Adware

Adware.ISTBar removal

Malware Removal

The Adware.ISTBar is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.ISTBar virus can do?

  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Spanish (Mexican)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

How to determine Adware.ISTBar?


File Info:

crc32: 12DC0AF2
md5: 100ae215dab51282ba28dbe1221d4994
name: 100AE215DAB51282BA28DBE1221D4994.mlw
sha1: 0e2abdbec2df46fb410035ef295fe8bd9161ab74
sha256: b1f7826497f06c5a310f6accd432d881ba20beeca52588ff709b874938de38ed
sha512: 707edc78eb3f8e20f44cc5f8167cdc68d77b9134a73670b87a253597536b0c39119d60cf53ad7ecba0b6afd772cc461876cc51bf8e6f0fee50891983c19bb1b3
ssdeep: 3072:0I6WE63PT9wTinir4d6iNPyZ6dXve3D1Iir:0Ik2JwTiiriqgdXveOE
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2014
InternalName: Elis
FileVersion: 2, 14, 4, 14
CompanyName: Satinfo SL.
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Aplicacixf3n Elis
SpecialBuild:
ProductVersion: 2, 14, 4, 14
FileDescription: Utilidad Anti-Virus
OriginalFilename: Elis.EXE
Translation: 0x0c0a 0x04b0

Adware.ISTBar also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053af701 )
Elasticmalicious (high confidence)
ALYacGen:Variant.Razy.262397
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.25073
SangforTrojan.Win32.Save.a
AlibabaRansom:Win32/Blocker.77d94e94
K7GWTrojan ( 0053af701 )
Cybereasonmalicious.5dab51
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.gfig
BitDefenderGen:Variant.Razy.262397
NANO-AntivirusTrojan.Win32.Blocker.dloavf
SUPERAntiSpywareRansom.Blocker/Variant
MicroWorld-eScanGen:Variant.Razy.262397
Ad-AwareGen:Variant.Razy.262397
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanDownloader.IstBar.~L@f815z
BitDefenderThetaGen:NN.ZexaF.34770.imLfayiqy4L
VIPREBackdoor.Win32.Hupigon.eml (fs)
McAfee-GW-EditionBehavesLike.Win32.Dropper.cc
FireEyeGeneric.mg.100ae215dab51282
EmsisoftGen:Variant.Razy.262397 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Blocker.ksv
WebrootW32.Malware.Gen
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Heur.KVM005.a.(kcloud)
MicrosoftTrojan:Win32/Occamy.CB1
GDataGen:Variant.Razy.262397
AhnLab-V3Malware/Win32.Generic.C733175
McAfeeGenericRXAA-FA!100AE215DAB5
MAXmalware (ai score=100)
VBA32BScope.Trojan.DiskWriter
MalwarebytesAdware.ISTBar
PandaTrj/CI.A
IkarusTrojan-Dropper.Agent
FortinetW32/Blocker.GFIG!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HwsBEpsA

How to remove Adware.ISTBar?

Adware.ISTBar removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment