YourSiteBar Installer Removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by JellyBean3350, Feb 14, 2005.

  1. JellyBean3350

    JellyBean3350 Private E-2

    At windows startup I am prompted to install "Your Site Bar". I've never installed it, but can't seem to get rid of this. The process is "ysbinstall_1002648_3.exe".

    1) I ran Spybot S&D and Adaware SE Personal. Neither detected or removed it.

    2) I ran HijackThis and fixed:

    O4 - HKLM\..\Run: [ysbinstall_1002648_3.exe] C:\WINDOWS\system32\ysbinstall_1002648_3.exe

    3) I deleted "ysbinstall_1002648_3.exe"

    4) I've searched Google for a solution with no luck.

    I turned off System Restore and disabled the process in Task Manager before doing all of the above. Nothing has worked. Still being prompted at startup.

    Please help.

    JB
     
    Last edited: Feb 14, 2005
  2. TheOldThug

    TheOldThug First Sergeant

    Welcome :eek:

    It might help if you work through the following TUTORIAL first.
    This site has alot of good tools for cleaning up your computer. It's very important that the first thing you do is the following:

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal.
    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    Try this... you may find it's all you need. If not post your results and I am sure someone wll help you. Everyone is quite busy, as you can see by the number of posts, so hang in there. Good Luck!! :)

    After doing ALL of the above if you still have a problem:

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, INCLUDING YOUR WEB BROWSER, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder for example C:\Program Files\HJT
     
  3. JellyBean3350

    JellyBean3350 Private E-2

    Ok. I have done everything in the tutorial. Still no fix. :rolleyes:

    Any help would be greatly appreciated.

    Thank you,

    JB
     
  4. TheOldThug

    TheOldThug First Sergeant

    Submit a HJT log. Be sure to follow the instructions, in #2 in this thread, regarding the use and posting of a HJT log.
     
  5. JellyBean3350

    JellyBean3350 Private E-2

    Ha. Well, I rebooted again to get an accurate HJT, since I had shut down the process on the previous reboot. It's gone now! Voila!

    The only thing I did different on the previous reboot was use HJT to fix a "test.exe" that was showing up under system32 (I think that's where it was, now that it's gone I can't tell you for sure).

    But maybe it was associated with the YSB somehow? Who knows, but they are both gone now. Hopefully they will stay gone, and I won't have to come back.

    Thank you for your time, though. Hope I didn't waste too much of it.

    :)
     
  6. JellyBean3350

    JellyBean3350 Private E-2

    Just FYI in case anyone else has trouble with YSB.

    C:\WINDOWS\system32\test.exe was the last thing I fixed with HJT.

    Not sure that was finally what fixed it, but definitely worth mentioning since my problem went away after I did it.
     
  7. TheOldThug

    TheOldThug First Sergeant


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds