Home Malware Programs Bad Toolbars Toolbar.SmileysWeLove

Toolbar.SmileysWeLove

Posted: July 16, 2013

Threat Metric

Ranking: 2,677
Threat Level: 2/10
Infected PCs: 74,816
First Seen: July 16, 2013
Last Seen: October 16, 2023
OS(es) Affected: Windows

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files (x86)\SqueakyChocolate\UpdateChecker\UpdateCheckerApp.exe File name: UpdateCheckerApp.exe
Size: 7.16 KB (7168 bytes)
MD5: 28bd57319117e0b51d5c4be3a47448be
Detection count: 10,614
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\SqueakyChocolate\UpdateChecker\UpdateCheckerApp.exe
Group: Malware file
Last Updated: March 20, 2023
%PROGRAMFILES(x86)%\SqueakyChocolate\UpdateChecker\UpdateCheckerApp.exe File name: UpdateCheckerApp.exe
Size: 7.16 KB (7168 bytes)
MD5: 111affa25d92db4ebe2126c84f6bc4c0
Detection count: 663
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\SqueakyChocolate\UpdateChecker\UpdateCheckerApp.exe
Group: Malware file
Last Updated: July 18, 2023
C:\Program Files (x86)\SqueakyChocolate\UpdateChecker\uninstall.exe File name: uninstall.exe
Size: 50.69 KB (50699 bytes)
MD5: 35d8ed6e0e74ca5e5cea486ab1c2f2b8
Detection count: 80
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\SqueakyChocolate\UpdateChecker\uninstall.exe
Group: Malware file
Last Updated: May 26, 2023
C:\Users\<username>\AppData\Local\Temp\be7d544b39314b81a58656b9283a082738\SmileyStubSilent.exe File name: SmileyStubSilent.exe
Size: 561.61 KB (561619 bytes)
MD5: fd154046ce28e527cb5ccb68da72804b
Detection count: 75
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\be7d544b39314b81a58656b9283a082738\SmileyStubSilent.exe
Group: Malware file
Last Updated: April 15, 2023
%PROGRAMFILES%\SqueakyChocolate\UpdateChecker\UpdateCheckerApp.exe File name: UpdateCheckerApp.exe
Size: 34.81 KB (34816 bytes)
MD5: 45a8745a2cf4cced3ffae9a9c063d1ac
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\SqueakyChocolate\UpdateChecker
Group: Malware file
Last Updated: January 16, 2014
%PROGRAMFILES%\SqueakyChocolate\UpdateChecker\UpdateCheckerApp.exe File name: UpdateCheckerApp.exe
Size: 34.81 KB (34816 bytes)
MD5: 872d71d3e7675eaf62af8c0126531a02
Detection count: 24
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\SqueakyChocolate\UpdateChecker
Group: Malware file
Last Updated: January 16, 2014
%TEMP%\be7d544b39314b81a58656b9283a082738\SmileyStubSilent.exe File name: SmileyStubSilent.exe
Size: 598.38 KB (598387 bytes)
MD5: a949740d859fde71ceb8deb2cbbae566
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\be7d544b39314b81a58656b9283a082738
Group: Malware file
Last Updated: March 3, 2016
%USERPROFILE%\My Documents\smileyswelove_installer.exe File name: smileyswelove_installer.exe
Size: 687.2 KB (687200 bytes)
MD5: 5f7fade404fc18f4b60aa06132264147
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\My Documents
Group: Malware file
Last Updated: March 3, 2016
%PROGRAMFILES%\SqueakyChocolate\UpdateChecker\UpdateCheckerApp.exe File name: UpdateCheckerApp.exe
Size: 7.16 KB (7168 bytes)
MD5: 63101db3cb68adbb0c41cc82ed8530cb
Detection count: 6
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\SqueakyChocolate\UpdateChecker
Group: Malware file
Last Updated: January 16, 2014

Registry Modifications

The following newly produced Registry Values are:

CLSID{056D2AC6-7234-3769-BE94-25215E6A718F}{0DDD0901-01F1-3F7E-BAAA-0A56984C0A51}{0E10443B-7A46-3A74-86AA-1D2FA932A32A}{0E611C89-D119-39D5-9629-315592819086}{0E619751-1565-323D-8B24-4E824C15ABC8}{1459C27F-154F-3D18-8849-D0F51F1EC388}{1F182FAC-DBDE-32F2-B77C-2B63234F8259}{24F2561C-A5FE-3C0A-B2C3-2BEF9761CDC8}{28C6AF4C-15C3-3171-A5B7-2D4F6AEC759C}{3052DEE6-1F52-3CA8-9F3A-62DA48805FBF}{387BFD62-AD3C-4AB5-B3D9-5E3F4F20A38A}{3BA46537-97DD-3A05-9BF2-D4C997996796}{3BF3CEC6-D4A4-3E85-BF7F-B914991D1CFA}{3D954F15-72BA-3C5E-8B2B-BF0D65A1B98B}{409A172F-B978-3E21-B16C-D439179282A1}{40C2EF38-2F5B-3A36-9E28-BC8457FFD7C7}{41711DB1-1D7F-3DC2-9DDE-D625535B0F09}{41B16212-76DF-3B9F-AF9C-455AB8CA942C}{435ECDAD-B8F5-3B7D-A27B-D9FBFA4FFB60}{43C25947-3125-34A1-B543-B80C4D2EC0E2}{486AFD26-55CB-310A-8C13-BAAFC8C4A6F9}{4B3C4278-AB91-32DC-AEA4-606C6509DFB4}{53F35F01-B6FE-3E11-B431-3D80DB227FEB}{647EFA4E-6349-3093-8C57-B26EC1ACA785}{6864B108-6F84-3DE7-BBCD-3BF03E1DE3F5}{7410574D-5A41-3172-97C0-1E570B259075}{77A0E495-9E74-3ECD-A4EB-788185AA6BAC}{7A8C80C1-CB31-39DF-BD01-C0C8C7F634C1}{7B19CC07-9D3A-33F0-9F37-CB3A56766E11}{7DF4CA61-D733-3D4A-97E8-E2A9C779FB1F}{7FD45008-86E6-3366-B2F2-00120191DE57}{801B480C-0052-3474-90B0-2B853494196E}{804E1EF5-BEA4-331E-8318-C77F6C0E68AD}{8097B661-105D-3B2D-BA8A-B2AA0C1A2CBA}{80D2367D-6D45-3939-96FE-8B97CB2CACFB}{827597A8-A701-3D49-A228-13301E214380}{83C7340F-6336-3BF5-AAF0-B33D89B590A8}{8A6E668C-308A-3456-8D66-5BD429A17A88}{8AEF580C-E6E9-3ABC-BC53-2761AED95EFD}{97EF02F9-8BAB-41EB-97D1-BEC6EC3D36FF}{9E1D4C49-E255-3A4D-8364-E69B3DCD5421}{A830CF64-0BF6-3C3D-9AC2-713DCE11059B}{A9DD9207-9BD0-3939-A4F6-70A55939F71A}{AE815BAF-3E4E-3159-9B64-3E3B641B6629}{B58E7259-FC8B-3C69-822F-F94BF46455ED}{B781EE97-26A2-388A-802C-29BE927500AF}{BFB18DD2-51C1-34EC-BE7F-58B9D83B2B33}{C0DCBF24-2D34-3C1B-8E29-C0F79A02B487}{cf0f43ab-9c23-4d7b-8040-201b82844854}{D029C6E7-2145-323B-8340-0AEC5315042F}{D197155F-198E-394A-B80F-7EA70F1562DD}{DD60DCFB-247F-3298-B63D-9FAAA3DC9502}{DFB21C15-2B19-3069-A620-0B4CD37B0512}{E30DA02E-EB04-3ABB-A3B4-A26FF74C14F3}{E39B96A4-1932-3BDC-A7F3-2F02415B0C0F}{E4EF8A64-0A30-48F5-B3FE-5FDA978DA775}{EC3EE6DF-5BBC-3493-81D9-2A72A63933DC}{EE1AF166-E97B-346A-9155-642CA5A42502}{EF250318-E93A-3279-8896-F8DF95C0CF2B}{F27880EC-A940-3583-9CE5-3E189AE6A5F2}{F2ABA345-659B-3560-886B-0EF0BE1961F7}{FAD866D9-325F-39E0-8870-47ECCE2706A5}{FC991D27-AB93-3043-B430-7FF0918E9623}{FFD3B562-EAC3-37EB-B56A-68FAFAE413BA}File name without pathhttp_smileyswelove.com_0.localstoragehttp_smileyswelove.com_0.localstorage-journalhttp_smileyswelove.net_0.localstoragehttp_smileyswelove.net_0.localstorage-journalsmileyswelove[1].xmlsmileyswelove_installer.exeRegexp file mask%Temp%\bhfiles\smileyswelovetoolbar[RANDOM CHARACTERS].crx%Temp%\bhfiles\smileyswelovetoolbar[RANDOM CHARACTERS].xpiHKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\SmileysWeLoveToolbar.IEModule+IECustomCommandsSOFTWARE\Classes\SmileysWeLoveToolbar.IEModule+IECustomContextMenuCommandsSOFTWARE\Classes\SmileysWeLoveToolbar.PopupFormSOFTWARE\Classes\SmileysWeLoveToolbar.PopupForm+AltActionClickedEventArgsSOFTWARE\Classes\SmileysWeLoveToolbar.PopupForm+SmileyClickedEventArgsSOFTWARE\Classes\SmileysWeLoveToolbar.SWLIEToolbarSOFTWARE\Classes\SmileysWeLoveToolbar.SWLSettingsSOFTWARE\Classes\SmileysWeLoveToolbar.WatermarkTextBoxSoftware\Microsoft\Internet Explorer\Approved Extensions\{CF0F43AB-9C23-4D7B-8040-201B82844854}Software\Microsoft\Internet Explorer\Approved Extensions\{E4EF8A64-0A30-48F5-B3FE-5FDA978DA775}Software\Microsoft\Internet Explorer\DOMStorage\smileyswelove.netSOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\1afb8e7a-a08b-475a-beb2-376df461eb17SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e4ef8a64-0a30-48f5-b3fe-5fda978da775}SOFTWARE\Microsoft\Tracing\smileyswelove_RASAPI32SOFTWARE\Microsoft\Tracing\smileyswelove_RASMANCSSOFTWARE\Microsoft\Tracing\SmileysWeLove_SetupS_v1_RASAPI32SOFTWARE\Microsoft\Tracing\SmileysWeLove_SetupS_v1_RASMANCSSOFTWARE\Microsoft\Tracing\smileyswelove_v6p4_RASAPI32SOFTWARE\Microsoft\Tracing\smileyswelove_v6p4_RASMANCSSoftware\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E4EF8A64-0A30-48F5-B3FE-5FDA978DA775}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CF0F43AB-9C23-4D7B-8040-201B82844854}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E4EF8A64-0A30-48F5-B3FE-5FDA978DA775}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CF0F43AB-9C23-4D7B-8040-201B82844854}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E4EF8A64-0A30-48F5-B3FE-5FDA978DA775}Software\PopajarSoftware\SmileysWeLoveSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\1afb8e7a-a08b-475a-beb2-376df461eb17SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e4ef8a64-0a30-48f5-b3fe-5fda978da775}SOFTWARE\Wow6432Node\Microsoft\Tracing\smileyswelove_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\smileyswelove_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\SmileysWeLove_SetupS_v1_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\SmileysWeLove_SetupS_v1_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\smileyswelove_v6p4_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\smileyswelove_v6p4_RASMANCSSoftware\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E4EF8A64-0A30-48F5-B3FE-5FDA978DA775}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{65F14D6F-B4B7-498A-BAFA-203C114356B9}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{85463B84-D66A-4E4D-8D92-87E3F8A859AD}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Squeaky Chocolate, LLC UpdateCheckerSqueakyChocolate, LLC UpdateChecker{4B67E501-761A-4544-BD88-3CCB23746516}{5D57E386-D294-41BA-9146-FADE0C76EB2A}{A82BD48E-3547-4B94-BC0C-42EFED86B0EB}{B283C489-AF73-4DA0-A409-8C62B9AECA61}{DD36B76E-AAC3-4BB7-9946-A5FBBE121C33}

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\SmileysWeLove for IE%ProgramFiles%\Smileys We Love Toolbar for IE%ProgramFiles%\Squeaky Chocolate, LLC%ProgramFiles%\SqueakyChocolate%ProgramFiles%\SqueekyChocolate, LLC%ProgramFiles(x86)%\Smileys We Love Toolbar for IE%ProgramFiles(x86)%\Squeaky Chocolate, LLC%ProgramFiles(x86)%\SqueakyChocolate%ProgramFiles(x86)%\SqueekyChocolate, LLC%USERPROFILE%\AppData\LocalLow\smileyswelove%USERPROFILE%\Application Data\smileyswelove%appdata%\SmileysWeLove
The following URL's were detected:
SmileysWeLove
Loading...