persistent isearch and hotsearch

Discussion in 'Malware Help (A Specialist Will Reply)' started by besure, Jan 10, 2005.

  1. besure

    besure Private E-2

    Hi,

    I have followed all the advice and steps listed on this site to get rid of this spyware but it still seems to be lingering. I have read through most of the threads but no matter what I do I can't seem to get rid of it all. I have run Ad Aware SE with the VX2 Add On, Spybot Search and Destroy as well as the other tools recommended, all to no avail.

    I don't have the isearch toolbar, but everyonce in a while my browser goes to the isearch page, even when I'm following a link on this site. I also seem to have arbitrary words assigned links to 'sponsored link' in the body of online text. My browser also attempts to redirect to 'hotsearch' every once in a while.

    If I post a HJT log can somebody take a look and give me some advice?

    Thank you very much for your assistance
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have run ALL the steps of the READ ME FIRST and still have a problem, make sure you follow the guidelines below and post your HJT log.


    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. besure

    besure Private E-2

    Chaslang,

    I did run through the process outlined in the 'Read me first' and although it cleaned up a lot, I still have the occasional redirection as well as words like 'internet' and 'date' in any online text acting as 'Sponsored Links'.

    Here is the HJT log...

    I appreciate any help you can give me.

    Thanks
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try giving this a run:

    http://securityresponse.symantec.com/avcenter/FxIstbar.exe

    It comes from this link:
    http://securityresponse.symantec.com/avcenter/venc/data/adware.istbar.html#removalinstructions

    Then run the below steps:

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).
    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side.
    Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\system32\smss32.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.isearch.com/index.php?app=SE&affjump=1&affiliate=ODQ6NTo5&Terms=
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R3 - URLSearchHook: (no name) - _{1C78AB3F-A857-482e-80C0-3A1E5238A565} - (no file)
    R3 - URLSearchHook: (no name) - _{20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)
    O2 - BHO: ohb - {285B5CCD-C3F0-4EB6-9632-7D0A3C3AF824} - C:\WINDOWS\system32\hsrb.dll
    O4 - HKLM\..\Run: [UsbD] C:\WINDOWS\system32\smss32.exe
    O4 - HKLM\..\Run: [7AOcmú*ÀaîžaaøY§ÄC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\eyvis.exe
    O9 - Extra button: (no name) - {F2570A0D-001D-477D-93D1-D05EF5EB95CD} - (no file)
    O23 - Service: ZESOFT - Unknown - C:\WINDOWS\zeta.exe (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\smss32.exe
    C:\WINDOWS\system32\hsrb.dll

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Do you know what this Atheros Service is:
    O23 - Service: Atheros Configuration Service - Unknown - C:\WINDOWS\system32\acs.exe


    Also a comment: be careful using Microsoft AntiSpyware it has problems with deteting valid items as bad (this is referred to as false positives). One of them is two hits on a registry key with Search Squire. The registry key it finds was put into the restricted zone by Spybot (or similar) to protect you. MS Antispyware wrongly detects this as bad and removes it. It also Detects this file c:\winnt\avxoscan\bdupd.dll as Brilliant Digital. This is also a false positive. This is BitDefender.
     
  5. besure

    besure Private E-2

    Thanks Chaslang, I'll follow your instructions and let you know how it goes.

    You asked if I knew what 'O23 - Service: Atheros Configuration Service - Unknown - C:\WINDOWS\system32\acs.exe' is. I'm not sure, but I am using a D-Link 802.11G Wireless PCMCIA card for my internet connection. It may be for that??

    Thanks again...
     
  6. besure

    besure Private E-2

    Chaslang,

    I have followed your instructions and am posting the resulting HJT log as per your request. I'll play around a bit and see how it's working now.

    Thanks again for your help... you guys are awesome...
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HJT again and have it fix these lines:


    R3 - URLSearchHook: (no name) - _{20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)
    O9 - Extra button: TREND MICRO HouseCall - {2B5EA4F8-620A-4A8B-B003-4C8C5EBEA826} - http://uk.trendmicro-europe.com/enterprise/products/housecall_pre.php (file missing)

    Also I forgot a couple items to clean up last time. Find these and delete them (if found):
    C:\Program Files\ISTsvc <--- the whole folder
    C:\WINDOWS\eyvis.exe


    How are things running?
     
  8. besure

    besure Private E-2

    I ran HJT and removed the files you indicated. I then checked but couldn't find the other two files you mention. It seems to be working pretty good now. I haven't been hijacked by either isearch or the hotsearchbar since you had me clean things up. I did have a scare today with a couple of 'critical shutdowns' but I think it was because of the hammering my laptop took from airport security. They ran it through the x-ray 5 times. Don't know what they thought they saw??? I cringed everytime they dropped the tray on the belt. After the second blue screen I took the RAM out, cleaned the contacts with an alcohol swab and reseated it. Seems to be ok now... keeping fingers crossed. I had that happen to me on another trip and after trying everything from bios updates to increased cooling I found that the RAM had a bad contact. May need to breakdown and purchase some new memory.

    Thanks again for all your help. I really do appreciate what you do for us technically challenged people out here.

    I have attached the results of another HJT scan. If you see anything else I should remove, please let me know.

    Thank you.
     

    Attached Files:

  9. oshout

    oshout Private E-2

    I skimmed over this thread and I belive you have your problem pretty much fixed - but just in case..

    Some software comes with ads/spyware on it. Take AIM for example. As long as your running aim, you'll get their crappy little popups. The only way to stop them is to stop AIM..
    The only way I know to stop a program from inflicting ads and whatnot is to uninstall it.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Your all clean now! You should now check out the information here:
    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds