Internet Products
1834156 Members
2254 Online
110064 Solutions
New Discussion

cannot! remove ISTsvc.exe

 
Richie Jones
New Member

cannot! remove ISTsvc.exe

I have tried everything to remove this ISTsvc.exe... adaware, search and destroy and manual removal from the reg. This my most recent Hijack This log. If anyone has a tip on how to successfully and permanently remove this, it would be great appreciated!!
Thank you
Logfile of HijackThis v1.97.7
Scan saved at 5:04:58 PM, on 12/13/2004
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP1 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\SYSTEM32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\loadqm.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINNT\pesppupk.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\AutoCAD 2002\acad.exe
C:\WINNT\regedit.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\WINNT\explorer.exe
C:\Program Files\ISTsvc\istsvc.exe
C:\Documents and Settings\Richard\Local Settings\Temp\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\system32\otqoj.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\system32\otqoj.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\system32\otqoj.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\system32\otqoj.dll/sp.html#28129
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar.dll
O2 - BHO: (no name) - {F484474E-55C8-74F9-AADE-E2E5DDF50964} - C:\WINNT\atlbp32.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AefQ] C:\WINNT\pesppupk.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKLM\..\RunOnce: [AAW] "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe" "+b1"
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\googletoolbar.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\googletoolbar.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\googletoolbar.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\googletoolbar.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\googletoolbar.dll/cmtrans.html
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/096d9dbb3e8bf10ade23/netzip/RdxIE601.cab
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Program Files\AutoCAD 2002\AcDcToday.ocx
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\AutoCAD 2002\InstBanr.ocx
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Program Files\AutoCAD 2002\InstFred.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD 2002\AcPreview.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{6231B0C4-ECCE-470A-B05C-D26EF71AF1FF}: NameServer = 192.168.1.254,205.152.0.5
11 REPLIES 11
Jay Bollyn
Honored Contributor

Re: cannot! remove ISTsvc.exe

Hi Richie,

Here is what I suggest:

Update Spybot S&D with the most recent definitions;

Reboot into win2k Safe Mode (press F8 at reboot);

Run Spybot S&D, Fix problems;

Run HJT, delete suspicious entries;

Reboot into Normal mode, download win2k Service Pack 4; install (with the uninstall option).

If you need more detailed help than this, I'm sure Ron will be around.

:-) Jay
check Facebook
Ron Kinner
Honored Contributor

Re: cannot! remove ISTsvc.exe

As always, make a manual System Restore Point before proceding and also make sure you have a copy of WinsockXPFix.exe from:

http://www.iup.edu/house/resnet/winfix.shtm

This is only to be used if after deleting the malware you are unable to get back on the internet.

You actually have two infections. The sp (spooner or about:blank) as well as the istsvc.

http://www.trojaner-info.de/cgi-bin/download.cgi?file=sphjfix

May get rid of the sp infection. It's a German program but somehow it knows to use English when it runs on my computer. If it comes up in German then press the button on the right. It will reboot your PC when it is done.

As far as your HijackThis log:

Boot into Safe Mode (F8) without networking. Do not start any browsers. Rerun HijackThis and Scan your system and check the following (if they are still there after running the sphjfix) and then Fix Checked.

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\system32\otqoj.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\system32\otqoj.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\system32\otqoj.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\system32\otqoj.dll/sp.html#28129
O2 - BHO: (no name) - {F484474E-55C8-74F9-AADE-E2E5DDF50964} - C:\WINNT\atlbp32.dll
O4 - HKLM\..\Run: [AefQ] C:\WINNT\pesppupk.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.frame.crazywinnings.com

Do not reboot yet. Open Windows Explorer (Right click on Start and Select Explore then locate the file:

C:\Program Files\ISTsvc\istsvc.exe


Delete it but leave the folder. Right click on the folder and select Properties then Security. You will see several users like Administration, System Power Users etc. Highlight each one then click the Deny box after Full Control. When you have done all of them then click OK. This prevents the folder from ever being used again and will hopefully keep the istsvc from ever returning.

Make sure you can see System and Hidden files and their extensions:

http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/win_fcab_show_file_extensions.mspx

Look in C:\windows\dllcache and C:\Windows for the following files and try to delete them everywhere they show up:

otqoj.dll
atlbp32.dll
pesppupk.exe

They will be in C:\windows and also probably in C:\windows\dllcache. Check the C:\windows\dllcache first and if you find the file delete it there first and then quickly delete it from C:\windows



Now reboot into normal mode and rerun HijackThis and post the new log.

Ron
Richie Jones
New Member

Re: cannot! remove ISTsvc.exe

Thank you sincerely for your help. I followed Ron's instructions, but am running Win2K and could not find any traces of otqoj.dll. etc... but may not have been looking in all the right place (hidden files were being shown). Also, I did deny full control on the ISTsvc folder. I ran adaware se once and istbar was found 3 times as a reg key and reg value... I deleted them. I just ran it again and no traces. Here is the latest hjt log. Do you think I'm in the clear?
Thank you!
Logfile of HijackThis v1.97.7
Scan saved at 11:21:27 AM, on 12/14/2004
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP1 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\SYSTEM32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\WINNT\loadqm.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Richard\Local Settings\Temp\HijackThis.exe

O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\googletoolbar.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\googletoolbar.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\googletoolbar.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\googletoolbar.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\googletoolbar.dll/cmtrans.html
O15 - Trusted Zone: *.frame.crazywinnings.com
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/096d9dbb3e8bf10ade23/netzip/RdxIE601.cab
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Program Files\AutoCAD 2002\AcDcToday.ocx
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\AutoCAD 2002\InstBanr.ocx
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Program Files\AutoCAD 2002\InstFred.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD 2002\AcPreview.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{6231B0C4-ECCE-470A-B05C-D26EF71AF1FF}: NameServer = 192.168.1.254,205.152.0.5
Thomas Bianco
Honored Contributor

Re: cannot! remove ISTsvc.exe

always count on Ron to have the answer.

looks fairly clean to me, but
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
looks a bit suspect. i'd make sure this is really part of Symantec.
There have been Innumerable people who have helped me. Of course, I've managed to piss most of them off.
Ron Kinner
Honored Contributor

Re: cannot! remove ISTsvc.exe

If you ran the German SP program I recommended it probably killed off the otqoj.dll before you started looking for it. Sorry if I sent you on a wild goose chase but I like to make sure things are gone.

You are now clean as far as about:blank and istsvc go. The only thing I don't like is


O15 - Trusted Zone: *.frame.crazywinnings.com

Did you miss that when checking boxes or was HijackThis unable to get rid of it? Or is that a site you really trust? Looks a bit suspicious to me. In IE if you go Tools / Internet Options / Security then click on the green Trusted Sites icon and finally Sites you should be able to delete it by Highlighting it and pressing Remove. If it won't let you in because it wants a password which you don't know and HijackThis can't remove it there is a registry hack to bypass the password but I will have to look for it.

Ron
Richie Jones
New Member

Re: cannot! remove ISTsvc.exe

Thanks again for the help. Everything is working good now, except for the trusted site I can't get rid of. HJT could not delete it, nor could internet options and it is definetely not a trusted site. I have no idea what it is??

Everything else is clear though.
Thanks a ton!!
R
Ron Kinner
Honored Contributor

Re: cannot! remove ISTsvc.exe

Close Internet Explorer.

Start Run regedit


This should bring up the registry editor. You move through it just like Windows Explorer.

Look -for:

HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Policies \ Ratings

There should be nothing in the pane on the right except
(Default) Reg_Sz (Value not set). If you see a value double click on (default) and delete it then OK.

If you see anything other than (Default) highlight it and Delete it.

Now Open Internet Explorer and Tools /Internet Options / Security and see if you can now go to Trusted Sites Sites and delete the evil site.

Ron

Nathan Smith_5
New Member

Re: cannot! remove ISTsvc.exe

Hi. Im having the se problem getting id of ISTSVC on my computer, as neither Adaware or the specific Symantec fix have worked. Im running Windows XP Pro, however, so there is no "Security" tab under Properties in the ISTSVC Folder. Consequently, whenever I delete either the file or the folder, it simply reappears after startup. Any help with this would be greatly appreciated.
Nathan Smith_5
New Member

Re: cannot! remove ISTsvc.exe

Ok, Ive gotta be either the smartest or the dumbest guy on the planet. After spending several hours combing the net for a reasonable fix for this thing, which people are complaining about on countless forums, I found out I can just uninstall the thing on "Add/Remove Programs". Its tireless at duplicating itself if you try anything else, but it actually lets you uninstall via the control panel. Unreal, I feel very silly. It still hasnt stopped my IE from hanging on startup and creating new windows, but I guess thats a whole other mess to deal with.
Ron Kinner
Honored Contributor

Re: cannot! remove ISTsvc.exe

Nathan,

Start your own thread and attach a HijackThis log and we will see what we can do about your problem.

Ron
ugnius
New Member

Re: cannot! remove ISTsvc.exe

Discussion about Istsvc removal can be found here: http://www.2-spyware.com/file-istsvc-exe.html