This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

ISTbar, YourSiteBar, KnownBadSites, PurityScan

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

You are certainly welcome, glad I could help a little :)
You can override cookie handling proceedures like this: Internet Explorer > Tools > Internet Options > Privacy > Edit. You can list cookies you always want to block and always wish to allow.

Do let me know if turning off "Cookies" and "Active Scripting" is advisable. Also, how much am I supposed to donate?


Up to the individual users choice. I block all cookies myself, but it did take a while for the computer to learn which cookies I wanted blocked and did not want to be asked about. Now I very rarely find a cookies when I run Ad-aware/Spybot. Cookies I need for online banking, password, etc. are listed to always be allowed.
:) I am a volunteer and your thanks is what I work for. Tom can always use donations to defray the costs of running a site like this. What you give or even if you give is up to you.
Hope this helps…Phil
Well thank you again, everything seems to be working Great! I haven't had one pop up scince your advice, which is a very good thing. I know I said this was the last time but I do have one more small alarm. I went to MSCONFIG>Startup> and I looked at the list of programs. C:\Program Files\rttt\ersr.exe is still on the list of Startup Programs. The location next to it is: SOFTWARE\Microsoft\Windows\ CurrentVersion\Run. I figured that it is something in the registry so I can go delete it. It turns out the closest location I can find is: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run the problem with that is that I don't see a value or key in there that seems to have anylink with whatever ersr.exe is. Is this a bad sign? Another thing I ment to ask about is that before I started removing all the viruses and junk I made a back up of the registry while I still had all the spyware and junk on my pc. It's ok to delete that immediately right? Because I think I should before I make a new back up. That way if something screws up I won't get the two confused somehow.
We looked at all of the programs and that item C:\Program Files\rttt\ersr.exe is not there. Make sure all files and folder are enabled and search for it. I don't think you will find it. I believe it is just a dead registry line. Try running "Issues" in CCleaner again. If it finds anything you will get a prompt to back up, do so. Once that is done I would move on and concern myself with not allowing the junk to get on your computer again.

I would think that any registry backup you made before the cleanup began would not be something you would want back on the computer. My thought would be to create a new backup if you do any editing in your registry.
http://service1.symantec.com/SUPPORT/tsgen…17?OpenDocument

I used to use Jouni Vuoro's RegCleaner log ago then they it stopped being freeware. Seems He has returned with a new freeware product if you want to try a cleaner. I still suggest a backup.
http://www.worldstart.com/weekly-download/…-cleaner4.3.htm

Good luck…Phil
I hate to say it but I have more bad news. I just finished running Spybot, Ad-Aware, ewido, and CCleaner, which did not detect anything. However I ran SpywareDoctor and Xoftspy And both of them detected the same threats. Here are the threats….Note: I also put the Type and catagory

ISTBar - RegistryKey - Malware - software\microsoft\windows\currentversion\internetsettings\zonemap\domains\
contentmatch.net

Mirar - RegistryKey - Worm - software\microsoft\windows\currentversion\internetsettings\zonemap\domains\net- nucleus.com

CWS.Homepage - Host File Item - Browser Hijacker - websearch.com

There is something funny about those three threats, especially that last one. I just up dated the HOST file from the link that you sent. Also I went to regedit and had a look at the registry. I went to:

HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Internet Settings\Zonemap\Domains

There I saw a folder for every entry in the HOST File. The only program I downloaded was Cleanup! a few days ago, I downloaded that from the link you posted. I did have to enable cookies in order to sign in to Ebay on one night. Which reminds me to ask, should I list ebay as a trusted site? I'm not sure what's going on, but if you have time to help me out again I will really appreciate it. I turned off cookies, I'm not sure if that junk could come through there anyways, and I haven't used Bearshare since the day when my computer was still clean. Here is my log:

Logfile of HijackThis v1.99.1
Scan saved at 7:21:16 PM, on 9/21/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\Program Files\HijackThis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://download.windowsupdate.com
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1111273098488
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
I hate to say it too, but we have carried this about as far as we can. I have no faith in either of the programs you mention. I gave you a link to an excellent registry cleaner. If you want those registry lines gone, back up the registry and remove them. If you believe you have a problem with your hosts file, use this tool: http://www.funkytoad.com/hoster.htm to restore your original Hosts file, or use it to do whatever else you want to do with your Hosts files.

I did have to enable cookies in order to sign in to Ebay on one night. Which reminds me to ask, should I list ebay as a trusted site?

That is your choice, I allow NOTHING in my trusted zone. I do not believe anything else is getting on your computer. I believe this is just clutter left from removing old malware. Your HJT log is still clean. Thanks
Ok, thanks, for your help, I have the cleaner downloaded and will get on it immediately. The only sites I have in my trusted sites zone are the windows update sites, though I'll look at removing those too. Thanks again and sorry to bother you. This will be my last post so don't worry. lol I have a plane to catch.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI