VooMuu

VooMuu

Known Toolbar

by Pinball Corporation

What is VooMuu?

VooMuu is software application developed by Pinball Corporation. It is most commonly found on computers running Windows 7 with nearly 75.00% of installations running this operating system. VooMuu's installer is typically 551.00 KB in size and installs around 4 files. The most common release is 1.0.36.0 with 37.50% of all installations currently using this version.

VooMuu is most popular in the United States with 75.76% of installations residing in this country.

VooMuu adds 1 scheduled task to the Windows Task Scheduler launching the program at randomly scheduled times.

About VooMuu?

VooMuu is a web browser toolbar and extension that functions as adware. Its primary purpose is to modify the user's web browser by changing the search provider and redirecting web searches to a specific search engine partner with whom the publisher has a revenue relationship. This is done to increase the likelihood of users clicking on sponsored advertising through search. The toolbar's behaviors include changing the default home page and search provider of the web browser, as well as modifying the functionality of the 'new tab' feature to launch the modified search portal page. It also provides automatic updates without user initiation and adds alternative error page and page not found functionality. Additionally, it includes features designed to protect the search and home page settings. VooMuu is also capable of accessing the HTML of all visited pages and capturing URLs of pages and search terms. In some cases, it injects advertising in the form of context ads, pop-ups, and pop-unders. (Note: Specific information about the specific capabilities of the VooMuu software may need to be updated based on the latest available information.)

Multiple virus scanners have detected malware in VooMuu.

VooMuuSAHook.dll (MD5: 3b2644861776605c9eb9560683811bbc) has been flagged by 40 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Generic.393290
Agnitum Outpost Riskware.Adware
AhnLab-V3 Adware/Win32.Shopper
Avira AntiVir TR/Offend.2.11985
AVG Skodna.Generic_r
Baidu-International AdWare.Win32.Shopper.aS
Bitdefender Application.Generic.393290
Bkav FE W32.Cloda50.Trojan
CAT-QuickHeal AdWare.Hotbar (Not a Virus)
Comodo Security UnclassifiedMalware
Dr.Web Adware.Zango.15
ESET-NOD32 a variant of Win32/Adware.HotBar.S
Fortinet FortiGate W32/Adware_fam.NB
F-Secure Application.Generic.393290
G Data Application.Generic.393290
IKARUS anti.virus AdWare.Win32.HotBar
Jiangmin DangerousObject.Multi.fky
K7 AntiVirus Adware
K7GW Adware ( 004503d21 )
Kaspersky not-a-virus:AdWare.Win32.Shopper
Kingsoft AntiVirus Win32.Malware.Heur_Generic.A.(kcloud)
Malwarebytes Adware.HotBar.VM
McAfee Generic PUP.x!wr
McAfee-GW-Edition Generic PUP.x!wr
Microsoft Security Essentials Adware:Win32/Hotbar
MicroWorld-eScan Application.Generic.393290
NANO AntiVirus Trojan.Win32.Zango.dynsq
Norman Suspicious_Gen4.IJGR
Sophos Hotbar
Symantec Trojan.Gen
Trend Micro TROJ_SPNR.1ELQ11
TrendMicro-HouseCall TROJ_SPNR.1ELQ11
Vba32 AntiVirus AdWare.Shopper
VIPRE Antivirus Trojan.Win32.Generic!BT
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.HotBar
avast! Win32:PUP-gen [PUP]
CMC Antivirus AdWare.Win32.HotBar!O
F-Prot W32/180Solutions.D.gen!Eldorado
Qihoo-360 Win32/Virus.Adware.4bb
Tencent Win32.Trojan.Spnr.Eaxn
VooMuuSA.exe (MD5: 1ba31401c5d2f8e27ba3014d8ff6864b) has been flagged by 36 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Generic.382363
Agnitum Outpost Adware.Agent!IZ4GDGQ7ZhY
AhnLab-V3 Adware/Win32.Hotbar
Avira AntiVir Adware/ClickPotato.A.11
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.HotBar
avast! Win32:PUP-gen [PUP]
AVG Skodna.Generic_r.AF
Baidu-International Adware.Win32.HotBar.aTqh
Bitdefender Application.Generic.382363
Bkav FE W32.Clodcee.Trojan.fafe
CMC Antivirus AdWare.Win32.HotBar!O
Comodo Security UnclassifiedMalware
Dr.Web Adware.Zango.15
ESET-NOD32 probably a variant of Win32/Adware.180Solutions
Fortinet FortiGate Adware/Hotbar
F-Prot W32/180Solutions.D.gen!Eldorado
F-Secure Application.Generic.382363
G Data Application.Generic.382363
IKARUS anti.virus AdWare.Win32.ClickPotato
K7 AntiVirus Backdoor ( 04c4c5891 )
K7GW Backdoor ( 04c4c5891 )
Kingsoft AntiVirus Win32.Troj.HotBar.fr.(kcloud)
Malwarebytes Adware.HotBar.CP
McAfee Artemis!1BA31401C5D2
McAfee-GW-Edition Artemis!1BA31401C5D2
Microsoft Security Essentials Adware:Win32/ClickPotato
MicroWorld-eScan Application.Generic.382363
NANO AntiVirus Trojan.Win32.Zango.nqual
Qihoo-360 Win32/Virus.Adware.4bb
Sophos Hotbar
Symantec WS.Reputation.1
Tencent Win32.Trojan.Spnr.Eaxn
Trend Micro TROJ_SPNR.1ELQ11
TrendMicro-HouseCall TROJ_SPNR.1ELQ11
Vba32 AntiVirus AdWare.HotBar
VIPRE Antivirus Zango.CommonElements

Software Behaviors

Scheduled tasks:
  • VooMuuSA.exe is scheduled as a task named 'RunAsStdUser Task' (runs on registration).

Software Details

URL:
https://www.voomuu.com
Support:
https://www.voomuu.com/support.html
Installation path:
C:\Program Files\voomuu\bin\1.0.34.0
Uninstaller:
"C:\Program Files\VooMuu\bin\1.0.34.0\VooMuuUninstaller.exe" Web
Size:
551.00 KB
Language:
English

VooMuu Executable Details

Primary executable:
VooMuuSAHook.dll
Name:
VooMuu
Path:
C:\Program Files\voomuu\bin\1.0.34.0\VooMuuSAHook.dll
MD5:
3b2644861776605c9eb9560683811bbc
SHA-1:
SHA-256:
Files installed by VooMuu
File Type Filename MD5
EXE
3ec0738fb57eb646da5f4efd202b1b47
EXE
99ee522d690acf50028af713a629e77f
DLL
3b2644861776605c9eb9560683811bbc
EXE
1ba31401c5d2f8e27ba3014d8ff6864b