Eniro Toolbar

EniroEniro is the search company in the Nordic media market. Eniro makes it easy to find people, businesses and products using directories, directory assistance, Internet and mobile services. Eniro’s core markets are the Nordic countries and Poland.The Eniro Toolbar helps user to find business, people, product etc on the web. The toolbar has features of highlighting search text and blocking popup. By using the toolbar use can easily access the Enrino.The toolbar is not designed in English language. When the user searches from the toolbar the search results contains sponsored links and it also contains ads which are part of the search page itself. The toolbar also collects data from the search field of the toolbar and watches users browsing habits.Characteristics/Symptoms: Collects data about the users browsing habitsSlows the browser Communicates with the host serverShows ads as on the search pages.Changes the user’s search settingsWorks in backgroundDate of Found: 2006-02-22Security Level: HighOperating OS: WIN XPInstallation Type: Installed through EXEOperation: After InstallationTime of Operation: After restarting browser.Screenshot:2. Installation Sample and Image2.1. Installation SampleOrigin URL: http://www.eniro.dk/toolbar/enirotoolbarsetupdk.exe3. Changes after installation 3.1. Process: Files and Location: 3.2 Directories:Eniro Toolbar installer creates following directory:C:\WINDOWS\system32\EniroToolbar3.3. ActiveX Information ActiveX Screenshot:File location

General information:

Malware Name: Eniro Toolbar
Malware Type: Toolbar
Company Name: Eniro
Company URL: http://www.eniro.com/
Threat Level: High
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After restarting browser.

Company Description:

Eniro is the search company in the Nordic media market. Eniro makes it easy to find people, businesses and products using directories, directory assistance, Internet and mobile services. Eniro’s core markets are the Nordic countries and Poland.

Spyware Description:

EniroEniro is the search company in the Nordic media market. Eniro makes it easy to find people, businesses and products using directories, directory assistance, Internet and mobile services. Eniro’s core markets are the Nordic countries and Poland.The Eniro Toolbar helps user to find business, people, product etc on the web. The toolbar has features of highlighting search text and blocking popup. By using the toolbar use can easily access the Enrino.The toolbar is not designed in English language. When the user searches from the toolbar the search results contains sponsored links and it also contains ads which are part of the search page itself. The toolbar also collects data from the search field of the toolbar and watches users browsing habits.Characteristics/Symptoms: Collects data about the users browsing habitsSlows the browser Communicates with the host serverShows ads as on the search pages.Changes the user’s search settingsWorks in backgroundDate of Found: 2006-02-22Security Level: HighOperating OS: WIN XPInstallation Type: Installed through EXEOperation: After InstallationTime of Operation: After restarting browser.Screenshot:2. Installation Sample and Image2.1. Installation SampleOrigin URL: http://www.eniro.dk/toolbar/enirotoolbarsetupdk.exe3. Changes after installation 3.1. Process: Files and Location: 3.2 Directories:Eniro Toolbar installer creates following directory:C:\WINDOWS\system32\EniroToolbar3.3. ActiveX Information ActiveX Screenshot:File location

Characteristics/Symptoms:

    -> Collects data about the users browsing habits -> Slows the browser -> Communicates with the host server -> Shows ads as on the search pages. -> Changes the user’s search settings -> Works in background0

Additional information might be found here:

google Search at Google for Eniro Toolbar
bing Search at Bing for Eniro Toolbar
yahoo Search at Yahoo for Eniro Toolbar

Processes Running:

File information Created after Installation:

File Location Size (Bytes) Type
C:\WINDOWS\system32\EniroToolbar\TRFFC13.ICO 1078 Icon
C:\WINDOWS\system32\EniroToolbar\ToolBand.dll 221184 Application Extension
C:\WINDOWS\system32\EniroToolbar\uninstall.exe 47342 Application

Folder information Created after Installation:

Folder Location

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\EniroToolbar
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EniroToolbar
HKEY_LOCAL_MACHINE \SOFTWARE\NTier