Associated Malware Groups
The unsafe files using this name are associated with the malware group:
File Behavior
TOOLBAR.DLL has been seen to perform the following behavior:
- Changes the Internet Explorer Search Page
- Registers a Dynamic Link Libray (DLL) File
- Adds products to the system registry
- This Process sends MIME Email
- Creates new file extentions so that Internet Explorer will automatically open and potentially execute additional file types
- Creates a Toolbar Extension for Internet Explorer
- Found on infected systems and resists interrogation by security products
- Enables an In Process Object/Server - Common with DLL Injections
- Creation and Registers a Browser Helper Object in Internet Explorer
- Makes outbound connections to other computers using NETBIOSOUT protocols
- Executes a Process
- This process creates other processes on disk
- Adds an ActiveX component changing or modifying the function of your browser
- This Process Deletes Other Processes From Disk
- The process hooks code into all running processes which could allow it to take control of the system or record keyboard input, mouse activity and screen contents
- Opens browser pop ups
- Includes file creation code which could be used to test for interception by security products
TOOLBAR.DLL has been the subject of the following behavior:
- Registered as a Dynamic Link Library File
- Created as a Toolbar Extension for Internet Explorer
- Registered as a Dynamic Link Libray (DLL) File
- Created as a process on disk
- Deleted as a process from disk
- Created and Registered as a Browser Helper Object in Internet Explorer
- Enabled as an In Process Object/Server - Common with DLL Injections
- Executed as a Process
- Added as an ActiveX component
- Deleted as an ActiveX component
- Created by processes which appear to be checking for interception by security products
Country Of Origin
The filename TOOLBAR.DLL was first seen on May 8 2007 in the following geographical regions of the Webroot community:
- The United States on May 8 2007
- Vietnam on May 8 2007
- Europe on Sep 30 2007
- Germany on Sep 30 2007
File Name Aliases
TOOLBAR.DLL can also use the following file names:
- BACKUP-20070611-104526-752.DLL
- BACKUP-20070309-082247-235.DLL
- TOOLBAR.DLL.BAK
- BACKUP-20070619-210223-478.DLL
- TOOLBAR(n).DLL
- NEWS.DLL
- TOOLBAR(1).DLL
- MALWARE_24.EXE
- NIPA_TOOLBAR.DLL
- SANOOK_TAI.DLL
- PETITEPAGE.DLL
- LIKE_YAHOO.DLL
- WEVOKE.DLL
- SKIPDIFF_IE.DLL
- ENHANCER.DLL
- WIKISEEK.DLL
- TURKISH.DLL
- SKOUK.DLL
- TOOLBAR-W-GOOGLE-R.DLL
- ASTROBAR.DLL
- TBCORE3U.DLL
- SOBAR.DLL
- TTTT.DLL
- VS000768.DLL
- VS000774.DLL
- 365SO.DLL
- 57729B3.RBF
- 1A03A622.RBF
- 37DDEC.RBF
- ؛
- 489818.RBF
- 19537A.RBF
- 329D61.RBF
Filesizes
The following file size has been seen:
- 681,552 bytes
- 552,960 bytes
- 1,205,512 bytes
- 127,864 bytes
- 593,920 bytes
- 1,257,472 bytes
File Type
The filename TOOLBAR.DLL refers to many versions of a dynamic link library.
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.