SweetPacks Toolbar Redirected Search



Share on Twitter Share on Stumble Upon Share on Digg Share on Delicious


Providing cost-effective local computer repair and network support in the middle Tennessee area

Remote Access Portal

Remote Access Icon
Home About Us Onsite Services Online Services Self Help Pricing Blog Inquiries

The SweetPacks Toolbar and also the SweetIM Toolbar are browser hijackers that may be installed unintentionally, because they may be bundled with free downloaded software that users might install. Once it's been installed, Sweetpacks will install the SweetPacks Toolbar or the SweetIm toolbar in your web browser. And it will also change your browser's home page and search settings to sweetim.com. In some situations this hijacker can be somewhat hard to remove once it's been installed. This SweetPacks removal guide will help you to remove the toolbars from your web browser if you have trouble removing them by conventional techniques.


Software that you will need to download to remove the SweetPacks Toolbar


To uninstall this browser hijacker, you will need to download a few utilities. You should be able to download them on the compromised computer, but if the browser hijacker hinders your efforts,  you’ll need to download the needed software on a clean computer and then transfer it to the infected one via a burned cd.


You will need to download:

  1. rKill
  2. Adwcleaner
  3. Shortcut cleaner
  4. Emsisoft Emergency Kit



How to remove the SweetPacks and SweetIM Toolbar


  1. First restart your computer into “Safe Mode with Networking”.
  2. Once you’re at the Windows Desktop, make sure that all web browsers are closed.
  3. Next, copy the downloaded files to an easily accessible location on the compromised computer
  4. Next, execute the copy of “rKill” by double clicking on it’s executable. This utility will terminate any malicious processes that it locates running in your computer’s memory.
  5. After “rKill” has completed, execute the copy of “Adwcleaner” .














  1. After Adwcleaner has completed it’s scan adware on your computer, it will display a log file. The log file will contain detailed information about your computer’s configuration. At this point the log file can be closed.


























  1. Next, click on “Delete” on the Adwcleaner interface to remove any detected adware.














  1. Next, click on “Uninstall” to remove “Adwcleaner” from your computer.














  1. Next, execute the copy of “Shortcut Cleaner” to removal any possibly hijacked shortcuts.
















  1. After “Shortcut Cleaner” has completed, execute the copy of “Emsisoft Emergency Kit”. Once it has been decompressed, start it by clicking on “Start.exe”. Once it starts update it and perform a deep scan of your computer.




































  1. Once Emsisoft completes it’s scan, quarantine any malicious files that it has located on your computer.
  2. Next restart your computer normally and open your web browser. Once the browser is open (Example of Internet Explorer) click on the tools drop down and then click on “Internet Options”.





















  1. Next, click on the advanced tab and then click on reset down at the bottom.





















  1. Next, click on the General tab and then change the home page tab settings to what ever web page you would like to open first when you open the browser and then click on okay and then close the browser.






















The toolbar should be completely removed at this point from your computer. And everything should be back to normal.



Associated SweetPacks Toolbar Data Files:


c:\Program Files\SweetIM\Communicator\mgcommon.dll

c:\Program Files\SweetIM\Communicator\mgcommunication.dll

c:\Program Files\SweetIM\Communicator\mgsimcommon.dll

c:\Program Files\SweetIM\Communicator\mgxml_wrapper.dll

c:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe

c:\Program Files\SweetIM\Communicator\resources\sqlite\mgSqlite3.dll

c:\Program Files\SweetIM\Messenger\ContentPackagesActivationHandler.exe

c:\Program Files\SweetIM\Messenger\default.xml

c:\Program Files\SweetIM\Messenger\mgAdaptersProxy.dll

c:\Program Files\SweetIM\Messenger\mgArchive.dll

c:\Program Files\SweetIM\Messenger\mgcommon.dll

c:\Program Files\SweetIM\Messenger\mgcommunication.dll

c:\Program Files\SweetIM\Messenger\mgconfig.dll

c:\Program Files\SweetIM\Messenger\mgFlashPlayer.dll

c:\Program Files\SweetIM\Messenger\mgsimcommon.dll

c:\Program Files\SweetIM\Messenger\mgSweetIM.dll

c:\Program Files\SweetIM\Messenger\mgUpdateSupport.dll

c:\Program Files\SweetIM\Messenger\mgxml_wrapper.dll

c:\Program Files\SweetIM\Messenger\mgYahooAuto.dll

c:\Program Files\SweetIM\Messenger\mgYahooMessengerAdapter.dll

c:\Program Files\SweetIM\Messenger\msvcp71.dll

c:\Program Files\SweetIM\Messenger\msvcr71.dll

c:\Program Files\SweetIM\Messenger\SweetIM.exe

c:\Program Files\SweetIM\Messenger\resources\images\AudibleButton.png

c:\Program Files\sweetpacks bundle uninstaller\uninstaller.exe

c:\WINDOWS\system32\dmwu.exe

c:\WINDOWS\system32\ImHttpComm.dll

c:\WINDOWS\system32\ARFC\wrtc.exe

c:\WINDOWS\system32\jmdp\SweetNT.crx

c:\WINDOWS\system32\WNLT\Installation\uninstaller.exe

%CommonAppData%\SweetIM\Communicator\conf\communicator.xml

%CommonAppData%\SweetIM\Messenger\conf\adapter.xml

%CommonAppData%\SweetIM\Messenger\conf\autoupdate.xml

%CommonAppData%\SweetIM\Messenger\conf\contentpackages.xml

%CommonAppData%\SweetIM\Messenger\conf\logger.xml

%CommonAppData%\SweetIM\Messenger\conf\messages.xml

%CommonAppData%\SweetIM\Messenger\conf\sweetim.xml

%CommonAppData%\SweetIM\Messenger\conf\sweetimapp.xml

%CommonAppData%\SweetIM\Messenger\conf\users\main_user_config.xml

%CommonAppData%\SweetIM\Messenger\data\Bars\Default\100\bar.html

%CommonAppData%\SweetIM\Messenger\data\contentdb\cache_indx.dat

%CommonAppData%\SweetIM\Messenger\data\packages\FailDialog\activationFail.htm

%CommonAppData%\SweetIM\Messenger\data\packages\FailDialog\close_but.gif

%CommonAppData%\SweetIM\Messenger\data\packages\FailDialog\failure_dialog_BG.jpg

%CommonAppData%\SweetIM\Toolbars\Internet Explorer\cache\ccbd8b558f1d599e360b3dc00c89e1b1.facebook2.png

%CommonAppData%\SweetIM\Toolbars\Internet Explorer\cache\d7663980840977888075cdf06da9e63d.facebook2_hover.png

%CommonAppData%\SweetIM\Toolbars\Internet Explorer\cache\dda5971490977d5465f836a12522f1a1.games3.png

%UserProfile%\Desktop\Search the Web.url


Associated SweetPacks Toolbar Registry Modifications:


HKEY_CURRENT_USER\Software\IM

HKEY_CURRENT_USER\Software\ImInstaller

HKEY_CURRENT_USER\Software\SweetIM

HKEY_CURRENT_USER\Software\WNLT

HKEY_CLASSES_ROOT\sim-packages

HKEY_CLASSES_ROOT\SWEETIE.IEToolbar

HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1

HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook

HKEY_CLASSES_ROOT\Toolbar3.SWEETIE

HKEY_CLASSES_ROOT\Toolbar3.SWEETIE.1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SweetIM.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}

HKEY_LOCAL_MACHINE\SOFTWARE\SweetIM

HKEY_LOCAL_MACHINE\SOFTWARE\WNLT

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} "FaviconURL" =

"http://cdn.web.sweetim.com/toolbarff/searchplugin/sweetim.ico"

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} "URL" = "http://search.sweetim.com/search.asp?

src=6&crg=3.61010009&ptr=100&st=12&q={searchTerms}&barid={297A90D1-EEED-11E2-9F91-080027EB26AB}"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} "DisplayName" = "SweetIM search"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} "FaviconURL" =

"http://cdn.web.sweetim.com/toolbarff/searchplugin/sweetim.ico"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} "URL" = "http://search.sweetim.com/search.asp?

src=6&crg=3.61010009&ptr=100&st=12&q={searchTerms}&barid={297A90D1-EEED-11E2-9F91-080027EB26AB}"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "SweetIM" = "C:\Program Files\SweetIM\Messenger\SweetIM.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Sweetpacks Communicator" = "C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0C43FE6B-E881-4AFC-B384-4AEBC90047E8}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A0C9DF2B-89B5-4483-8983-18A68200F1B4}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DD85D6BF-4787-4A93-99A5-3F0CF0AE8834}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EA8FA6BE-29BE-4AF2-9352-841F83215EB0}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SweetIM Bundle by SweetPacks

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WNLT

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IBUpdaterService








Smith Technical Resources makes no guarantees or claims that the information contained in this article will help you completely remove the above listed malicious program(s) from your computer.  There are several variations of each particular virus in the wild . And the procedure listed above may not be adequate for the specific version of the virus that your computer has been compromised by.

If you feel uncomfortable performing any of the procedures that we've listed on this page, please contact a professional computer repair company in your area and have them complete the needed repairs on your computer. Smith Technical Resources takes no responsibility for any possible damage that could result from your use of the above instructions.

©Smithtechres.com 2013 All Rights Reserved. Website Privacy Policy. Site Map

Adwcleaner interface Adwcleaner scan results Adwcleaner interface Adwcleaner uninstallation Shortcut Cleaner Results Example Internet Explorer Tools and Options Menu Internet explorer reset screen Internet explorer home page settings Emsisoft Emergency Kit Interface Emsisoft Emergency Kit Deep Scan Option

Related Tutorials That May Be Of Interest To You

  1. Web browser configuration tutorials
  2. Computer virus removal tutorials


Internet Explorer Logo Google Chrome Logo Opera Browser Logo Apple Safari Browser Logo

Sweetpacks Toolbar Removal Tutorial