Isearchtech problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by Trenton24, Apr 4, 2005.

  1. Trenton24

    Trenton24 Private E-2

    G'day all

    I am having a problem with ISearch Tech. I have completed the "DO NOT POST UNTIL YOU HAVE READ THIS: How to: Spyware, Trojan And Virus Removal" instructions and ran into the following problems

    Firstly, I couldn't dial-up the net when I booted in safe mode with networking enabled to run the virus scans online.

    Also the CWshredder program won't run. I get an error msg saying its not a valid win32 application.

    I completer the Bitdefender and RAV antivirus scans and found the following files I think are significant.

    IstBAR.exe
    Small.AFF
    Backdoor.Rbot system 32/slserves.exe

    and from RAV
    slserves.exe - win32/RpcDcom.gen
    system32\TFTP2828 - Backdoor:IRC/SdBot.dam#2

    When I run Spybot Search and Destroy it finds the following entries, and can't remove them even after restart.

    DyFuCA.InternetOptimizer
    ISearchTech.PowerScan
    ISearchTech.SideFind
    and get an error stating Xurron55.Installdollars

    I have downloaded HijackThis, but am uncertain of where to go from here.

    Any help appreciated
    Cheers
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you cannot run the online scans in safe mode the READ ME tells you to run them in normal boot mode.

    After completing the scans, do the below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. Trenton24

    Trenton24 Private E-2

    cool thamks, forgot to mention I did run the online scans in normal mode.

    Have downloaded HijackThis will post the log file shortly
     
  4. Trenton24

    Trenton24 Private E-2

    My HijackThis log file
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are no signs of the TrendMicro and Symantec online scans being run in your log.
    If they were run, they would leave traces in the O16 section of your log. Are you sure you ran them?? What browser did you used to run them?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O4 - HKLM\..\Run: [etbrun] C:\windows\system32\eliteycr32.exe

    Is the below something you installed and know to be safe? If not, fix it too.
    O4 - Startup: WallpaperKing.lnk = C:\Program Files\WallpaperKing\WP.exe3

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\windows\system32\eliteycr32.exe <--- also look for and delete other files beginning with elite and ending with exe. There could be as many as ten more.

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  7. Trenton24

    Trenton24 Private E-2

    Thanks very much for your help,

    I have followed your instructions.

    Come to think of it I don't think the TrendMicro scan would work even in normal mode, but I definetly ran the symantec one. Maybe the trendmicro will work now some other problems are fixed, should I try it?

    My computer seems to be working a bit faster, especially on boot up, and it appears that some occasional pop-ups have gone. - thanks :)

    However the sbybot entries that I previously mention (ISearchTech etc) are still coming up when I run that.

    with regard to the elite exe in the system32 folder I found the following files, but was unsure of whether or not to delete them as they are not execute files. They are;

    EliteSideBar <-- folder
    EliteToolBar <-- folder

    EliteSideBar 08.dll
    EliteToolBar version 59.dll
    EliteToolBar version 60.dll
    ELITEVJU32.EXE-33BB8438.pf
    ELITEYCR32.EXE-17736AAF.pf

    Once again thanks for your help the new HijackThis log is attached
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes fix all the folders and files but did you forget to fix the one I gave before and to delete al the files. Did you find the files? You need to fix the below line using HJT and delete all the files beginning with elite and ending in exe especially eliteycr32.exe

    O4 - HKLM\..\Run: [etbrun] C:\windows\system32\eliteycr32.exe

    Also, post you Spybot log!
     
  9. Trenton24

    Trenton24 Private E-2

    Don't know why that entry didn't go the first time, I am sure I checked it, it is definetly gone now.
    I also deleted those files.
    Spybot and HijackThis logs attached
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to post the logs!
     
  11. Trenton24

    Trenton24 Private E-2

    sorry, so I did
    Thanks for all your help
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixspy.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Double-click on the fixspy.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to add into the registry say yes.
    After doing the above check Spybot now. Tell me how things look.
     
  13. Trenton24

    Trenton24 Private E-2

    Thanks mate, the spybot came up clean, except for this error;

    Error during check!: Xuron55.Installdollars (Datei C:\WINDOWS\win.ini kann nicht geƶffnet werden. The process cannot access the file because it is being used by another process) ()

    don't know if that is anything worth worrying about. Thanks for all your help, think that is everything - let me know if you think there is any other action I should take.

    Cheers
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you get that message if you run Spybot after booting in safe mode?
     
  15. Trenton24

    Trenton24 Private E-2

    Yep, get the same thing in safe mode, but still clean other than that.

    I also re-ran TrendMicro online virus scan, and it removed an ISTBar file and a DotCom trojan file.

    Here is my latest HIJACKTHIS log. Thanks
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  17. Trenton24

    Trenton24 Private E-2

    Thanks got a clean bill of health on spybot search and destroy, but things still aren't right.

    All my virus stuff is uptodate, but I am still getting virus warnings and sometimes I will start up a program (particually internet explorer 6) and it will take 4-5 mins to load, but once its done it runs fine. Other times it runs fine.

    I don't know what else to do?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are still having problems try two things:

    1) Make sure you now have the current version of SpyBot-Search & Destroy


    2) Please download, install, and update: Spy Sweeper

    Then run a full scan with Spy Sweeper and fix what it finds. Post the log from Spy Sweeper as an attachment.
     
    Last edited: May 3, 2005
  19. sjpa

    sjpa Private E-2

    I have the same problem for many days now. I followed the whole regimen of the spyware tools as listed in your regimen, but to no avail the IST still remains. Keeps popping up even after clean bill of health in safe mode, even after cleaning out the registry. Also in the registry I found snapple as in Legacy_Snapple still there and will not be erased also HW Clock as in Legacy_HWClock. So sometimes in AdAware will pop up as DyFuca. Both spybot and the adaware always says that they deleted it, but again pops up.

    I did not use the HiJack as the warnings scaraed me off.

    Also how long after the cleaning does one enable the system restore again so the cleaning keeps in effect? How long to close down before restarting? I tried many times at different intervals but to no avail. Just from one opening and closing of the registry after deletion will find IST appears again.
    So what to do?
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please start your own thread for your problem. If you have run all the steps in the READ ME. You should be posting in your own thread. This is considered thread hijacking which is similar to what the malware is doing to you.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds