SoftwareTipsandTricks Forum

Go Back   SoftwareTipsandTricks Forum > Operating Systems > Windows NT/2000/2003
User Name
Password


ISTbar regkey

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes

  #1  
Old 12-19-2004, 08:05 PM
NeutroFox Offline
Junior Member
 
Join Date: Dec 2004
Posts: 2
Red face ISTbar regkey

I had an ISTsvc.exe installed on my computer. Thankfully Ad-aware was able to remove the components of it I followed several sites that explained how to get rid of it and it did. NO MORE ISTsvc! (w00t) However,

ISTbar is still left on my comp. It is located only uner Regkey adn value when ad-aware scans it. I can deleat it but it would only reappear 5 minutes later. Help please!

Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

istbar Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-343818398-1788223648-682003330-1000\software\ist

istbar Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-343818398-1788223648-682003330-1000\software\ist
Value : Recover

Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 2
Objects found so far: 2


Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
<STOP>
6:45:32 PM Scan stopped by user

Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:00:07.312
Objects scanned:27552
Objects identified:2
Objects ignored:0
New critical objects:2
Reply With Quote

  #2  
Old 12-19-2004, 10:31 PM
Play_The_0dds's Avatar
Play_The_0dds Offline
Risk it all
 
Join Date: Oct 2003
Posts: 2,231
removal instructions and a removal tool can be found on the link below...happy hollidays

http://sarc.com/avcenter/venc/data/adware.istbar.html
Reply With Quote

  #3  
Old 01-05-2005, 10:46 AM
jewellb Offline
Junior Member
 
Join Date: Jan 2005
Location: Near St. Louis
Posts: 7
ISTBAR

I have the "exact" same problem with the ISTBAR except I 'm running WinXP Professional. Have tried Ad-Aware, SpyBot, Norton Antivirus 2005 (including the Norton site suggested by “play the odds”), w/o success. Ad-Aware detects and deletes them, but they almost immediately return. Have manually deleted the registry entry but it returns on reboot. Have tried numerous manual removal instructions with no success.

Just dunno
Reply With Quote

  #4  
Old 01-05-2005, 04:52 PM
jewellb Offline
Junior Member
 
Join Date: Jan 2005
Location: Near St. Louis
Posts: 7
ISTBAR Good News/Bad News

Good News: I was finally able to permanentely eliminate all pieces of ISTBAR, inlcuding the two registry entries referred to above.

Bad News: I'm not 100% certiain just how I did it as I performed a number of actions including the download of several additional free SPYWARE software packages.

The following may be the "fix". Download and run "Bazooka Scanner". This software identified 3 spyware entries, inlcuding ISTBAR. At least one of the two remaining entries was somehow related to ISTBAR. I followed the manual removal instructions for all three entries. Ran AdAware again, deleted the typical ISTBAR entries (again) and now it seems to be gone for good.

Give it a try and let us know!
Reply With Quote

  #5  
Old 01-06-2005, 01:29 PM
loni2142's Avatar
loni2142 Offline
Junior Member
 
Join Date: Jan 2005
Location: CC, TX
Posts: 5
Send a message via AIM to loni2142 Send a message via Yahoo to loni2142
istsvc.exe

I have been trying to remove this file! I have tried to download Bazooka Scanner & apparently it doesn't download. I can't even delete the folder from the Programs File folder. It says I don't have access to remove it. Somebody, please help me!
__________________
loni2142
Reply With Quote

  #6  
Old 01-08-2005, 08:05 AM
jewellb Offline
Junior Member
 
Join Date: Jan 2005
Location: Near St. Louis
Posts: 7
You could boot in safe mode and manually delete the file but it will most likely reload on your next reboot.

Suggest you try using Microsoft’s new antispyware software (beta version) or wait for the final product release. It seems to me to be a very good anti spyware software package, especially considering it’s free, and may very well take care of that ISTBAR crapola. It will probably identify and remove lot of other spyware on your pc as well.

Good Luck!
Reply With Quote

  #7  
Old 01-09-2005, 06:31 PM
loni2142's Avatar
loni2142 Offline
Junior Member
 
Join Date: Jan 2005
Location: CC, TX
Posts: 5
Send a message via AIM to loni2142 Send a message via Yahoo to loni2142
Smile

Hi! Thanks for the info. I did download/install the Microsoft Antispyware. Ran it once. Found that and more, as you said! I ran it again & found nothing. However, my antivirus program (AVG) detected that file but under C:/System...

I think it something about restore??

Do you know how I can completely remove this "crapola" as you call it?!
__________________
loni2142
Reply With Quote

  #8  
Old 01-09-2005, 08:47 PM
jewellb Offline
Junior Member
 
Join Date: Jan 2005
Location: Near St. Louis
Posts: 7
Crapola

The antispy software should be able to identify and delete the sypway/scumware crapola from your restoration files too. Assuming you haven’t done so already, try running a “full system scan” with the antispy software instead of the quick scan
Reply With Quote

  #9  
Old 01-09-2005, 09:02 PM
loni2142's Avatar
loni2142 Offline
Junior Member
 
Join Date: Jan 2005
Location: CC, TX
Posts: 5
Send a message via AIM to loni2142 Send a message via Yahoo to loni2142
Thanks for the quick reply. Actually, I have been running full system scans every time.

This is what the virus warning message says,

"Virus Trojan horse downloader.istbar.5.AJ is found in file C:\System Volume Information\restore{94B4087E...}\RP110\A0008737.ex e"

This warning message comes up provided by my antivirus program AVG from GRISOFT. What is also strange is that when I actually run the AV program, it comes back clean.
__________________
loni2142
Reply With Quote

  #10  
Old 01-10-2005, 07:08 PM
NeutroFox Offline
Junior Member
 
Join Date: Dec 2004
Posts: 2
Smile ISTbar permenantly removed

I fixed my istbar problem a few weeks back. What i did was found the program, Hijackthis.exe. You can download it somewhere off the internet, just google it. Well anyway, when you got it, restart the computer in safe mode, and use the program to find the istbar file. Deleate it. Afterward I restarted again in the normal boot, and scanned my comp and it never reappeared. I've been about 3 weeks free of all that IST crap. Hope this works
Reply With Quote

  #11  
Old 01-10-2005, 07:16 PM
loni2142's Avatar
loni2142 Offline
Junior Member
 
Join Date: Jan 2005
Location: CC, TX
Posts: 5
Send a message via AIM to loni2142 Send a message via Yahoo to loni2142
Thanks for the suggestion! I will try that route & let you know!
__________________
loni2142
Reply With Quote

  #12  
Old 01-11-2005, 01:26 PM
loni2142's Avatar
loni2142 Offline
Junior Member
 
Join Date: Jan 2005
Location: CC, TX
Posts: 5
Send a message via AIM to loni2142 Send a message via Yahoo to loni2142
Unhappy

Well, I ran HijackThis & I didn't see anything in the log about Istsvc.exe or anything about Ist period. Does this mean it's completely gone? If so, why do I still get that warning message from my antivirus program? Warning says (Resident shield from AVG) to run AVG (antivirus program) to remove that file. What do I do next?
__________________
loni2142
Reply With Quote
Reply




Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump



All times are GMT -5. The time now is 06:19 PM.


Designed by eXtremepixels. Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 2.3.2 © 2005, Crawlability, Inc.