Largest Directoty of Internet Security Software

Internet Security Threats

Home Software Threats Security
News
 

Trojan-Downloader.Win32.IstBar.bo

RISK LEVEL:2



This Trojan downloads other programs via the Internet and launches them on thevictim machine without the user’s knowledge or consent. The program itselfis a Windows PE EXE file. It is 8,704 bytes in size. It is packed using UPX.The unpacked file is approximately 40KB in size. It is written in C++.

Once launched, the Trojan searches the system registry for the following keys:

[HKLM\Software\ISTsvc]"popup_url" = "http://www.slotch.com/ist/scripts/istsvc_***_data.php""version""account_id""app_date"

If the Trojan does not find the first key shown below, it will create it.

The Trojan will then attempt to connect to the Internet. If it is unableto establish a connection, it will cease running. If the Trojan does establisha connection, it will download a file called “istsvc.exe” from thefollowing address:

http://install.***toolbar.com/ist/softwares/addins/istsvc.exe— this file is 21 504 bytes in size, and will be detectedby Kaspersky Anti-Virus as Trojan-Downloader.Win32.IstBar.pd

This file will be saved to the current user’s temporary directory:

%Documents and Settings%\%Current_user%\Local Settings\Temp\istsvc.exe

The Trojan then creates a directory called “%Program Files%\ISTsvc".It copies the downloaded file to this directorz and launches it for execution.It then deletes the file from the temporarz directory and ceases running.

If your computer does not have an up-to-date antivirus, or does not have anantivirus solution at all, follow the instructions below to delete the maliciousprogram:

  1. Delete the original Trojan file (the location will depend onhow the program originally penetrated the victim machine).
  2. Delete the following registry keys:
    [HKLM\Software\ISTsvc]"popup_url" = "http://www.slotch.com/ist/scripts/istsvc_***_data.php""version""account_id""app_date"
  3. Delete the following directory and its contents:
    Program Files%\ISTsvc
  4. Delete the following file (if the Trojan program has not alreadydeleted it):
    %Documents and Settings%\%Current_user%\Local Settings\Temp\istsvc.exe
  5. Update your antivirus databases and perform a full scan of thecomputer (download a trial version of Kaspersky Anti-Virus).


Printed From:http://www.viruslist.com/en/viruses/encyclopedia?virusid=39488


Similar Virus/Threat >>
  •   Trojan-Downloader.Win32.QDown.b
  • This Trojan downloads other malicious programs from the Internet and launchesthem on the victim machine. The program itself is a Windows PE EXE file. Itis 43008 bytes in size. It is not packed in...
  •   Trojan-Downloader.Win32.Nurech.at
  • This Trojan downloads files via the Internet without the knowledge or consentof the user. It is a Windows PE EXE file. The file is approximately 28KB insize. It is packed using UPX. The unpacked...
  •   Trojan-Downloader.Win32.Small.jk
  • This Trojan downloads other programs via the Internet without the knowledgeor consent of the user and launches them on the victim machine. The programitself is a Windows PE EXE file. It is 36,352...
  •   Trojan-Downloader.Win32.IstBar.ah
  • This Trojan downloads files from the Internet to the victim machine and launchesthem for execution. The Trojan itself is a Windows PE EXE file. It is 16 896bytes in size, and packed using UPX. The...
  •   Trojan-Downloader.Win32.Small.ddp
  • This Trojan downloads other malicious programs. It is a Windows PE EXE file.It is written in Microsoft Visual C++. It is not packed in any way. The sizeof infected files may vary from 20KB to...
  •   Trojan-Downloader.Win32.Small.eqn
  •   Trojan-Downloader.Win32.Bagle.cu



  • Window Washer
  • symantec PCanywhere 12.0
  • Kaspersky Anti-Hacker
  • iSpyNOW
  • Diet Kaza

  • Acronis Privacy Expert Suite 8.0
    (31,781KB - $29.99)
    AIM Spy Monitor 2007
    (3,145KB - $39.99)
    BlazingTools Secure Office
    (1,301KB - $54.95)
    Yahoo! Messenger Spy Monitor 2007
    (4,034KB - $39.99)
    Encrypt my Folder
    (1,530KB - $24.95)

    Cookie Cleaner   |    History Eraser   |    Popup Killer   |   Firewall   |   Antivirus   |   Security Encryption   |   UnInstaller   |   Security News
    eTrust Pestpatrol Anti-Spyware   PestPatrol 5   Ad-Aware SE Removal   Ad-Aware SE   Ad-Watch   SpyFighter Cleaner Pro   Free Adware Remover   Spy Sweeper  Webroot Spy Sweeper 
    Copyright © 2002-2007 Internet Security Software.All rights reserved.
    Directory of Internet Security Software - Cookie & Cache Cleaner, History & Evidence Eraser, Popup Killer, Firewall