IST search problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by blackbird157, May 16, 2005.

  1. blackbird157

    blackbird157 Private E-2

    I cannot remove IST search from my computer. My problem sounds similar to a person Sipa who posted here in the past.
    I have already followed the instructions on the -DO NOT POST UNTIL YOU HAVE READ THIS: How to: Spyware, Trojan And Virus Removal- page and
    I have also downloaded the removal tool from symantec which could not find it.
    The trend micro found 4 different versions of it but when I signed up to have them fixed it couldn't fix it 3 different times.
    I also removed Microsoft Java Virtual Machine and Installed Sun Java.
    I did all this about three weeks ago and everytime I run the adaware and spybot it detects dyfuca and ISTsearch and seems to detect it in even more places.
    Besides the IST folder in my program files that reappears all the time, there is another folder there I do not recognise it is called xerox and inside is a supposedly empty folder (which is empty even when files and folders are not hidden) called nwwia yet everytime I try to remove it, it says I can't because nwwia is being used. I did delete it once in safe mode, but it returned as soon as I went back into regular mode.
    I am hoping to download hijack this and run it if you tell me that I can post the log file here and you will tell me how to remove this and what else to remove.
    Also I am pretty irritated, I guess like most people, about this spyware invasion, but especially since this one is putting porn on my computer which my kids also use. I noticed that there was a removal tool on the IST website but there is no way I trust it and I am wondering if anyone knows anything about it. Thank you.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).

    Also post the log from Spybot that shows what it is finding.
     
  3. blackbird157

    blackbird157 Private E-2

    I am attaching the hijack this logfile.
    I just did an adaware and spybot search to attach those logfiles also, but they are coming up clean. As this has been a recurrent and persistent problem for over 6 weeks I would be surprised if it was suddenly gone, but I guess it is possible.
    Besides there are some other problems that maybe can be found.
    thank you for your help.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click Start > Run > enter (copy and paste is better) the following text, then click OK:

    regsvr32 /u btxppanel.dll

    If it doesn't work, enter it this way:

    regsvr32 /u C:\WINDOWS\system32\btxppanel.dll


    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [ulqv] C:\WINDOWS\ulqv.exe
    O4 - HKLM\..\Run: [ohifgdyz] C:\WINDOWS\ohifgdyz.exe
    O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll

    I do not believe that it is valid for CWShredder to be see running as a service. And there is no reason for it to be running that way either. So I'm going to have you fix this too?
    O23 - Service: CWShredder Service - InterMute, Inc. - C:\Documents and Settings\me\My Documents\program set ups\random malware removal shit\CWShredder.exe

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\ulqv.exe
    C:\WINDOWS\ohifgdyz.exe
    C:\WINDOWS\system32\btxppanel.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.


    Quickly check a new HJT log at this point. If your HJT log now still show CWShredder.exe running, perform the below steps.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.

    On the page that opens, scroll down to CWShredder Service ... right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    CWShredder Service


    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  5. blackbird157

    blackbird157 Private E-2

    I am again attaching the hjt log to this file.
    I followed all the instructions the only thing was that these two files did not exist.
    C:\WINDOWS\ulqv.exe
    C:\WINDOWS\ohifgdyz.exe

    I cleaned it all up 2 days ago, then today when I went to use the computer there was a strange icon on my desk. something access and a pop up window which wanted me to click on it.
    In my start menu, this access folder was a new program and in the program files folder it had a .exe file and a couple other things.
    I ran spybot scan which found it but couldn't fix it all, so I opened the task manager and there was a 5 numbered .exe program running, which I assume was it, and then I ran adaware which also found it and deleted some registry entries and the program file. I am sorry I did not think to keep the exact names but when I went back into spybot it was listed under connect mfc application, and had a few registry values. there was also something somewhere about instant access.
    I booted into safe mode and ran that microtrend scan again and it found 3 places where troj_istbar.cj still exists, but it could not fix it. then I ran that stinger and adaware and spybot and they all came up clean.
    also in my program files folder that xerox folder is still there with that wierd empty but not empty folder called nwwia.
    Is there anything else I can do or try?
    thanks so much for the help so far.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is much easier for us to help you if you help us. You must provide specifics. The above is too vague to be useful. Give exact filenames and paths. Tell us the exact symptoms. Tell us folder names. Tell us what .exe file name. Tell us what the "couple other things". Tell us exactly what Spybot found or post the log. By now I think you get the point of what I'm requesting.

    There are no problems showing in your HijackThis log. You do need to get a real firewall installed to protect you properly and then the one in WinXP SP2 should be disabled. See the link below and make sure you have complete ALL of those steps (or the equivalents):

    How to Protect yourself from malware!
     
  7. blackbird157

    blackbird157 Private E-2

    sorry about the vague descriptions of the last posting.
    here I am attaching the log files from adaware and spybot from the time I found that other problem.
    that instant access problem could very well be solved now, the reason I mentioned that problem at all is that it seemed to be affiliated with the ist bar and then when I went into safe mode and microtrend still found 3 places that troj_istbar.cj existed I thought this even more.
    I do not know what the xerox folder is this is what I know about it.
    C:\Program Files\xerox\nwwia
    this was not there before this ist problem began and now it does not go away. I have deleted it in safe mode but it has returned which makes me feel that it is affiliated with or works in the same way as the ist stuff. it is checked as read only which I guess is why I can't delete it normally? but as I do not know much about these problems I figured it was better to find out what it was and see if it was a problem and it was related.
    Thank you for the firewall information- I am having trouble because my e mail is not accessible for some reason when I use a firewall. I know I need to fix this, and will when I am not so busy.
    This IST problem is my fault as I accidentally downloaded it when it disguised itself as something I needed to download. the fact that it has spread so much is also my fault I guess because from what I have read the more you try to remove it the more it hides and spreads?
    I really do appreciate the help you guys give because I have been looking for more than 6 weeks for removal information about this, and you are the only place with good real advice.
    thank you.
     

    Attached Files:

  8. blackbird157

    blackbird157 Private E-2

    attatched is the 2nd spybot log
     

    Attached Files:

  9. blackbird157

    blackbird157 Private E-2

    that access control problem just happened again. it is the same one listed in the two logs I just attached.
    an ugly blue pop up window is there with the message-
    You must be connected to Internet to run this program.Please connect yourself with your ISP and CLICK on YES !
    there is an icon on my desk with a black and white face and it says
    access_control
    this is also listed in my start menu and there is a little exciting note to tell me a new program has been installed.
    C:\Program Files\access_control
    contains the following items
    instant access.exe - this has the same black and white icon and says application mfc underneath it.
    dialerexe.ini which when I open it with notepad seems like it must be the code for the pop up window.
    there is an img folder
    inside the img folder is the icon image called dialerxxx.ico
    I will run a hijack this scan now and post you the log so that you can see if this problem appears.
    I have been doing everything listed on your malware protection list. virus scans updates spyware gaurds etc. the only time I used IE on this computer was to download firefox.
    thanks again
     
  10. blackbird157

    blackbird157 Private E-2

    here is the new hijack this log which may show this aspect of the problem?
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Look in Add/Remove programs for Daily Weather Forecast and uninstall it if found. Please tell me if found.

    Copy the below locally or print it. You must exit all browsers before running this and also disconnect from the Internet.

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixIA.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixIA.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to add into the registry, click YES!



    Just incase the Daily Weather Forecast item had no uninstall, I included it in the fixes below.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\Program Files\Daily Weather Forecast\weather.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [Daily Weather Forecast] C:\Program Files\Daily Weather Forecast\weather.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\Daily Weather Forecast <--- the whole folder
    C:\Documents and Settings\wilder\Local Settings\Temp\17778.exe
    C:\WINDOWS\ExeDialer.exe
    C:\Program Files\Instant Access <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
    Last edited: May 23, 2005
  12. blackbird157

    blackbird157 Private E-2

    I did all you asked, not sure if it cleared up the problems but I have attached the logfile.
    the file C:\documents and settings\...temp\17778
    did not exist but there was one there with the access control icon so I deleted that. also there was two folders instant access and access_control which I needed to delete. I am hoping they are just completely gone now.
    thanks also for helping me get that weather.exe thing out of there. I think I have a bit of an idea where to look and how and what to delete but if this continues to be a problem I will let you know. thanks again.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why aren't you sure? All you have to do is check Spybot again and see it it still gives you the reported problems.
     
  14. blackbird157

    blackbird157 Private E-2

    just mentioned I was not sure because spybot and adaware will come up clean after I clean this IST thing out and then it will emerge either later that day or the next or so... I am still a bit wary of it because I tried everything I could for 6 weeks to make it go away and still that recent microtrend scan found the troj_istbar.cj in three places on my computer, and with that wierd adware like xerox folder in the program files that does not go away. I just am hoping that the problem is not hidden and waiting to re emerge.
    thanks for the help you have given me.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So right now you are clean other then your question on the Xerox folder?

    What files are in this folder and is there anything in Add/Remove programs you do not recognize?

    Do the below:

    Open HijackThis, click Open Misc Tools section
    Click "Open Uninstall Manager"
    Click "Save List" (generates uninstall_list.txt)
    Click Save, copy and paste the results in your next post.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds