Trojan

About “TrojanDownloader:Win32/Istbar” infection

Malware Removal

The TrojanDownloader:Win32/Istbar is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Istbar virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity contains more than one unique useragent.
  • Checks the version of Bios, possibly for anti-virtualization

Related domains:

www.ysbweb.com
ww1.ysbweb.com
install.xxxtoolbar.com

How to determine TrojanDownloader:Win32/Istbar?


File Info:

crc32: B64CD384
md5: 982e1dc689dd41b856da25be7b326671
name: 982E1DC689DD41B856DA25BE7B326671.mlw
sha1: 2e29a5204900c1b7404b3fdc344d403c46361308
sha256: a692de630809ef7094f49bfcd8bcd0068e8768dbef2421b967ec8e0a1931465a
sha512: 95efb5af5af812017e883e71422703a2c23c351831913dbcb97cdaeed87fe641e3cc42738dd8a8db5ddb2b18363a1bfb2323797272e3eb9ac4926615082d2ef8
ssdeep: 384:uLG4Yp4pvh548+iK/tCNRKWbGm2dHWT73FWk0mvtY/cL5nL12kqNZ9:uLxvhKiK1KRKWCm2d2v3b0mvtYipJ2
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

TrojanDownloader:Win32/Istbar also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebAdware.Rapidblaster
MicroWorld-eScanTrojan.Downloader.Istbar.JR
FireEyeGeneric.mg.982e1dc689dd41b8
CAT-QuickHealTrojan.Agent
McAfeeArtemis!982E1DC689DD
CylanceUnsafe
ZillyaDownloader.IstBar.Win32.987
AlibabaTrojanDownloader:Win32/IstBar.ae53e6aa
BitDefenderThetaAI:Packer.128DBCBE1D
CyrenW32/Istbar.SWIT-6600
SymantecAdware.Istbar
APEXMalicious
AvastWin32:IstBar-BC [Trj]
KasperskyTrojan-Downloader.Win32.IstBar.jr
BitDefenderTrojan.Downloader.Istbar.JR
NANO-AntivirusTrojan.Win32.IstBar.hdrx
Paloaltogeneric.ml
RisingDownloader.Istbar!8.57 (TFE:5:iqNXEopMDlE)
Ad-AwareTrojan.Downloader.Istbar.JR
SophosIstbar (PUA)
ComodoTrojWare.Win32.TrojanDownloader.IstBar.~F@f8153
F-SecureTrojan.TR/Dldr.IstBar.B.2
VIPRETrojan.Win32.Generic!BT
TrendMicroPossible_IST
McAfee-GW-EditionAdware-ISTbar.b
EmsisoftTrojan.Downloader.Istbar.JR (B)
SentinelOneStatic AI – Suspicious PE
GDataTrojan.Downloader.Istbar.JR
JiangminTrojanDownloader.IstBar.ae
AviraTR/Dldr.IstBar.B.2
Antiy-AVLTrojan[Downloader]/Win32.IstBar
ArcabitTrojan.Downloader.Istbar.JR
AegisLabTrojan.Win32.IstBar.a!c
ZoneAlarmTrojan-Downloader.Win32.IstBar.jr
MicrosoftTrojanDownloader:Win32/Istbar
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.KillAV.R103614
VBA32TrojanDownloader.Win32.IstBar.ar
ALYacTrojan.Downloader.Istbar.JR
MAXmalware (ai score=99)
MalwarebytesMalware.Heuristic.1003
ESET-NOD32a variant of Win32/TrojanDownloader.IstBar
TrendMicro-HouseCallPossible_IST
TencentWin32.Trojan-downloader.Istbar.Hsio
YandexTrojan.GenAsa!n3Mt62OA5/k
IkarusTrojan-Downloader.Win32.IstBar
FortinetW32/Generic.AP.2970D4!tr
WebrootW32.Malware.Downloader
AVGWin32:IstBar-BC [Trj]
Cybereasonmalicious.689dd4
PandaAdware/IST.ISTBar
Qihoo-360Win32/Trojan.Downloader.f6c

How to remove TrojanDownloader:Win32/Istbar?

TrojanDownloader:Win32/Istbar removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment