How to remove Trojan.Downloader.Istbar.BU
THREAT NAME
Trojan.Downloader.Istbar.BU
CLEAN INSTRUCTIONS
1. Open Windows Explorer, locate the infected file and delete it.
2. Run a full system scan with BullGuard.
SYMPTOMS
1. Increased network traffic.
2. A process named bundleinstall might be observed in Task Manager.
DESCRIPTION
1. When run, it will try to get the temporary path (usually C:\Documents and Settings\User\Local Settings\Temp).
2. It will initiate a connexion to http://www.slotch.com.
3. It will download a file named bundler_kart.ex.
4. The file will be saved as C:\Documents and Settings\User\Local Settings\Temp\bundleinstall.exe.
After the download is finished this file will be executed.
Author:
The BullGuard Team