Home Malware Programs Bad Toolbars Swagbucks Toolbar

Swagbucks Toolbar

Posted: May 21, 2013

Threat Metric

Ranking: 3,118
Threat Level: 5/10
Infected PCs: 13,469
First Seen: May 21, 2013
Last Seen: October 16, 2023
OS(es) Affected: Windows

Swagbucks Toolbar is a potentially unwanted toolbar that once installed on the vulnerable computer changes the default home page, default search engine and new tab page to Search.swagbucks.com. Swagbucks Toolbart might also be called the SBTV Toolbar or Swag Code Toolbar. Swagbucks.com enables Internet users to earn virtual currency by searching the web, shopping at their favorite retailers, engaging in other activities such as submitting polls, phone recycling, and completing special offers. Swagbucks Toolbar is owed by Prodege LLC. While the Swagbucks Toolbar itself as well as the website Search.swagbucks.com are not malicious and do not make any direct damage to the computer system, having these might be very annoying to the PC user. Whenever the web user performs any online search, he/she will get diverted to the search page of Swagbucks or any other website that is pushed by the Swagbucks Toolbar. Although the computer user might not see big differences from, for example, Google or Yahoo!, Search.swagbucks.com gives relevant search results mixed with advertised links. The two types of the links are not marked differently; therefore, the PC user might easily click on the advertised link instead of a relevant one. Prodege LLC does not take any responsibility for the content it shows, which means the computer user might click on a link that is malicious or take to a hijacked website that is designed to affect the computer with malware.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{85675E8E-5807-456E-8005-29ECDFB5AA98}{8BDEA9D6-6F62-45EB-8EE9-8A81AF0D2F94}HKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\Swag_BucksSoftware\AppDataLow\Toolbar\RegisteredSources\CT2260173SOFTWARE\Classes\Toolbar.CT2260173Software\Microsoft\Internet Explorer\Approved Extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}Software\Microsoft\Internet Explorer\URLSearchHooks\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}SOFTWARE\Wow6432Node\Google\Chrome\Extensions\apjkpjchfbckhjhokinlgdbmibpbbjakSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{85675e8e-5807-456e-8005-29ecdfb5aa98}SOFTWARE\Wow6432Node\Swag_BucksHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Swag Bucks ToolbarSwag_Bucks Toolbar

Additional Information

The following directories were created:
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\apjkpjchfbckhjhokinlgdbmibpbbjak%PROGRAMFILES%\Swag_Bucks%PROGRAMFILES(x86)%\Swag_Bucks%TEMP%\CT2260173%USERPROFILE%\AppData\LocalLow\Swag_Bucks
Loading...