ISTbar

Description: Spyware
Risk Level: High
Date of First Occurence: Tuesday, April 15, 2008
Software Developer: Integrated Search Technologies
Brief Info: Istbar is an adware component, which installs an Internet Explorer toolbar and pops up advertisements.
Removal: This threat can be removed using "Spyware Terminator"

SUPPRIMER SPYWARE »

Geographical Distribution of Threat "ISTbar"

Threat Info

View All

Detected Items

  1. Detected Files: %PROGRAMFILES%\YourSiteBar\ysb.dll MD5: 9418D6FB6CA9633A53B30DE551B0A62B Size:76288 MD5: A38E52E24025CCD0EB166B0C113487DF Size:90624 MD5: B04DBC026B5E827088E550BEC3077EFA Size:90112 MD5: A1475F10329651D6FF845D6576B2AE73 Size:91136 MD5: C92C5EC275D28C7568B298672C5DC3FB Size:89088 MD5: C40A3D71AC9DD36F98CCEC2EDD20DDE1 Size:90112 MD5: E279027BF504261FE9222A0FF86ACA72 Size:94208 MD5: 24D0707B385F94E7FB13837A9DF92168 Size:78336 MD5: 2A82E1CAEDAD949B19CD45296E348212 Size:95232 %DOWNLOADEDPROGRAMFILES%\ISTactivex.dll MD5: 9793F7689B3E41F234C937434BF0F180 Size:40960 MD5: B531D2F1C29858390AEC6493AABD90BA Size:16384 MD5: 410069ACB81973D5FE840EC3DE0722E5 Size:16384 MD5: EDCADE6D3257041B76CD6B59395CDDB0 Size:32768 %TEMP%\istbar.dll MD5: DF24AF4FB14668EB3F914B502CEBA63A Size:52224 MD5: B28C9F18C41946CE46E809D1BA4B5E95 Size:69632 MD5: 118F485D88ADC68E5F0AE39426C276EA Size:69632 MD5: 55FDBD32D167AD53275C599F3EE01ECB Size:68608 MD5: B9B341D1B76423A72292DBC0A8734E13 Size:69120 MD5: 595B6370085508D035F9EE8B1CA84BCA Size:82432 %TEMP%\iinstall.exe MD5: 641196DF465B8D9A1CCF6150294B2B40 Size:15360 MD5: 0D18B2AB5936B785C7565BA290858CA0 Size:16384 MD5: AE0916DA92D026D748106731D7DFAC74 Size:24064 MD5: D22C399D83B1752867EEA85A6F3F9467 Size:26112 MD5: B1B3D017FE45A1C9D0C087B3FBCD70BE Size:27136 MD5: B1733A7319540F6526DC93E5C58F01EE Size:24576 MD5: 959705073906328706FCA7C77B6ACA5C Size:15872 MD5: 36DAB8D700A12525E77571F3AC5B3A48 Size:17920 MD5: 04C99DFE8EA8CCBF2E866BF7B969AAB1 Size:49152 MD5: 86AD885B86918349C75B5158C349476E Size:17920 MD5: 76652FADBC5CD5AE7A38A1BC77AAC11E Size:27648 MD5: C0A86ACA8F6816A90FEE29F072DEA61B Size:32256 and more.... %DOWNLOADEDPROGRAMFILES%\ysbactivex.dll MD5: 0F583EBEDA6325C6FF867EDE8328E165 Size:61440 MD5: 1182EA1261E3F2356315CB3D0E5AF107 Size:57344 MD5: 06A566DC77295353FD17B4AB92171E15 Size:45056 MD5: B5A9E3A6EE7D4596118B83C3FAAC191F Size:69632 MD5: A5B244BC30763A2EEB0DFF8B1B9EB82E Size:61440 MD5: 5337D880AA691BC0552476C5894639D8 Size:69632 MD5: 690F5FA520C7164BC1E7688D3B5FC3CD Size:69632 MD5: EC1134046279C885B2EC3EAB65F80FA1 Size:69632 %TEMP%\ISINST.EXE MD5: F7909C192AD234C715B4B8A705291BD3 Size:33792 MD5: 54B163EC8495A104A0FE1DF16D4698F5 Size:33280 MD5: 07EFFD268FBF6B72C6B68F953B0A3CF1 Size:27648 MD5: 78E13C07A57B1CC0191B5196401799D3 Size:220128 MD5: 308826D0EF741942F9184F7F71AC855F Size:28516 MD5: 35D2F302F17536F8397B9729D1C68991 Size:30720 MD5: 3E0BC56B81DF2421F367A7F0B1438E8B Size:32256 MD5: 2B1B108C6CAA51157ACB3C6FDB611D38 Size:288 MD5: C2F95074BF1B94DDB912A5EC6A20DCD8 Size:30720 MD5: 03C497E277690FAB36DF47594A0EDF12 Size:41984 MD5: 79F78A1DB14A555F88965B74EF1C0D91 Size:71168 MD5: 321B7F529887EAFD07FEFE6B8CE467DF Size:42496 and more.... %DOWNLOADEDPROGRAMFILES%\YSBACTIVEX.DLL MD5: 2078375BAB8848370E1FB58636C846F4 Size:69632 MD5: C523DEF305800E8A506CB11E1CF922C8 Size:61440 MD5: 08961E2D4623BFE8E402DD90AF810CAA Size:43008 MD5: AAF9D89787B31FEBA2B0B74A9AD92CAC Size:69632 MD5: E2B8434EA79623A21279D4611321A146 Size:69632 MD5: DD57099CA88E7CB9EEBA4D7142DDD703 Size:57344 MD5: 59E4DA23F590F1992BB1346CD114F4BC Size:65536 MD5: C81CAF135BD94E40A77B821949234410 Size:57344 MD5: FF2918A4219F312F346E768D38DB6DF6 Size:33280 MD5: 5BA0E3A0C3752D76FD5D408D28654459 Size:61440 MD5: 3B488DE4B96375B4E5FDA1BE5B90D481 Size:69632 MD5: 3AC82C4DFFEB1281929D2928DAFD6797 Size:69632 and more.... %PROGRAMFILES%\ISTsvc\istsvc.exe MD5: CAC8087D858DF68FF318C8AE6B99A918 Size:199126 MD5: 6FB8C63BC9BA28D468ED03A99D0E48E9 Size:11264 MD5: FEE9C1CF52B11FE4C6886E19FB1F1089 Size:20992 MD5: D3E9A5E3371AC9CBE4CA93DCAD4D7935 Size:41984 MD5: DF01E0B79EDEFA13CDFD2E1F2924139A Size:17408 MD5: E21B015C107B553AFB1D2382D8DB124F Size:18432 MD5: 424FD7F0D1CBBCE141D8327584C61365 Size:127030 MD5: 9DA7F10F0A4865623883A3F809E852DD Size:12800 MD5: 4ED71CD2753C5946AA8C16558B513730 Size:10752 MD5: 4E288CB46FF822E187D257A3DDAC7F54 Size:9728 MD5: 7970B3D57477420338395C239132D7F5 Size:19968 MD5: F1AA31F5BA90926DE7E703B208E819A4 Size:196574 and more.... %SYSDIR%\AUPDATE.EXE MD5: 09BDF1DF9CAAB3D05160D537D2494499 Size:43520 %DOWNLOADEDPROGRAMFILES%\YSBactivex.dll MD5: 38795B8805380B94881170C9BE77D1CA Size:57344 MD5: FDD67A64DAA047D70040873184648613 Size:40960 MD5: 0308E8D8B68D8ABA7C0456D45D926292 Size:61440 MD5: AC78B04564EA38E64E9F68B54D0633D5 Size:15360 MD5: AF0F52C6E22D87ED693797663D073025 Size:16384 MD5: 8930C373A0B221FF541F01F6EC3EEBA9 Size:57344 %DOWNLOADEDPROGRAMFILES%\istactivex.dll MD5: F30BC86B34BBBC3C5A23F829DF708A08 Size:40960 MD5: 5BA2BC28E0CB39C889C7C0639BAE7A00 Size:15872 MD5: 0ECDCCAFC664EFE5A77F922C895BB77E Size:61440 MD5: D42B5A53D06B27A810596C223412E3AC Size:65536 MD5: 92F012094E6E37C36B5A7F59706F9518 Size:16384 MD5: F5B8A278D73A4B0C26718DB70F440EB6 Size:61440 MD5: D1888FA47F3BACA4A918C37A254A760F Size:16384 MD5: 18E9A5040B28E578B21FB4EA43F5B781 Size:16896 MD5: C96875BB8B67434AB0A048A8E05CA52E Size:57344 MD5: A7622B8FDB65C758DD3F0EDACA06472A Size:17408 MD5: A801FC8954009827B1B683443427B6E2 Size:57344 %PROGRAMFILES%\ISTbar\istbar.dll MD5: 4EAC1BF779E3249EFF840F349B84FC11 Size:69632 MD5: A715A2F072D770F4F6CC093B41AC1B99 Size:88576 %DOWNLOADEDPROGRAMFILES%\YSBACTIVEX.DLL MD5: 44E3A81AF69AE418D8D194FEEC0EEAE5 Size:69632 MD5: 98AADF4D5AC57E320FA995BC8646DFC7 Size:40960 MD5: FC36370A9891F603026B111C054F06FE Size:69632 MD5: A7C89D4989C6853468617D196732E104 Size:69632 MD5: E63226D0D06E82E322437DB390F953BA Size:61440 MD5: 747C1D2B60D84D627E787ACC63E3A942 Size:69632 MD5: 5F4CE3A4F607E53CB8B059F3D54A4EE7 Size:61440 MD5: 4EA6C40764B050E52E84A786CE65E2A1 Size:69632 MD5: 45DEEA593990D81DB2B714DCB5DFB593 Size:40960 MD5: AEF13E846FAB43F6A1B15F447BB8575B Size:61440 MD5: AAA7E5A5F63C808AB994B24C1EE646D5 Size:69632 MD5: B4BAA03EE37A323956D1E8E4244BA3E9 Size:69632 and more.... %TEMP%\iinstall.exe MD5: 1E7B3E57196C925083EE0EF3909F1751 Size:16384 MD5: 015E74C1345690F469EF901058942F83 Size:26112 MD5: C419A6CDF30C30C7AF4F04D19B1647CE Size:28672 MD5: F9D040FE4FB61E90DBF7798EF5DE27D5 Size:15872 MD5: 2E504BBF7FC5695F841ED036401C33BC Size:15360 MD5: 2192F2EB714BCA8846E296E559208D0A Size:17920 MD5: B0B01A86C65BAD01F4CAEB342F2D079A Size:28160 MD5: D1E2E1B63C418E8E735A56337C6A4163 Size:16384 MD5: 823D193B8168700178379E7D6CDF5781 Size:27136 MD5: 66179787396729BB23D7496ACACDEA47 Size:17408 MD5: 887C318552D13631A8367C1D087F99B6 Size:15360 MD5: EFEA46BE2825BFF404D98240A1D7AFD9 Size:15872 and more.... %PROGRAMFILES%\istbar\istbar.dll MD5: 02540F5394C643C7B81609E7793B373A Size:176128 MD5: 971C827C8D68D12CD30F91535732BAEA Size:69632 %TEMP%\ysb.dll MD5: B3361F3C13D894C845640E46F0521FC8 Size:61440 %SYSDIR%\aupdate.exe MD5: CD3B63DB1FA44C3E67D4BA8982D05320 Size:31744 MD5: C9EBE8C434C0B2BAA50D324C541CAF5A Size:23552 %TEMP%\ISINST.EXE MD5: DEAE4132497308AADE00473F7D2BB80B Size:215 %PROGRAMFILES%\ISTsvc\istsvc.exe MD5: A1513D181F2D153FD0AA0BC93E2B0DE0 Size:19968 MD5: 5ABEB6014B05C416443FF1406034797E Size:12288 MD5: F7EDCFBCB4AE5556E8D41A81712EB704 Size:12800 MD5: 86E9A6E64D8362BAE7631E12891889D2 Size:18944 MD5: C895D646548BB831BEE2862775AC414D Size:8192 MD5: 6052C6F15DD076C3106211E3C794ECCD Size:27136 %PROGRAMFILES%\ISTbar\cmctl.dll MD5: 763B678253C7B717A7B23D559C8AADF0 Size:34304 %TEMP%\iinstall.exe MD5: EE0AA0AE8DA993D7854804B22E40D7D6 Size:16384 MD5: C552DA229D68C071C477593F392006BB Size:26624 MD5: CF0E066FCA4E3B5C077DFBF00C39468C Size:14848 MD5: 9222581BAAB68EE0BB6ACB0F21797F85 Size:28160 MD5: FD310E48949016B8551C365B9CB100FD Size:16384 MD5: C911A195060B81C9AF5252726A42CCF7 Size:15360 MD5: FEC7338E6D791B343AA2A55091E20994 Size:17920 MD5: 12F6B67BA59DF91D7C01DDBB6E2784FE Size:27648 MD5: D00F5140B06095AA72017B9419EBC02E Size:31744 MD5: 5C2DA931177DEBFD6BD0AEEDB732F149 Size:16384 MD5: B9D5E3F885D550DC0AF760CD58AFC025 Size:27136 MD5: 06CEB6F4B30ECB00AC6F5FB203AFF398 Size:29696 and more.... %DOWNLOADEDPROGRAMFILES%\YSBACTIVEX.DLL MD5: 574966B10FF88359FAC795D0F59A5050 Size:69632 MD5: E4A862DA1674664B3FD04CE5B2A1D66F Size:57344 MD5: 1075F60D8DD14620D58B83490869F398 Size:69632 MD5: 6F43BA67B62C53A10CF06E2D0F25B2E7 Size:69632 MD5: AA72AF48801C89371B2E4B40E78D138E Size:69632 %PROGRAMFILES%\istbar\istbarcm.dll MD5: B0C2716CF0701BFB87D4D7294351C8EC Size:90624
  2. Detected Files with variable Filenames: MD5: 50C0DFABC15562C972BDCD0BA28DBA74 Size: 21504 %PROGRAMFILES%\ISTsvc\istsvc.exe %PROGRAMFILES%\ISTsvc\istsvc.exe.ren %PROGRAMFILES%\ISTsvc\ISTSVC.0XE MD5: A38E52E24025CCD0EB166B0C113487DF Size: 90624 %PROGRAMFILES%\YourSiteBar\ysb.dll %USERPROFILE%\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3GW6CSIN\ysb[1].dll %USERPROFILE%\Local Settings\Temporary Internet Files\Content.IE5\KNK7U9GN\ysb[1].dll %TEMP%\ysb.dll %PROGRAMFILES%\YourSiteBar\YSB.0LL %SystemDiskRoot%\System Volume Information\_restore{445CB752-38E3-495A-9392-C8FA2C59DC8D}\RP3\A0001391.dll %USERPROFILE%\Configuraes locais\Temporary Internet Files\Content.IE5\2LJMQ3I4\ysb[1].dll %USERPROFILE%\Local Settings\Temporary Internet Files\Content.IE5\C5EZ41Q7\ysb[1].dll %USERPROFILE%\Configuraes locais\Temporary Internet Files\Content.IE5\Q01NUSNR\ysb[1].dll %SystemDiskRoot%\System Volume Information\_restore{95D4D9F7-667A-4866-8C6B-3C953EC7823A}\RP137\A0178478.dll MD5: E69456733A1FFDE0776DB64280DEC2A9 Size: 65536 %DOWNLOADEDPROGRAMFILES%\istactivex.dll %TEMP%\ICD2.tmp\ISTactivex.dll MD5: 167871BD4E14A511C5018EB714ADADC7 Size: 17408 %TEMP%\ICD1.tmp\istactivex.dll %DOWNLOADEDPROGRAMFILES%\istactivex.dll %TEMP%\.\istactivex.dll MD5: B04DBC026B5E827088E550BEC3077EFA Size: 90112 %PROGRAMFILES%\YourSiteBar\ysb.dll %TEMP%\ysb.dll %PROGRAMFILES%\YourSiteBar\ysb.dll.ren MD5: B28C9F18C41946CE46E809D1BA4B5E95 Size: 69632 %TEMP%\istbar.dll %PROGRAMFILES%\ISTbar\istbar.dll MD5: 1E404DC691DAD7ACFA785D529939E243 Size: 67676 %TEMP%\install\setup.exe %DESKTOP%\graphique foto\setup.exe l:\Downloads\JUANKA\motiondv studio\setup.exe MD5: EF39319973D3B064CAE192B098961E0A Size: 32000 %TEMP%\Setup4.exe %TEMP%\nss125.tmp %TEMP%\nse140.tmp %SystemDiskRoot%\Documents and Settings\\Local Settings\Temp\Setup4.exe %TEMP%\setup4.exe.ren %TEMP%\Setup(2).exe %SystemDiskRoot%\Documents and Settings\Tim McCormick\Local Settings\Temp\nsu5D.tmp %SystemDiskRoot%\Documents and Settings\Tim McCormick\Local Settings\Temp\nsl55.tmp %SystemDiskRoot%\Documents and Settings\Tim McCormick\Local Settings\Temp\nse6C.tmp %SystemDiskRoot%\Documents and Settings\Tim McCormick\Local Settings\Temp\nsc4D.tmp %SystemDiskRoot%\Documents and Settings\Tim McCormick\Local Settings\Temp\nsc41.tmp and next 3 variations. MD5: A1475F10329651D6FF845D6576B2AE73 Size: 91136 %PROGRAMFILES%\YourSiteBar\ysb.dll %TEMP%\ysb.dll MD5: C92C5EC275D28C7568B298672C5DC3FB Size: 89088 %PROGRAMFILES%\YourSiteBar\ysb.dll %TEMP%\ysb.dll MD5: F587B518A16E2A2B73DA398EED0C281A Size: 16384 %TEMP%\ICD5.tmp\ISTactivex.dll %DOWNLOADEDPROGRAMFILES%\istactivex.dll MD5: BF4AEA6076216C28A47D7C38A9A6E852 Size: 16896 %TEMP%\ICD25.tmp\istactivex.dll %TEMP%\ICD19.tmp\istactivex.dll %TEMP%\ICD18.tmp\istactivex.dll %TEMP%\ICD17.tmp\istactivex.dll %DOWNLOADEDPROGRAMFILES%\istactivex.dll MD5: 49AAEF598A317679C33413BBA7B0CB01 Size: 17408 %TEMP%\ICD15.tmp\ISTactivex.dll %TEMP%\ICD10.tmp\ISTactivex.dll %DOWNLOADEDPROGRAMFILES%\istactivex.dll MD5: 6FB8C63BC9BA28D468ED03A99D0E48E9 Size: 11264 %PROGRAMFILES%\ISTsvc\istsvc.exe %PROGRAMFILES%\ISTsvc\istsvc.exe.ren MD5: FEE9C1CF52B11FE4C6886E19FB1F1089 Size: 20992 %PROGRAMFILES%\ISTsvc\istsvc.exe %PROGRAMFILES%\ISTsvc\istsvc.exe.ren MD5: 55FDBD32D167AD53275C599F3EE01ECB Size: 68608 %TEMP%\istbar.dll %PROGRAMFILES%\ISTbar\istbar.dll MD5: B9B341D1B76423A72292DBC0A8734E13 Size: 69120 %TEMP%\istbar.dll %PROGRAMFILES%\ISTbar\istbar.dll MD5: D42B5A53D06B27A810596C223412E3AC Size: 65536 %DOWNLOADEDPROGRAMFILES%\istactivex.dll %TEMP%\ICD2.tmp\ISTactivex.dll MD5: 18E9A5040B28E578B21FB4EA43F5B781 Size: 16896 %DOWNLOADEDPROGRAMFILES%\istactivex.dll %TEMP%\ICD1.tmp\istactivex.dll MD5: 321B7F529887EAFD07FEFE6B8CE467DF Size: 42496 %TEMP%\ISINST.EXE %TEMP%\iinstall.exe MD5: EDCADE6D3257041B76CD6B59395CDDB0 Size: 32768 %DOWNLOADEDPROGRAMFILES%\ISTactivex.dll %TEMP%\ICD1.tmp\ISTactivex.dll

Detecting items list:

  1. Files by Name %ProgramFiles%\ISTsvc\istsvc.exe %TEMP%\*\ISTactivex.dll %TEMP%\ISINST.EXE %SYSDIR%\gjefpet.exe %DOWNLOADEDPROGRAMFILES%\istactivex.dll %DOWNLOADEDPROGRAMFILES%\YSBACTIVEX.DLL %TEMP%\iinstall.exe %TEMP%\istbar.dll %sysdir%\AUPDATE.EXE %TEMP%\ysb.dll %PROGRAMFILES%\ISTbar\istbar.dll
  2. Files by MD5 MD5: 8BD0601DC849CE428D2DE086D95C4503 Size: 111584
  3. Files by Directories %ProgramFiles%\ISTsvc %ProgramFiles%\YourSiteBar %ProgramFiles%\istbar
  4. Files by CLSID or Name CLSID=FAA356E4-D317-42A6-AB41-A3021C6E7D52 CLSID=5F1ABCDB-A875-46c1-8345-B72A4567E486 CLSID=771A1334-6B08-4a6b-AEDC-CF994BA2CEBE CLSID=42F2C9BA-614F-47c0-B3E3-ECFD34EED658 CLSID=86227D9C-0EFE-4F8A-AA55-30386A3F5686 CLSID=386A771C-E96A-421f-8BA7-32F1B706892F CLSID=018B7EC3-EECA-11D3-8E71-0000E82C6C0D CLSID=DC341F1B-EC77-47BE-8F58-96E83861CC5A CLSID=7C559105-9ECF-42b8-B3F7-832E75EDD959 CLSID=A36A5936-CFD9-4B41-86BD-319A1931887F CLSID=DC065FA6-08F9-4C50-99DC-275D16CFC5BD CLSID=339D8AFF-0B42-4260-AD82-78CE605A9543 CLSID=BF06DA8E-2BEB-4816-9BBD-F7625246E245 CLSID=7B9A715E-9D87-4C21-BF9E-F914F2FA953F CLSID=90CE74CC-788A-4A00-B38D-CBCA08CC9E8F CLSID=EAF2CCEE-21A1-4203-9F36-4929FD104D43 CLSID=0985C112-2562-46F2-8DA6-92648BA4630F CLSID=9388907F-82F5-434D-A941-BB802C6DD7C1 CLSID=0E704BA4-C517-4BE7-A1CD-C3FFDA1E1FFE CLSID=03B800F9-2536-4441-8CDA-2A3E6D15B4F8 CLSID=DFBCC1EB-B149-487E-80C1-CC1562021542 CLSID=E9A5B71C-093B-4F34-AF07-34FCA89BA0DF CLSID=8C752C5E-3C10-4076-AF0A-FFC69FA20D1B CLSID=58634367-D62B-4C2C-86BE-5AAC45CDB671 CLSID=89A10D64-83BF-41A4-86A3-7AAF1F8F3D1B CLSID=D0288A41-9855-4A9B-8316-BABE243648DA CLSID=DB447818-96B4-40DF-8A55-720DA496F514 CLSID=CC257918-F435-4A33-8231-2B8195990CCA CLSID=6D3F5DE4-E980-4407-A10F-9AC771ABAAE6 CLSID=67907B3C-A6EF-4A01-99AD-3FCD5F526429 CLSID=4EE12B71-AA5E-45EC-8666-2DB3AD3FDF44 CLSID=5F1ABCDB-A875-46C1-8345-B72A4567E486
  5. Registry Keys HKLM\SOFTWARE\ISTsvc HKLM\SOFTWARE\ISTbar HKLM\SOFTWARE\YourSiteBar HKCU\SOFTWARE\IST HKCU\SOFTWARE\ISTbar HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ISTbar HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ISTsvc HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ISTbar ISTbar HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YourSiteBar HKCR\ISTx.Installer
  6. Registry Values HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ValueName=IST Service HKCU\Software\Microsoft\Internet Explorer\Main ValueName=Bandrest

« Go to Software Database