ISTbar remover HELP

Discussion in 'Malware Help (A Specialist Will Reply)' started by cimburgia, Feb 2, 2005.

  1. cimburgia

    cimburgia Private E-2

    I've read through a mojrity of the ISTbar relate dposts and have done several thinigs to get rid of ISTbar. I'm completely frustrated now and looking for some help. I've run Panda Platinum and Ad Aware SE in safe mode. They got rid of most everythiing. I deleted ISTsvc but I still have IST bar showing up when I run Spyware Scan. Following is the log from Hijack This:

    Help would be GREATLY appreciated.

    Logfile of HijackThis v1.99.0
    Scan saved at 8:27:45 PM, on 2/2/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)


    C:\Documents and Settings\Chris Imburgia\Application Data\Microsoft\Internet Explorer\Quick Launch\HijackThis.exe
     
    Last edited by a moderator: Feb 2, 2005
  2. TheOldThug

    TheOldThug First Sergeant

    Welcome

    We ask that you first try to do the TUTORIAL listed below. After doing that we will ask for a HJT log. It must not be inline but rather as a .log or .txt attachment.

    This site has alot of good tools for cleaning up your computer. It's very important that the first thing you do is the following:

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal.
    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    Try this... you may find it's all you need. If not post your results and I am sure one of the PROS can help you. These guys are quite busy, as you can see by the number of posts, so hang in there. Good Luck!! :)
     
  3. PhilliePhan

    PhilliePhan Guest

    Hi Cimburgia,

    You should move HijackThis to a safer folder – C:\Program Files\HijackThis!

    Delete this:
    C:\WINDOWS\jwrcjge.exe

    Fix these lines in HJT:
    O2 - BHO: DownloadRedirect Class - {00000000-6CB0-410C-8C3D-8FA8D2011D0A} - C:\Program Files\iMesh\iMesh5\iMeshBHO.dll (file missing)
    O4 - HKLM\..\Run: [22PfCxI] C:\WINDOWS\jwrcjge.exe
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comned.com/signuptem...iveSecurity.cab

    Those are the items that jump out at me from your log.

    Don't really like this one either:
    F2 - REG:system.ini: UserInit=C:\WINDOWS\regedit /s C:\pav.reg,C:\WINDOWS\system32\pavdr.exe,C:\WINDOWS\system32\userinit.exe,

    PP :)

    EDIT: Sorry Star & Thug - Didn't see youse guys :)
     
    Last edited by a moderator: Feb 2, 2005
  4. cimburgia

    cimburgia Private E-2

    ISTbar is gone. MANY THANKS for the help!!! :)
     
  5. PhilliePhan

    PhilliePhan Guest

    You're welcome! We are happy to help :)

    To ward off further problems, have a peek at Chaslang's Suggestions!

    PP :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds