Engineering.com Toolbar

Engineering.com.The ENGINEERING.com Toolbar is an IE Toolbar provided by ENGINEERING.com to increase the productivity of the engineer. The toolbar provide ENGINEERING.com Search, Reference to the material found at Engineering.com and give current engineering technical education via Training.The toolbar shows ads related to education and training. The toolbar is equipped with an automatic update program. The toolbar also gathers information about the terms that user searches through the toolbar and general browsing.Characteristics/Symptoms: Collects data about the users browsing habitsSlows the browser Communicates with the host serverShows education and training related adsCan update itself automaticallyWorks in backgroundDate of Found: 2006-02-22Security Level: HighOperating OS: WIN XPInstallation Type: Installed through ActiveXOperation: After InstallationTime of Operation: After restarting browser.Screenshot:2. Installation Sample and Image2.1. Installation SampleOrigin URL: http://toolbar.engineering.com/install.html 3. Changes after installation 3.1. Process: Files and Location: 3.2 Directories:Engineering.com Toolbar installer does not create any directory:3.3. ActiveX Information ActiveX Screenshot:File location

General information:

Malware Name: Engineering.com Toolbar
Malware Type: Toolbar
Company Name: Engineering.com.
Company URL: http://www.engineering.com/
Threat Level: High
Operating System: WIN XP
Installation Type: Installed through ActiveX
Operation: Time of After restarting browser.

Company Description:

The ENGINEERING.com Toolbar is an IE Toolbar provided by ENGINEERING.com to increase the productivity of the engineer. The toolbar provide ENGINEERING.com Search, Reference to the material found at Engineering.com and give current engineering technical education via Training.

Spyware Description:

Engineering.com.The ENGINEERING.com Toolbar is an IE Toolbar provided by ENGINEERING.com to increase the productivity of the engineer. The toolbar provide ENGINEERING.com Search, Reference to the material found at Engineering.com and give current engineering technical education via Training.The toolbar shows ads related to education and training. The toolbar is equipped with an automatic update program. The toolbar also gathers information about the terms that user searches through the toolbar and general browsing.Characteristics/Symptoms: Collects data about the users browsing habitsSlows the browser Communicates with the host serverShows education and training related adsCan update itself automaticallyWorks in backgroundDate of Found: 2006-02-22Security Level: HighOperating OS: WIN XPInstallation Type: Installed through ActiveXOperation: After InstallationTime of Operation: After restarting browser.Screenshot:2. Installation Sample and Image2.1. Installation SampleOrigin URL: http://toolbar.engineering.com/install.html 3. Changes after installation 3.1. Process: Files and Location: 3.2 Directories:Engineering.com Toolbar installer does not create any directory:3.3. ActiveX Information ActiveX Screenshot:File location

Characteristics/Symptoms:

    -> Collects data about the users browsing habits -> Slows the browser -> Communicates with the host server -> Shows education and training related ads -> Can update itself automatically -> Works in background0

Additional information might be found here:

google Search at Google for Engineering.com Toolbar
bing Search at Bing for Engineering.com Toolbar
yahoo Search at Yahoo for Engineering.com Toolbar

Processes Running:

File information Created after Installation:

File Location Size (Bytes) Type

Folder information Created after Installation:

Folder Location

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Code Store Database\Distribution Units\{4E7BD74F-2B8D-469E-C0FB-FA62BD92B438}\Contains\Files\C:\WINDOWS\Downloaded Program Files\engineer.dll
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/engineer.dll
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\Downloaded Program Files\engineer.dll