I.Search.Tech.YSB trouble

Discussion in 'Malware Help (A Specialist Will Reply)' started by Internationaldave, May 21, 2006.

  1. Internationaldave

    Internationaldave Private E-2

    Hello,

    Can anyone give me advice on how to remove ISearchTech.YSB. It has been on the computer for a while. I have run the read me instructions, all except for the windows defender as it cannot find the genuine certificate for windows. I have to look into it but i asure you it is. It shows a path of HKEY_LOCAL_MACHINE\SOFTWARE\YourSiteBar. I have tried deleting the key in normal and safe mode, and all the checks could not get rid of it. Also eveytime i run Spybot it comes up with these two: Windows Security Center.FirewallDisableNotify and Windows Security Center.AntiVirusDisableNotify. i can delete the regisrty for them but they keep coming back. CCleaner deleted a lot , CShredder did not find anything, Adaware only found net cookies. Vundo found nothing. My spybot log ans HJT log are attached.

    Please help,

    Davey. :mad:
     

    Attached Files:

  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    The only indication that you have or had YourSIte Bar is this Registry entry HKEY_LOCAL_MACHINE\SOFTWARE\YourSiteBar. Open REGEDIT and delete that entry.
     
  3. Internationaldave

    Internationaldave Private E-2

    I have tried on many occasions to do this, both in normal and safe mode. It just says 'error whilst deleting key' or something to that effect. Is there a special trick to get round this?

    Davey. :confused:
     
  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

  5. Internationaldave

    Internationaldave Private E-2

    Thanks for the suggestion, i'd love to tell you it worked, unfortunately, same message "access denied". I tried deleting its contents instead, but no cigar! Any further suggestions?

    Davey.
     
  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Take ownership of the key.

    In Registrar Lite, click on the key, click Security in the menu, select Take Ownership.
     
  7. Internationaldave

    Internationaldave Private E-2

    I downloaded registrarlite and the 'take ownership function' function is only available in the paid for version. Unfortunately, i neither have access to a payment method nor can i afford to buy a years sub. Any other tricks up your sleeve? :confused:
     
  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not true! Try downloading and installing again but this time DO NOT download from the Authors Site link. Download from one of the Majorgeeks links. It works fine if you do it that way.
     
  10. Internationaldave

    Internationaldave Private E-2

    Bingo! Ewido trial version could not do it, but i downloaded registrarlite again and it let me take control and i deleted it, no fuss!!

    Thanks guys, you're angels! (in a manly kind of way :) !!! )

    Dave.
     
  11. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You're Welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds