Home Malware Programs Bad Toolbars Video Scavanger Toolbar

Video Scavanger Toolbar

Posted: April 29, 2011

Threat Metric

Ranking: 2,226
Threat Level: 1/10
Infected PCs: 26,128
First Seen: April 29, 2011
Last Seen: October 17, 2023
OS(es) Affected: Windows

Aliases

Win32.Trojan [eSafe]Adware.Funweb-12 [ClamAV]Win32:PUP-gen [PUP] [Avast]not-a-virus:WebToolbar.Win32.MyWebSearch.tyx [Kaspersky]Tool.InstallToolbar.5 [DrWeb]Win32:FunWeb-K [PUP] [Avast]Win32:FunWeb-F [PUP] [Avast]AdWare/Win32.FunWeb.gen [Antiy-AVL]AdInstaller.FunWeb [AVG]Trojan-Dropper [Ikarus]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\VideoScavenger_1e\bar\1.bin\1ebarsvc.exe File name: 1ebarsvc.exe
Size: 28.76 KB (28766 bytes)
MD5: 5383494d213164f485b038de5ca5b36b
Detection count: 4,911
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\VideoScavenger_1e\bar\1.bin
Group: Malware file
Last Updated: March 7, 2014
%PROGRAMFILES%\VideoScavenger_1e\bar\1.bin\1ebrmon.exe File name: 1ebrmon.exe
Size: 20.48 KB (20480 bytes)
MD5: 412b9f5484cd6be10be839be7d607c92
Detection count: 4,502
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\VideoScavenger_1e\bar\1.bin
Group: Malware file
Last Updated: March 7, 2014
%PROGRAMFILES%\VideoScavenger_1e\bar\1.bin\1eSrcAs.dll File name: 1eSrcAs.dll
Size: 53.24 KB (53248 bytes)
MD5: a616c3d4e45f2c44d75b590e3c804889
Detection count: 3,979
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\VideoScavenger_1e\bar\1.bin
Group: Malware file
Last Updated: June 29, 2019
%PROGRAMFILES%\VideoScavenger_1e\bar\1.bin\1ebar.dll File name: 1ebar.dll
Size: 675.84 KB (675840 bytes)
MD5: 1b059104d1dd256193d5eb3f2e635098
Detection count: 3,951
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\VideoScavenger_1e\bar\1.bin
Group: Malware file
Last Updated: June 29, 2019
%PROGRAMFILES%\VideoScavenger_1e\bar\1.bin\1eSrcAs.dll File name: 1eSrcAs.dll
Size: 49.15 KB (49152 bytes)
MD5: 951fbd8bb96d4db7f811618de831521f
Detection count: 90
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\VideoScavenger_1e\bar\1.bin
Group: Malware file
Last Updated: March 7, 2014
%PROGRAMFILES%\VideoScavenger_1e\bar\1.bin\1eSrchMn.exe File name: 1eSrchMn.exe
Size: 120.36 KB (120360 bytes)
MD5: 37f55b452254f3c8fb4a46538c3602cd
Detection count: 80
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\VideoScavenger_1e\bar\1.bin
Group: Malware file
Last Updated: March 7, 2014
%PROGRAMFILES%\VideoScavenger_1e\bar\1.bin\1ebarsvc.exe File name: 1ebarsvc.exe
Size: 116.23 KB (116232 bytes)
MD5: 0fe5873b9d69216036b44cf497659d39
Detection count: 80
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\VideoScavenger_1e\bar\1.bin
Group: Malware file
Last Updated: March 7, 2014
%PROGRAMFILES%\VideoScavenger_1e\bar\1.bin\1eSrchMn.exe File name: 1eSrchMn.exe
Size: 112.16 KB (112168 bytes)
MD5: a6860a6a75414be4aa47da70eb047130
Detection count: 51
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\VideoScavenger_1e\bar\1.bin
Group: Malware file
Last Updated: March 7, 2014
%PROGRAMFILES%\VideoScavenger_1e\bar\1.bin\1eHighIn.exe File name: 1eHighIn.exe
Size: 22.04 KB (22048 bytes)
MD5: dae642ec8acf5d5972706c13b8543f5c
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\VideoScavenger_1e\bar\1.bin
Group: Malware file
Last Updated: April 29, 2022
%PROGRAMFILES(x86)%\VideoScavenger_1e\bar\3.bin\1eSrchMn.exe File name: 1eSrchMn.exe
Size: 116.26 KB (116264 bytes)
MD5: 67896d79d31228e8175d3aaa919a9ba0
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\VideoScavenger_1e\bar\3.bin
Group: Malware file
Last Updated: March 7, 2014
%PROGRAMFILES%\VideoScavenger_1e\bar\1.bin\1eSrchMn.exe File name: 1eSrchMn.exe
Size: 112.16 KB (112168 bytes)
MD5: 8cec20f362c9653481db48171348df6f
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\VideoScavenger_1e\bar\1.bin
Group: Malware file
Last Updated: March 7, 2014
%PROGRAMFILES%\VideoScavenger_1e\bar\1.bin\1ebar.dll File name: 1ebar.dll
Size: 655.36 KB (655360 bytes)
MD5: a555120d3a1461b05041cc58d395e205
Detection count: 9
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\VideoScavenger_1e\bar\1.bin
Group: Malware file
Last Updated: March 7, 2014
%PROGRAMFILES%\VideoScavenger_1e\bar\1.bin\1ebrmon.exe File name: 1ebrmon.exe
Size: 135.17 KB (135172 bytes)
MD5: d16ebb3340be83de74cac53398451db1
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\VideoScavenger_1e\bar\1.bin
Group: Malware file
Last Updated: March 7, 2014
%PROGRAMFILES(x86)%\VideoScavenger_1e\bar\1.bin\1emedint.exe File name: 1emedint.exe
Size: 20.59 KB (20598 bytes)
MD5: d4f76da2359efc8158c016fa69f0dbca
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\VideoScavenger_1e\bar\1.bin
Group: Malware file
Last Updated: March 7, 2014
%PROGRAMFILES%\VideoScavenger_1e\bar\1.bin\1ebarsvc.exe File name: 1ebarsvc.exe
Size: 116.23 KB (116232 bytes)
MD5: 76d4111f8eb542acdfc68c1060867172
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\VideoScavenger_1e\bar\1.bin
Group: Malware file
Last Updated: March 7, 2014
%PROGRAMFILES%\VideoScavenger_1e\bar\1.bin\1eSrchMn.exe File name: 1eSrchMn.exe
Size: 112.16 KB (112168 bytes)
MD5: f86a2983c6610b67e5943cb6a222b64f
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\VideoScavenger_1e\bar\1.bin
Group: Malware file
Last Updated: March 7, 2014
%PROGRAMFILES(x86)%\VideoScavenger_1e\bar\1.bin\1ebrmon.exe File name: 1ebrmon.exe
Size: 20.48 KB (20480 bytes)
MD5: c56ac96d1cd5d32af4cd235db2e542e3
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\VideoScavenger_1e\bar\1.bin
Group: Malware file
Last Updated: March 7, 2014
%USERPROFILE%\\AppData\Local\Apple\VideoScavenger_1e\jfoaicddma.dll File name: jfoaicddma.dll
Size: 1.84 MB (1840128 bytes)
MD5: ee48520e21cf82bdb5dd103c1595fef2
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %USERPROFILE%\\AppData\Local\Apple\VideoScavenger_1e
Group: Malware file
Last Updated: March 7, 2014
%PROGRAMFILES%\VideoScavenger_1e\bar\1.bin\1eSrchMn.exe File name: 1eSrchMn.exe
Size: 36.86 KB (36864 bytes)
MD5: 9395ed3eba4e19a36066b85572e26261
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\VideoScavenger_1e\bar\1.bin
Group: Malware file
Last Updated: March 7, 2014

Registry Modifications

The following newly produced Registry Values are:

CLSID{02984AE5-06D4-4683-BC2C-A11AE3880A75}{0574BCFE-3611-4AD5-9114-2218C8F1A423}{0AFB9872-419A-466E-A8DC-10504076DEB3}{0B5629F3-8E8C-4406-B1AB-25F86AFFB2D9}{149a544b-9203-49f5-b177-4f62b4b219b4}{23CA83AE-6D59-4B12-AD20-12C9B4814840}{28ECA842-8B53-456E-8DDC-772E86E9B396}{2D8FDA07-6836-475F-8ABB-E6B26B63F864}{2F3F4ADB-1C1C-4D5E-9FBC-C3AA53596CCC}{311c61de-a01b-414e-a7c1-68eae31aae8a}{31EB29B9-27C0-4442-90E7-4C6F731EEFF3}{33B63E5E-73E3-4ECC-859F-8A185B4DE045}{33EAE4D4-8B3B-4AAF-80FB-387C05CCDFC8}{35c636a4-4435-4723-b751-5b62d04ba15b}{3ECAC16A-A8C3-48C8-85BE-C6002305780C}{426036C7-93B0-4824-8CE9-FD92A1255717}{43724E5E-6101-4508-B5D9-A61B481CDE28}{52695F97-1A52-40A0-AFCD-99D149A1D0B8}{548E3328-D7EC-4FEE-AD39-3B4EC4A54D7B}{57dc49cc-5a9f-446c-bcf8-65c52b7060a6}{59446FD8-5B6F-4B16-94BA-E7DCC1804A9B}{612EB90E-13E5-42B5-8C0A-E30C055DEE21}{69B14A10-BF3C-49CD-A262-739B83973186}{6BB55738-B6A7-4114-840D-A2F98B87C33C}{748FA372-339E-4075-B913-86D0740A1DE9}{78036010-b4c0-45e5-8630-8c1eb84e05f0}{7B5949EC-6B5A-4B6F-955E-2F1E0C6B9077}{7E651229-9439-4AB7-BE20-7041E6456335}{807210b2-c03e-4203-a5e0-cb1b3496426b}{83D2434F-B0F2-4E42-AC6F-FE126786130D}{88B45DCB-9FBC-4BAF-A4A6-C150E98A9F32}{8B03E21E-AE2A-4C72-A965-F4538BC7C680}{908641C3-E57E-4024-8ECF-9A4CA021C179}{94c801cd-46bf-4b4d-834b-8f0a69bdff24}{98AC878C-D40F-47A6-84F2-09D6E4AEF347}{9ca70986-06bc-49f5-9097-b17cf968af09}{9F5E1EC6-0C22-4932-B2C4-9C40116F41A4}{9FBC470B-098B-4953-9082-481D0D3566DC}{a3c735a6-c9fc-48c4-b1df-37eab7c5cf41}{a45fb14e-bfa8-48a7-ada6-73e30f50f657}{A4C7B974-DCBE-4FD1-9E37-997182655A35}{A52A113A-C61D-49A7-8C53-DEBFCAC59B4F}{acf7da4c-eeb2-484a-a3a1-303d4054d50c}{ad0c6fea-e1cd-454a-af7f-6c1d44a176c3}{B4EEF1F3-9B79-4D3C-9B15-C45057D7B9E3}{B6F125AF-6973-4077-8498-0BDEDDD8E5D4}{B8E823D0-E574-444E-93BD-DDEBFC9831BF}{BE40C362-3DDB-40C0-8C2A-267385081DB3}{c6549209-1ff1-4a5c-a815-981f64f34b19}{C830E688-5B4A-4B4B-9293-E14996161FC8}{cca1a3ba-194e-4e75-aff1-41cff3c4e5fe}{d047fe10-dfe2-45cf-9fbf-966b9e64920f}{DA84BB1A-5D7B-45CD-AE39-A82C382BFA73}{dc27caca-cb20-4b93-b5d7-87224164438f}{DFEB2BA5-6D66-4CAD-87CE-AC3A4304E992}{ef18fe12-f90d-4205-8a09-5426c14395eb}{F348A713-F310-470B-B6FD-7FAF04D14151}{f43c37b5-73ad-465d-9774-168be6c56a9a}{F53C4FFC-1A47-4ECA-B372-014EC02F7301}{F8AC68F4-81F0-4FE6-BA17-512BAE2DDD88}{fede4586-5ada-4476-9fe0-f01dcaf20a56}File name without pathhttp_videoscavenger.dl.tb.ask.com_0.localstoragehttp_videoscavenger.dl.tb.ask.com_0.localstorage-journalHKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{ACF7DA4C-EEB2-484A-A3A1-303D4054D50C}Software\Microsoft\Internet Explorer\Approved Extensions\{C6549209-1FF1-4A5C-A815-981F64F34B19}Software\Microsoft\Internet Explorer\Approved Extensions\{D047FE10-DFE2-45CF-9FBF-966B9E64920F}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2f3f4adb-1c1c-4d5e-9fbc-c3aa53596ccc}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9382487b-a914-4d6e-b87c-149c77ec5d19}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{968a2d60-fab7-4bea-bec0-24545c88cc31}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a3c735a6-c9fc-48c4-b1df-37eab7c5cf41}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a52a113a-c61d-49a7-8c53-debfcac59b4f}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{bdae34e3-0a1a-45c8-a13b-d25f209e60ab}Software\Microsoft\Internet Explorer\SearchScopes\{194de045-cc5e-4840-b031-1ca9db98919d}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{311c61de-a01b-414e-a7c1-68eae31aae8a}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{94c801cd-46bf-4b4d-834b-8f0a69bdff24}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{cca1a3ba-194e-4e75-aff1-41cff3c4e5fe}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{d5763432-1edd-4a32-ae09-7ad46833676e}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{dc27caca-cb20-4b93-b5d7-87224164438f}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F53C4FFC-1A47-4ECA-B372-014EC02F7301}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{ACF7DA4C-EEB2-484A-A3A1-303D4054D50C}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C6549209-1FF1-4A5C-A815-981F64F34B19}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D047FE10-DFE2-45CF-9FBF-966B9E64920F}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{94C801CD-46BF-4B4D-834B-8F0A69BDFF24}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{ACF7DA4C-EEB2-484A-A3A1-303D4054D50C}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C6549209-1FF1-4A5C-A815-981F64F34B19}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D047FE10-DFE2-45CF-9FBF-966B9E64920F}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D5763432-1EDD-4A32-AE09-7AD46833676E}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2f3f4adb-1c1c-4d5e-9fbc-c3aa53596ccc}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9382487b-a914-4d6e-b87c-149c77ec5d19}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{968a2d60-fab7-4bea-bec0-24545c88cc31}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a3c735a6-c9fc-48c4-b1df-37eab7c5cf41}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a52a113a-c61d-49a7-8c53-debfcac59b4f}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{bdae34e3-0a1a-45c8-a13b-d25f209e60ab}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{194de045-cc5e-4840-b031-1ca9db98919d}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{311c61de-a01b-414e-a7c1-68eae31aae8a}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{94c801cd-46bf-4b4d-834b-8f0a69bdff24}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{cca1a3ba-194e-4e75-aff1-41cff3c4e5fe}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{d5763432-1edd-4a32-ae09-7ad46833676e}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{dc27caca-cb20-4b93-b5d7-87224164438f}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F53C4FFC-1A47-4ECA-B372-014EC02F7301}

Additional Information

The following directories were created:
%LOCALAPPDATA%\VideoScavenger_1e%PROGRAMFILES%\VideoScavenger_1e%PROGRAMFILES(x86)%\VideoScavenger_1e
The following URL's were detected:
VideoScavenger
Loading...