First move HJT to a permanent folder - like C:\HJT
Print this out
Istsvc http://securityresponse.symantec.com/avcenter/FxIstbar.exe
From Symantec
Note:
· The date and time displayed will be adjusted to your time zone, if your computer is not set to the Pacific time zone.
· The removal tool may terminate Internet Explorer and Windows Explorer. It is recommended that users save their work and log out of these programs before running the removal tool.
· The removal tool will reset the Internet start page to a blank page. The start page can be modified by clicking on Tools > Internet Options in Internet Explorer.
· The removal tool will not delete some harmless Temporary Internet files, which Adware.Istbar created, in C:\Documents and Setings\Administrator\Local Settings\Temporary Internet Files.
These can be manually deleted using the following steps:
a. Start Internet Explorer.
b. Click Tools > Internet Options.
c. In the Temporary Internet Files section, then click the Delete Files button.
Check Delete all offline content, and then click OK.
Boot to safe mode
With HJT fix
O2 - BHO: CWebDirObj Object - {C003C49F-53E4-4A72-B7D6-0B2B9997392F} - C:\WINDOWS\webdir.dll
O4 - HKLM\..\Run: [FPyJ] C:\WINDOWS\ciojv.exe
O4 - HKLM\..\Run: [¢¸K0¨4W
}ïÁz î[ 8C:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\ciojv.exe
O4 - HKLM\..\Run: [¢¸K0¨4W
}ïÁz îigÝC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\ciojv.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
View Hidden
Open Windows Explorer. Go to Tools, Folder Options and click on the View tab.
Make sure that "Show hidden files and folders" is checked.
Also uncheck "Hide protected operating system files".
Now click "Apply to all folders", Click "Apply" then "OK"
Delete these files
C:\WINDOWS\webdir.dll
C:\WINDOWS\ciojv.exe
And this folder C:\Program Files\ISTsvc
Boot and post a new log
Print this out
Istsvc http://securityresponse.symantec.com/avcenter/FxIstbar.exe
From Symantec
Note:
· The date and time displayed will be adjusted to your time zone, if your computer is not set to the Pacific time zone.
· The removal tool may terminate Internet Explorer and Windows Explorer. It is recommended that users save their work and log out of these programs before running the removal tool.
· The removal tool will reset the Internet start page to a blank page. The start page can be modified by clicking on Tools > Internet Options in Internet Explorer.
· The removal tool will not delete some harmless Temporary Internet files, which Adware.Istbar created, in C:\Documents and Setings\Administrator\Local Settings\Temporary Internet Files.
These can be manually deleted using the following steps:
a. Start Internet Explorer.
b. Click Tools > Internet Options.
c. In the Temporary Internet Files section, then click the Delete Files button.
Check Delete all offline content, and then click OK.
Boot to safe mode
With HJT fix
O2 - BHO: CWebDirObj Object - {C003C49F-53E4-4A72-B7D6-0B2B9997392F} - C:\WINDOWS\webdir.dll
O4 - HKLM\..\Run: [FPyJ] C:\WINDOWS\ciojv.exe
O4 - HKLM\..\Run: [¢¸K0¨4W
}ïÁz î[ 8C:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\ciojv.exe
O4 - HKLM\..\Run: [¢¸K0¨4W
}ïÁz îigÝC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\ciojv.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
View Hidden
Open Windows Explorer. Go to Tools, Folder Options and click on the View tab.
Make sure that "Show hidden files and folders" is checked.
Also uncheck "Hide protected operating system files".
Now click "Apply to all folders", Click "Apply" then "OK"
Delete these files
C:\WINDOWS\webdir.dll
C:\WINDOWS\ciojv.exe
And this folder C:\Program Files\ISTsvc
Boot and post a new log