iSearch Toolbar and W32/DOWNLOADER.YQ

Discussion in 'Malware Help (A Specialist Will Reply)' started by Martie, Jan 24, 2005.

  1. Martie

    Martie Private E-2

    History: Switched from cranky IE to Firefox, and from McAfee to Authentium security at the same time. KABOOM!!! Have since experienced:

    iSearch Toolbar popup. Cannot be deleted, quarantined or fixed by AdAware, Spybot S&D, McAfee or Authentium, though all but McAfee detects it.

    Authentium detected /W32/DOWNLOADER.YQ in /WINDOWS/isrvs.sysupd.dll. Sorry to say that their support was 0. Nothing else detects this and it can't be deleted because it's in a "protected" file. Microtrend did not detect it in System Volume Information.

    Could not contact my work server because it used Java Virtual Machine and somehow that was involved and no longer worked. Found the uninstall here and then installed JRE. Also installed Kerio firewall from here.

    Am now running Firefox with aforementioned. Have set a Restore Point. Have zipped HijackThis in a safe folder, not on desktop.

    IE will not connect to any Java apps yet, but Firefox will, so at least I'm back to work. I'd really like these things out of my computer and life.

    Thanks for any help.
     
  2. TheOldThug

    TheOldThug First Sergeant

    Hi

    This site has alot of good tools for cleaning up your computer. It's very important that the first thing you do is the following:

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal.
    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    Try this... you may find it's all you need. If not post your results and I am sure one of the PROS can help you. These guys are quite busy, as you can see by the number of posts, so hang in there. Good Luck!! :)

    TheOldThug
     
  3. Martie

    Martie Private E-2

    I followed the "READ This...." to the letter prior to this post.

    In safe mode, Symantec found the W32/Downloader file and it appears to be fixed. I did run Symantec again following reboot in safe mode and nothing coming up. No other viruses were detected by any of the other programs.

    The iSearch Toolbar is a different story. In safe mode, AdAware found it in three files and appeared to remove it. It reappeared in Spybot (still in safe mode) in two files and it could not be removed: "Some problems couldn't be fixed; the reason could be that the associated files are still in use (in memory). This could be fixed after a restart." Tried that, again in safe mode, and got the same mesage

    After a restart in normal mode, it still could not be fixed via Spybot and I got the same mesage. I re-ran AdAware and it came up with no files detected. No other program run found it in either safe or normal mode.

    Help???
     
  4. Martie

    Martie Private E-2

    Just (10 minutes after last post) installed avast! and it is again detecting the downloader virus: /W32/DOWNLOADER.YQ in /WINDOWS/isrvs.sysupd.dll. Appears that despite doing everything in all steps, it isn't gone. Think I'm back to square one.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have mentioned using 3 antivirus applications (not including the online Symantec scan because it is not an installed antivirus app). You mentioned McAfee, Authentium, and now Avast. If you have all of these installed, you must choose which one you want to use and uninstall the others. You must only use one antivirus application!

    If you are still having problems, do the below.

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  6. Martie

    Martie Private E-2

    I've only had one AVP running at a time (I pay attention to the Pros..). Hijack This log attached as requested. Thanks so much.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Reboot your system into safe mode and do not run anything but what is requested.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - Default URLSearchHook is missing
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O3 - Toolbar: (no name) - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - (no file)
    O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O3 - Toolbar: (no name) - {64634180-B0EA-48B6-82B7-9620D33362C1} - (no file)
    O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
    O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
    O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} - http://akamai.downloadv3.com/binaries/IA/nethv32_EN_XP.cab
    O16 - DPF: {79B96C72-C0D0-4DC8-BC7E-9F314A918228} - http://ak.imgfarm.com/images/nocache/myspeedbar/myinitialsetup1.0.0.7.cab
    O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1437/ftp.coupons.com/v3123/cpbrkpie.cab


    After clicking Fix, exit HJT.

    Now reboot again into safe mode and use Windows Explorer to delete:

    C:\WINDOWS\isrvs <-- the whole folder
    C:\WINDOWS\mqrt.dll or c:\windows\system32\mqrt.dll


    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  8. Martie

    Martie Private E-2

    Oh, Happy Day!!! It appears that all is well. Thanks, again, for the sharing of expertise. An updated log is attached.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  10. Martie

    Martie Private E-2

    The log showed as an attachment the first time .... sorry. If it doesn't appear this time, means that now something is wrong attaching documents.

    Have checked out the Malware post and am following it: Kerio, avast!, etc. Just need to do the settings part.

    BTW: When deleting the isvrs.dll file via Explorer, the contents of the file deleted but the named folder itself is still showing up. Is this "normal?" (Okay, "normal" is a misnomer this early on a Saturday :)
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's a good thing I asked for your log. You still have problems.

    I asked you to delete:
    C:\WINDOWS\isrvs <-- the whole folder

    not just the isvrs.dll file.


    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
    O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\isrvs <--- the whole folder
    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Let me know if you have any problems deleting this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  12. Martie

    Martie Private E-2

    Ran HJT and was able to fix the two files. Rebooted in safe mode and several searches via Explorer did not find C:\WINDOWS\isvrs folder or any files or folders containing "isvrs". Have created a new log but will wait to send it until asked to do so since not everything happened that should've.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Martie,

    If your sure those lines are no longer in your HJT log, I don't need to see it. If you want me to check it over to make sure, you can post it. Either way you should now perform the steps in the below thread:

    How to Protect yourself from malware!
     
  14. Martie

    Martie Private E-2

    Everything from the Malware post is done. I've run the gamut again just to keep things as clean as possible.

    Despite every search trick I know, I swear to you that the folder \WINDOWS\isvrs has vanished. The perplexing part is that the two files I keep fixing keep showing up on HJT after reboot, so it's gotta be somewhere.

    I've sent an updated log (ID#4 to keep things straight) with the hope that I'm missing something obvious.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy and paste the information in the below quote box to notepad. Save it to a file that you will have access to later when you boot into safe mode. Name it fix.reg. Then boot into safe mode, run Windows Explorer and locate the fix.reg file. Doubleclick it and grant it permission to merge in the registry entries.
    Then run HJT (while in safe mode) and fix (if still there):
    O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
    O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe

    Now open a command prompt by click Start, Run and enter cmd and click OK.
    Now enter the following commands each follow by the enter key:
    cd c:\windows
    dir isrvs <--- tell me if you get any output for this
    exit

    Now reboot a couple of times and let me know if those lines are gone or have come back.
     
  16. Martie

    Martie Private E-2

    Did everything in post with following results:

    After granting permission for fix.reg to merge: "Information in fix.reg has been successfully entered into the regustry."

    After searching for isvrs: "File Not Found"

    After rebooting three times, ran log file (ID#6) attached. The two isvrs files appear to be gone. Log attached for your review.

    Again, thanks so much for all your help thusfar.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Your log is now clean!
     
  18. Martie

    Martie Private E-2

    Yesterday iSearch Toolbar reappeared on Spybot S&D. Shows two files are involved:
    HKey_Users\S-1-5-18\Software\iSearch
    HKey_Users\Default\Software\iSearch
    Then ran everything else in tutorial. CCCleaner "Issues" found iSearch Firefox Toolbar which was "successfully uninstalled" using the CCCleaner uninstaller. Nothing else found anything other than a few tracking cookies. Rebooted and reran Spybot -- same reference came up.
    Ran HJT log but didn't see anything that exactly matched.
    Can someone rescue me again?
    Martie
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  20. Martie

    Martie Private E-2

    The uninstaller didn't uninstall. Because the website said that it may not work if spyware/adware detection programs were running, I TEMPORARILY uninstalled Spybot S&D (the one program I have that detects iSearch Toolbar) and ran uninstall again. Again, it remained. Did this in both safe and normal modes.

    Through Windows Explorer, ran a search and iSearch files were found in the Documents and Settings folder. No mention of the HKEY_Users references still coming up on Spybot. Tried to delete the D&S files but they didn't delete even after being sent to the Recycle Bin and deleted from there.

    Then Googled iSearch and the only other legitimate-looking website to deal with iSearch is Pest Patrol. If anyone thinks that the Pest Patrol instructions for removing iSearch will work, I'll be glad to give them a shot. To be honest, I'm leery since the iSearch website claims that nothing but its uninstaller will uninstall this program, and even that doesn't work.

    Having learned a little more about iSearch, and because I use Firefox rather than IE, I'm not particularly concerned about the effects iSearch may have. BUT -- I don't want a program when it's only job is to enable other nasties to enter via IE.

    Chaslang, you have been so patient and helpful. Am I the only one (yeh, right!) who can't get rid of this???

    Martie
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please post your log from Spybot that shows the iSearch problem.

    Also search your registry for iSearch and tell me what matches you get (provide full registry key info which should be the same as what Spybot reveals).
     
  22. Martie

    Martie Private E-2

    Attached is the Spybot S&D log.

    I did a search through My Computer for all files, hidden or not etc., for any file or folder names containing iSearch. Only the removal .exe and application file came up. Is there a different way to search the registry?
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the Registry Search Tool from here:

    http://www.billsway.com/vbspage/vbsfiles/RegSrch.zip

    Unzip to your Desktop and double click on regsrch.vbs
    (if you have script protection, please allow this to run)

    In the dialog that opens enter the following:

    iSearch

    Press 'OK'

    The search will run for a while then alert you when it is finished.

    Press 'OK' and copy the contents of the WordPad window and post in this thread.


    Also post a new HJT log.
     
  24. Martie

    Martie Private E-2

    The two logs are attached.
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have system restore disabled and viewing of hidden files enabled.


    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file move.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.)
    Double-click on the move.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to merge say yes.



    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R3 - URLSearchHook: (no name) - {1C78AB3F-A857-482e-80C0-3A1E5238A565} - (no file)
    O4 - HKLM\..\RunOnce: [Desktop Search Removal Tool] "C:\WINDOWS\inst\kill.exe" /VERYSILENT /NOCANCEL /NORESTART /SP-
    O4 - HKLM\..\RunOnce: [Bonus Sites Removal Tool] "C:\WINDOWS\inst\kill.exe" /VERYSILENT /NOCANCEL /NORESTART /SP-
    O4 - HKLM\..\RunOnce: [iSearch Toolbar Removal Tool] "C:\WINDOWS\inst\kill.exe" /VERYSILENT /NOCANCEL /NORESTART /SP-


    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\inst <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Let me know if you have any problems finding or deleting any of these files.


    Now reboot in normal mode and post a new HJT log. And tell me how things are working.
    See if Spybot still detects anything.
     
  26. Martie

    Martie Private E-2

    Spybot did not detect iSearch!!!!!!! HJT log#12 attached.

    BTW: Since we "gave" Pedro to the Mets, am I forgiven for having such a persistent piece of malware?????? :)
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're clean now!


    Hmmm! Gave him to the Met's? Seemed like you lost him to me! ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds