Nothing removes Istbar

  • Thread starter Thread starter adrian pan
  • Start date Start date
A

adrian pan

is there a way to remove Istbar malware? Nothing works,
not MS, not Spyware Doctor, Ad-aware, Spybot etc.
Each time i reboot it comes back, and each time MS, and
my Spyware Doctor detects the same entries, removes them,
and everything is cool until i reboot. Safe Mode scans
don't do anything either.
Thanks

adrian p
 
Boot into Safe Mode (F8) at Start Up;

Empty your temporary files AND your Temporary Internet Files C:\Documents

and Settings\Username\Local Settings\Temporary Internet Files folder ;

Run the scan while in safe mode;

If you are running SP2, open IE--->Tools--->Manage Add-ons, and uncheck any

BHO's that you don't recognize.
 
Here is some additional information from Ron Kinner (previous post):
I believe the reason AntiSpy can't get rid of it is that
it is attached to Explorer.exe (your desktop) which is
usually running when you run AntiSpy. The program also
saves copies of itself in the Temporary files. So try the
following:

First get ccleaner from ccleaner.com and install it.
Don't run it yet.

Get HijackThis.exe from
http://tomcoyote.org/hjt/hjt199//HijackThis.exe

Save it to C:\hjt (new folder) but don't run it yet either.

Finally get Pocket Killbox.

http://www.bleepingcomputer.com/files/killbox.php

Download it and extract it to C:\hjt

Boot into Safe Mode (F8) without networking.

Run ccleaner but on the first page uncheck the cookies and
the log files then press Run Cleaner. This guy hides
copies of himself in the temp files with .txt extensions
so we want to get rid of them first.


Start AntiSpy but don't tell it to do anything yet.

Start HijackThis but don't tell it to do anything yet.

Start Killbox the same way.

Right click on the clock and select Task Manager. Select
Processes tab.


Find and highlight explorer.exe and press End Process.
(ignore the warning) This will make your desktop disappear
but don't panic.

Check the other processes to see if any of the known bad
guys are running:

winstall.exe
on-line.exe
dropper.exe

In Task Manager, select Applications, highlight Killbox
and Switch To.

IF you saw any of the bad processes running: In the
killbox screen at the bottom right you will see a dropdown
list with a yellow triangle next to it. Press on the down
arrow to the left of the triangle to open the list. Find
and highlight any of the bad processes that are still
running and press the yellow triangle. It will tell you
that it is just stopped and not deleted. OK. Recheck to
make sure it is stopped.

Now copy and paste the following into the box below
Full Path of File To Delete:

c:\Windows\System32\winstall.exe

then press the red circle with the white x. It will try
to delete the file. IF it can, good, if it says it can't
then select the Delete on Reboot option and try again.
Repeat for
c:\Windows\System32\wininet32.dll

Go Back To Task Manager and Switch To HijackThis. Select
Scan Only and examine the output closely to see if any
entries mention
winstall.exe
on-line.exe
dropper.exe
wininet32.dll

Check any you find and then when all the bad guys are
checked, press Fix Checked.

Now Switch To AntiSpy:

Open Advanced Tools, System Explorers, Internet Explorer,
IE BHOs highlight and BLOCK anything you find there.
Repeat for System, Shell Extensions except leave anything
with a pretty yellow star. (Especially do not block
Shell32.dll).

Now under Scan Option make sure you have all three options
checked. Do a full Scan. If it finds anything on the
first pass, run ccleaner again with the same options as
before and then let it run a second time.

Go back to task manager and restore the desktop by File,
New Task (Run), explorer.exe, OK)

Reboot and run HijackThis, Sacn and Save log and send me
the log. Put Hijack in the subject so I will know it's
not Spam.

Ron Kinner

(e-mail address removed)
 
adrian said:
is there a way to remove Istbar malware? Nothing works,
not MS, not Spyware Doctor, Ad-aware, Spybot etc.
Each time i reboot it comes back, and each time MS, and
my Spyware Doctor detects the same entries, removes them,
and everything is cool until i reboot. Safe Mode scans
don't do anything either.
Thanks

adrian p

You might try a-squared, either the free version or the trial of the pay
version.

http://www.emsisoft.com/en/software/free/
 
thanks a lot
i guess im gonna try all these one by one.
I did download this app. The scan doesnt come up with
anything, however, when i reboot, its real time
protection blocks a process from downloading files from
the internet.It says it's malicious activity

The path is HelYa(Name?) C:\windows\ajpmh.exe

i deleted this file, but each time i reboot i get the
prompt on this activity
 
i found the phantom!!...its called ajpmh.exe (never heard
of it, and i found no reference about it on the web),but A
Squared 2 scan, as i said, labeled it as malware, there
were 2 entries associated with this in the registry, i
deleted them in safe mode, rebooted, and now all the scans
come up clean. woo hooo
-)
thanks to everyone!!!!
much appreciated

adrian
 
I too found ajpmh.exe in my Run list in the registry. Now deleted and
ISTbar is no longer coming back. ISTbar is the most persistent piece of
malware I've ever had. It's a real problem and I hope that MS
anti-spyware is updated to deal with it once and for all.

JM2€W,

Simon
 
I too found ajpmh.exe in my Run list in the registry. Now deleted and
ISTbar is no longer coming back. ISTbar is the most persistent piece of
malware I've ever had. It's a real problem and I hope that MS
anti-spyware is updated to deal with it once and for all.

JM2€W,

Simon
 
Back
Top