Sophos

Troj/IstBar-M

Category
Type
What to do
Prevalence low high

Summary

 
Included in our products from September 2004 (3.85)
Protection available since 12 July 2004 08:16:45 (GMT)
Detected by All Sophos products

Action

Please follow the instructions for removing Trojans.

You should also change your Internet Explorer settings using Tools|Internet options|General to remove any modifications made by the Trojan.

More Information

Troj/IstBar-M is an aggressive downloading adware provided by Integrated Search Technologies/CDT Inc. It is capable of downloading adware from http://install.xxxtoolbar.com/ and various other websites.
The adware it downloads includes: IstSvc, StatBlaster, Avenye Media Internet Optimizer, Bargins, SideFind, SideSearch, 180Solutions msbb, Power Scan.

Depending on which adware it has downloaded, it will attempt to:
1. create related registry entries under HKLM/Software/[Adware name]
2. create start and uninstall entries for the adware
3. report to the related server about the installation

It will also attempt to hook Internet Explorer's StartPage and SearchPage to:
www.couldnotfind.com and www.slotch.com.

It is registered as a COM object in the system with a clsid of:
[018B7EC3-EECA-11D3-8E71-0000E82C6C0D]
and as a BHO under the clsid of:
[60E78CAC-E9A7-4302-B9EE-8582EDE22FBF]

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer