Istbar help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by zombie7899, Feb 27, 2005.

  1. zombie7899

    zombie7899 Private E-2

    I've followed the how to guide and I can't get rid of this. I've tried the removal tools through symantec and it still comes back. I've got the latest version of hijack this, and analyzed the log through help2go and hijack this analysis; followed their suggestions, but it keeps coming back. Can anyone help?
     
  2. PhilliePhan

    PhilliePhan Guest

    Hi Zombie,

    I assume you looked in Add or Remove Programs for IstSvc and removed it? Did you do the same in your Program Files folder?

    Please send us a HijackThis Log. Please be sure to follow the instructions below:

    Note that your HijackThis should be up-to-date (v1.99.1) and MUST be extracted to its own safe folder – C:\Program Files\HijackThis! Should you need a Fresh Download of HJT, get it HERE: HijackThis v1.99.1

    Also note that, before you scan, you MUST close all running programs including your web browser, e-mail and items in the system tray.

    Please save your HJT Log as a .txt File and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    Somebody will try to take a look as soon as they get a chance.

    PP:)
     
  3. zombie7899

    zombie7899 Private E-2

    I removed it from add/remove but it comes back, here is the hjt log. Thank you.
     
  4. PhilliePhan

    PhilliePhan Guest

    Hi Zombie,

    Before you start the instructions below, you MUST disable SpyBotSD's "Tea Timer" function as it may interfere with the fixing process!!


    Please print out these instructions so that you can operate with All Browser Windows CLOSED.
    Please make sure System Restore is OFF and the Viewing of Hidden Files is Enabled as per the tutorial.


    Now, look in Task Manager (Ctrl-Alt-Del) for the following running processes and, if you see them, try to END them:

    istsvc.exe
    bsfgx.exe


    Now scan with HijackThis and Check the Boxes for the following:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch

    O4 - HKLM\..\Run: [LoGV8ep3L] C:\WINDOWS\bsfgx.exe
    O4 - HKLM\..\Run: [LoGV80°¿ÔÇs]µ9Ó3âC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\bsfgx.exe
    O4 - HKLM\..\Run: [LoÈ´0°¿ÔÇs]µ9Ó3âÕC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\bsfgx.exe

    O23 - Service: VAIO Media Music Server (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (file missing)
    O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
    O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)

    Again, make sure All Browser Windows are Closed when you Click FIX.

    NOW:
    Please boot into Safe Mode with the Viewing of Hidden Files Enabled and navigate to and DELETE the following if they should remain:

    C:\Program Files\ISTsvc ---> The Folder
    C:\WINDOWS\bsfgx.exe

    NEXT:
    Run CCleaner and Spybot S&D and have Spybot fix what it finds.

    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    Reboot to Normal Windows and Scan with HijackThis and attach that log.
    Let me know of any problems you may have encountered with the above instructions and how your computer is running now. I will try to check back when time permits.

    Best luck :)
    PP
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    PP,

    I would be careful removing these Sony VAIO services without first check to see if the files are really missing. I'm starting to wonder if there is a bug in HijackThis that indicates files are missing for any service it declares to have an Unknown owner. I would expect the user to be having a variety of problems with this PC if all these services actually had their files missing.
     
  6. zombie7899

    zombie7899 Private E-2

    Hi PP, I followed your instructions and had no problems with them. My PC is running better now. None of the scanners are showing the ist, so I am assuming that it is gone. Thanks, here is the hjt log.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach the log.

    Did you actually have HJT fix the O23 lines for your Sony Vaio? How is all the multimedia stuff for it working? Any problems with any sound or music?

    How about the Media Music Server or Media Photo Server ?
     
  8. zombie7899

    zombie7899 Private E-2

    Oopsie.. i don't know what has happened, but the button to attach files is not showing up. I've reloaded this page a few times. Is there another way to attach files?
     
  9. zombie7899

    zombie7899 Private E-2

    I had hjt fix the O23 lines, but when I ran it again they came back. No audio or video problems.

    I've never used those media music servers, so I can't say.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click the Go Advanced button first.
     
  11. zombie7899

    zombie7899 Private E-2

    I'm having a brain fart right now..but where is the go advanced button? Sorry.
     
  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Are you trying to add an attachment to your post?
     
  13. PhilliePhan

    PhilliePhan Guest

    Jus copy and paste the complete new log into your post and I'll deal with it.

    PP :)
     
  14. zombie7899

    zombie7899 Private E-2

    Here it is, sorry guys.
     

    Attached Files:

    Last edited by a moderator: Feb 27, 2005
  15. PhilliePhan

    PhilliePhan Guest

    Your HJT Log looks OK to me!

    If you desire, you can clean this McAfee Remnant:
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)

    And this line if not using Kaspersky:
    O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize

    I saw nothing evil remaining. I trust things are running well?

    While you're here, have a peek at Chaslang's Recommendations!!

    PP :)
     
  16. zombie7899

    zombie7899 Private E-2

    Everything is fine now. Thank you PP! :D
     
  17. PhilliePhan

    PhilliePhan Guest

    You're Welcome! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds