I ran a couple of routine anti-malware scans this morning and although Ad-Aware and SpyBot didn’t find anything, PestPatrol came up with ISTBar, which a Google search suggests is a bad actor. Anyone else have any experience with this? PestPatrol took care of it, but I’m curious about the ramifications.
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
ISTBar
Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » ISTBar
- This topic has 8 replies, 6 voices, and was last updated 19 years, 10 months ago.
AuthorTopicWScharlotte
AskWoody LoungerJune 28, 2005 at 2:30 pm #421238Viewing 2 reply threadsAuthorReplies-
WSKenK
AskWoody LoungerJune 28, 2005 at 3:30 pm #956492Hi Charlotte
Here’s a little info on ISTBar.
ISTbar is a homepage and search hijacking adware. It adds a toolbar to Internet Explorer and displays popup ads that come mainly from porn sites. This adware is distributed by Integrated Search Technologies/CDT Inc. It may also install third-party adware and spyware on the computer.
ISTbar is an IE toolbar, homepage- and search-hijacker provided by Integrated Search Technologies/CDT Inc.
Troj/Istbar-O is an downloader Trojan and browser hijacker.
Troj/Istbar-O attempts to download and install executables without notifying the user. Names of files downloaded may include: ……Symantec and other AV sites have more info on this little feller.
Have a Great day!!!
Ken -
WSLiberty Raynes
AskWoody LoungerJune 28, 2005 at 7:46 pm #956534Charlotte,
I know that Pest Patrol is highly rated, but I’m beginning to have more than a few passing doubts about the program. I just ran the online version of Pest Patrol on my main machine, and it found not only the ISTBar, but also Bonzi Buddy. Needless to say, that grape ape hasn’t been within a mile of my computers, ever! Neither of these “so-called” problems show up in the Registry at the locations that the scans indicate, which tells me that perhaps the folks at Pest Patrol may be doing a little salting in order to drum up business.Hold on a moment — I just did a little checking…
On another machine — a brand-new installation of XPSP2 — one which IE 6 has seen no other web sites other than Windows Update and Office Update — the Pest Patrol scanner found the ISTBar. It did not find evidence of Bonzi Buddy. Unless Microsoft is installing third party spyware/adware, I don’t see how it is possible for the ISTBar to be there. I think it’s probably a false positive — could be in your case, too.
I rechecked the machine on which traces of Bonzi Buddy were found. There was a Registry key for Bonzi.com, but no value had been set. It’s simply listed as a domain that’s blocked. Big deal — it was a false positive, as I thought. Between SpySweeper, AdAware, Spybot S&D, MS Antispyware, SpywareBlaster, and CleanMOCache, I think I’m pretty well set, and anything PestPatrol finds can be discounted as a false positive.
So, Charlotte, I’m guessing that you may find the ISTBar is a false positive as well.
Liberty R. -
WSDenGar
AskWoody Lounger -
WSLiberty Raynes
AskWoody LoungerJune 28, 2005 at 11:53 pm #956574DenGar,
I’m not saying that your malware didn’t exist, or that PestPatrol has no merit. What I am saying is that I am now discounting what I believe to be false positives found by PestPatrol on my systems. Your machine, as well as your security precautions, may be entirely different than mine.
Yes, it’s possible for the online version to be different than the retail version; there are probably many more options available during a scan done with the retail version. It’s possible that CA has the heuristics cranked up super-high in their online version. Who knows? Maybe someone from PestPatrol will answer Charlotte’s post, and we’ll get some answers. Good question, though.
-
-
WScharlotte
AskWoody LoungerJune 28, 2005 at 11:50 pm #956573I don’t know about the on-line scan, since I’ve never used it, but PestPatrol often misidentifies some things as BonziBuddy because certain libraries in legitimate products are also used by spyware. I ran into this with EasyMailSMTP. The thing to do with PestPatrol or any other anti-malware product, is to notify the publisher when they throw false positives like that. If you’re sure the file is legitmate and belongs to a valid product, letting the publisher know often leads to a very fast patch.
-
-
WSPhil Rabichow
AskWoody LoungerJune 28, 2005 at 8:34 pm #956544Hi Charlotte:
I think Liberty Raynes is right. I have the free version of Pest Patrol, so I have to delete anthing it finds manually. I ran PP & it found ISTBar. However, it gave the location as a registry entry:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftDownloadManagerWhen I checked that location in the registry, it only had a Name default, with no value set. I ran MS AntiSpyware, Ad-Aware, & Spybot S&D. All were negative. When I went to the Pest Patrol Spyware Encyclopedia to look it up, I had none of the running processes they mention should be removed. I also spot checked a number of registry entries associated with ISTBar & none existed. (I didn’t check everything).
It seems to me that Pest Patrol errs on the side of caution. Whenevery it finds a registry key or cookie, etc. whose name may or may not be spyware (depending upon other entries), it lists it as spyware.
By the way, I ran PP about a week ago & ISTBar didn’t show up, so we must be visiting the same p–n sites.
Cheers,
P.S. Just kidding. I don’t visit those sites intentionally. -
WScharlotte
AskWoody LoungerJune 28, 2005 at 11:46 pm #956572I use the Pro versions (if available) of all my anti malware products, and PestPatrol definitely found something which wasn’t there the last time it looked. I’m not suggesting it is any better or worse than the other products, but if you look at those google searches carefully, you’ll find PP listed as one of the products that finds and removes ISTBar. Yes, it does err on the side of caution and it can throw false positives, so I tend to track down the results before I take steps. I was just asking whether anyone had encountered any popups, etc., as a result of ISTBar, more as a matter of curiousity than anything else.
-
WSAlanMiller
AskWoody LoungerJune 29, 2005 at 11:12 am #956658Another possible scenario is if a particular malware is identified by, say Spybot, but the program is unable to clean up all vestiges of its original installation. Even though the malware is negated, some of its old footprints remain. Then when another program does its malware scanning, using other methods, it finds one of these old forgotten entries and alerts you to an infection.
The best guide IMO is to check out a manual removal guide, if possible. This should give a fair indication as to whether the offender is just an innocuous orphan, or whether the malware is really still there.
Alan
-
Viewing 2 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Intel : CVE-2024-45332, CVE-2024-43420, CVE-2025-20623
by
Alex5723
10 minutes ago -
False error message from eMClient
by
WSSebastian42
4 hours, 49 minutes ago -
Awoke to a rebooted Mac (crashed?)
by
rebop2020
3 hours, 5 minutes ago -
Office 2021 Perpetual for Mac
by
rebop2020
4 hours, 18 minutes ago -
Difface : Reconstruction of 3D Human Facial Images from DNA Sequence
by
Alex5723
7 hours, 49 minutes ago -
Seven things we learned from WhatsApp vs. NSO Group spyware lawsuit
by
Alex5723
8 hours, 12 minutes ago -
Outdated Laptop
by
jdamkeene
13 hours, 15 minutes ago -
Updating Keepass2Android
by
CBFPD-Chief115
18 hours, 40 minutes ago -
Another big Microsoft layoff
by
Charlie
18 hours, 20 minutes ago -
PowerShell to detect NPU – Testers Needed
by
RetiredGeek
1 hour, 15 minutes ago -
May 2025 updates are out
by
Susan Bradley
40 minutes ago -
Windows 11 Insider Preview build 26200.5600 released to DEV
by
joep517
1 day ago -
Windows 11 Insider Preview build 26120.3964 (24H2) released to BETA
by
joep517
1 day ago -
Drivers suggested via Windows Update
by
Tex265
1 day ago -
Thunderbird release notes for 128 esr have disappeared
by
EricB
22 hours, 1 minute ago -
CISA mutes own website, shifts routine cyber alerts to X, RSS, email
by
Nibbled To Death By Ducks
1 day, 7 hours ago -
Apple releases 18.5
by
Susan Bradley
1 day, 1 hour ago -
Fedora Linux 40 will go end of life for updates and support on 2025-05-13.
by
Alex5723
1 day, 8 hours ago -
How a new type of AI is helping police skirt facial recognition bans
by
Alex5723
1 day, 9 hours ago -
Windows 7 ISO /Windows 10 ISO
by
ECWS
16 hours, 36 minutes ago -
No HP software folders
by
fpefpe
1 day, 17 hours ago -
Which antivirus apps and VPNs are the most secure in 2025?
by
B. Livingston
14 hours, 20 minutes ago -
Stay connected anywhere
by
Peter Deegan
1 day, 22 hours ago -
Copilot, under the table
by
Will Fastie
49 minutes ago -
The Windows experience
by
Will Fastie
2 days, 4 hours ago -
A tale of two operating systems
by
Susan Bradley
8 hours, 51 minutes ago -
Microsoft : Resolving Blue Screen errors in Windows
by
Alex5723
2 days, 9 hours ago -
Where’s the cache today?
by
Up2you2
3 days, 1 hour ago -
Ascension says recent data breach affects over 430,000 patients
by
Nibbled To Death By Ducks
2 days, 18 hours ago -
Nintendo Switch 2 has a remote killing switch
by
Alex5723
1 day, 18 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.