ISTBar

C

Chris

Hi

Ive found that the IST bar isnt blocked by antispyware
and managed to install itself and a whole load of other
stuff successfully. It seems that the program
doesnt "protect" like an antivirus program would, but
rather "monitor" and deal with things "after-the-fact".
I would consider this a weakness in the program.

Chris
 
G

Guest

Exactly, I am also a victim of the IST.Bar threat...Could
any1 tell me how to remove it???

P.S. Maybe this helps...(Hijackthis log)

Logfile of HijackThis v1.99.1
Scan saved at 5:42:40 PM, on 2/20/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norman\bin\ZANDA.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\PROGRAM FILES\NORMAN\Nvc\BIN\NVCSCHED.EXE
C:\PROGRAM FILES\NORMAN\Nvc\BIN\nipsvc.exe
C:\Program Files\Norman\bin\NJEEVES.EXE
C:\PROGRAM FILES\NORMAN\Nvc\BIN\nvcoas.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\AcerGoto.exe
C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
C:\Program Files\RAM Idle\RAM_XP.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.24.0
\gnotify.exe
C:\WINDOWS\soundman.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\Hewlett-Packard\HP Share-to-
Web\hpgs2wnd.exe
C:\Program Files\Norman\bin\ZLH.EXE
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\sqgoggpa.exe
C:\WINDOWS\system32\wini.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-
Web\hpgs2wnf.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Norman\Nvc\BIN\NIP.EXE
C:\Program Files\Magic Keyboard\MagicKey.exe
C:\Program Files\Norman\Nvc\bin\cclaw.exe
C:\Program Files\Magic Keyboard\V3D.exe
C:\Program Files\Magic Keyboard\OSD.EXE
C:\Program Files\AdTools Service\AdTools.exe
C:\Program Files\ISTsvc\istsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Loesje\My
Documents\Other\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL
=

http://www.fountianofyouth.com
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Search Bar =

http://www.couldnotfind.com/search_page.html?
&account_id=157986
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Search Page =

http://www.couldnotfind.com/search_page.html?
&account_id=157986
R1 - HKCU\Software\Microsoft\Internet
Explorer\Search,SearchAssistant =

http://www.couldnotfind.com/search_page.html?
&account_id=157986
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local
Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local
Page =
O2 - BHO: AcroIEHlprObj Class -

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program

Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-
206D7942484F} - (no file)
O2 - BHO: BAHelper Class - {A3FDD654-A057-4971-9844-
4ED8E67DBBB8} -

C:\Program Files\SideFind\sfbho.dll
O2 - BHO: Google Toolbar Helper -

{AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program

files\google\googletoolbar1.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-
FADC6B084872} - (no

file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-
009027A5CD4F} -

c:\program files\google\googletoolbar1.dll
O3 - Toolbar: ISTbar - {5F1ABCDB-A875-46c1-8345-
B72A4567E486} -

C:\PROGRA~1\ISTbar\istbar.dll
O4 - HKLM\..\Run: [AcerGoto] C:\WINDOWS\System32
\AcerGoto.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program

Files\Java\j2re1.4.2_01\bin\jusched.exe
O4 - HKLM\..\Run: [RAM Idle Professional] C:\Program
Files\RAM

Idle\RAM_XP.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-
b109a192b4c2}] C:\Program

Files\Google\Gmail Notifier\G001-1.0.24.0\gnotify.exe
O4 - HKLM\..\Run: [SoundMan] soundman.exe
O4 - HKLM\..\Run: [ATIPTA] atiptaxx.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon]
C:\Program

Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32
\\NeroCheck.exe
O4 - HKLM\..\Run: [Norman ZANDA] C:\Program
Files\Norman\bin\ZLH.EXE

/LOAD /SPLASH
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft

AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [QeAd] C:\WINDOWS\sqgoggpa.exe
O4 - HKLM\..\Run: [<°ÜZJÝYMÝlY«Q°aÆ+À¼C:\Program

Files\ISTsvc\istsvc.exe] C:\WINDOWS\sqgoggpa.exe
O4 - HKLM\..\Run: [virtual-machine] wini.exe
O4 - HKLM\..\Run: [AdTools Service] C:\Program
Files\AdTools

Service\AdTools.exe
O4 - HKLM\..\Run: [IST Service] C:\Program
Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power
Scan\powerscan.exe
O4 - HKLM\..\RunServices: [virtual-machine] wini.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32
\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN
Messenger\msnmsgr.exe"

/background
O4 - HKCU\..\Run: [win-xp] winis.exe
O4 - HKCU\..\Run: [virtual-machine] wini.exe
O4 - HKCU\..\RunServices: [win-xp] winis.exe
O4 - HKCU\..\RunServices: [virtual-machine] wini.exe
O4 - Global Startup: Magic Keyboard.lnk = C:\Program
Files\Magic

Keyboard\MagicKey.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program
Files\Microsoft

Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet
Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet
Explorer\Control Panel present
O8 - Extra context menu item: &Google Search -
res://C:\Program

Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links -
res://C:\Program

Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page -
res://C:\Program

Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel -


res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages -
res://C:\Program

Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English -
res://C:\Program

Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-
00401C608501} -

C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-
B3F6EC39B807} -

C:\Program Files\SideFind\sidefind.dll
O9 - Extra button: Turbo Memory Charger -

{ECC5778A-6E89-BFCE-13CE-81F134789E7B} -

C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Turbo Memory Charger -

{ECC5778A-6E89-BFCE-13CE-81F134789E7B} -

C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-
00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://global.acer.com/
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C}
(Checkers Class) -

http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94}
(PCPitstop Utility) -

http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {11111111-1111-1111-1111-111111111147} -
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
(Windows Genuine

Advantage Validation Tool) -

http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C}
(ICSScannerLight

Class) -
http://download.zonelabs.com/bin/free/cm/ICSCM.cab
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E}
(Microsoft PID

Sniffer) -
https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B}
(FilePlanet

Download Control Class) -

http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} -

http://www.xblock.com/download/xclean_micro.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
(WUWebControl

Class) -

http://v5.windowsupdate.microsoft.com/v5consumer/V5Control
s/en/x86/client/wuw

eb_site.cab?1097256290328
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D}

(MessengerStatsClient Class) -

http://messenger.zone.msn.com/binary/MessengerStatsClient.
cab
O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125}
(mhLabel Class) -

http://www.pcpitstop.com/mhLbl.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539}
(Crucial cpcScan)

- http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46}
(IMDownloader

Class) -
http://www2.incredimail.com/contents/setup/downloader/imlo
ader.cab
O23 - Service: Norman API-hooking helper (NipSvc) -
Unknown owner -

C:\PROGRAM FILES\NORMAN\Nvc\BIN\nipsvc.exe
O23 - Service: Norman NJeeves - Unknown owner -
C:\Program

Files\Norman\bin\NJEEVES.EXE
O23 - Service: Norman ZANDA - Unknown owner - C:\Program

Files\Norman\bin\ZANDA.EXE
O23 - Service: Norman Virus Control on-access component
(nvcoas) - Norman

ASA - C:\PROGRAM FILES\NORMAN\Nvc\BIN\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler
(NVCScheduler) - Norman Data

Defense Systems - C:\PROGRAM
FILES\NORMAN\Nvc\BIN\NVCSCHED.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32
\HPZipm12.exe
 
C

Chris Newman

Yes, I found instructions and a removal tool on the Symantec Web Site

Exactly, I am also a victim of the IST.Bar threat...Could
any1 tell me how to remove it???

P.S. Maybe this helps...(Hijackthis log)

Logfile of HijackThis v1.99.1
Scan saved at 5:42:40 PM, on 2/20/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norman\bin\ZANDA.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\PROGRAM FILES\NORMAN\Nvc\BIN\NVCSCHED.EXE
C:\PROGRAM FILES\NORMAN\Nvc\BIN\nipsvc.exe
C:\Program Files\Norman\bin\NJEEVES.EXE
C:\PROGRAM FILES\NORMAN\Nvc\BIN\nvcoas.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\AcerGoto.exe
C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
C:\Program Files\RAM Idle\RAM_XP.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.24.0
\gnotify.exe
C:\WINDOWS\soundman.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\Hewlett-Packard\HP Share-to-
Web\hpgs2wnd.exe
C:\Program Files\Norman\bin\ZLH.EXE
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\sqgoggpa.exe
C:\WINDOWS\system32\wini.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-
Web\hpgs2wnf.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Norman\Nvc\BIN\NIP.EXE
C:\Program Files\Magic Keyboard\MagicKey.exe
C:\Program Files\Norman\Nvc\bin\cclaw.exe
C:\Program Files\Magic Keyboard\V3D.exe
C:\Program Files\Magic Keyboard\OSD.EXE
C:\Program Files\AdTools Service\AdTools.exe
C:\Program Files\ISTsvc\istsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Loesje\My
Documents\Other\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL
=

http://www.fountianofyouth.com
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Search Bar =

http://www.couldnotfind.com/search_page.html?
&account_id=157986
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Search Page =

http://www.couldnotfind.com/search_page.html?
&account_id=157986
R1 - HKCU\Software\Microsoft\Internet
Explorer\Search,SearchAssistant =

http://www.couldnotfind.com/search_page.html?
&account_id=157986
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local
Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local
Page =
O2 - BHO: AcroIEHlprObj Class -

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program

Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-
206D7942484F} - (no file)
O2 - BHO: BAHelper Class - {A3FDD654-A057-4971-9844-
4ED8E67DBBB8} -

C:\Program Files\SideFind\sfbho.dll
O2 - BHO: Google Toolbar Helper -

{AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program

files\google\googletoolbar1.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-
FADC6B084872} - (no

file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-
009027A5CD4F} -

c:\program files\google\googletoolbar1.dll
O3 - Toolbar: ISTbar - {5F1ABCDB-A875-46c1-8345-
B72A4567E486} -

C:\PROGRA~1\ISTbar\istbar.dll
O4 - HKLM\..\Run: [AcerGoto] C:\WINDOWS\System32
\AcerGoto.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program

Files\Java\j2re1.4.2_01\bin\jusched.exe
O4 - HKLM\..\Run: [RAM Idle Professional] C:\Program
Files\RAM

Idle\RAM_XP.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-
b109a192b4c2}] C:\Program

Files\Google\Gmail Notifier\G001-1.0.24.0\gnotify.exe
O4 - HKLM\..\Run: [SoundMan] soundman.exe
O4 - HKLM\..\Run: [ATIPTA] atiptaxx.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon]
C:\Program

Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32
\\NeroCheck.exe
O4 - HKLM\..\Run: [Norman ZANDA] C:\Program
Files\Norman\bin\ZLH.EXE

/LOAD /SPLASH
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft

AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [QeAd] C:\WINDOWS\sqgoggpa.exe
O4 - HKLM\..\Run: [<°ÜZJÝYMÝlY«Q°aÆ+À¼C:\Program

Files\ISTsvc\istsvc.exe] C:\WINDOWS\sqgoggpa.exe
O4 - HKLM\..\Run: [virtual-machine] wini.exe
O4 - HKLM\..\Run: [AdTools Service] C:\Program
Files\AdTools

Service\AdTools.exe
O4 - HKLM\..\Run: [IST Service] C:\Program
Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power
Scan\powerscan.exe
O4 - HKLM\..\RunServices: [virtual-machine] wini.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32
\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN
Messenger\msnmsgr.exe"

/background
O4 - HKCU\..\Run: [win-xp] winis.exe
O4 - HKCU\..\Run: [virtual-machine] wini.exe
O4 - HKCU\..\RunServices: [win-xp] winis.exe
O4 - HKCU\..\RunServices: [virtual-machine] wini.exe
O4 - Global Startup: Magic Keyboard.lnk = C:\Program
Files\Magic

Keyboard\MagicKey.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program
Files\Microsoft

Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet
Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet
Explorer\Control Panel present
O8 - Extra context menu item: &Google Search -
res://C:\Program

Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links -
res://C:\Program

Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page -
res://C:\Program

Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel -


res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages -
res://C:\Program

Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English -
res://C:\Program

Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-
00401C608501} -

C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-
B3F6EC39B807} -

C:\Program Files\SideFind\sidefind.dll
O9 - Extra button: Turbo Memory Charger -

{ECC5778A-6E89-BFCE-13CE-81F134789E7B} -

C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Turbo Memory Charger -

{ECC5778A-6E89-BFCE-13CE-81F134789E7B} -

C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-
00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://global.acer.com/
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C}
(Checkers Class) -

http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94}
(PCPitstop Utility) -

http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {11111111-1111-1111-1111-111111111147} -
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
(Windows Genuine

Advantage Validation Tool) -

http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C}
(ICSScannerLight

Class) -
http://download.zonelabs.com/bin/free/cm/ICSCM.cab
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E}
(Microsoft PID

Sniffer) -
https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B}
(FilePlanet

Download Control Class) -

http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} -

http://www.xblock.com/download/xclean_micro.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
(WUWebControl

Class) -

http://v5.windowsupdate.microsoft.com/v5consumer/V5Control
s/en/x86/client/wuw

eb_site.cab?1097256290328
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D}

(MessengerStatsClient Class) -

http://messenger.zone.msn.com/binary/MessengerStatsClient.
cab
O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125}
(mhLabel Class) -

http://www.pcpitstop.com/mhLbl.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539}
(Crucial cpcScan)

- http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46}
(IMDownloader

Class) -
http://www2.incredimail.com/contents/setup/downloader/imlo
ader.cab
O23 - Service: Norman API-hooking helper (NipSvc) -
Unknown owner -

C:\PROGRAM FILES\NORMAN\Nvc\BIN\nipsvc.exe
O23 - Service: Norman NJeeves - Unknown owner -
C:\Program

Files\Norman\bin\NJEEVES.EXE
O23 - Service: Norman ZANDA - Unknown owner - C:\Program

Files\Norman\bin\ZANDA.EXE
O23 - Service: Norman Virus Control on-access component
(nvcoas) - Norman

ASA - C:\PROGRAM FILES\NORMAN\Nvc\BIN\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler
(NVCScheduler) - Norman Data

Defense Systems - C:\PROGRAM
FILES\NORMAN\Nvc\BIN\NVCSCHED.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32
\HPZipm12.exe
 
K

KC

-----Original Message-----
Yes, I found instructions and a removal tool on the Symantec Web Site

Exactly, I am also a victim of the IST.Bar threat...Could
any1 tell me how to remove it???

P.S. Maybe this helps...(Hijackthis log)

Logfile of HijackThis v1.99.1
Scan saved at 5:42:40 PM, on 2/20/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
All I have to say is PLEASE dont mess with your registry
keys unless you know what you are doing, even then BE VERY
CAREFULL!!!! I am having the same problem, but mine seems
to be worse than everyone else. Mine as far as I know got
deleted through Microsoft's AntiSpyware. Although now
Internet Explorer refuses to work. I posted about it "I
don't know what to call this" I dont know where its at
though im looking
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top