Home Malware Programs Potentially Unwanted Programs (PUPs) iToolbox

iToolbox

Posted: October 21, 2014

Threat Metric

Threat Level: 2/10
Infected PCs: 314
First Seen: October 20, 2014
Last Seen: May 6, 2023
OS(es) Affected: Windows

According to reputable anti-virus and anti-malware programs, iToolbox is a Potentially Unwanted Program (PUP) distributed using third-party download managers. Adware-related applications like iToolbox are designed to enhance your web-browsing experience, but in reality, all they do is to cause endless advertisements to be displayed. What is more, iToolbox may make your browser actually run slower and start having crashes very often. According to leading computer threat specialists, it is advised to read the EULA (End User License Agreement) of apps carefully because in iToolbox's EULA, it is states: 'The application has a new feature: it displays search results from some of your favorite sites directly in the window that you have opened. On search engines there will be ads beneath iToolBox, the ads are recognized as originating from iToolBox.'

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\iToolBox\IE\tbhelper2.exe File name: tbhelper2.exe
Size: 204 KB (204000 bytes)
MD5: d968561d714b2ceff111ac9b55ce7628
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\iToolBox\IE
Group: Malware file
Last Updated: April 16, 2020
C:\Program Files (x86)\iToolBox\AddonsHelper.exe File name: AddonsHelper.exe
Size: 1.02 MB (1028096 bytes)
MD5: 1b2d4eff4a422946b0065e4f4ca031ee
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\iToolBox\AddonsHelper.exe
Group: Malware file
Last Updated: August 20, 2021

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{763C6A28-39E4-4086-A444-7CB728DBBEB3}Software\Microsoft\Internet Explorer\Approved Extensions\{9B0D6D1F-805C-4B09-A4F1-044A6E96A9F0}Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{763C6A28-39E4-4086-A444-7CB728DBBEB3}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{763C6A28-39E4-4086-A444-7CB728DBBEB3}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{763C6A28-39E4-4086-A444-7CB728DBBEB3}

Additional Information

The following directories were created:
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\ecofmnklbjjdkddlahildccddjleeofg%ProgramFiles%\iToolBox%ProgramFiles(x86)%\iToolBox
The following URL's were detected:
search.internettoolbox.org
Loading...