Movies Toolbar

Threat Scorecard

Popularity Rank: 3,497
Threat Level: 50 % (Medium)
Infected Computers: 97,635
First Seen: July 1, 2013
Last Seen: July 28, 2026
OS(es) Affected: Windows

Movies Toolbar Image

Movies Toolbar is a toolbar/ browser hijacker that is able to enter vulnerable computers packed with numerous freeware applications from the Internet. Movies Toolbar can be installed on Internet Explorer, Mozilla Firefox or Google Chrome. Movies Toolbar makes changes to the affected web browser's settings, inserts its toolbar, and replaces the default homepage and default search engine with some suspicious website. Movies Toolbar is also categorized as a potentially unwanted program (PUP). Movie Toolbar is delivered by Bandoo Media, which is responsible for advertising more applications such as this one. The aim of Movies Toolbar is to push some doubtful advertisement websites by using tricky techniques. Movies Toolbar will force the affected PC user to use Search.ask.com as the main search engine. Movies Toolbar also adds numerous sponsored websites to the search results in any legal search engine on the targeted PC. Movies Toolbar can also result in unwanted hits to dubious websites and numerous pop-up ads shown on the victimized PCs.

Aliases

15 security vendors flagged this file as malicious.

Antivirus Vendor Detection
Fortinet Riskware/SearchSuite
Ikarus PUA.Bandoo
Panda Trj/Chgt.C
GData Win32.Application.Searchsuite.C
AhnLab-V3 PUP/Win32.SearchSuite
Antiy-AVL RiskWare[WebToolbar:not-a-virus]/Win64.SearchSuite
McAfee-GW-Edition Artemis
Kaspersky not-a-virus:WebToolbar.Win64.SearchSuite.d
K7AntiVirus Trojan ( 0049f9491 )
McAfee Artemis!5D8BE8191754
AVG MalSign.Generic.1EE
McAfee Artemis!B9678C037594
AVG Toolbar.SearchSuite
McAfee Artemis!6AC8FDB0D943
Fortinet Riskware/Agent

SpyHunter Detects & Remove Movies Toolbar

File System Details

Movies Toolbar may create the following file(s):
# File Name MD5 Detections
1. searchresultsDx.dll.vir 775b7ee21c3bf311359c6f17ab7faa42 4,222
2. IACNativeMsgHost.exe 25abf2393eebf6a731708170e4accb37 1,453
3. __searchresultsDx.dll 1a1aa1878f88a247728e2af246ee8245 499
4. __searchresultsDx.dll.vir 3a560e3678cbd0d4dfa3c7210dea0aa1 296
5. searchresultsDx.dll e1650d38200291ca948bfeefaedd1553 152
6. DatamngrUI.exe 90f82064bfe53d79ca75fa71a7a00040 73
7. setmgrc1.cfg 24a97cf9304d38b5515ef4a23f0e7505 69
8. safetynut.exe 780a11e50ae157025b2f41d70b1659ab 24
9. SafetyNutManager.exe c11903cdaf06b5af763427d92e5fb083 13
10. DatamngrCoordinator.exe 683e592d74beb6c543da211bb5fcadd7 9
More files

Registry Details

Movies Toolbar may create the following registry entry or registry entries:
CLSID
{0050C303-0E30-48D3-B402-FB5D490CB89F}
{08AE5E13-70CC-4FBB-AD00-EF4B90A44451}
{338a754c-b46e-4bf2-8ac8-23de36862ad3}
{3444c3c5-6c56-4a16-a453-832b05bf6ea4}
{3d86a75b-cb6b-4764-885d-ca6336f04ba2}
{44E16FC6-3A79-4F00-8BF3-399AD9C403BF}
{587604F0-C55C-4F3F-8339-D634E878828E}
{6014D692-4409-4EDD-ABB2-36CA26DC2A2E}
{934BEE21-C5A4-457E-B130-77CA098FBBD3}
{c75a2d66-6d1d-4735-8f63-9d85dcc026a6}
{CC2542C4-3251-4AC4-845E-F7E742BBE6DE}
{d6715933-3f8b-44bc-b4b2-682164832b31}
Software\APN DTX
Software\APN DTX\{3444c3c5-6c56-4a16-a453-832b05bf6ea4}
Software\APNDTX
Software\AppDataLow\Software\somotomoviestoolbar1
Software\AppDataLow\Software\somotomoviestoolbar181
SOFTWARE\Classes\AppID\SavevidPluginCore.EXE
SOFTWARE\Classes\MoviesToolbarHelper.DNSGuard
SOFTWARE\Classes\MoviesToolbarHelper.DNSGuard.1
SOFTWARE\Classes\SavevidPluginCore.PluginManager
SOFTWARE\Classes\SavevidPluginCore.PluginManager.1
SOFTWARE\Classes\Wow6432Node\AppID\SavevidPluginCore.EXE
Software\imeshkoyotesoftmoviestoolbar
Software\Microsoft\Internet Explorer\Approved Extensions\{338A754C-B46E-4BF2-8AC8-23DE36862AD3}
Software\Microsoft\Internet Explorer\Approved Extensions\{C75A2D66-6D1D-4735-8F63-9D85DCC026A6}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\${dtUserElevationPolicyID}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3444c3c5-6c56-4a16-a453-832b05bf6ea4}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3d86a75b-cb6b-4764-885d-ca6336f04ba2}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{c75a2d66-6d1d-4735-8f63-9d85dcc026a6}
SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{52db1893-8a90-4192-aede-08e00b8f8473}
SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2427}
SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2446}
SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2459}
SOFTWARE\Microsoft\Internet Explorer\Toolbar\{08ae5e13-70cc-4fbb-ad00-ef4b90a44451}
SOFTWARE\Microsoft\Internet Explorer\Toolbar\{3d86a75b-cb6b-4764-885d-ca6336f04ba2}
SOFTWARE\Microsoft\Internet Explorer\Toolbar\{c75a2d66-6d1d-4735-8f63-9d85dcc026a6}
SOFTWARE\Microsoft\Internet Explorer\Toolbar\{cc2542c4-3251-4ac4-845e-f7e742bbe6de}
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{3d86a75b-cb6b-4764-885d-ca6336f04ba2}
Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c0caa5fe-7c9c-4dca-a265-63cf55379d1a}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c75a2d66-6d1d-4735-8f63-9d85dcc026a6}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C75A2D66-6D1D-4735-8F63-9D85DCC026A6}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{338a754c-b46e-4bf2-8ac8-23de36862ad3}
SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3D86A75B-CB6B-4764-885D-CA6336F04BA2}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C75A2D66-6D1D-4735-8F63-9D85DCC026A6}
SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3D86A75B-CB6B-4764-885D-CA6336F04BA2}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C75A2D66-6D1D-4735-8F63-9D85DCC026A6}
SOFTWARE\SafetyNut
Software\Savevid
Software\savevidmoviestoolbarha
Software\Somoto
Software\somotomoviestoolbar1
Software\somotomoviestoolbar181
SOFTWARE\Wow6432Node\APNDTX
SOFTWARE\Wow6432Node\Classes\AppID\SavevidPluginCore.EXE
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\${dtUserElevationPolicyID}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3444c3c5-6c56-4a16-a453-832b05bf6ea4}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3d86a75b-cb6b-4764-885d-ca6336f04ba2}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{c75a2d66-6d1d-4735-8f63-9d85dcc026a6}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{52db1893-8a90-4192-aede-08e00b8f8473}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2446}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2459}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{08ae5e13-70cc-4fbb-ad00-ef4b90a44451}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{3d86a75b-cb6b-4764-885d-ca6336f04ba2}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{c75a2d66-6d1d-4735-8f63-9d85dcc026a6}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{cc2542c4-3251-4ac4-845e-f7e742bbe6de}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{3d86a75b-cb6b-4764-885d-ca6336f04ba2}
Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c0caa5fe-7c9c-4dca-a265-63cf55379d1a}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C75A2D66-6D1D-4735-8F63-9D85DCC026A6}
SOFTWARE\Wow6432Node\SafetyNut
SYSTEM\ControlSet001\Enum\Root\LEGACY_F06DEFF2-5B9C-490D-910F-35D3A9119622
SYSTEM\ControlSet001\services\DatamngrCoordinator
SYSTEM\ControlSet001\Services\F06DEFF2-5B9C-490D-910F-35D3A9119622
SYSTEM\ControlSet001\services\F06DEFF2-5B9C-490D-910F-35D3A91196222
SYSTEM\ControlSet001\services\SafetyNutManager
SYSTEM\ControlSet001\services\SavevidService
SYSTEM\ControlSet002\Enum\Root\LEGACY_F06DEFF2-5B9C-490D-910F-35D3A9119622
SYSTEM\ControlSet002\services\DatamngrCoordinator
SYSTEM\ControlSet002\Services\F06DEFF2-5B9C-490D-910F-35D3A9119622
SYSTEM\ControlSet002\services\F06DEFF2-5B9C-490D-910F-35D3A91196222
SYSTEM\ControlSet002\services\SafetyNutManager
SYSTEM\ControlSet002\services\SavevidService
SYSTEM\CurrentControlSet\Enum\Root\LEGACY_F06DEFF2-5B9C-490D-910F-35D3A9119622
SYSTEM\CurrentControlSet\services\DatamngrCoordinator
SYSTEM\CurrentControlSet\Services\F06DEFF2-5B9C-490D-910F-35D3A9119622
SYSTEM\CurrentControlSet\services\F06DEFF2-5B9C-490D-910F-35D3A91196222
SYSTEM\CurrentControlSet\services\SafetyNutManager
SYSTEM\CurrentControlSet\services\SavevidService
ilividmoviestoolbar20CR
imeshkoyotesoftmoviestoolbarCR
imeshkoyotesoftmoviestoolbarFF
imeshkoyotesoftmoviestoolbarIE
Savevid
savevidmoviestoolbarhaCR
savevidmoviestoolbarhaFF
somotomoviestoolbar181CR
somotomoviestoolbar181FF
somotomoviestoolbar181IE
somotomoviestoolbar1CR
somotomoviestoolbar1FF
somotomoviestoolbar1IE

Directories

Movies Toolbar may create the following directory or directories:

%ALLUSERSPROFILE%\Application Data\SafetyNut
%ALLUSERSPROFILE%\SafetyNut
%LOCALAPPDATA%\ilividmoviestoolbar20
%LOCALAPPDATA%\imeshkoyotesoftmoviestoolbar
%LOCALAPPDATA%\imeshsavevidmoviestoolbar
%LOCALAPPDATA%\savevidmoviestoolbarha
%LOCALAPPDATA%\somotomoviestoolbar1
%PROGRAMFILES%\Browser Tab Search by Ask\SafetyNut
%PROGRAMFILES%\Movies App
%PROGRAMFILES%\Savevid
%PROGRAMFILES%\ilividmoviestoolbar20
%PROGRAMFILES%\ilividmoviestoolbar280
%PROGRAMFILES(x86)%\Browser Tab Search by Ask\SafetyNut
%PROGRAMFILES(x86)%\Savevid
%PROGRAMFILES(x86)%\ilividmoviestoolbar20
%PROGRAMFILES(x86)%\ilividmoviestoolbar280
%ProgramFiles%\Movies Toolbar
%ProgramFiles(x86)%\Movies Toolbar
%TEMP%\{2977d8cc-8902-4340-be88-2c676bf96b8d}
%USERPROFILE%\AppData\LocalLow\ilividmoviestoolbar20
%USERPROFILE%\AppData\LocalLow\imeshkoyotesoftmoviestoolbar
%USERPROFILE%\AppData\LocalLow\savevidmoviestoolbarha
%USERPROFILE%\AppData\LocalLow\somotomoviestoolbar1
%USERPROFILE%\AppData\LocalLow\somotomoviestoolbar181
%UserProfile%\Local Settings\Application Data\ilividmoviestoolbar20
%UserProfile%\Local Settings\Application Data\imeshkoyotesoftmoviestoolbar
%UserProfile%\Local Settings\Application Data\somotomoviestoolbar1

URLs

Movies Toolbar may call the following URLs:

somotomoviestoolbar1

Analysis Report

General information

Family Name: Movies Toolbar
Signature status: Self Signed

Known Samples

MD5: ba13ec2db60e3561e41c6514cd712660
SHA1: 179ffd67ded020068300c3aea385ef1a350e7288
SHA256: 2DDBC6E5DB715BCB6871D5EACC4FFC3073DE763FC1D63F079CABADA4C047AD66
File Size: 1.89 MB, 1893320 bytes
MD5: 9d96cce033f0e901efecaf4ec3035bce
SHA1: 6f58714fe0731ae1446d12e61f06ad85d4b74653
SHA256: E0814CFD7CFE4C8DC0079C39527ADCF200DF3301E65780AA1B8B31800064BC45
File Size: 8.13 MB, 8126696 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Igor Pavlov
  • SafetyNut Inc.
File Description
  • 7z Console SFX
  • Movies Toolbar Install
File Version
  • 9.20
  • 5.0.0.10781
Internal Name 7z.sfx
Legal Copyright
  • Copyright (c) 1999-2010 Igor Pavlov
  • Copyright (c) 2005 - 2013
Original Filename 7z.sfx.exe
Product Name
  • 7-Zip
  • MoviesToolbar
Product Version
  • 9.20
  • 5.0.0.10781

Digital Signatures

Signer Root Status
SafetyNut Inc. Thawte Code Signing CA - G2 Self Signed

Files Modified

File Attributes
c:\users\user\appdata\local\temp\4082.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\40a2.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\40b3.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\40c3.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\40d4.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\4104.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\4143.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\4164.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\4174.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\4185.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
Show More
c:\users\user\appdata\local\temp\nsc2f37.tmp\helper.dll Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\nsc2f37.tmp\helper.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsc2f37.tmp\helper.dll Generic Write,Read Attributes,Delete,LEFT 262144
c:\users\user\appdata\local\temp\nsc2f37.tmp\helper.dll Generic Write,Read Attributes,LEFT 262144
c:\users\user\appdata\local\temp\nsc2f37.tmp\helper.dll Generic Write,Read Data,Read Attributes,Delete,LEFT 262144
c:\users\user\appdata\local\temp\nsc2f37.tmp\helper.dll Generic Write,Read Data,Read Attributes,LEFT 262144
c:\users\user\appdata\local\temp\nsc2f37.tmp\registry.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsc2f37.tmp\starter.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsc2f37.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsc2f37.tmp\userinfo.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsm2f26.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\image file execution options\bprotect.exe::debugger tasklist.exe RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\image file execution options\browserprotect.exe::debugger tasklist.exe RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\image file execution options\browserdefender.exe::debugger tasklist.exe RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\image file execution options\bitguard.exe::debugger tasklist.exe RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\image file execution options\snapdo.exe::debugger tasklist.exe RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\image file execution options\browsersafeguard.exe::debugger tasklist.exe RegNtPreCreateKey
Show More
HKLM\software\microsoft\windows nt\currentversion\image file execution options\bpsvc.exe::debugger tasklist.exe RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\image file execution options\protectedsearch.exe::debugger tasklist.exe RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\image file execution options\stinst32.exe::debugger tasklist.exe RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\image file execution options\stinst64.exe::debugger tasklist.exe RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetUserName
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Other Suspicious
  • AdjustTokenPrivileges