There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
 
Tag Cloud
access audio avg avg 8 bios blue screen boot bsod computer connection cpu crash css dell desktop dma driver drivers dvd email error excel explorer firefox firefox 3 freeze gimp graphics hard drive hardware hijackthis hjt install internet internet explorer itunes keyboard laptop macro malware monitor motherboard network networking outlook outlook 2003 outlook 2007 outlook express pio problem problems router seo server slow sound sp3 spyware trojan usb video virtumonde virus vista vundo windows windows vista windows xp winxp wireless
Tech Tips & Tricks
Search
Search in:
 
Advanced Search
Tech Support Guy Forums > General Technology > Tech Tips & Tricks >
ISTsvc.exe


HELLO AND WELCOME! Before you can post your question, you'll have to register -- it's completely free! Click here to join today! We highly recommend that you print a copy of our Guide for New Members. Enjoy!

 
Thread Tools
Ciberblade's Avatar
Computer Specs
Community Moderator with 15,700 posts.
 
Join Date: Sep 2003
Location: Heart of the Bluegrass Ky
Experience: Mostly Harmless
05-May-2005, 11:29 AM #1
Post ISTsvc.exe
Been doing battle with this little ad malware program...and it has not returned in the last two days. For others that might run across this guy...the details:

I was brought in to look at this problem at the request of two other techs that could not seem to find the cause. The user complaint was rather typical "all of a sudden I get a popup ad even when I'm not online"

Ad-aware was able to detect and remove the process, registry entries, and files associated with it (after a reboot). All would seem fine, the process, file and folder were not present. Then 15mins later, it would show back up (completely transparent to the user).

All the spy/adware scans were unable to remove the bug totally -- because of one file. I found this file in "C:\WINDOWS\Prefetch" with the file name "ISTSVC.ECE-0b9ca3a6.pf"
Deleting this file first...running the scans and removing the entries has seemingly stopped the file from returning. This was on a WinXP-SP2 system.
The user did not know how the bug was downloaded.
__________________
82,268
*AD-Aware*AIDA32*AVG-7*Filemon*Hijack This*PortMon*Process Explorer*TSG Forums menu*

Far righty-tighty Wingnut Libertarian ( ) - annoyingly free thinking with no tendency to agree on anything with anyone. - BF

If you wish...you can now come to church with me! A church that is NOT normal...a church for people who don't like 'church'
WhitPhil's Avatar
Distinguished Member with 8,346 posts.
 
Join Date: Oct 2000
Location: Whitby, Ontario
05-May-2005, 11:32 AM #2
That is sort of curious!

Did you delete the actual ISTsvc.exe file??

The entry in PF should do nothing without the corresponding EXE file.
Arky's Avatar
Senior Member with 548 posts.
 
Join Date: Aug 2004
Experience: Advanced
05-May-2005, 11:35 AM #3
For a host of references to this problem do a Yahoo or Google search on istsvc.exe.
Ciberblade's Avatar
Computer Specs
Community Moderator with 15,700 posts.
 
Join Date: Sep 2003
Location: Heart of the Bluegrass Ky
Experience: Mostly Harmless
05-May-2005, 12:17 PM #4
yes I did delete the ISTsvc.exe file and folder...but I came back.

I also followed the info I gathered from the searches on Yahoo.

It's only been two days...I'll see if it shows back and post more next week.
Ciberblade's Avatar
Computer Specs
Community Moderator with 15,700 posts.
 
Join Date: Sep 2003
Location: Heart of the Bluegrass Ky
Experience: Mostly Harmless
05-May-2005, 05:37 PM #5
So I checked again...and seems I posted this thread a tad premature Hate it when that happens

This file is activated by a parent program -- that is how it reproduces itself. Finding that parent program was not simple (unless you know where to look)

Alrighty, now to the fun stuff!
The parent program has been called by many names (according to my Yahoo/Google searches) -- but it must have a registry entry. The spyware detection programs can find and remove all parts of the know bug -- just not the install program (the parent)
Go to your registry: "hkey_local_machine/software/microsoft/windows/current version/run"
and look through and verify the entries one by one (yeah, I know)
In this case, it was a file named kkwoix.exe in the Windows folder "C:\Windows\kkwoix.exe"

Further inspection of computers in the office revealed two more systems with that process running, the parent program was named "jube1.exe" and "dyfuca.exe" In each case the program was installed in the Windows folder.

Will post when I learn more.
__________________
82,268
*AD-Aware*AIDA32*AVG-7*Filemon*Hijack This*PortMon*Process Explorer*TSG Forums menu*

Far righty-tighty Wingnut Libertarian ( ) - annoyingly free thinking with no tendency to agree on anything with anyone. - BF

If you wish...you can now come to church with me! A church that is NOT normal...a church for people who don't like 'church'
Skivvywaver's Avatar
Computer Specs
Distinguished Member with 14,073 posts.
 
Join Date: Mar 2001
Location: Behind my wall
Experience: WTH???
05-May-2005, 06:18 PM #6
dyfuca.exe is listed when spybot scans. I don't know if it removes it or not but spybot looks for it. Ciber, I figure you ran spybot, did it miss it?
Ciberblade's Avatar
Computer Specs
Community Moderator with 15,700 posts.
 
Join Date: Sep 2003
Location: Heart of the Bluegrass Ky
Experience: Mostly Harmless
05-May-2005, 06:25 PM #7
Nope...didn't miss it -- dyfuca.exe was one one of the other systems I checked and cleaned.

I guess if the parent had that name on all systems, then SpyBot could remove it w/o it showing back up. I deleted the file manually, then let the bot do the rest
__________________
82,268
*AD-Aware*AIDA32*AVG-7*Filemon*Hijack This*PortMon*Process Explorer*TSG Forums menu*

Far righty-tighty Wingnut Libertarian ( ) - annoyingly free thinking with no tendency to agree on anything with anyone. - BF

If you wish...you can now come to church with me! A church that is NOT normal...a church for people who don't like 'church'
WhitPhil's Avatar
Distinguished Member with 8,346 posts.
 
Join Date: Oct 2000
Location: Whitby, Ontario
05-May-2005, 07:54 PM #8
ISTSvc would appear to be the ISTbar Adware with a removal tool here

And Dyfuca would appear to be NetOptimizer Adware with a removal tool here
Ciberblade's Avatar
Computer Specs
Community Moderator with 15,700 posts.
 
Join Date: Sep 2003
Location: Heart of the Bluegrass Ky
Experience: Mostly Harmless
05-May-2005, 07:59 PM #9
Quote:
Originally Posted by WhitPhil
ISTSvc would appear to be the ISTbar Adware with a removal tool here

And Dyfuca would appear to be NetOptimizer Adware with a removal tool here
Thanks for the links....will add them to my 'toolkit'
WhitPhil's Avatar
Distinguished Member with 8,346 posts.
 
Join Date: Oct 2000
Location: Whitby, Ontario
05-May-2005, 09:57 PM #10
Hope they help.

And, a BTW, an easy trick to try and track down these unknown files (when they are viral in nature) is to use the Google advanced search, put the file name in the "with all the words" field, and then (in the above case) put Symantec.com in the Domain field.

And, then if Symatec hasn't heard of it, try Kaspersky.com or any of the other vendors.
Ciberblade's Avatar
Computer Specs
Community Moderator with 15,700 posts.
 
Join Date: Sep 2003
Location: Heart of the Bluegrass Ky
Experience: Mostly Harmless
09-May-2005, 01:59 PM #11
**update**

The bug is still gone
Dr. G's Avatar
Junior Member with 14 posts.
 
Join Date: May 2005
Location: Stuart, Florida (Hurricane Central)
Experience: Intermediate
31-May-2005, 01:36 AM #12
ISTsvc monster
Ciberblade,
I'm still battling the ISTsvc monster. It sounds like you're on the right track looking for the "parent." I'm surprised why the removal tool by Symantek doesn't work. I've seen three different removal tracks on the tech guy forums. Derek seems to be advocating something different than what you arrived at, and someone else suggests simple running Kaspersky. Have you gotten any further with your investigation? If the bug is still gone, I'm not clear how you found the problem in the registry. Trial and error seems pretty ominous for even an intermediate user!!

Your thoughts would be appreciated. I'm on my second all-nighter doing battle with this thing. I record everything religiously, trying to apply scientific methods, but this thing defies logic! Thanks!!
huntedpadfoo's Avatar
Junior Member with 3 posts.
 
Join Date: Jun 2005
Location: Sydney!
Experience: Beginner
10-Jun-2005, 03:24 AM #13
Hi, new here. I've recently got this problem and i have Ad-aware, it removes the registry files and all, but the virus stays. I can't even go to the task manager(ctrl+alt+delete thingo) because of this virus. There are a few applications i have found, but i cant delete them, because a message comes up saying that the program is in use, when it isnt!!! i need to shut down the process, then delete the file, but i can't, since i can't go to the task manager! BOTHER THIS !
wdm2291's Avatar
Senior Member with 393 posts.
 
Join Date: Nov 2004
Experience: Advanced
16-Jun-2005, 04:38 PM #14
huntedpad, why don't you. .
go here and download a program called HijackThis,

http://www.spywareinfo.com/~merijn/files/HijackThis.exe

Create a folder on your desktop called "HijackThis" and save/download the program into that folder.

Then double click on the program (in that folder) to run it -- choose to run a scan and save a log. . then cut and paste that log and post it as a new thread in the "Security" section of this site's forums (instead of "Tips & Tricks") so someone can take a look at it.

DO NOT have HijackThis fix anything until after someone on here looks at it for you, as most of what it will show is stuff your computer needs to run properly.

Hope this helps,

Wayne
__________________
I edit my posts frequently, so check back regularly for any changes

"To be kind, Evolution (Darwinism) is a fraud." - Dr. Raymond Damadian, MRI inventor
http://www.answersingenesis.org/home...sd/Sarfati.asp

Creation/Evolution headlines (awesome page!):
http://www.crev.info

Is Islam really peaceful?. . or evil?
find out here:

http://www.prophetofdoom.net/

This (above) site contains many direct quotes from Mohammed, the sole source of all Islam teaches
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are Off
Refbacks are Off

You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 11:43 PM.
Copyright © 1996 - 2008 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Powered by Cermak Technologies, Inc.