Win32.IstBar.gen
Started by
tarahardt
, Oct 12 2005 10:21 PM
#1
Posted 12 October 2005 - 10:21 PM
#2
Posted 12 October 2005 - 10:37 PM
It's atrojan downloader and it migh put this kind of registyvalues
[HKLM\SOFTWARE\DR_S]
[HKCU\SOFTWARE\DR_S]
[HKLM\SOFTWARE\Classes\drs.n\uID]
[HKCU\SOFTWARE\Classes\drs.n\uID]
Every 30 minutes a program from this family will download a file from, for example , http://www.adzhooter.com/DR_S/gSD.html. This file contain addresses which direct the Trojan to other sites where it can download additional malicious programs:
|5|20050406|
ts|http://www.adzhooter.com/DR_S/bp/as_8_new.exe|1|bs_8_new.exe|1.0|1|
adsh|http://www.adzhooter.com/DR_S/bp/afita.exe|2|afita.exe|1.2|1|
sfitb|http://www.adzhooter.com/DR_S/bp/SYSsfita.dll|3|SYSsfita.dll|1.0|2
sfitb||
ezu|http://www.adzhooter.com/DR_S/bp/wzStub.exe|3|wzStub.exe|1.0|1|
sfisb|http://www.adzhooter.com/DR_S/bp/ReplaceSearch.dll|3|ReplaceSearch
sfisb|.dll|1.0|2|
here are the other names of it.
(Kaspersky Lab) is also known as: Trojan.StartPage.61 (Doctor Web), TR/Dldr.IstBar.G.1 (H+BEDV), Trojan.Downloader.Istbar-38 (ClamAV)
I foubnd some directions. so you can try them
Removing Adware Entries from the Registry
Open Registry Editor. Click Start>Run, type REGEDIT, then press Enter.
In the left panel, double-click the following:
HKEY_CURRENT_USER>Software
Still in the left panel, right-click the following key and choose Delete:
IST
In the left panel, double-click the following:
HKEY_CURRENT_USER>Software>Microsoft>
Internet Explorer>Main
In the right panel, locate and delete the entry:
BandRest = "Never"
In the left panel, double-click the following:
HKEY_LOCAL_MACHINE>Software>Microsoft>
Internet Explorer>Main
In the right panel, locate and delete the entry:
BandRest = "Never"
In the left panel, double-click the following:
HKEY_USERS>S-1-5-21-1275210071-1303643608-682003330-1117>
Software
Still in the left panel, right-click the following key and choose Delete:
IST
In the left panel, double-click the following:
HKEY_USERS>S-1-5-21-1275210071-1303643608-682003330-1117>
Software>Microsoft>Internet Explorer>Main
In the right panel, locate and delete the entry:
BandRest = "Never"
Close Registry Editor.
[HKLM\SOFTWARE\DR_S]
[HKCU\SOFTWARE\DR_S]
[HKLM\SOFTWARE\Classes\drs.n\uID]
[HKCU\SOFTWARE\Classes\drs.n\uID]
Every 30 minutes a program from this family will download a file from, for example , http://www.adzhooter.com/DR_S/gSD.html. This file contain addresses which direct the Trojan to other sites where it can download additional malicious programs:
|5|20050406|
ts|http://www.adzhooter.com/DR_S/bp/as_8_new.exe|1|bs_8_new.exe|1.0|1|
adsh|http://www.adzhooter.com/DR_S/bp/afita.exe|2|afita.exe|1.2|1|
sfitb|http://www.adzhooter.com/DR_S/bp/SYSsfita.dll|3|SYSsfita.dll|1.0|2
sfitb||
ezu|http://www.adzhooter.com/DR_S/bp/wzStub.exe|3|wzStub.exe|1.0|1|
sfisb|http://www.adzhooter.com/DR_S/bp/ReplaceSearch.dll|3|ReplaceSearch
sfisb|.dll|1.0|2|
here are the other names of it.
(Kaspersky Lab) is also known as: Trojan.StartPage.61 (Doctor Web), TR/Dldr.IstBar.G.1 (H+BEDV), Trojan.Downloader.Istbar-38 (ClamAV)
I foubnd some directions. so you can try them
Removing Adware Entries from the Registry
Open Registry Editor. Click Start>Run, type REGEDIT, then press Enter.
In the left panel, double-click the following:
HKEY_CURRENT_USER>Software
Still in the left panel, right-click the following key and choose Delete:
IST
In the left panel, double-click the following:
HKEY_CURRENT_USER>Software>Microsoft>
Internet Explorer>Main
In the right panel, locate and delete the entry:
BandRest = "Never"
In the left panel, double-click the following:
HKEY_LOCAL_MACHINE>Software>Microsoft>
Internet Explorer>Main
In the right panel, locate and delete the entry:
BandRest = "Never"
In the left panel, double-click the following:
HKEY_USERS>S-1-5-21-1275210071-1303643608-682003330-1117>
Software
Still in the left panel, right-click the following key and choose Delete:
IST
In the left panel, double-click the following:
HKEY_USERS>S-1-5-21-1275210071-1303643608-682003330-1117>
Software>Microsoft>Internet Explorer>Main
In the right panel, locate and delete the entry:
BandRest = "Never"
Close Registry Editor.
#3
Posted 13 October 2005 - 11:13 PM
Someone.....
Similar Topics
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users