.com ftp.sophos.com go.microsoft.com liveupdate.symantec.com mast.mcafee.com mcafee.com msdn.microsoft.com my-etrust.com nai.com networkassociates.com office.microsoft.com phx.corporate-ir.net secure.nai.com securityresponse.symantec.com service1.symantec.com sophos.com spd.atdmt.com support.microsoft.com symantec.com update.symantec.com updates.symantec.com us.mcafee.com vil.nai.com viruslist.ru windowsupdate.microsoft.com www.avp.ch www.avp.com www.avp.ru www.awaps.net www.ca.com www.f-secure.com www.kaspersky.ru www.mcafee.com www.my-etrust.com www.nai.com www.networkassociates.com www.sophos.com www.symantec.com www.trendmicro.com www.viruslist.com www.viruslist.ru www3.ca.com
    O4 - HKLM\..\Run: [jxel] C:\WINDOWS\System32\ahqvkdj.exe
    O4 - HKLM\..\RunServices: [jxel] C:\WINDOWS\System32\ahqvkdj.exe


    Then post a new HJT log.
     
  15. pace

    pace Private First Class

    I did run the CCleaner during the last steps. I just ran the Killbox and the file
    C:\WINDOWS\System32\ahqvkdj.exe
    is gone but
    C:\Windows\System32\rdriv.sys
    is still there. I did have to attempt to delete on Reboot but it still didn't get rid of it. When I ran HJT I found the first entry:
    O1 - Hosts: 255.255.255.255 etc.

    But when the other two entries were not on the list:
    O4 - HKLM\..\Run: [jxel] C:\WINDOWS\System32\ahqvkdj.exe
    O4 - HKLM\..\RunServices: [jxel] C:\WINDOWS\System32\ahqvkdj.exe

    but I did notice a similar entry that seems to change everytime that I reboot. On the last HJT log (attached to this post) the entry I noticed is:

    O4 - HKLM\..\Run: [jxel] C:\WINDOWS\System32\eqzcm.exe
    O4 - HKLM\..\RunServices: [jxel] C:\WINDOWS\System32\eqzcm.exe

    The previous HJT it was the same path but instead of eqzcm it started with a bh......(I cant remember the rest of the path, I didn't write it down the first time since I wasn't sure if it meant anything.)

    The computer seems to be running fine but I do get the Avast alert about rdriv.sys virus.

    Thanks.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not look like you fixed the O1 Hosts line because it is still there. I understand why the O4 lines are not fixed. That's because the file names are changing after reboot. You must avoid rebooting (or doing a power down) after posting your HJT log. Otherwise, what I tell you to look for will no longer be present.

    Try the below for the Hosts file problem:

    Download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    For the rdriv.sys file try using Killbox again but select the following options:
    Replace on Reboot and check the Use Dummy box too. Also check the End Explorer Shell While Killing File option.


    Then post a new HJT log and do not reboot or power down. I'm guessing that the O4 lines from you last HJT log have already changed. They were:
    O4 - HKLM\..\Run: [jxel] C:\WINDOWS\System32\eqzcm.exe
    O4 - HKLM\..\RunServices: [jxel] C:\WINDOWS\System32\eqzcm.exe
     
  17. pace

    pace Private First Class

    Here is the latest HJT log. This time when I ran killBox and deleted the rdriv.sys file it did not give me the error message that it was being used by another program. The 04 entries did change again.

    Thanks.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run HOSTER?


    Run Killbox just like you last did for rdriv.sys and have it delete: C:\WINDOWS\System32\zsmbhtkxji.exe

    But do not reboot when prompted. Instead of rebooting, pull the power chord (yes that's what I said). We want to avoid a graceful shutdown because that may be where the file is respawning and renaming. Wait a couple minutes and then plug the power back in and boot your PC into safe mode with no network support. Run HijackThis and fix the below lines:

    O4 - HKLM\..\Run: [jxel] C:\WINDOWS\System32\zsmbhtkxji.exe
    O4 - HKLM\..\RunServices: [jxel] C:\WINDOWS\System32\zsmbhtkxji.exe

    Now exit HijackThis and reboot into normal mode. Post a new log and let me know the results of these steps and how things are working.
     
    Last edited: Jul 8, 2005
  19. pace

    pace Private First Class

    Yes, I did run Hoster, it seemed to work correctly. Here is the latest HJT log after following the steps of your last post.

    Thanks.
     

    Attached Files:

  20. pace

    pace Private First Class

    Also, I just got the alert from Avast about rdriv.sys

    The computer is working fine otherwise.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! We got rid of the O4 line trojans that kept renaming themselves. And the O1 Hosts line is now gone. Now let's fix this rdriv.sys problem.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to Workstation Service Library (or it could be named Microsoft Locator Service ) Then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Workstation Service Library

    Or if that does not work, use the other name: Microsoft Locator Service

    After doing that you will probably told you need to reboot. Reboot but reboot to safe mode.

    In safe mode run Windows Explorer. Find the below files and delete them:
    C:\WINDOWS\wkssvc.exe
    C:\Windows\System32\rdriv.sys

    Now run Ccleaner. Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell me the results of doing the above and how things are working.
     
  22. pace

    pace Private First Class

    When I went into the Run, Services.msc box I found the Workstation Service Library entry but it would not let me press 'Stop Service'. I could select disable on start-up type. When I tried running the HJT and entered Workstation Service Library it told me it was not a complete path and could not delete the entry. Should I enter:

    "C:\WINDOWS\wkssvc.exe"

    That is the path listed on the properties "pop-up" screen.

    Thanks.
     
  23. pace

    pace Private First Class

    Here is the latest HJT log, I went into safe mode and looked for the files that you noted. I found:

    C:\Windows\System32\rdriv.sys

    and deleted it but I could not find:

    C:\WINDOWS\wkssvc.exe,

    the only thing close that I found was:
    C:\WINDOWS\System32\wkssvc.dll

    and I didn't mess with it since I assume it was supposed to be there, I scrolled too far down with looking for rdriv.sys and noticed it.

    I also ran the CCleaner and cleaned out the Prefetch folder (actually it was already empty).

    Thanks.
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You were correct in not deleting the wkssvc.dll file. It is a valid Windows file.

    Is rdriv.sys still gone? Are you having anymore problems?
     
  25. pace

    pace Private First Class

    Everything seems to be working fine, I checked for rdriv.sys and couldn't find it in the system, I also ran Avast and it came up clean. I did run HJT and noticed the following files are still present, they are files that you had ask me to try to delete originally but they wouldn't go away. They are:

    O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - (no file)
    O23 - Service: Computer Browser (Browser) - Unknown owner - (no file)
    O23 - Service: Error Reporting Service (ERSvc) - Efficient Networks, Inc. - (no file)
    O23 - Service: Event Log (Eventlog) - Efficient Networks, Inc. - (no file)
    O23 - Service: COM+ Event System (EventSystem) - Efficient Networks, Inc. - (no file)


    Should I try to do anything with these?

    Thanks for all of your help, are there additional steps that I can take to protect my computer?
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No leave them alone. They are all valid services that normally do not show in a HJT log since they are system defaults. I'm not sure why they are showing. It could be that something in them looks different to HJT. But since everything is working OK, ignore them.

    You should now work through the steps in the below thread to help keep you clean:

    How to Protect yourself from malware!
     
  27. pace

    pace Private First Class

    I will go through the list, Thanks for all of your help.
     
  28. pace

    pace Private First Class

    One more question, I have noticed that any time I go to the Mircosoft website and try to download updates I always get a page that says 'Updates were NOT successfully downloaded' followed by the following in a box:

    Update for Background Intelligent Transfer Service (BITS) 2.0 and WinHTTP 5.1 (KB842773)
    Microsoft Windows Installer 3.1

    Is there anyway to fix this?
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should post that question in the Software Forum. But where you using Internet Explorer? If not, you must use IE to get MS updates.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds