ISTbar/Powerscan, TinyBar , eXactSearch

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Maynard, Oct 30, 2004.

  1. Maynard

    Maynard Private E-2

    ISTbar/Powerscan, TinyBar , eXactSearch

    I have these three on my system and Spybot Search and Destroy, AdAware6, and Super Utilities won't get rid of them.

    They delete them and the registry entries but the next time I use the internet they are back. I have gone to the Norton site which showed what files were associated with each and after either manually deleting them or allowing the programs to delete them none of the files are present on my computer. Then after using the internet they are back.

    I have ZA Pro v4 and also have my system set not to allow Active X to run unless its signed.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow all the steps in this Sticky thread < READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal >

    Ad-Aware 6 is out of date. Make sure you update ALL programs per the ones in the read me. And as soon as you install them, check for updates again.

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.
     
  3. Maynard

    Maynard Private E-2

    Umm, no. AdAware6 SpyBot S&D, and Super Utilities are all 100% up to Date. I updated them just prior to running these detections and removal attempts.

    Thanks for the point to the thread though, I missed that one and although I have tried several of the steps in it already I see a couple other things I didn't think of to do. I'll try that and will let you know if it solved the problem.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Umm no! Ad-Aware 6 is old. Ad-Aware SE Version 1.05 is the current product. There are no more updates to Ad-Aware 6.

    You need to run all the steps in that thread, in the order given and in the mode (safe or normal boot) as specified, and run the online scans.
     
  5. Maynard

    Maynard Private E-2

    Yep, my bad I figured out after that you meant upgrade to SE not to update the definations file. I ran all the tests and SE still does not find the three file only the Super Utilities Pro finds them.

    I ran all the test in the order that they are prescribed and while in safe mode also ran Super Utilities Pro. During checking in safe mode only the Super Utilities Pro found the three files in question. After letting the programs do what they needed I rebooted to normal and ran SpyBot S&D, AdAwareSE and Super Utilities Pro again and nothing was found.

    I Then went on the internet and after closing IE rechecked the system. AdAwareSE and Spybot S&D came up clean but Super Utilities Pro reported finding ISTbar, TinyBar, and eXactSearch again.

    Have you ever heard of or used Super Utilities Pro? I got it from ZDNet downloads section. Is there a possiblity that this program is giving false readings?
     
  6. Maynard

    Maynard Private E-2

    Sorry I forgot add what steps I took.

    1: Disable System Restore temporarily: Done

    2: Network Security, Workstation Netlogon Services & Remote Procedure Call (RPC) Helper: Not Present

    3: Enable viewing of hidden files and folders and extensions; Done

    4: Downloading Tools; Done
    Ad-Aware SE
    Ad-Aware VX2 Cleaner Plug-In
    CCleaner
    Spybot.
    SpywareBlaster.
    McAfee AVERT Stinger.
    CWShredder.
    Kill2me.
    about:Buster.
    HSRemove.

    5: Online scan at Trend Micro's Free Online Virus Scan; Done

    6; Online scan at Symantec Security Check; Done

    7; Boot in safe mode with networking; Done

    8; Run McAfee AVERT Stinger; Done

    9: Clean Your Hard Drive with CCleaner. Run CCleaner with the default options to clean out temporary files. Optionally, check the clean "Delete Index.dat" checkbox; Done

    10: Main Spyware Scan And Removal; Scan your machine with Ad-Aware SE (remember to install the Ad-Aware VX2 Cleaner Plug-In for it) and Spybot. Look for the Immunize feature in Spybot and use it; Done

    11: Secondary Spyware Scan And Removal: Run CWShredder, Kill2me, about:Buster and HSRemove; Done

    12: Scan With Hijack This; Done

    13: Windows Update; Done

    14:Remove Microsoft Java; Done
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Super Utilities Pro is also available here http://www.majorgeeks.com/download3937.html
    I have not used it myself but from the write up its main focus is not that of a spyware removal tool. It is probably picking up left over registry tracks (not files) from ISTbar/Powerscan, TinyBar, and eXactSearch.

    You said, "During checking in safe mode only the Super Utilities Pro found the three files in question." It found them but did it remove them or did it just point them out. Also tell me what it said exactly. I don't think (as I said above) it is reporting files but rather registry keys.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder, or from a sub-folder of C:\Documents and Settings, or choose run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    Make sure you have HJT version 1.98.2
     
  9. Maynard

    Maynard Private E-2

    You're right, the three detects are registry key's and it does remove them only to have them reappear after running the internet again.

    Before deleting them when I first found them I went to the symantec site and read up on how to manually remove them and the file they state it hides in was not found. I thought that the files must have been deleted and the keys got left behind by accident. I let the program delete them and thought that that would be the last I would see of them, but the keys still keep coming back. The fact that AdAware SE and Spybot S&D do not find them makes me think its a false reporting.

    I will run HJT and post a log as you request.
     
  10. Maynard

    Maynard Private E-2

    Thanks for your help in all this.


    Edit by chaslang: HJT log changed to an attachment
     

    Attached Files:

    • hjt.txt
      File size:
      2.9 KB
      Views:
      3
    Last edited by a moderator: Oct 31, 2004
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. But that's not an inline log! And didn't you say that you ran all of the READ ME FIRST? I see no signs of the online scans being run.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Questions:

    1) Do you know what these two lines are:
    O4 - Startup: SMASHER.lnk = C:\Program Files\SMASHER\smasher.exe
    O16 - DPF: {01CA75F1-054B-4A63-9221-C6926369EC52} (HS_live Control) - http://install.homestead.com/~site/...ive/HS_live.cab

    Comment: MS Office FastFInd is a waste of system resources and cause lots of disk churn. I would have HJT fix the below line.
    O4 - Global Startup: Microsoft Office Find Fast Indexer.lnk = C:\MSOffice\Office\FINDFAST.EXE


    Have HJT fix the below two lines:
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do the below too:
    1) go here and download Registrar lite and install it: http://www.majorgeeks.com/download469.html
    2) Run it
    3) Use the search function built into Registrar Lite and let it look for matches to ISTbar, Powerscan, TinyBar, and eXactSearch (one at a time). But before doing that make sure when Registrar Lite first opens that you click in the left window to put the cursor on the top of the registry where the two little computer appear next to the word Registry. Then click on the magnifiying glass for search and enter the search string and hit enter. Tell me what matches you get if any (for each item)
     
  14. Maynard

    Maynard Private E-2

    I just re-read the thread and yep I did miss the post as txt attachment and I don't understand what you mean by an inline log. As for the online scans entry's (Opps) I saw those lines and deleted(fixed) them as I figured I didn't need to run the scans again since they were clean.

    The O4 - Startup: SMASHER.lnk = C:\Program Files\SMASHER\smasher.exe is my Smasher Popup Stopper program.
    The O16 - DPF: {01CA75F1-054B-4A63-9221-C6926369EC52} (HS_live Control) - http://install.homestead.com/~site/...ive/HS_live.cab, is for my web sites stuff.

    I'll delete the others you pointed out, and I'll get back to you after I run the Registrar Lite program and let you know what it found.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In line is just like the text I am typing now. That is what you posted before. Look at how I changed it to an attachment.

    Please do not delete those scanner entries any more. It will save you the time of downloading those objects again the next time you have a problem and need to scan. Plus if we don't see them, we will tell you to run them again.
     
  16. Maynard

    Maynard Private E-2

    ISTbar - No Hits
    Powerscan - No Hits
    eXactSearch - No Hits
    TinyBar: - 2 Hits

    HKEY_USERS\S-1-5-21-1229272821-823518204-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\tinybar.com

    HKEY_USERS\S-1-5-21-1229272821-823518204-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\www.tinybar.com

    Looks like only this one parasite remains. Do you want me to run this in Safe Mode and delete it from the registry?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! Those lines are entries put into your registry by programs like SpyBot and SpywareBlaster to protect you from going to bad sites like that. There are 1000 or more of these types of lines entered into your registry under the ZoneMap\Domains key.
     
  18. Maynard

    Maynard Private E-2

    Ok, Thanks for all your help. I think I will not run Super Utilities Pro anymore. I had it on the trial period right now so I think I will just remove it and use the tools you guys recomended.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! You should check this out too: How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds