(_)
-. Windows (PE EXE-), UPX. 32 256 . 90 . Visual C++.
www.ysbweb.com.
, .
:
Complete :
ISTdownloadMuTEX .
, :
istsvc.exe (19 456 ).
Trojan-Downloader.Win32.IstBar.gen.
: %Program Files%\ISTsvc\.
istbarcm.dll (91 136 ).
Trojan-Downloader.Win32.IstBar.kg.
: %Program Files%\ISTBar\
optimize.exe (52 104 ).
Trojan-Downloader.Win32.Dyfuca.ei.
: %Program Files%\InternetOptimizer\
<6 >.exe
: bnaoqc.exe (10 240 ).
Trojan-Downloader.Win32.IstBar.ij.
: %WinDir%\
saferscan.exe (91 136 )
: %Program Files%\SaferScan\
SAcc.exe (110 592 )
: %Program Files%\SurfAccuracy\
SAccU.exe (16 384 )
: %Program Files%\SurfAccuracy\
<8 >.exe
: fowkxcmy.exe (52 104 ).
: %WinDir%\
:
http://www.ysbweb.com
http://www.surfaccuracy.com
http://www.tbcode.com
http://www.slotch.com
:
[HKCU\Software\SaferScan]
"account_id"="0"
[HKCU\Software\IST]
"account_id"="dword:00000000"
"config"=""
"exe_start"="dword:00000001"
"InstallDate"="%date% %time%"
"Recover"="!ZpHc:"
[HKLM\Software\ISTbar]
"installTitle"="SlotchBar"
"barTitle"="SlotchBar"
"serverpath"="http://cache.slotch.com/ist/bars/istbar_cm/"
"urlAfterInstall"="http://www.ysbweb.com/install/welcome.html"
"gUpdate"="0"
"TBRowMode"="dword:00000000"
"xml_istbar.xml"="-206472906"
"imagemap_normal.bmp"="-942107825"
"imagemap_over.bmp"="-942107825"
"showcorrupted"="1"
"updatever"=""
"refreshscope"="1440"
"allowupdate"="0"
"LastCheckTime"="dword:4400260c"
"version.txt"="-186917087"
"UpdateBegin"="0"
[HKLM\Software\ISTbar\Historyfiles]
"C:\Program Files\ISTbar\xml_istbar.xml"="dword:00000001"
"C:\Program Files\ISTbar\imagemap_normal.bmp"="dword:00000001"
"C:\Program Files\ISTbar\imagemap_over.bmp"="dword:00000001"
"C:\Program Files\ISTbar\version.txt"="dword:00000001"
[HKLM\Software\ISTsvc]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\ISTsvc]
"DisplayName"="ISTsvc"
"UninstallString"="C:\PROGRAM FILES\ISTSVC\ISTSVC.EXE /remove"
"NoModify"="dword:00000001"
[HKLM\Software\SAcc]
"accid"="104"
"subaccid"="0"
"Version"="dword:0x480"
"InstallDate"="dword:0x44002606"
"DbgInfo"="|2006-02-25 10:50:22 GetInetFile - CInternetException produced error 12029."
"srecovery"="!ZpH..."
"CfgReloadAttempts"="dword:00000001"
[HKLM\Software\Policies\Microsoft\Windows\Safer]
COM- ISTbar:
[HKCR\IstBar.BarObj]
"CLSID"={FAA356E4-D317-42a6-AB41-A3021C6E7D52}
[HKCR\CLSID\{FAA356E4-D317-42a6-AB41-A3021C6E7D52}]
"ProgId"="ISTbar.BarObj"
:
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"IST Service"="C:\Program Files\ISTsvc\istsvc.exe"
"aKCSidSjW"="%WinDir%\bnaoqc.exe"
"SurfAccuracy"="C:\Program Files\SurfAccuracy\SAcc.exe"
"Internet Optimizer"="C:\Program Files\Internet Optimizer\optimize.exe"
"SaferScan"=""C:\Program Files\SaferScan\saferscan.exe" /aid:0"
"ReJf5vH"="%WinDir%\fowkxcmy.exe"
:
http://www.ysbweb.com/install/welcome.html
:
bnaoqc.exe
istsvc.exe
optimize.exe
Sacc.exe
saferscan.exe
:
[HKCU\Software\SaferScan]
[HKCU\Software\IST]
[HKCU\Software\ISTbar]
[HKCU\Software\ISTsvc]
[HKLM\Software\SAcc]
[HKLM\Software\Policies\Microsoft\Windows\Safer]
[HKCR\IstBar.BarObj]
[HKCR\CLSID\{FAA356E4-D317-42a6-AB41-A3021C6E7D52}]
:
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"IST Service"
"aKCSidSjW" - ( 9 )
"SurfAccuracy"
"Internet Optimizer"
"SaferScan"
"ReJf5vH" - ( 7 )
:
%Program Files%\ISTBar\
%Program Files%\ISTsvc\
%Program Files%\InternetOptimizer\
%Program Files%\SaferScan\
%Program Files%\SurfAccuracy\
%WinDir%\<8 >.exe
%WinDir%\<6 >.exe