Incomplete Removal - IST.ISTBar

S

Steve

Removal of IST.ISTBar (maybe other variants as well)
leaves sqldata1.exe in the %SystemRoot% directory, and
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run key.
 
S

Steve

Didn't try in safe mode.

There was no running process for this program (hence the
safe mode question ?). The sqldata1 executable was being
fired by the run key which prompted the user (not my
machine) for their dialup connection, which in turn
downloads and installs the ISTBar trojans. The security
agents picked it up and blocked as it, but failed to
remove the root-cause of the problem.

The user level security at the time had Admin privileges.

Hope this helps.
 
B

Bill Sanderson

Thanks - yes, the safe mode recommendation is to deal with a running process
which may prevent deletion of files. It shouldn't be necessary, but
experience has shown that it helps in enough cases that it is worth trying.

Dosn't sound like it would help for your case, though. What Windows version
was this on?

--
FAQ for Microsoft Antispyware:
http://www.geocities.com/marfer_mvp/FAQ_MSantispy.htm

Steve said:
Didn't try in safe mode.

There was no running process for this program (hence the
safe mode question ?). The sqldata1 executable was being
fired by the run key which prompted the user (not my
machine) for their dialup connection, which in turn
downloads and installs the ISTBar trojans. The security
agents picked it up and blocked as it, but failed to
remove the root-cause of the problem.

The user level security at the time had Admin privileges.

Hope this helps.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top