My New Books!
- ***Discovered: A New Shakespeare Sonnet*** Now Available at Amazon/Kindle
- ***Edward de Vere was Shake-speare: at long last the proof*** is now available at Amazon/ Kindle
- ***Henry David Thoreau and Two Other Autistic Lives: before the diagnosis existed*** is now available on Amazon/Kindle
- ***The Ties of the Railroad Tracks Home: the Poetry of Jared Carter*** Now Available at Amazon / Kindle
Monday, November 28, 2005
Adware & Malware Identifier Index
How to Remove ISTBar.
The following is a detail page of Virtual Grub Street's Adware & Malware Identifier Index:
The information in the Adware & Malware Identifier Index is the result of thousands of web searches. It can not, however, possibly be complete. The subject is vast and constantly changing. Moreover, vendor uninstall tools and other removal tools do not necessarily remove all of an infection from your computer. Vendor uninstall tools, for instance, may silently leave cookies or other tracking software installed. It is suggestible to follow up a removal with one or more adware scans and/or to do an inspection using a HijackThis log. The information on the page is not guaranteed correct and any use you may choose to make of it is entirely at your own risk. ISTBar, SideFind
- Associated Worms/Trojans: W32.IST [Panda]; Win32.IstBar.ap; Win32.IstBar.bp; Win32.IstBar.bm; Win32.Istbar.bo; Win32.Istbar.bu; Win32.Istbar.bx; Win32/IstBar.ce [Computer Associates]; W32/Istbar.CK@dl [F-Prot]; Win32.Istbar.cl; Win32.Istbar.dh; Win32.Istbar.dr; Win32.IstBar.e [Kaspersky]; Win32.Istbar.eo; Win32.IstBar.gen [Kaspersky]; Win32.IstBar.gu [Kaspersky]; Win32.IstBar.i; W32/Istbar.MY [NORMAN]; Win32.IstBar.p[Kaspersky]; Win32.Istbar.u; Win32/PMagic.A [Computer Associates].
- Executable Files: l9lecc.exe; istsvc[1].exe; bb.exe; bundlernetscape.exe; crack.exe; dust.exe; games.exe; iinstall.exe; iinstall19866.exe; installs.exe; ist.exe; ist1.exe; istdownload.exe; istinstall_154074.exe; istinstall_netscape.exe; optimize.exe; scan.exe; penmzp.exe; sidefind.exe; srcle32.exe; ssdbkup.exe; start.exe; uveu42at.exe; ymhfvu.exe.
- Dynamic Link Libraries: acsproxy.dll; cmctl.dll; flashplayer.dll; fwntoolbar.dll; gzlib.dll; istbar.dll; imgconv.dll; intrigue.dll; istactivex.dll; istbar_mainstream[1].dll; istbarcm.dll; lhqibp.dll; mediaaccc.dll; nem218.dll; sfbho.dll; sidefind.dll; srchbar.dll; vic32.dll; ysbactivex.dll.
- Directory/Search Page:
- Uninstall page URL:
- Related Articles: Fighting Malware with Standard Windows Tools (February 25, 2007). You may have more in your bag of tricks than you realize. How to Remove ISearchTech.SideFind; ISearchTech.SideFind Update (08-27-05); How to Remove YourSiteBar; Important Removal Tool Note.
- Notes: According to the Spyware Information Center, this infection is also known as: "DownloadPlus and SearchBarCash-Hijacker. ISTbar/MSCache is also known as MSUpdates\MSCache., Trj/W32.IST[Panda], TrojanDownloader.Win32.IstBar.e[Kaspersky], Spyware/ISTbar[Panda], TrojanDownloader.Win32.IstBar.p[Kaspersky], Trojan Horse[Panda], Adware/nCase[Panda], Win32/IstBar.ce!Downloader[Computer Associates], TrojanDownloader.Win32.IstBar.t[Kaspersky], Win32/PMagic.A!Trojan[Computer Associates], TrojanDownloader.Win32.IstBar.p, actalert.exe, W32/Istbar.CK@dl [F-Prot], Trojan-Downloader.Win32.IstBar.gu [Kaspersky], Adware-ISTbar [McAfee], W32/Istbar.MY [NORMAN]". All variants use a corresponding variant of the TrojanDownloader.Win32.IstBar. ISTBar may download various other parasites while installed. These items may have to be removed separately.
- Most versions of this infection can now be removed by using Spybot S&D.
VGS encourages you to post comments about the service it offers, and, in particular, about your experiences with the removal tools suggested in its pages. Removal tool comments will be most effective in helping those who come after you if you post them to the individual detail page for the malware item you used the tool to remove. Please be as clear and as detailed as possible. The most effective comments might include such information as: 1) What browser and operating system you are are running on your computer (i.e. Windows 98, NT, XP, Linux, Internet Explorer 6.0, Firefox); 2) What updates are installed (i.e. SP1, SP2); 3) What anti-virus/malware package(s) are resident in your computer; and 4) the actions you took in the order you took them.
Wednesday, November 16, 2005
EliteBar Removal Tool Updates to V.2.0.0!!!!!
or How to Remove SearchMiracle/EliteBar (Alt. 1, Rev. 3)
EliteBar; EliteToolbar; EliteSidebar; BargainBuddy; Browser Aid; CashToolbar; FreshBar; GameSpy; MoneyTree; Nail.exe; NaviSearch; navpsrvc.exe (also known as: W32/Forbot-EF, worm); SearchMeUp; SideStep; Spybot - Randex; SupportSoft; SurfSideKick; Win32.RBot; Winmon.exe (also known as: W32/Agobot-KA, trojan); WinMoviePlugIn; and [InternetExplorer Plugin].
The "How to Remove" detail pages for SearchMiracle/EliteBar consist of the articles regularly posted at VGS. The file information for EliteBar is located on the Adware & Malware Indentifier Index itself. Further detail pages will be added on a continuing basis.
Simply Tech's description of the reason why SearchMiracle/EliteBar is so difficult to remove verifies the information in the various Virtual Grub Street articles over the past months:
Actually some software like [SpyBot S&D] v.1.3, CWShredder v.2.12, Noadware, [Ad-Aware] v.6, SpyNuker 2004 and SBC Yahoo! Anti-spy have no success in deleting this very frustrating malware. These programs find and delete it, but it keeps coming back since this new variant is very difficult to remove from the operating system.
The main problem is that the malware creates a lot of registry entries and executes at PC startup, winding itself into RAM and deletes its own *.exe from the C:\Windows\System32 directory.
When ordinary tools try to remove it, they only clean the registry calls, the C:\Windows\EliteToolbar directory and the cabinets files where it originated from, but they don't take any action against the malware itself that is currently running in RAM and waiting for the PC OS to be shut down only to repeat the infestation once again!
This is now well known to be a trick that the newer adware and malware products are widely copying. Perhaps this is the reason that the Elitebar Removal Tool has added so many products to the list of infections it removes. It is certainly the reason that most HijackThis and manual removal instructions direct the user to do file deletions while in Safe Mode.
An [h]euristhic search done with commercial antivirus programs (like Norton AntiVirus and McAfee Virus Scan) gave some FALSE POSITIVE messages when they opened the ETRemover_V130.exe and ETRemover_V131.exe files....The new version 2.0.1 (and the previous beta V.2.0.0) overcomes to this problem by using an external ETRDEF.DAT file wich contains the definitions of all the malwares, virus, trojans and the Registry keys scanned by the program to clean the infected pc.
Also see:
- LQfix Information Page (October 15, 2005) There's a new tool in town!
- How to Remove PokaPoka. (October 12, 2005) Does your EliteBar variant include PokaPoka.exe?
- EliteBar Removal Tool Updates to 2.0.1. (September 21, 2005) The EliteBar Removal Tool now comes in two flavors and two generations!
- SearchMiracle.EliteBar Then and Now (September 20, 2005).
- More on Variant ADW_ELITEBAR.D. (May 27, 2005). "It is a standard XP with two top-end commercial anti-virus programs. Moreover, one of the anti-virus programs -- Trend Micro's PC-Cillin -- we already know..."
- Diabolical new EliteBar variant Strikes the Web!!!! or the one the EliteBar Removal Tool can't remove (May 22, 2005).
- EliteBar Removal Tool Updates to 1.3.0!!!!!or How to Remove SearchMiracle/EliteBar (Alt. 1, Rev. 2)
- Key File Index (May 18, 2005).
- Adware & Malware Identifier Index (May 9, 2005). "The following is an in-progress index of some of the more common malware toolbars/browser helper objects at large on the Internet."
- Is Google Associated with a SearchMiracle Knock-Off? (April 27, 2005). "A question begs the asking: How does NetNucleus generate revenue from its Mirar Toolbar search directory if it enters search terms in the Google Search Engine?"
- HijackThis vs. the Elitebar Removal Tool (April 23, 2005). "While this approach may provide some limited, and temporary, relief, SearchMiracle will soon be back in full force."
- EliteBar Removal Tool Alert: Update V.1.2.2.!!! (April 18, 2005). "The new variants of the malware also completely conceal the presence of the EliteToolbarRemoverV10.exe, so that if you are opening the archive you can only see the readme.doc file that is attached to that and you cannot see the *.exe even if though it is really there!"
- HijackThis vs. SearchMiracle/EliteBar (April 11, 2005).
- How to Remove SearchMiracle/ EliteBar (February 27, 2005).
- Online Bibliography (Regularly updated). A bibliography of Gilbert Wesley Purdy's work on the Web and elsewhere including computer topics.
[re: SearchMiracle.EliteBar Search Miracle Elite Bar EliteToolBar Elitum Elite Toolbar Elite Tool Bar ETBrun YupSearch Yup Search.]
How to Remove small.gz.
The following is a detail page of Virtual Grub Street's Adware & Malware Identifier Index:
The information in the Adware & Malware Identifier Index is the result of thousands of web searches. It can not, however, possibly be complete. The subject is vast and constantly changing. Moreover, vendor uninstall tools and other removal tools do not necessarily remove all of an infection from your computer. Vendor uninstall tools, for instance, may silently leave cookies or other tracking software installed. It is suggestible to follow up a removal with one or more adware scans and/or to do an inspection using a HijackThis log. The information on the page is not guaranteed correct and any use you may choose to make of it is entirely at your own risk.
small.gz
- Executable Files: desktopdancer[1].exe; setup.exe.
- Dynamic Link Libraries:
- Directory/Search Page:
- Uninstall page URL:
- Related Articles: Fighting Malware with Standard Windows Tools (February 25, 2007). You may have more in your bag of tricks than you realize. Important Removal Tool Note.
- Notes: This trojan has recently been used to download SearchMiracle.EliteBar. I have personally found, on one occasion, that Panda detected but did not remove the small.gz trojan but there are reports that this infection can now be removed using Panda's Free Online Scan.
VGS encourages you to post comments about the service it offers, and, in particular, about your experiences with the free removal tools suggested in its pages. Removal tool comments will be most effective in helping those who come after you if you post them to the individual detail page for the malware item you used the tool to remove. Please be as clear and as detailed as possible. The most effective comments might include such information as: 1) What browser and operating system you are are running on your computer (i.e. Windows 98, NT, XP, Linux, Internet Explorer 6.0, Firefox); 2) What updates are installed (i.e. SP1, SP2); 3) What anti-virus/malware package(s) are resident in your computer; and 4) the actions you took in the order you took them.
How to Remove downloader.bjg.
The information in the Adware & Malware Identifier Index is the result of thousands of web searches. It can not, however, possibly be complete. The subject is vast and constantly changing. Moreover, vendor uninstall tools and other removal tools do not necessarily remove all of an infection from your computer. Vendor uninstall tools, for instance, may silently leave cookies or other tracking software installed. It is suggestible to follow up a removal with one or more adware scans and/or to do an inspection using a HijackThis log. The information on the page is not guaranteed correct and any use you may choose to make of it is entirely at your own risk.
downloader.bjg
- Associated Worms/Trojans:
- Executable Files: A0034787.exe; EDow_AS2.exe; installer_MARKETING18.exe; SSK3_B5 Seedcorn 4.exe; VB3.exe ; wrapperouter.exe
- Dynamic Link Libraries:
- Directory/Search Page:
- Uninstall page URL:
- Related Articles: Fighting Malware with Standard Windows Tools (February 25, 2007). You may have more in your bag of tricks than you realize. Important Removal Tool Note.
- Notes: Notes: This infection can be removed using Panda's Free Online Scan.
VGS encourages you to post comments about the service it offers, and, in particular, about your experiences with the free removal tools suggested in its pages. Removal tool comments will be most effective in helping those who come after you if you post them to the individual detail page for the malware item you used the tool to remove. Please be as clear and as detailed as possible. The most effective comments might include such information as: 1) What browser and operating system you are are running on your computer (i.e. Windows 98, NT, XP, Linux, Internet Explorer 6.0, Firefox); 2) What updates are installed (i.e. SP1, SP2); 3) What anti-virus/malware package(s) are resident in your computer; and 4) the actions you took in the order you took them.
How to Remove YourSiteBar.
The following is a detail page of Virtual Grub Street's Adware & Malware Identifier Index:
The information in the Adware & Malware Identifier Index is the result of thousands of web searches. It can not, however, possibly be complete. The subject is vast and constantly changing. Moreover, vendor uninstall tools and other removal tools do not necessarily remove all of an infection from your computer. Vendor uninstall tools, for instance, may silently leave cookies or other tracking software installed. It is suggestible to follow up a removal with one or more adware scans and/or to do an inspection using a HijackThis log. The information on the page is not guaranteed correct and any use you may choose to make of it is entirely at your own risk.
ISearchTech.YSB, YourSiteBar
- Associated Worms/Trojans:
- Executable Files:
- Dynamic Link Libraries: ysb[1].dll; ysbactivex.dll; ysb.dll.
- Directory/Search Page: http://www.sidefind.com/ist/softwares/sidefind/; http://www.sidefind.com/ist/softwares/sidefind/v1.3/.
- Uninstall page URL: http://www.ysbweb.com/uninstall.html. Requires user to install new software the nature of which is not described.
- Related Articles: Fighting Malware with Standard Windows Tools (February 25, 2007). You may have more in your bag of tricks than you realize. How to Remove the ISearchTech Family; How to Remove ISearchTech.SideFind; ISearchTech.SideFind Update (08-27-05); Important Removal Tool Note.
- Notes: As of 10/03/05, according to the YSB EULA, this software comes bundled with the following additional adware: BullsEye; ContextPlus; DealHelper; Internet Optimizer; ShopAtHomeSelect; and Surfaccuracy.
- This infection can be removed by Ewido Security Suite trialware.
- According to ISearchTech, Your Site Bar (ISearchTech.YSB) versions of this infection 'can be uninstalled via the Add or Remove Programs dialog in the Windows Control Panel: Control Panel>Add or Remove Programs>remove all listings for the following : ISTsvc, Yoursitebar or Slotchbar or xxxtoolbar.'
- It may be possible to remove some early versions of this infection using Spybot S&D (see "ISearchTech.SideFind Update (08-27-05)"!).
VGS encourages you to post comments about the service it offers, and, in particular, about your experiences with the removal tools suggested in its pages. Removal tool comments will be most effective in helping those who come after you if you post them to the individual detail page for the malware item you used the tool to remove. Please be as clear and as detailed as possible. The most effective comments might include such information as: 1) What browser and operating system you are are running on your computer (i.e. Windows 98, NT, XP, Linux, Internet Explorer 6.0, Firefox); 2) What updates are installed (i.e. SP1, SP2); 3) What anti-virus/malware package(s) are resident in your computer
PokaPoka.exe + Nothing = YupSearch.
Some few of readers may recall the article YupSearch Addendum posted in VGS's pages this past March 18th. Of course, seven months ago is ancient history on the Internet (and especially ancient in matters of adware and malware). I had since noticed, in passing, that there seemed to have been some changes in how that search engine front-page was being employed. I promised myself to set aside some time, eventually, in order to check out the new version and have discovered a few items to pass along.
To recap, very briefly, a key point from the Addendum:
YupSearch... detects when "404" pages ("page not found") load up into the browser and redirects the browser to the base search engine in their place.
The original YupSearch was a redirect target only. It had no toolbar of its own.
That ended with the EliteSideBar version of the EliteBar infection (a.k.a. adw_elitebar.b). The EliteSideBar opens on left side of screen with numerous entries from the YupSearch front-page rather than from Searchmiracle. Or at least at first, for the EliteSideBar is programmed to download the full-bore Elite ToolBar after the SideBar is installed. If the download is successful, an Elite***32.exe or Kalv***32.exe file is installed and the file InprocServer32 and the YupSearch hijack target are deleted. Thus:
EliteSideBar 08dll + InprocServer32 = the adw_elitebar.b version of YupSearch
or perhaps better put:
EliteSideBar 08dll + Nothing = YupSearch (EliteBar.b version).
Correspondingly:
EliteSideBar 08dll + elite***32.exe (or kalv***32.exe) = EliteSideBar with a YupSearch redirect
and the user (or technician) will find a HijackThis (or other) entry for the SearchMiracle front-page as hijacker target.
The EliteSideBar, however, with its EliteSideBar 08dll and InprocServer32, seems not to have been a very effective variant of EliteBar. It has been all but abandoned for another trojan downloader the name of which has since become infamous: PokaPoka**.exe. The scheme is the same:
PokaPoka + Nothing = YupSearch
Correspondingly:
PokaPoka.exe + Elite***32.exe = EliteBar with a YupSearch redirect..
Once Elite***.exe is downloaded, the YupSearch hijacker target is deleted and the SearchMiracle hijacker installed. The YupSearch front-page target now only appears, if it appears at all, on special redirects, the most common being redirects away from 404 ("page not found") pages.
The reason I refer to SearchMiracle and YupSearch "front-pages" rather than "search engines" is explained in YupSearch Addendum.
Also See:
- Elite Toolbar Remover Information Page (October 17, 2005).
- LQfix Information Page (October 15, 2005) There's a new tool in town!
- How to Remove PokaPoka. (October 12, 2005) Does your EliteBar variant include PokaPoka.exe?
- EliteBar Removal Tool Updates to 2.0.1. (September 21, 2005) The EliteBar Removal Tool now comes in two flavors and two generations!
- SearchMiracle.EliteBar Then and Now (September 21, 2005). Hijacks, heroes, updates and links.
- EliteBar Removal Tool Updates to 2.0.0!!!!! (September 15, 2005). Includes expanded list of infections removed by the removal tool.
- More on Variant ADW_ELITEBAR.D. (May 27, 2005). "It is a standard XP with two top-end commercial anti-virus programs. Moreover, one of the anti-virus programs -- Trend Micro's PC-Cillin -- we already know..."
- Diabolical new EliteBar variant Strikes the Web!!!! or the one the EliteBar Removal Tool can't remove (May 22, 2005).
- EliteBar Removal Tool Updates to 1.3.0!!!!! (May 20, 2005). Includes expanded list of infections removed by the removal tool.
- Adware & Malware Identifier Index (updated regularly). "The following is an in-progress index of some of the more common malware toolbars/browser helper objects at large on the Internet."
- Is Google Associated with a SearchMiracle Knock-Off? (April 27, 2005) "A question begs the asking: How does NetNucleus generate revenue from its Mirar Toolbar search directory if it enters search terms in the Google Search Engine?"
- EliteBar Removal Tool Alert: Update V.1.2.2.!!! (April 18, 2005). "The new variants of the malware also completely conceal the presence of the EliteToolbarRemoverV10.exe, so that if you are opening the archive you can only see the readme.doc file that is attached to that and you cannot see the *.exe even if though it is really there!"
- HijackThis vs. SearchMiracle/EliteBar (April 11, 2005).
- YupSearch Addendum (March 18, 2005).
- Audio Seek Alert (March 18, 2005).
- How to Remove SearchMiracle/ EliteBar (February 27, 2005).
- Online Bibliography (Regularly updated). A bibliography of Gilbert Wesley Purdy's work on the Web and elsewhere including computer topics.
[re: SearchMiracle.EliteBar Search Miracle Elite Bar EliteToolBar Elite Toolbar Elite Tool Bar Elitum ETBrun YupSearch Yup Search.]