Home Malware Programs Bad Toolbars ScenicReflections Toolbar

ScenicReflections Toolbar

Posted: April 18, 2014

Threat Metric

Ranking: 7,178
Threat Level: 2/10
Infected PCs: 18,826
First Seen: April 18, 2014
Last Seen: October 16, 2023
OS(es) Affected: Windows


ScenicReflections Toolbar is a Visicom toolbar that may be installed in a Web browser and then collect and store information about a computer user's web browsing activity and transfer this information to Visicom so they can offer services or show ads via the ScenicReflections Toolbar. The website of Scenic Reflections, ScenicReflections.com, is one of the largest free screensaver websites on the Internet. ScenicReflections.com offers free screensavers with beautiful images or 3D effects and soothing music. ScenicReflections.com also offer free wallpapers, free ecards, free games and more.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files\mystarttb\dtUser.exe File name: dtUser.exe
Size: 89.08 KB (89088 bytes)
MD5: dee76de9b1552f90a8c7d86569cce20e
Detection count: 157
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files\mystarttb\dtUser.exe
Group: Malware file
Last Updated: June 2, 2023
AllMyWebToolbar.exe File name: AllMyWebToolbar.exe
Size: 2.05 MB (2059216 bytes)
MD5: ec2eb16431a46b1129976d0a75117f25
Detection count: 86
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 18, 2014
%PROGRAMFILES%\scenicreflectionstb\scenicreflectionsDx.dll File name: scenicreflectionsDx.dll
Size: 86.69 KB (86696 bytes)
MD5: 13afcd2af857612815635b7d2aad75f3
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\scenicreflectionstb
Group: Malware file
Last Updated: April 18, 2014
%PROGRAMFILES%\scenicreflectionstb\auxi\scenicreflectionsAu.dll File name: scenicreflectionsAu.dll
Size: 262.31 KB (262312 bytes)
MD5: 1ae26066fa138a75e595cbdb26bef320
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\scenicreflectionstb\auxi
Group: Malware file
Last Updated: April 18, 2014
dtUser.exe File name: dtUser.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
scenicreflectionstb.dll File name: scenicreflectionstb.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
scenicreflectionsDx.dll File name: scenicreflectionsDx.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

CLSID{3a47260c-5db6-4371-91ce-f3c30748704f}{66E8DCC7-97D2-4A89-8E08-D0610FF0878C}{cd9094dd-9c64-45c6-8cab-7c3b96825be3}HKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\antiphishing-scenic2_0dnSoftware\AppDataLow\Software\scenicreflectionstbSoftware\Microsoft\Internet Explorer\Approved Extensions\{3A47260C-5DB6-4371-91CE-F3C30748704F}Software\Microsoft\Internet Explorer\Approved Extensions\{6cb6a60d-0ade-40db-bc9c-015674ae79cb}Software\Microsoft\Internet Explorer\Approved Extensions\{CD9094DD-9C64-45C6-8CAB-7C3B96825BE3}Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\tb_ScenicReflections.exeSoftware\Microsoft\Windows\CurrentVersion\Ext\Settings\{3A47260C-5DB6-4371-91CE-F3C30748704F}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CD9094DD-9C64-45C6-8CAB-7C3B96825BE3}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3A47260C-5DB6-4371-91CE-F3C30748704F}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD9094DD-9C64-45C6-8CAB-7C3B96825BE3}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{54ceb99c-50a4-48e2-97c8-ea0e66c8584a}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{3a47260c-5db6-4371-91ce-f3c30748704f}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{cd9094dd-9c64-45c6-8cab-7c3b96825be3}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}scenicreflectionstb

Additional Information

The following directories were created:
%APPDATA%\ScenicReflections%APPDATA%\TB\ChromeExtData\jfbiccdmmgfhdaomohbjmciknobhaone%APPDATA%\scenicreflectionstb%LOCALAPPDATA%\NativeMessaging\CT2811276%LOCALAPPDATA%\antiphishing-scenic2_0dn%PROGRAMFILES%\scenicreflectionstb%PROGRAMFILES(x86)%\scenicreflectionstb%USERPROFILE%\AppData\LocalLow\scenicreflectionstb%USERPROFILE%\Local Settings\Application Data\antiphishing-scenic2_0dn
The following URL's were detected:
Scenicreflections.ourtoolbar.com
Loading...