Home Malware Programs Potentially Unwanted Programs (PUPs) Mindspark Toolbars

Mindspark Toolbars

Posted: April 28, 2014

Threat Metric

Ranking: 35
Threat Level: 1/10
Infected PCs: 9,244,854
First Seen: April 28, 2014
Last Seen: October 17, 2023
OS(es) Affected: Windows

Mindspark is a collaboration of applications designed to offer various functions for popular web browser applications in addition to being a company that markets such programs over the Internet. Mindspark programs and its toolbars may offer methods for searching the Internet or provide services for offering games, add-on components, web browser helpers, and many other types of programs that add functions to your web browsing experience. Many of Mindspark programs are considered to be Potentially Unwanted Programs (PUP), which some computer users will find the apps to be unwanted in their offers and functions. Computer users who wish to remove Mindspark and its applications may do so manually by finding and eliminating any associated web browser extensions or add-on components.

Aliases

Zango [AVG]Win32:Mindspark-A [PUP] [Avast]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\Users\<username>\partnerid.js File name: partnerid.js
Size: 16.4 KB (16402 bytes)
MD5: ecdfb045323e5f31f04689de4223586b
Detection count: 1,943,376
File type: JavaScript file
Mime Type: unknown/js
Path: %SYSTEMDRIVE%\users\neide
Group: Malware file
Last Updated: October 17, 2023
%SYSTEMDRIVE%\Users\<username>\splashpageredirecthandler.js File name: splashpageredirecthandler.js
Size: 2.86 KB (2868 bytes)
MD5: bed60158e51b498d51e0871159d9da29
Detection count: 190,427
File type: JavaScript file
Mime Type: unknown/js
Path: %SYSTEMDRIVE%\users\neide
Group: Malware file
Last Updated: October 17, 2023
%PROGRAMFILES%\MyWebSearch\bar\1.bin\M3SRCHMN.EXE File name: M3SRCHMN.EXE
Size: 34.33 KB (34336 bytes)
MD5: 864a139fbd7beb081a68c8370c5cfdca
Detection count: 543
File type: Executable File
Mime Type: unknown/EXE
Path: %PROGRAMFILES%\MyWebSearch\bar\1.bin
Group: Malware file
Last Updated: March 23, 2016
%PROGRAMFILES(x86)%\PopularScreensavers_7i\bar\1.bin\AppIntegrator64.exe File name: AppIntegrator64.exe
Size: 485.96 KB (485960 bytes)
MD5: 81023fe149fb4393d3f333b78cdf2aa0
Detection count: 494
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\PopularScreensavers_7i\bar\1.bin
Group: Malware file
Last Updated: January 8, 2020
%PROGRAMFILES(x86)%\MyScrapNook_12\bar\1.bin\AppIntegrator.exe File name: AppIntegrator.exe
Size: 225.86 KB (225864 bytes)
MD5: 8436c5b7f8866dad1a956d95bf529c03
Detection count: 342
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\MyScrapNook_12\bar\1.bin
Group: Malware file
Last Updated: June 4, 2020
%APPDATA%\win32.exe File name: win32.exe
Size: 172.83 KB (172832 bytes)
MD5: 07c5192b7843b83d7ae8f70bc2e47ed6
Detection count: 192
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: March 25, 2016
%APPDATA%\Win32.exe File name: Win32.exe
Size: 318.71 KB (318710 bytes)
MD5: e5dc66aadb2e2cc5b46633b9168c8683
Detection count: 131
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: March 25, 2016
%PROGRAMFILES%\PopularScreensavers_7i\bar\2.bin\7ibar.dll File name: 7ibar.dll
Size: 859.72 KB (859720 bytes)
MD5: 831ec56548b362259bf8e52513260051
Detection count: 96
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\PopularScreensavers_7i\bar\2.bin
Group: Malware file
Last Updated: May 19, 2014
%APPDATA%\win32.exe File name: win32.exe
Size: 131.07 KB (131072 bytes)
MD5: 97f980b37edec12c11e90343bd9223d8
Detection count: 75
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: November 6, 2019
%LOCALAPPDATA%\TelevisionFanatic\GLU32.dll File name: GLU32.dll
Size: 490.49 KB (490496 bytes)
MD5: e8abc0c21bb78dcc176c08ba63257481
Detection count: 44
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%\TelevisionFanatic
Group: Malware file
Last Updated: July 4, 2014
%PROGRAMFILES%\PopularScreensavers_7i\bar\1.bin\7iSrchMn.exe File name: 7iSrchMn.exe
Size: 122.6 KB (122608 bytes)
MD5: eb6ebb56ac66e9d2c34a662ad9514eb8
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\PopularScreensavers_7i\bar\1.bin
Group: Malware file
Last Updated: May 19, 2014
%PROGRAMFILES(x86)%\FromDocToPDF_65\bar\1.bin\AppIntegrator64.exe File name: AppIntegrator64.exe
Size: 1.06 MB (1061376 bytes)
MD5: 5b6407e12a27b1e23f9d0c68d7492a1d
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\FromDocToPDF_65\bar\1.bin
Group: Malware file
Last Updated: April 28, 2014
%PROGRAMFILES(x86)%\SafePCRepair_89\bar\1.bin\AppIntegrator64.exe File name: AppIntegrator64.exe
Size: 485.44 KB (485448 bytes)
MD5: 3d2f9354463e2dd516271dcaa26c6bb7
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\SafePCRepair_89\bar\1.bin
Group: Malware file
Last Updated: April 28, 2014
%PROGRAMFILES%\PopularScreensavers_7i\bar\1.bin\7ibarsvc.exe File name: 7ibarsvc.exe
Size: 116.23 KB (116232 bytes)
MD5: db21f5d5fd041127589c1a5fdbebafe4
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\PopularScreensavers_7i\bar\1.bin
Group: Malware file
Last Updated: May 19, 2014
%PROGRAMFILES%\PopularScreensavers_7i\bar\1.bin\7iSrchMn.exe File name: 7iSrchMn.exe
Size: 565.24 KB (565248 bytes)
MD5: 8bccf79a2c638434fc81d06e8e4c305b
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\PopularScreensavers_7i\bar\1.bin
Group: Malware file
Last Updated: May 19, 2014
%PROGRAMFILES(x86)%\PopularScreensavers_7i\bar\1.bin\7iSrchMn.exe File name: 7iSrchMn.exe
Size: 593.92 KB (593920 bytes)
MD5: 8b8a9b69c16823d69b9f717b4c28b1db
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\PopularScreensavers_7i\bar\1.bin
Group: Malware file
Last Updated: May 19, 2014
%PROGRAMFILES(x86)%\VideoDownloadConverter_4z\bar\1.bin\AppIntegrator64.exe File name: AppIntegrator64.exe
Size: 485.96 KB (485960 bytes)
MD5: e3ffe5ff6f54c3d698c9b4258f53e309
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\VideoDownloadConverter_4z\bar\1.bin
Group: Malware file
Last Updated: April 28, 2014
%PROGRAMFILES(x86)%\GardeningEnthusiast_7j\bar\1.bin\AppIntegrator64.exe File name: AppIntegrator64.exe
Size: 1.06 MB (1061376 bytes)
MD5: 1df750a352562bb2b8e3f31fd04134ab
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\GardeningEnthusiast_7j\bar\1.bin
Group: Malware file
Last Updated: April 28, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

File name without pathhp.myway[1].xmlhttp_ext.ask.com_0.localstoragehttp_ext.ask.com_0.localstorage-journalhttp_ext.dl.tb.ask.com_0.localstoragehttp_ext.dl.tb.ask.com_0.localstorage-journalhttp_hp.myway.com_0.localstoragehttp_hp.myway.com_0.localstorage-journalHKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\MindsparkSoftware\Microsoft\Internet Explorer\BrowserStorage\DomainTrustStatus\myway.comSOFTWARE\Microsoft\Internet Explorer\DOMStorage\hp.myway.comSOFTWARE\Microsoft\Internet Explorer\DOMStorage\myway.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\hp.myway.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\myway.comSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cab\OpenWithProgids\euz.cabSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip\OpenWithProgids\euz.zipSOFTWARE\MindsparkSOFTWARE\Wow6432Node\Mindspark

Additional Information

The following directories were created:
%LOCALAPPDATA%\Mindspark%LOCALAPPDATA%\Mindspark_Interactive_Net%PROGRAMFILES%\FestiveBar_3g%PROGRAMFILES%\Mindspark%PROGRAMFILES(x86)%\FestiveBar_3g%PROGRAMFILES(x86)%\Mindspark%UserProfile%\Local Settings\Application Data\Mindspark%UserProfile%\Local Settings\Application Data\Mindspark_Interactive_Net
The following cookies were detected:
dl.myway.comhp.myway.commyway.comsearch.myway.com
The following URL's were detected:
"current":"Ask Web Sx-SAE@iacsearchandmedia.com>Mindspark<Mindspark_betterconverterpro.combetterconverterprotab.comextensions.toolbar.mindsparkhttp://dl.myway.comhttp://hp.mywebsearch.com/mywebsearchhttps://int.search.myway.com/search/GGmain.jhtml?https://search.mysearch.com/web?q=https://search.myway.com/search/mindspark._nativemessagingHostName": "com.mindspark.search.myway.com
Loading...