Remove ISTbar. Description and removal instructions

 
Title: ISTbar

Type: Browser Plugins
Severity scale:ISTbar severity is 49  (49 / 100)
 
ISTbar is a malicious Internet Explorer search toolbar that hijacks a web browser by changing its default home and start pages and modifying related settings. It also adds numerous bookmarks leading to advertising resources, displays undesirable pop-up advertisements and pornographic content. ISTbar downloads and installs multiple third-party adware and spyware parasites without asking for user permission. It has the ability to silently update itself via the Internet. ISTbar is usually installed by some infamous advertising and pornographic web sites. The parasite automatically runs on every Windows startup.


ISTbar properties:
• Changes browser settings
• Shows commercial adverts
• Connects itself to the internet
• Stays resident in background

Automatic ISTbar removal:

remover for ISTbar

ISTbar manual removal:

Kill processes:
istsvc.exe, istdownload.exe, gjefpet.exe, juhpad.exe, sfsetup.exe, sidefind.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\IST Service
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page=[site address]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Bar=[site address]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page=[site address]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Bandrest=never
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Use Search Assistant=no
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\SearchAssistant=[site address]
HKEY_LOCAl_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Bandrest=never
HKEY_CURRENT_USER\Software\IST
HKEY_CURRENT_USER\Software\ISTbar
HKEY_LOCAL_MACHINE\SOFTWARE\ISTsvc
HKEY_LOCAL_MACHINE\SOFTWARE\ISTbar
HKEY_LOCAL_MACHINE\SOFTWARE\Sidefind
HKEY_LOCAL_MACHINE\SOFTWARE\YourSiteBar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DownloadManager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Sidefind
HKEY_CLASSES_ROOT\BrowserHelperObject.BAHelper
HKEY_CLASSES_ROOT\BrowserHelperObject.BAHelper.1
HKEY_CLASSES_ROOT\ISTbar.BarObj
HKEY_CLASSES_ROOT\ISTactivex.Installer
HKEY_CLASSES_ROOT\ISTactivex.Installer.1
HKEY_CLASSES_ROOT\ISTactivex.Installer.2
HKEY_CLASSES_ROOT\ISTx.Installer
HKEY_CLASSES_ROOT\ISTx.Installer.2
HKEY_CLASSES_ROOT\Pugi.PugiObj
HKEY_CLASSES_ROOT\Pugi.PugiObj.1
HKEY_CLASSES_ROOT\SideFind.Finder
HKEY_CLASSES_ROOT\SideFind.Finder.1
HKEY_CLASSES_ROOT\TestContentMatchControl1.ContentMatchTag
HKEY_CLASSES_ROOT\TestContentMatchControl1.ContentMatchTag.1
HKEY_CLASSES_ROOT\Ysb.YsbObj
HKEY_CLASSES_ROOT\Ysb.YsbObj.1
HKEY_CLASSES_ROOT\YSBactivex.Installer
HKEY_CLASSES_ROOT\YSBactivex.Installer.1
HKEY_CLASSES_ROOT\CLSID\{018B7EC3-EECA-11D3-8E71-0000E82C6C0D}
HKEY_CLASSES_ROOT\CLSID\{386A771C-E96A-421f-8BA7-32F1B706892F}
HKEY_CLASSES_ROOT\CLSID\{42F2C9BA-614F-47c0-B3E3-ECFD34EED658}
HKEY_CLASSES_ROOT\CLSID\{5F1ABCDB-A875-46c1-8345-B72A4567E486}
HKEY_CLASSES_ROOT\CLSID\{771A1334-6B08-4a6b-AEDC-CF994BA2CEBE}
HKEY_CLASSES_ROOT\CLSID\{7C559105-9ECF-42b8-B3F7-832E75EDD959}
HKEY_CLASSES_ROOT\CLSID\{86227D9C-0EFE-4F8A-AA55-30386A3F5686}
HKEY_CLASSES_ROOT\CLSID\{8CBA1B49-8144-4721-A7B1-64C578C9EED7}
HKEY_CLASSES_ROOT\CLSID\{A3FDD654-A057-4971-9844-4ED8E67DBBB8}
HKEY_CLASSES_ROOT\CLSID\{DC341F1B-EC77-47BE-8F58-96E83861CC5A}
HKEY_CLASSES_ROOT\CLSID\{FAA356E4-D317-42A6-AB41-A3021C6E7D52}
HKEY_CLASSES_ROOT\Interface\{03B800F9-2536-4441-8CDA-2A3E6D15B4F8}
HKEY_CLASSES_ROOT\Interface\{0985C112-2562-46F2-8DA6-92648BA4630F}
HKEY_CLASSES_ROOT\Interface\{0E704BA4-C517-4BE7-A1CD-C3FFDA1E1FFE}
HKEY_CLASSES_ROOT\Interface\{339D8AFF-0B42-4260-AD82-78CE605A9543}
HKEY_CLASSES_ROOT\Interface\{7B9A715E-9D87-4C21-BF9E-F914F2FA953F}
HKEY_CLASSES_ROOT\Interface\{90CE74CC-788A-4A00-B38D-CBCA08CC9E8F}
HKEY_CLASSES_ROOT\Interface\{A36A5936-CFD9-4B41-86BD-319A1931887F}
HKEY_CLASSES_ROOT\Interface\{BF06DA8E-2BEB-4816-9BBD-F7625246E245}
HKEY_CLASSES_ROOT\Interface\{DC065FA6-08F9-4C50-99DC-275D16CFC5BD}
HKEY_CLASSES_ROOT\Interface\{DFBCC1EB-B149-487E-80C1-CC1562021542}
HKEY_CLASSES_ROOT\Interface\{EAF2CCEE-21A1-4203-9F36-4929FD104D43}
HKEY_CLASSES_ROOT\TypeLib\{4EE12B71-AA5E-45EC-8666-2DB3AD3FDF44}
HKEY_CLASSES_ROOT\TypeLib\{58634367-D62B-4C2C-86BE-5AAC45CDB671}
HKEY_CLASSES_ROOT\TypeLib\{67907B3C-A6EF-4A01-99AD-3FCD5F526429}
HKEY_CLASSES_ROOT\TypeLib\{6D3F5DE4-E980-4407-A10F-9AC771ABAAE6}
HKEY_CLASSES_ROOT\TypeLib\{89A10D64-83BF-41A4-86A3-7AAF1F8F3D1B}
HKEY_CLASSES_ROOT\TypeLib\{8C752C5E-3C10-4076-AF0A-FFC69FA20D1B}
HKEY_CLASSES_ROOT\TypeLib\{CC257918-F435-4A33-8231-2B8195990CCA}
HKEY_CLASSES_ROOT\TypeLib\{D0288A41-9855-4A9B-8316-BABE243648DA}
HKEY_CLASSES_ROOT\TypeLib\{DB447818-96B4-40DF-8A55-720DA496F514}
HKEY_CLASSES_ROOT\TypeLib\{E9A5B71C-093B-4F34-AF07-34FCA89BA0DF}
HKEY_CLASSES_ROOT\Component Categories\{00021494-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CurrentVersion\Explorer\Browser Helper Objects\{A3FDD654-A057-4971-9844-4ED8E67DBBB8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{10E42047-DEB9-4535-A118-B3F6EC39B807}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\%Windir%/Downloaded Program Files/istactivex.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{7C559105-9ECF-42B8-B3F7-832E75EDD959}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\contentmatch.net
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ISTbar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ISTsvc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ISTbarISTbar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SideFind
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YourSiteBar
Unregister DLLs:
cmctl.dll, istactivex.dll, istbar.dll, istbarcm.dll, istbar_dh.dll, sidefind.dll, sfbho.dll, ysb.dll, ysbactivex.dll

Delete files:
istsvc.exe, istdownload.exe, gjefpet.exe, juhpad.exe, sfsetup.exe, sidefind.exe, cmctl.dll, istactivex.dll, istbar.dll, istbarcm.dll, istbar_dh.dll, sidefind.dll, sfbho.dll, ysb.dll, ysbactivex.dll
Delete directories:
C:\Program Files\ISTsvc
C:\Program Files\SideFind
C:\Program Files\YourSiteBar
Misc:
The parasite may use randomly named files and registry keys.

[site address] is an adress of a web site on the couldnotfind.com or slotch.com domain.

Other programs to remove ISTbar:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 19/03/04
Information updated: 03/09/05

Additional resources related to ISTbar:

Attention: If you know or you have a website or page about ISTbar removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about ISTbar parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:


Comments from visitors:


1. re: comment about ISTbar by fudgefactor. 2005-03-06 20:03:22
i got the message "omg this is so funny and a link", then my computer went crazy and it is driving me nuts. every time i try to remove it in add/remove programs, it locks up. seems like im not the only one.

2. re: comment about ISTbar by wtf. 2005-03-06 19:03:59
GOD! I hate this thing! I hope the removal works!

3. re: comment about ISTbar by salsaman. 2005-03-03 16:03:57
When Microsoft Antispyware is unable to fully remove the istbar: restart in safe mode (hold the F8 button when the computer is restarting, select safe mode) then do a search (Start button, then Search) look for all files with *.exe created on the day that your machine was infected, and delete them (if in doubt: save them on a USB stick or CD to keep a copy)

4. re: comment about ISTbar by ragdollop 2005-02-28 22:02:07
i think that someone should program viruses that would attack these companys! that would be coool!

5. re: comment about ISTbar by tom. 2005-02-28 14:02:49
the file name was something completely different on mine. forget now, cause I deleted it ! but the clue was, that it was created the same day I was infected. there was only one I didn't recognize, and that was it. It quit re-creating itself after that was deleted. ALSO, easier to do in SafeMode.

6. re: comment about ISTbar by Chris 2005-02-25 12:02:52
Okay this thing is seriously pissin me off. I am running SS&D, Adaware SE Personal, Spyware Doctor, Spyhunter, and Microsoft Antispyware and all of them detect it but none can seem to clean it however microsoft antispyware does block it from reinstalling however it just keeps trying and trying to reinstall cuz i cannot find the parent file. Sorry I am a newb at this so arrrgghhh

7. re: comment about ISTbar by Guest. 2005-02-24 12:02:01
Thanks for the comments on number 2. It is worth adding that I searched through my exe's by date and found another exe had been installed on the same date as istsvc.exe. i ended the process of both, I then deleted all reference to istsvc on the hard drive, registry including ulcapt.exe. This appears to have done the trick

8. re: comment about ISTbar by emonahan. 2005-02-12 16:02:00
I thought I was pretty computer savvy, until I realized I had this on my system. I used SS&D and Adaware, both detected it, and when I hit "fix the problems" my comp crashed. Twice. One day and 2 rebuilds later, I still have it, so thanks for the manual removal instructions - now let's go see if I can crash this baby again :|

9. re: comment about ISTbar by Veen. 2005-02-11 01:02:06
Be aware, that there is a Parent file that will reinstall ISTsvc.exe. If you do not find and remove the Parent file, deleting ISTsvc from your registry will only temporarily remove it. The parent file can be named anything. In my case it was called ulcapt.exe. There are several fixes to this problem, some simple and some complex. My method was to end the ISTsvc process under Windows Task Manager along with another process that I was unfamilar with. Wait a couple of minutes and if ISTsvc reappears under processes, then repeat until you find the Parent exe file. Once I found the Parant file, I deleted all references to ISTsvc and the parent file from my registry.

10. re: comment about ISTbar by me2. 2005-02-09 07:02:37
a pain in the neck. i discovered it after updating my win2k with sp4. if u set up a new pc and make an online update - make sure to run a firewall/av first, b4 running windows updates, m8s.

another removal can be found at:
http://securityresponse.symantec.com/avcenter/venc/data/adware.istbar.html

btw - it installs other spyware like powerscan or the optimize.exe
kind've annoying, but killable :)

11. re: comment about ISTbar by static. 2005-02-08 08:02:15
hey , found this by accident, anyways had this malicious spyware in my machine and it drove me nuts, took a lot of work to remove it too.



i did learn a few things about spyware though and how to remove them which means knowledge is a POWER.. thanks for the help..

12. by Stas. 2004-03-02 20:20:50
ISTbar/AUpdate installs a TinyBar variant to implement its toolbar, and will be detected by the script at this site as TinyBar/B. The hijacker is aimed at my-internet.info and blazefind.com; distribution is managed by searchbarcash.com, its controlling server.

ISTbar/XXXToolbar is an update based around porn. It uses its own toolbar code. The hijacker is aimed at its controlling server xxxtoolbar.com, and slotch.com; distribution is controlled by toolbarcash.com.

ISTbar alse installs other parasites: both variants install porn pop-up producer RapidBlaster/lp; the AUpdate variant is also known to install DownloadPlus.


Related news:
Similar parasites:
Related articles:
Related discussions: