G

Guest

Guest
Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

hi

i have windows XP SP2 os, i use AVG antivirus,spybot n adaware (all

freewares).i keep them updated.Whenever i use adaware for scanning my hard

disk AVG starts giving warning abt a trojan horse ISTbar. but it is not able

to fix up the problem.I've tried many things including trying to delete its

entry keys in registry but to no avail.Kindly help me to fix the problem
thx
gaggan
 
G

Guest

Guest
Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

From: "gaggan" <gaggan@discussions.microsoft.com>

| hi
|
| i have windows XP SP2 os, i use AVG antivirus,spybot n adaware (all
|
| freewares).i keep them updated.Whenever i use adaware for scanning my hard
|
| disk AVG starts giving warning abt a trojan horse ISTbar. but it is not able
|
| to fix up the problem.I've tried many things including trying to delete its
|
| entry keys in registry but to no avail.Kindly help me to fix the problem
| thx
| gaggan

If you don't have Ad-aware SE v1.05 download it.
Otherwise follow the instructions for its use below.

Dump the contents of the IE Temporary Internet Folder cache (TIF)

start --> settings --> control panel --> internet options --> delete files

1) Download the following three items...

Trend Sysclean Package
http://www.trendmicro.com/download/dcs.asp

Latest Trend Pattern File.
http://www.trendmicro.com/download/pattern.asp

Ad-aware SE (free personal version v1.05)
http://www.lavasoftusa.com/

Trend Sysclean Method 1
---------------------------------------
Create a directory.
On drive "C:\"
(e.g., "c:\sysclean")

Download SYSCLEAN.COM and place it in that directory.
Download the signature files (pattern files) by obtaining the ZIP file.
For example; lpt556.zip

Extract the contents of the ZIP file and place the contents in the same directory as
SYSCLEAN.COM.

Trend Sysclean Method 2
---------------------------------------
The utility SYSCLEAN_FE in "Procedure 1" at the following URL
http://www.ik-cs.com/got-a-virus.htm automates the download and execution process of the
Trend Sysclean Package.

2) Update Ad-aware with the latest definitions.
3) Disable System Restore
http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
4) Reboot your PC into Safe Mode and shutdown as many applications as possible
5) Using both the Trend Sysclean utility and Ad-aware, perform a Full Scan of your
platform and clean/delete any infectors/parasites found.
(a few cycles may be needed)
6) Restart your PC and perform a "final" Full Scan of your platform using both the
Trend Sysclean utility and Adaware
7) Re-enable System Restore and re-apply any System Restore preferences,
(e.g. HD space to use suggested 400 ~ 600MB),
8) Reboot your PC.
9) Create a new Restore point

* Please report back your results ! *


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm
 
G

Guest

Guest
Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

Microsoft Antispyware Beta1 will remove ISTBar rather easily. Check for
updates after installing it and then do a Full system scan with all 3
options checked. Then do another scan to ensure that IST is gone.

MowGreen [MVP 2004-2005]

===============
*-343-* FDNY
Never Forgotten
===============

gaggan wrote:

> hi
>
> i have windows XP SP2 os, i use AVG antivirus,spybot n adaware (all
>
> freewares).i keep them updated.Whenever i use adaware for scanning my hard
>
> disk AVG starts giving warning abt a trojan horse ISTbar. but it is not able
>
> to fix up the problem.I've tried many things including trying to delete its
>
> entry keys in registry but to no avail.Kindly help me to fix the problem
> thx
> gaggan
 
G

Guest

Guest
Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

hi david
thx 4 the help....i tried all tht u said..
all went fine but the log file said tht few files were inaccessible...like
"An error occurred while scanning file "C:\Documents and
Settings\Administrator\NTUSER.DAT": Access is denied." n similarly many othe
r files...
else i haven't got tht warning which i used to get till now...
so wat now?
thx for ur help
gaggan

"David H. Lipman" wrote:

> From: "gaggan" <gaggan@discussions.microsoft.com>
>
> | hi
> |
> | i have windows XP SP2 os, i use AVG antivirus,spybot n adaware (all
> |
> | freewares).i keep them updated.Whenever i use adaware for scanning my hard
> |
> | disk AVG starts giving warning abt a trojan horse ISTbar. but it is not able
> |
> | to fix up the problem.I've tried many things including trying to delete its
> |
> | entry keys in registry but to no avail.Kindly help me to fix the problem
> | thx
> | gaggan
>
> If you don't have Ad-aware SE v1.05 download it.
> Otherwise follow the instructions for its use below.
>
> Dump the contents of the IE Temporary Internet Folder cache (TIF)
>
> start --> settings --> control panel --> internet options --> delete files
>
> 1) Download the following three items...
>
> Trend Sysclean Package
> http://www.trendmicro.com/download/dcs.asp
>
> Latest Trend Pattern File.
> http://www.trendmicro.com/download/pattern.asp
>
> Ad-aware SE (free personal version v1.05)
> http://www.lavasoftusa.com/
>
> Trend Sysclean Method 1
> ---------------------------------------
> Create a directory.
> On drive "C:\"
> (e.g., "c:\sysclean")
>
> Download SYSCLEAN.COM and place it in that directory.
> Download the signature files (pattern files) by obtaining the ZIP file.
> For example; lpt556.zip
>
> Extract the contents of the ZIP file and place the contents in the same directory as
> SYSCLEAN.COM.
>
> Trend Sysclean Method 2
> ---------------------------------------
> The utility SYSCLEAN_FE in "Procedure 1" at the following URL
> http://www.ik-cs.com/got-a-virus.htm automates the download and execution process of the
> Trend Sysclean Package.
>
> 2) Update Ad-aware with the latest definitions.
> 3) Disable System Restore
> http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
> 4) Reboot your PC into Safe Mode and shutdown as many applications as possible
> 5) Using both the Trend Sysclean utility and Ad-aware, perform a Full Scan of your
> platform and clean/delete any infectors/parasites found.
> (a few cycles may be needed)
> 6) Restart your PC and perform a "final" Full Scan of your platform using both the
> Trend Sysclean utility and Adaware
> 7) Re-enable System Restore and re-apply any System Restore preferences,
> (e.g. HD space to use suggested 400 ~ 600MB),
> 8) Reboot your PC.
> 9) Create a new Restore point
>
> * Please report back your results ! *
>
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>
>
 
G

Guest

Guest
Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

From: "gaggan" <gaggan@discussions.microsoft.com>

| hi david
| thx 4 the help....i tried all tht u said..
| all went fine but the log file said tht few files were inaccessible...like
| "An error occurred while scanning file "C:\Documents and
| Settings\Administrator\NTUSER.DAT": Access is denied." n similarly many othe
| r files...
| else i haven't got tht warning which i used to get till now...
| so wat now?
| thx for ur help
| gaggan
|

That's OK and NOT a problem. If a File Handle is open by the OS, that file can nont be
scanned. NTUSER.DAT is the User Registry, is not an executable and can not be infected,
etc.


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm
 
G

Guest

Guest
Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

hi MowGreen
thx 4 the help...i'll try it..


"MowGreen [MVP]" wrote:

> Microsoft Antispyware Beta1 will remove ISTBar rather easily. Check for
> updates after installing it and then do a Full system scan with all 3
> options checked. Then do another scan to ensure that IST is gone.
>
> MowGreen [MVP 2004-2005]
>
> ===============
> *-343-* FDNY
> Never Forgotten
> ===============
>
> gaggan wrote:
>
> > hi
> >
> > i have windows XP SP2 os, i use AVG antivirus,spybot n adaware (all
> >
> > freewares).i keep them updated.Whenever i use adaware for scanning my hard
> >
> > disk AVG starts giving warning abt a trojan horse ISTbar. but it is not able
> >
> > to fix up the problem.I've tried many things including trying to delete its
> >
> > entry keys in registry but to no avail.Kindly help me to fix the problem
> > thx
> > gaggan
>
 
G

Guest

Guest
Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

hi david
thx once again.
hope i won't have the problem again.
gaggan

"David H. Lipman" wrote:

> From: "gaggan" <gaggan@discussions.microsoft.com>
>
> | hi david
> | thx 4 the help....i tried all tht u said..
> | all went fine but the log file said tht few files were inaccessible...like
> | "An error occurred while scanning file "C:\Documents and
> | Settings\Administrator\NTUSER.DAT": Access is denied." n similarly many othe
> | r files...
> | else i haven't got tht warning which i used to get till now...
> | so wat now?
> | thx for ur help
> | gaggan
> |
>
> That's OK and NOT a problem. If a File Handle is open by the OS, that file can nont be
> scanned. NTUSER.DAT is the User Registry, is not an executable and can not be infected,
> etc.
>
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>
>