IST.ISTbarActiveX

S

Sandy

I cannot remove the above virus. Has been detected daily
for about two weeks. Should I be concerned?
 
A

Andre Da Costa

http://www.doxdesk.com/parasite/ISTbar.html

Or, use Ad-aware (or) SpyBot Search & Destroy.

Ad-aware here:

http://www.lavasoft.de/ms/index.htm

SpyBot here:

http://www.safer-networking.org/microsoft.en.html

by Ron Chamberlin - how possibly remove spyware and unwanted browser helper
objects in Windows, Internet Explorer with Microsoft AntiSpyware.

Boot into Safe Mode (F8) at Start Up;

Empty your temporary files AND your Temporary Internet Files C:\Documents

and Settings\Username\Local Settings\Temporary Internet Files folder ;

Run the scan while in safe mode;

If you are running SP2, open IE--->Tools--->Manage Add-ons, and uncheck any

BHO's that you don't recognize.
 
A

AndyManchesta

Its adware and a parasite but the problem can be fixed
easily enough:

First use this fixtool from Symantec :

http://securityresponse.symantec.com/avcenter/FxIstbar.exe

Download it to your desktop and reboot into safe mode
(reboot and keep tapping F8 then choose sfae mode)

double click the fix tool to start the istbar remover.

also run MS Antispy while in safe mode



To check for this manually try this:


Check your Add/Remove Programs for

MS AUpdate
MS Updates
ISTbar

Any remove if found


Open c/drive then Program files and check for a folder
called ISTBar if you find it Un-register the.dll as
explained below then remove the folder

Also check for any of these folders and remove if found

SideFind
YourSiteBar
ISTsvc


If you find the folder reboot into safe mode(reboot and
keep tapping F8 then choose safe mode from the list)


In safe mode:

Open a command prompt (Start >Run > and type cmd > then
paste this in and press enter :

cd "%WinDir%\System"
regsvr32 /u "\Program Files\ISTbar\istbar.dll"


Remove any folders found then reboot ,


The ActiveX issue can be cleared using hijack this if
thats all that remains of this.there is alot of registry
entries involved so using the remover is the best start
to make sure your not still infected , if this doesnt
clear the problem download hijack this and post the log
and we can take out the ActiveX causing this.


Hijack This

http://www.spywareinfo.com/~merijn/files/hijackthis.zip

Unpack it to its own folder(either c/drive or desktop) ,
Extract & run,Choose to run a scan and save the
logfile.The ActiveX entries are displayed as 016 DPF -
but post them if you need help


GoodLuck

Andy
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top