Home Malware Programs Spyware Teensearch Bar

Teensearch Bar

Posted: March 28, 2006

Teensearch Bar is an Internet Explorer toolbar providing a web search service. It tracks user web browsing habits and sends gathered information to predetermined remote servers. The threat also records unique product ID of installed Windows operating computer and specific details of the main hard disk volume. Teensearch Bar is distributed through Active drive-by downloads and therefore can get into the computer while visiting some insecure web sites. The malware runs every time the user launches Internet Explorer.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 acsproxy.dll
    2 identlibdll.dll
    3 srchbar.dll
    4 unregister.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOTCatalyst.HttpClientCtrl.1HKEY_CLASSES_ROOTSearchBarToolbar.ISubclassHKEY_CLASSES_ROOTSearchBarToolbar.SearchBarHKEY_CURRENT_USERSoftwareE-VenturesN.V.HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallSearchBar
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}EDD6BA23-9EBB-11D2-B89C-00104B30757B7C9E9A74-1922-409E-AB46-E48784336C3A15E7D23B-736E-46FA-BFFD-CBEC4126BEFDEDD6BA25-9EBB-11D2-B89C-00104B30757BEDD6BA24-9EBB-11D2-B89C-00104B30757B9CE15EB5-6B39-4656-9E1F-2D219EE42E0E68831D00-169E-4FEB-89B9-E099DF4393212DDD90D6-F153-4EA7-A324-4B2D83D1027EEDD6BA27-9EBB-11D2-B89C-00104B30757BEDD6BA26-9EBB-11D2-B89C-00104B30757BAA8C93E1-7E5F-497E-B67C-CC8FE2A40D3B01FC5803-8644-45D7-877B-5A3924D8ECC40A8CE102-FA03-4612-9BEE-7FE5452F4CB1
Loading...