Security Issue

Score
0
Vote Up
August 9, 2005 at 06:47:58 Pacific
Specs: Windows ME, 1.5GHZ 512

Can anyone help me.

I have spent many hours trying to solve a security issue.

I am using Trend Micro Pc-cillin 2004 and my firewall is showing "caution" "security rule matched", with alot of different IP addresses.

I have run a virus check, spybot, adaware, and PestPatrol, all updated, and only had 1 report which has prooved unremovable, ISTbar, I have located this in the registry and there is no value, but when i delete it from the registry it returns. I had a serious security issue some time ago, and the pc is completely clean, but I will admit this has occurred since the security issue.

I have run hijackthis, and this is clean, other than a couple of 17s which I have now found to be related to my broadband. (log available if needed).

My running processes are normal, no unusual startup items in msconfig, everything seems ok, but this security rule matched, and istbar are driving me mad.

I have followed removal instructions for istbar, but referenced files and registry entries are not on my pc.

After many hours I need help.

Many thanks


Reply ↓  Report •


#1
Vote Down
Score
0
Vote Up
August 9, 2005 at 07:23:48 Pacific

You state above
OS: Windows ME

You should post in the Windows ME forum, or
the Security and Virus forum.

This is the Windows XP forum.


Reply ↓  Report •

#2
Vote Down
Score
0
Vote Up
August 9, 2005 at 07:28:43 Pacific

Sorry OS is XP

Reply ↓  Report •

#3
Vote Down
Score
0
Vote Up
August 9, 2005 at 07:34:08 Pacific

OK please change your profiles. Thank you.

i_XpUser


Reply ↓  Report •

#4
Vote Down
Score
0
Vote Up
August 9, 2005 at 07:43:45 Pacific

XpUser--

What is that symbol before your name ??
Looks like an O with an i inside.
That is symbol for the company I retired from,
Owens-Illinois Inc.


Reply ↓  Report •

Related Posts

#5
Vote Down
Score
0
Vote Up
August 9, 2005 at 07:54:43 Pacific

chrlstine--

Have you tried your scans for nasties in Windows
Safe-Mode ?? Best to do scans there.

Also nasties like to hide in System Restore files. Turn off System Restore then scan.


Reply ↓  Report •

#6
Vote Down
Score
0
Vote Up
August 9, 2005 at 08:06:55 Pacific

thanks for reply chuck, yes already tried in safe mode and with system restore off.

Reply ↓  Report •

#7
Vote Down
Score
0
Vote Up
August 9, 2005 at 08:09:55 Pacific

What is that symbol before your name ??
Looks like an O with an i inside.
That is symbol for the company I retired from, Owens-Illinois Inc.

I wasn't aware that this symbol is Owens-Illinois Inc. corporate logo. Thanks for the info. Sci-Guy created it for me around the time KTTD was pressurizing me to learn HTML. The i in the O represents InfOrmation. Should I change it?


i_XpUser


Reply ↓  Report •

#8
Vote Down
Score
0
Vote Up
August 9, 2005 at 08:19:36 Pacific

XpUser--
I was just wondering.
O-I is the worlds largest glass container manufacturer.
If went in a market, pick up any glass or beverage container. Then look around at the heel (bottom edge)of the bottle. You may find an O with an i inside.

www.o-i.com


Reply ↓  Report •

#9
Vote Down
Score
0
Vote Up
August 9, 2005 at 08:32:48 Pacific

Thanks Chuck. I now recall seeing that familiar symbol impressed on glass products. Am I now in trouble with I-O over logo infringments, given the facts that you're a retired perwson and you obviously know someone in the company's legal department?

i_XpUser


Reply ↓  Report •

#10
Vote Down
Score
0
Vote Up
August 9, 2005 at 08:34:37 Pacific

Sorry chr1stine for my chattering with Chuck. It's just that we've known each others through this Forum. Hope you don't mind it :-)

i_XpUser


Reply ↓  Report •

#11
Vote Down
Score
0
Vote Up
August 9, 2005 at 08:42:54 Pacific

XP User---
I was just a "pee-on", maintainance mechanic, at one of the plants. I don't care.

Reply ↓  Report •

#12
Vote Down
Score
0
Vote Up
August 9, 2005 at 08:47:48 Pacific

chrlstine--

You could look here
I YAHOO
to see 320,000 web pages for answers.


Reply ↓  Report •

#13
Vote Down
Score
0
Vote Up
August 9, 2005 at 10:54:02 Pacific

Hi Chuck

I have ploughed through suggestions, and found i have already tried them. I have non of the files they suggest removing, yet all my spyware/adware keeps picking up this registry entry, istbar, that cannot be deleted, obviously something is pointing to it, and my firewall is still on caution, although i do not think the istbar is the cause for that.


Reply ↓  Report •

#14
Vote Down
Score
0
Vote Up
August 9, 2005 at 14:09:08 Pacific

I use a host of different spyware scanners but i've found that Ewido fixes this particular infection very well. Download it and give it a try. Also, use the online virus scanner for trendmicro.

http://housecall.trendmicro.com

After everything's clean...we can move on with the other problem. I'm currently using trendmico 2005 but without the firewall. I use Sygate Personal Firewall PRO. All the reviews i've read state that Trendmico catches more viruses then any other (norton, mcafee etc..) but the firewall feature lacks in a lot of ways. I also use the Wifi intrusion detection feature, that works pretty good. just my 2 cents.


Reply ↓  Report •

#15
Vote Down
Score
0
Vote Up
August 9, 2005 at 14:59:02 Pacific

Thanks for your help Scott.

I have already used Housecall, and I must admit it is something I use quite often as it does seem to find threats that pc-cillin 2004 misses.

I am now going to try Ewido, will post back tomorrow with results.


Reply ↓  Report •

#16
Vote Down
Score
0
Vote Up
August 9, 2005 at 16:15:31 Pacific

Hi Scott

I have done an online scan with ewido which could not clean items found. So I then downloaded trial software and again it could not clean. Report listed below:

HKLM\SOFTWARE\ISTbar -> Spyware.ISTBar : Error during cleaning

HKLM\SOFTWARE\ISTbar\Historyfiles -> Spyware.ISTBar : Error during cleaning

HKLM\SOFTWARE\ISTbar\Historystring -> Spyware.ISTBar : Error during cleaning


Reply ↓  Report •

#17
Vote Down
Score
0
Vote Up
August 9, 2005 at 16:24:13 Pacific

wow! this is the first time i've ever heard of it not cleaning that! i'm shocked. Are you logged on as administrator or have admin rights on your account? the report didnt give any more details? anyone else have any suggestions? i'll keep thinking and doing research and let you know if I can come up with anything.

Reply ↓  Report •

#18
Vote Down
Score
0
Vote Up
August 10, 2005 at 01:21:21 Pacific

thanks Scott

I know its mad isnt it, this is why I have spent so many hours on. This morning, for the first time ever, spybot does a scan on startup and calls it Isearch.Sidefind, but when looking at the registry entry it is that ISTbar. My feeling is it is a little dll file somewhere in the system that the registry is pointing at, but as you know there are thousands. Spybot reported it in the memory and would clean at next startup but it didn't. I have searched for every file associated with ISTbar on my system, not one, and this morning searched for files associated with isearch, one found patch.exe, which i know to be a virus, but it is also a file associated with trendmicro. I have files in quarrantine in lower case called patch.exe, but the one found is in c:\windows in upper case, and its well known so i know virus checker would have picked it up.


Reply ↓  Report •

#19
Vote Down
Score
0
Vote Up
August 10, 2005 at 07:51:27 Pacific

I have checked the "Pest Info" on my
Spyware X-terminator
program. In the list it shows 7 ISTBar related entries. So I presume the program will remove it. Program costs a few bucks. Paying for something will probably work better than free programs. Available in stores and online.

***Also, be sure to update any software online
after installation, and every 1-2 weeks.


Reply ↓  Report •

#20
Vote Down
Score
0
Vote Up
August 10, 2005 at 08:07:56 Pacific

"I presume the program will remove it. Program costs a few bucks. Paying for something will probably work better than free programs. Available in stores and online." HAH, its funny that nobody references that as a recommended download except very rarely! Also the free end products usually are commercial brands that cut a lot of the extras so freeloaners like us aren't going pirating. It's also funny that Download.com and even microsoft lists adaware and spybot as recommend spyware removal tools besides their own... Hah!


Anyway, try Spybot and adaware in safe mode, or simply just goto start, run, msconfig, and goto diagnostics, and try a scan with the programs from diag/safe.

Also try A2 Squared (less known but I like it),

Webroot (15 day trial http://www.download.com/Webroot-Spy-Sweeper/3000-8022_4-10192729.html?tag=txt

and

Spyware Doctor
http://www.download.com/Spyware-Doctor/3000-8022_4-10293212.html?tag=txt


Reply ↓  Report •

#21
Vote Down
Score
0
Vote Up
August 10, 2005 at 12:43:43 Pacific

also a very important tool to use is Hijack This.

Reply ↓  Report •

#22
Vote Down
Score
0
Vote Up
September 16, 2005 at 01:59:23 Pacific

If you still have this problem, it's because you need to change the permissions on the key before trying to delete it. I had the same problem and it took me several days to figure this out (on Windows 2000 in my case, so I had to use regedt32 instead of regedit). Anyhow, hope this helps someone out there.

Reply ↓  Report •

Reply to Message Icon Start New Discussion
« Windows Mngmnt Instrument... Windows XP Boot Sector Vi... »

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.

Ask the Community!
Describe your Problem
Example: Hard Drive Not Detected on My PC