Movies Toolbar

Movies Toolbar Description

ScreenshotMovies Toolbar is a toolbar/ browser hijacker that is able to enter vulnerable computers packed with numerous freeware applications from the Internet. Movies Toolbar can be installed on Internet Explorer, Mozilla Firefox or Google Chrome. Movies Toolbar makes changes to the affected web browser's settings, inserts its toolbar, and replaces the default homepage and default search engine with some suspicious website. Movies Toolbar is also categorized as a potentially unwanted program (PUP). Movie Toolbar is delivered by Bandoo Media, which is responsible for advertising more applications such as this one. The aim of Movies Toolbar is to push some doubtful advertisement websites by using tricky techniques. Movies Toolbar will force the affected PC user to use Search.ask.com as the main search engine. Movies Toolbar also adds numerous sponsored websites to the search results in any legal search engine on the targeted PC. Movies Toolbar can also result in unwanted hits to dubious websites and numerous pop-up ads shown on the victimized PCs.

Aliases: Adware.Win64.SearchSuite.AeVo, Riskware/SearchSuite [Fortinet], PUA.Bandoo [Ikarus], Trj/Chgt.C [Panda], Win32.Application.Searchsuite.C [GData], PUP/Win32.SearchSuite [AhnLab-V3], Win32.Troj.Generic.a.(kcloud), RiskWare[WebToolbar:not-a-virus]/Win64.SearchSuite [Antiy-AVL], Artemis [McAfee-GW-Edition], not-a-virus:WebToolbar.Win64.SearchSuite.d [Kaspersky], Suspicious_GEN.F47V0808, PUA.Toolbar.SearchSuite!, Trojan ( 0049f9491 ) [K7AntiVirus], Artemis!5D8BE8191754 [McAfee] and MalSign.Generic.1EE [AVG].

Technical Information

File System Details

Movies Toolbar creates the following file(s):
# File Name Size MD5 Detection Count
1 %SYSTEMDRIVE%\AdwCleaner\FileQuarantine\C\Program Files (x86)\ilividbandoomoviestoolbar\IE\searchresultsDx.dll.vir\searchresultsDx.dll.vir 115,584 775b7ee21c3bf311359c6f17ab7faa42 4,070
2 C:\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~1\IE\__searchresultsDx.dll\__searchresultsDx.dll 92,560 0f1ee891dc2acb8510a0dd7dacdaa07c 2,069
3 %SYSTEMDRIVE%\Users\Administrator\AppData\Local\perionappswatchermediatoolbar20\GC\IACNativeMsgHost.exe\IACNativeMsgHost.exe 156,088 600290bae905edc4eb07c84b372f92a5 287
4 C:\4_ OOPS Keys_2017\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~1\IE\__searchresultsDx.dll.vir\__searchresultsDx.dll.vir 92,592 3a560e3678cbd0d4dfa3c7210dea0aa1 271
5 %PROGRAMFILES%\Movies Toolbar\Datamngr\DatamngrUI.exe 3,579,904 1cc65ec6bda760819c39b40000898d7d 138
6 \??\C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\setmgrc1.cfg 36,216 24a97cf9304d38b5515ef4a23f0e7505 69
7 %PROGRAMFILES(x86)%\Movies Toolbar\Datamngr\DatamngrCoordinator.exe 3,180,032 411997298eb2bdc5d257703f4abd39a7 58
8 %PROGRAMFILES%\Browser Tab Search by Ask\SafetyNut\SafetyNutManager.exe 3,544,072 72cb619443c1d5b6bddf7e90867d3c58 31
9 %PROGRAMFILES%\Movies Toolbar\Datamngr\SRTOOL~1\IE\searchresultsDx.dll 115,640 bf5c1afa814fc7b627de38ad0b7f5e89 15
10 %PROGRAMFILES(x86)%\ilividmoviestoolbar20\IE\searchresultsDx64.dll 131,512 5d0df18f66099a1a643b4a50b6701515 4
11 %PROGRAMFILES%\Movies Toolbar\SafetyNut\safetynut.exe 3,538,952 2b3b78b4e82ea42a730aad810a2c1a4d 2
More files

Registry Details

Movies Toolbar creates the following registry entry or registry entries:
Directory
%ALLUSERSPROFILE%\Application Data\SafetyNut
%ALLUSERSPROFILE%\SafetyNut
%LOCALAPPDATA%\ilividmoviestoolbar20
%LOCALAPPDATA%\imeshkoyotesoftmoviestoolbar
%LOCALAPPDATA%\imeshsavevidmoviestoolbar
%LOCALAPPDATA%\savevidmoviestoolbarha
%LOCALAPPDATA%\somotomoviestoolbar1
%PROGRAMFILES%\Browser Tab Search by Ask\SafetyNut
%PROGRAMFILES%\ilividmoviestoolbar20
%PROGRAMFILES%\ilividmoviestoolbar280
%PROGRAMFILES%\Movies App
%ProgramFiles%\Movies Toolbar
%PROGRAMFILES%\Savevid
%PROGRAMFILES(x86)%\Browser Tab Search by Ask\SafetyNut
%PROGRAMFILES(x86)%\ilividmoviestoolbar20
%PROGRAMFILES(x86)%\ilividmoviestoolbar280
%PROGRAMFILES(x86)%\Movies App
%ProgramFiles(x86)%\Movies Toolbar
%PROGRAMFILES(x86)%\Savevid
%TEMP%\{2977d8cc-8902-4340-be88-2c676bf96b8d}
%USERPROFILE%\AppData\LocalLow\ilividmoviestoolbar20
%USERPROFILE%\AppData\LocalLow\imeshkoyotesoftmoviestoolbar
%USERPROFILE%\AppData\LocalLow\savevidmoviestoolbarha
%USERPROFILE%\AppData\LocalLow\somotomoviestoolbar1
%USERPROFILE%\AppData\LocalLow\somotomoviestoolbar181
%UserProfile%\Local Settings\Application Data\ilividmoviestoolbar20
%UserProfile%\Local Settings\Application Data\imeshkoyotesoftmoviestoolbar
%UserProfile%\Local Settings\Application Data\somotomoviestoolbar1
Registry key
Software\APN DTX
Software\APN DTX\{3444c3c5-6c56-4a16-a453-832b05bf6ea4}
Software\APNDTX
Software\AppDataLow\Software\somotomoviestoolbar1
Software\AppDataLow\Software\somotomoviestoolbar181
SOFTWARE\Classes\AppID\SavevidPluginCore.EXE
SOFTWARE\Classes\MoviesToolbarHelper.DNSGuard
SOFTWARE\Classes\MoviesToolbarHelper.DNSGuard.1
SOFTWARE\Classes\SavevidPluginCore.PluginManager
SOFTWARE\Classes\SavevidPluginCore.PluginManager.1
SOFTWARE\Classes\Wow6432Node\AppID\SavevidPluginCore.EXE
Software\imeshkoyotesoftmoviestoolbar
Software\Microsoft\Internet Explorer\Approved Extensions\{338A754C-B46E-4BF2-8AC8-23DE36862AD3}
Software\Microsoft\Internet Explorer\Approved Extensions\{C75A2D66-6D1D-4735-8F63-9D85DCC026A6}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\${dtUserElevationPolicyID}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3444c3c5-6c56-4a16-a453-832b05bf6ea4}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3d86a75b-cb6b-4764-885d-ca6336f04ba2}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{c75a2d66-6d1d-4735-8f63-9d85dcc026a6}
SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{52db1893-8a90-4192-aede-08e00b8f8473}
SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2427}
SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2446}
SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2459}
SOFTWARE\Microsoft\Internet Explorer\Toolbar\{08ae5e13-70cc-4fbb-ad00-ef4b90a44451}
SOFTWARE\Microsoft\Internet Explorer\Toolbar\{3d86a75b-cb6b-4764-885d-ca6336f04ba2}
SOFTWARE\Microsoft\Internet Explorer\Toolbar\{c75a2d66-6d1d-4735-8f63-9d85dcc026a6}
SOFTWARE\Microsoft\Internet Explorer\Toolbar\{cc2542c4-3251-4ac4-845e-f7e742bbe6de}
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{3d86a75b-cb6b-4764-885d-ca6336f04ba2}
Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c0caa5fe-7c9c-4dca-a265-63cf55379d1a}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c75a2d66-6d1d-4735-8f63-9d85dcc026a6}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C75A2D66-6D1D-4735-8F63-9D85DCC026A6}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{338a754c-b46e-4bf2-8ac8-23de36862ad3}
SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3D86A75B-CB6B-4764-885D-CA6336F04BA2}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C75A2D66-6D1D-4735-8F63-9D85DCC026A6}
SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3D86A75B-CB6B-4764-885D-CA6336F04BA2}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C75A2D66-6D1D-4735-8F63-9D85DCC026A6}
SOFTWARE\SafetyNut
Software\Savevid
Software\savevidmoviestoolbarha
Software\Somoto
Software\somotomoviestoolbar1
Software\somotomoviestoolbar181
SOFTWARE\Wow6432Node\APNDTX
SOFTWARE\Wow6432Node\Classes\AppID\SavevidPluginCore.EXE
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\${dtUserElevationPolicyID}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3444c3c5-6c56-4a16-a453-832b05bf6ea4}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3d86a75b-cb6b-4764-885d-ca6336f04ba2}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{c75a2d66-6d1d-4735-8f63-9d85dcc026a6}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{52db1893-8a90-4192-aede-08e00b8f8473}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2446}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2459}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{08ae5e13-70cc-4fbb-ad00-ef4b90a44451}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{3d86a75b-cb6b-4764-885d-ca6336f04ba2}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{c75a2d66-6d1d-4735-8f63-9d85dcc026a6}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{cc2542c4-3251-4ac4-845e-f7e742bbe6de}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{3d86a75b-cb6b-4764-885d-ca6336f04ba2}
Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c0caa5fe-7c9c-4dca-a265-63cf55379d1a}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C75A2D66-6D1D-4735-8F63-9D85DCC026A6}
SOFTWARE\Wow6432Node\SafetyNut
SYSTEM\ControlSet001\Enum\Root\LEGACY_F06DEFF2-5B9C-490D-910F-35D3A9119622
SYSTEM\ControlSet001\services\DatamngrCoordinator
SYSTEM\ControlSet001\Services\F06DEFF2-5B9C-490D-910F-35D3A9119622
SYSTEM\ControlSet001\services\F06DEFF2-5B9C-490D-910F-35D3A91196222
SYSTEM\ControlSet001\services\SafetyNutManager
SYSTEM\ControlSet001\services\SavevidService
SYSTEM\ControlSet002\Enum\Root\LEGACY_F06DEFF2-5B9C-490D-910F-35D3A9119622
SYSTEM\ControlSet002\services\DatamngrCoordinator
SYSTEM\ControlSet002\Services\F06DEFF2-5B9C-490D-910F-35D3A9119622
SYSTEM\ControlSet002\services\F06DEFF2-5B9C-490D-910F-35D3A91196222
SYSTEM\ControlSet002\services\SafetyNutManager
SYSTEM\ControlSet002\services\SavevidService
SYSTEM\CurrentControlSet\Enum\Root\LEGACY_F06DEFF2-5B9C-490D-910F-35D3A9119622
SYSTEM\CurrentControlSet\services\DatamngrCoordinator
SYSTEM\CurrentControlSet\Services\F06DEFF2-5B9C-490D-910F-35D3A9119622
SYSTEM\CurrentControlSet\services\F06DEFF2-5B9C-490D-910F-35D3A91196222
SYSTEM\CurrentControlSet\services\SafetyNutManager
SYSTEM\CurrentControlSet\services\SavevidService
CLSID
{0050C303-0E30-48D3-B402-FB5D490CB89F}
{08AE5E13-70CC-4FBB-AD00-EF4B90A44451}
{338a754c-b46e-4bf2-8ac8-23de36862ad3}
{3444c3c5-6c56-4a16-a453-832b05bf6ea4}
{3d86a75b-cb6b-4764-885d-ca6336f04ba2}
{44E16FC6-3A79-4F00-8BF3-399AD9C403BF}
{587604F0-C55C-4F3F-8339-D634E878828E}
{6014D692-4409-4EDD-ABB2-36CA26DC2A2E}
{934BEE21-C5A4-457E-B130-77CA098FBBD3}
{c75a2d66-6d1d-4735-8f63-9d85dcc026a6}
{CC2542C4-3251-4AC4-845E-F7E742BBE6DE}
{d6715933-3f8b-44bc-b4b2-682164832b31}
Uninstaller
ilividmoviestoolbar20CR
imeshkoyotesoftmoviestoolbarCR
imeshkoyotesoftmoviestoolbarFF
imeshkoyotesoftmoviestoolbarIE
Savevid
savevidmoviestoolbarhaCR
savevidmoviestoolbarhaFF
somotomoviestoolbar181CR
somotomoviestoolbar181FF
somotomoviestoolbar181IE
somotomoviestoolbar1CR
somotomoviestoolbar1FF
somotomoviestoolbar1IE

Related Posts

Site Disclaimer

Enigmasoftware.com is not associated, affiliated, sponsored or owned by the malware creators or distributors mentioned on this article. This article should NOT be mistaken or confused in being associated in any way with the promotion or endorsement of malware. Our intent is to provide information that will educate computer users on how to detect, and ultimately remove, malware from their computer with the help of SpyHunter and/or manual removal instructions provided on this article.

This article is provided "as is" and to be used for educational information purposes only. By following any instructions on this article, you agree to be bound by the disclaimer. We make no guarantees that this article will help you completely remove the malware threats on your computer. Spyware changes regularly; therefore, it is difficult to fully clean an infected machine through manual means.

Leave a Reply

Please DO NOT use this comment system for support or billing questions. For SpyHunter technical support requests, please contact our technical support team directly by opening a customer support ticket via your SpyHunter. For billing issues, please refer to our "Billing Questions or Problems?" page. For general inquiries (complaints, legal, press, marketing, copyright), visit our "Inquiries and Feedback" page.


HTML is not allowed.