Starware Horoscopes Toolbar

Starware Horoscopes Toolbar is a toolbar that makes unwanted changes browser, such as reconfiguring browser’s search settings. It tracks browsing and search queries. It also adds a toolbar to the web browser.

General information:

Malware Name: Starware Horoscopes Toolbar
Malware Type: Toolbar
Company Name: Starware
Company URL: http://www.starware.com/
Threat Level: Moderate Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation

Company Description:

Starware provides you the software Starware Horoscopes Toolbar that will bring to your daily horoscope and you ll also have access to a web search tool, weather, dating, ringtones, games, and more.

Spyware Description:

Starware Horoscopes Toolbar is a toolbar that makes unwanted changes browser, such as reconfiguring browser’s search settings. It tracks browsing and search queries. It also adds a toolbar to the web browser.

Characteristics/Symptoms:

    -> It adds a toolbar to the web browser. -> It has a search function and provides search results for paid advertisers. -> It tracks browsing and search queries.

Additional information might be found here:

google Search at Google for Starware Horoscopes Toolbar
bing Search at Bing for Starware Horoscopes Toolbar
yahoo Search at Yahoo for Starware Horoscopes Toolbar

Processes Running:

File information Created after Installation:

File Location Size (Bytes) Type
C:\Documents and Settings\[USER]\Application Data\Starware349\contexts\Related.xml 63192 XML Document
C:\Documents and Settings\[USER]\Application Data\Starware349\contexts\Travel.xml 116736 XML Document
C:\Documents and Settings\[USER]\Application Data\Starware349\images\walertXP.bmp 944 Bitmap Image

Folder information Created after Installation:

Folder Location
C:\Documents and Settings\[USER]\Application Data\Starware349\Manage
C:\Documents and Settings\[USER]\Application Data\Starware349\Movie

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_LOCAL_MACHINE \SOFTWARE\Classes\CLSID\{CA356D79-679B-4b4c-8E49-5AF97014F4C1}
HKEY_LOCAL_MACHINE \SOFTWARE\Classes\CLSID\{CA356D79-679B-4b4c-8E49-5AF97014F4C1}\InprocServer32 ThreadingModel
HKEY_LOCAL_MACHINE \SOFTWARE\Classes\CLSID\{D49E9D35-254C-4c6a-9D17-95018D228FF5}