Home Malware Programs Bad Toolbars SmartBar Toolbar

SmartBar Toolbar

Posted: February 27, 2013

Threat Metric

Ranking: 5,141
Threat Level: 5/10
Infected PCs: 16,179
First Seen: February 27, 2013
Last Seen: October 14, 2023
OS(es) Affected: Windows

SmartBar Toolbar is an unwanted toolbar that leads to annoying redirects to search.creativetoolbars.com website. SmartBar Toolbar claims to enhance your browsing experience however, in reality, makes some unwanted activities. Although SmartBar Toolbar is not linked to malicious programs, it uses unfair methods to install itself onto vulnerable computers. SmartBar Toolbar comes packaged with other programs, mostly free program downloads; therefore, PC users often do not notice additional software products that are being installed. SmartBar Toolbar targets all main web browsers including Mozilla Firefox, Google Chrome and Internet Explorer. SmartBar Toolbar changes the default search engine and homepage. SmartBar Toolbar redirects all search results in any search engine to search.creativetoolbars.com.

Aliases

W32/AutoRun.AAEH!worm [Fortinet]

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{0CCF693A-4357-4C28-9E5F-622656801508}{0CFBE80D-5608-4309-A0F5-3B1414833432}{1581739A-4E37-4453-B6DE-5E50C457329C}{22703927-CFEA-4372-B7CD-0C313221255D}{22EA7BB2-688B-4259-BB84-16EAFC831EA7}{28854827-554A-421A-9E4C-0BB3FF4FE5DC}{3E87D3B7-0291-4BF0-BF44-FA42724F32DA}{4756493F-BA26-4FA2-9865-E29852CE259F}{51A045FD-9441-41B2-9700-1CBCB7BD0B22}{8F5D0B07-E090-4163-A87D-99FAF3171187}{ACAF0AD7-4343-4D8E-9B28-FEB46DEEF0FB}{AEFCD9CA-7555-4765-98B4-830AF5DD5804}{AFE2031E-0596-471D-AB03-B652839D6577}{C0DA985C-09F8-44EC-967F-81073FA9403B}{C5E5951A-4ADD-4402-8A8E-EF97DCB9D8EC}{CB5345B3-6647-4351-842C-16A3921B0474}{E00D7C59-1D0B-4427-8742-06C64ADF7D4F}{E192147E-948F-497C-B7EC-FC37A46DF578}{E584D584-1FE3-4DB5-BF49-969822DD9716}{F1057CCB-9957-4499-8202-24F1336C4917}{F1E12282-ECAF-4225-BBD8-B75394A4CE54}{FD36FEBE-DBA1-4597-9DD1-B13794B92F68}HKEY..\..\..\..{RegistryKeys}Software\Bechiro S.L.\smartbarSOFTWARE\Classes\Bechiro.smartbarappCoreSOFTWARE\Classes\Bechiro.smartbarappCore.1SOFTWARE\Classes\Bechiro.smartbardskBndSOFTWARE\Classes\Bechiro.smartbardskBnd.1SOFTWARE\Classes\Bechiro.smartbarHlprSOFTWARE\Classes\Bechiro.smartbarHlpr.1SOFTWARE\Classes\esrv.smartbarESrvcSOFTWARE\Classes\esrv.smartbarESrvc.1Software\Microsoft\Internet Explorer\Approved Extensions\{0CFBE80D-5608-4309-A0F5-3B1414833432}Software\Microsoft\Internet Explorer\Approved Extensions\{FD36FEBE-DBA1-4597-9DD1-B13794B92F68}SOFTWARE\Wow6432Node\Bechiro S.L.\smartbarSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5452DABD-CA7F-4E35-A725-F8DBBCDD73F1}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{0CFBE80D-5608-4309-A0F5-3B1414833432}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{FD36FEBE-DBA1-4597-9DD1-B13794B92F68}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}smartbar

Additional Information

The following directories were created:
%PROGRAMFILES%\Bechiro S.L\smartbar%PROGRAMFILES(x86)%\Bechiro S.L\smartbar%TEMP%\mt_ffx\Bechiro S.L\smartbar%USERPROFILE%\AppData\LocalLow\Bechiro S.L\smartbar%USERPROFILE%\Application Data\Bechiro S.L\smartbar
The following URL's were detected:
search.creativetoolbars

Related Posts

One Comment

Loading...