Google Answers Logo
View Question
 
Q: ITSBar malware vulnerability exploited? ( Answered 4 out of 5 stars,   1 Comment )
Question  
Subject: ITSBar malware vulnerability exploited?
Category: Computers > Security
Asked by: goofer-ga
List Price: $3.00
Posted: 30 Apr 2004 05:30 PDT
Expires: 30 May 2004 05:30 PDT
Question ID: 338755
I'd like to know what browser vulnerability is used by the ITSBar
malware (virus) to hijack your browser and customize it with a toolbar
for porn sites, casinos, etc.

Request for Question Clarification by antivirus-ga on 03 May 2004 07:00 PDT
Is there a chance you are referring to ISTBar and not to ITSBar?

Can you clarify, please.

Thanks!

antivirus-ga

Clarification of Question by goofer-ga on 03 May 2004 18:35 PDT
Yep, my fault. It's ISTBar, not ITSBar. Thanks.

To the poster who pointed me to removal instructions, that's not an
issue any more, I wiped the computer. But I'm very concerned that my
company's default browser security settings are low enough that I
could get stung, and without doing anything silly like clicking
through a "would you like to install" message. So I'm really
interested in the specific browser vulnerability that was exploited so
I can close the hole on my computer and in our default config.

Thx,
- RBW
Answer  
Subject: Re: ITSBar malware vulnerability exploited?
Answered By: antivirus-ga on 03 May 2004 20:27 PDT
Rated:4 out of 5 stars
 
Hi goofer-ga,

Thanks for the clarification. ISTbar is closely tied to TinyBar, which
is a helper sometimes used to display ISTBar. TinyBar has been known
to exploit a vulnerability in Microsoft Java virtual machine. The
applicable patch is MS00-075 and can be found at:

http://www.microsoft.com/technet/security/bulletin/MS00-075.mspx

TinyBar has also been implicated in iframes cross-frame scripting
exploits. The applicable patch is MS02-066 and can be found at:

http://www.microsoft.com/technet/security/bulletin/MS02-066.mspx

A good resource for information on known TinyBar variants can be found at:
http://www.doxdesk.com/parasite/TinyBar.html

A good resource for information on known ISTBar variants can be found at:
http://www.doxdesk.com/parasite/ISTbar.html

Quite often, no vulnerability is involved, but rather affected by what
is often referred to as a drive-by download. The process starts with a
miscreant ActiveX control. To avoid this, make sure you've got
Internet Explorer configured properly. Mike Healan of Spywareinfo.com
has put together an excellent resource describing the necessary
settings:

http://www.spywareinfo.com/articles/hijacked/prevent.php

Though ISTBar is accused of being porn-related, insinuating that the
victim may have received it while visiting a porn site, this is a
rather common misconception. While a component of ISTBar is
porn-related, i.e. it launches pop-ups affiliate with porn sites,
ISTBar itself is not directly related to porn sites and the porn is a
side affect of the infection, not the cause.

So many of these hijackers are driven by affiliate ad programs.
Websites that sign up for such ad programs generally have no control
over what is advertised through them. The folks that do have control
seldom seem to bother checking out the types of ads that are pushed
through. Thus it is fairly easy to impact a wide range of victims and
often difficult to trace the source.

I hope this helps!

Regards,
antivirus-ga
goofer-ga rated this answer:4 out of 5 stars and gave an additional tip of: $1.00
Thanks--pointed me to just the right info!

Comments  
Subject: Re: ITSBar malware vulnerability exploited?
From: grinler-ga on 30 Apr 2004 10:02 PDT
 
Do you mean ISTBar?

If you are referring to that malware, it is placed on your computer in
one of two ways.  The first is from installing programs that are
affiliated with Integrated Search Technologies/CDT Inc.  These
affiliates are generally pornographic in nature.

The second way is that Internet Explorer's security settings are
improperly configured.

If you would like more information or to contact me directly, you can reach me at :

Http://www.bleepingcomputer.com

--
Grinler
http://www.bleepingcomputer.com
Source for Free Tech Support, Original Content and Tutorials for the
beginning computer user.

Important Disclaimer: Answers and comments provided on Google Answers are general information, and are not intended to substitute for informed professional medical, psychiatric, psychological, tax, legal, investment, accounting, or other professional advice. Google does not endorse, and expressly disclaims liability for any product, manufacturer, distributor, service or service provider mentioned or any opinion expressed in answers or comments. Please read carefully the Google Answers Terms of Service.

If you feel that you have found inappropriate content, please let us know by emailing us at answers-support@google.com with the question ID listed above. Thank you.
Search Google Answers for
Google Answers  


Google Home - Answers FAQ - Terms of Service - Privacy Policy