Author Topic: ISTsvc  (Read 1070 times)

0 Members and 1 Guest are viewing this topic.

A piece of spyware that almost impossible to get rid of, and my brother got it in his laptop. We have tired everything from a fix from symnatic to removing it manually in safemode. It still comes back. In safe mode it completely disappears but returns when we boot normally. Has any one here ever been successful in removing this without a format?
Si Vis Pacem Para Bellem
         "If you wish for peace, prepare for war."

 

Offline Holmes

  • 22
Try Microsoft antispyware: www.microsoft.com/spyware
If that doesn't work take a look at www.spywarewarrior.com
"But manhood is melted into courtesies, valour into compliment, and men are only turned into tongue, and trim ones too: he is now as valiant as Hercules that only tells a lie and swears it."  

--William Shakespeare, Much Ado About Nothing, Act IV, Scene I

 

Offline Liberator

  • Poe's Law In Action
  • 210
Try it manually.   Using regedit, delete all the keys that mention this.  Clear out the Temp folder, all the tempory internet folders, as well as delete whatever program installed it in the first place.
So as through a glass, and darkly
The age long strife I see
Where I fought in many guises,
Many names, but always me.

There are only 10 types of people in the world , those that understand binary and those that don't.

 
Got it. When the system shuts down the spyware hides its self. I just hit power and booted to safe mode again.

Edit: :mad:   spoke too soon. It’s back.
« Last Edit: January 22, 2005, 05:33:00 pm by 1410 »
Si Vis Pacem Para Bellem
         "If you wish for peace, prepare for war."

 

Offline Liberator

  • Poe's Law In Action
  • 210
Find out who uses it and sue 'em for illegal tracking and...stuff.
So as through a glass, and darkly
The age long strife I see
Where I fought in many guises,
Many names, but always me.

There are only 10 types of people in the world , those that understand binary and those that don't.

  

Offline WMCoolmon

  • Purveyor of space crack
  • 213
Have you tried Spybot S&D and Adaware?
-C

 

Offline Taristin

  • Snipes
  • 213
  • BlueScalie
    • Skelkwank Shipyards
Probably something that gets reinstalled on startup. What kind of proggies is he running that launch atomagically?
Freelance Modeler | Amateur Artist

 
My brothers tried that before they put me to work in it. They got rid of it, but when the computer was restarted it came back. Two chat programs come up right away. Yahoo and MSN.
Si Vis Pacem Para Bellem
         "If you wish for peace, prepare for war."

 

Offline Windrunner

  • 210
  • The Hammer.
As someone said use the microsoft antispyware. Their program will detect the IST spyware if they use the same antispyware database in their program as the company that they bought the software from.

or you can use www.avast.com antivirus(freeware)  it also detects the  IST spy.
Staffmember: Hard Light Productions
I said a lot of things.  Some of them were even true. - Aldo_14

 
Sounds like a job for hijackthis.  It should at least give you a big lead on how and what it's doing.

 
Sadly we already know what it’s doing. Ad popups….. mostly porn
Si Vis Pacem Para Bellem
         "If you wish for peace, prepare for war."

 

Offline mikhael

  • Back to skool
  • 211
  • Fnord!
    • http://www.google.com/search?q=404error.com
Spybot Search and Destroy, Adaware SE, Mike Lin's StartupCPL, and SysInternals PSTools and Process Explorer are just the tools for taking care of spyware.

Try looking to see if you have any BHOs that might be reinstalling the spyware when you run your browser. Also look to see if anything has replaced the normal session initialization binary in the registry.
[I am not really here. This post is entirely a figment of your imagination.]

 
Quote
Originally posted by Jonathan_S47
Sadly we already know what it’s doing. Ad popups….. mostly porn


Not exactly what I meant.  Hijackthis is a very powerful tool that will allow you to see all programs loaded by windows at startup through the registry or whatever, as well as any installed BHOs.  That really sounds like a combo of something snuck into your startup somehow to constantly reinstall itself and a pain in the ass BHO that makes it do all that stuff.

Hijackthis will show you everything, and let you remove even stubbon suckers like that.  Just be careful, since HJT shows everything, including neccessary bits.

 

Offline Bobboau

  • Just a MODern kinda guy
    Just MODerately cool
    And MODest too
  • 213
Hijackthis

the omega of spyware removal

only for those who know what they are doing!
Bobboau, bringing you products that work... in theory
learn to use PCS
creator of the ProXimus Procedural Texture and Effect Generator
My latest build of PCS2, get it while it's hot!
PCS 2.0.3


DEUTERONOMY 22:11
Thou shalt not wear a garment of diverse sorts, [as] of woollen and linen together

 
I should download it for my home system then.  :D

Anyway, Microsoft antispyware did the trick. It hasn’t reappeared yet and hopefully never will. Thanks for the help!
Si Vis Pacem Para Bellem
         "If you wish for peace, prepare for war."