eKith.com Toolbar

eKith.com Toolbar is a toolbar that may makes unwanted changes browser, such as reconfiguring browser’s search settings. It tracks browsing and search queries. It also adds a toolbar to the web browser.

General information:

Malware Name: eKith.com Toolbar
Malware Type: Toolbar
Company Name: eKith.com
Company URL: http://ekith.com/
Threat Level: Moderate Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation

Company Description:

eKith.com provides you the software eKith.com Toolbar that will give you instant access to all the advanced features of eKith. Single click access to your eMail, games, eBlog and much more! The toolbar has other useful features built into it, and we re working on more right now.  This toolbar is...SPYWARE FREE!

Spyware Description:

eKith.com Toolbar is a toolbar that may makes unwanted changes browser, such as reconfiguring browser’s search settings. It tracks browsing and search queries. It also adds a toolbar to the web browser.

Characteristics/Symptoms:

    -> It adds a toolbar to the web browser. -> It has a search function and provides search results for paid advertisers. -> It tracks browsing and search queries.

Additional information might be found here:

google Search at Google for eKith.com Toolbar
bing Search at Bing for eKith.com Toolbar
yahoo Search at Yahoo for eKith.com Toolbar

Processes Running:

File information Created after Installation:

File Location Size (Bytes) Type
C:\Program Files\eKith.com Toolbar\favicon.ico 9662 Icon
C:\Program Files\eKith.com Toolbar\ie_toolbar.dll 524288 Application Extension
C:\Program Files\eKith.com Toolbar\ie_toolbar.inf 1486 Setup Information

Folder information Created after Installation:

Folder Location
C:\Program Files\eKith.com Toolbar\Cach

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_CURRENT_USER \Software\XBTB05890\Toolbar toolbar_id
HKEY_CURRENT_USER \Software\XBTB05890\Toolbar updateXML
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Internet Explorer\Extensions\{D940F380-49C7-4A05-9E33-53930AF5768F} MenuText