Home Malware Programs Potentially Unwanted Programs (PUPs) Mindspark Toolbars

Mindspark Toolbars

Posted: April 28, 2014

Threat Metric

Ranking: 29
Threat Level: 1/10
Infected PCs: 9,436,230
First Seen: April 28, 2014
Last Seen: March 10, 2025
OS(es) Affected: Windows

Mindspark is a collaboration of applications designed to offer various functions for popular web browser applications in addition to being a company that markets such programs over the Internet. Mindspark programs and its toolbars may offer methods for searching the Internet or provide services for offering games, add-on components, web browser helpers, and many other types of programs that add functions to your web browsing experience. Many of Mindspark programs are considered to be Potentially Unwanted Programs (PUP), which some computer users will find the apps to be unwanted in their offers and functions. Computer users who wish to remove Mindspark and its applications may do so manually by finding and eliminating any associated web browser extensions or add-on components.

Aliases

Zango [AVG]Win32:Mindspark-A [PUP] [Avast]

Use SpyHunter to Detect and Remove PC Threats

If you are concerned that malware or PC threats similar to Mindspark Toolbars may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.

* See Free Trial offer below. EULA and Privacy/Cookie Policy.

Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\Users\<username>\partnerid.js File name: partnerid.js
Size: 16.4 KB (16402 bytes)
MD5: ecdfb045323e5f31f04689de4223586b
Detection count: 1,974,950
File type: JavaScript file
Mime Type: unknown/js
Path: %SYSTEMDRIVE%\users\neide
Group: Malware file
Last Updated: March 10, 2025
%SYSTEMDRIVE%\Users\<username>\splashpageredirecthandler.js File name: splashpageredirecthandler.js
Size: 2.86 KB (2868 bytes)
MD5: bed60158e51b498d51e0871159d9da29
Detection count: 192,029
File type: JavaScript file
Mime Type: unknown/js
Path: %SYSTEMDRIVE%\users\neide
Group: Malware file
Last Updated: March 9, 2025
%PROGRAMFILES%\OurBabyMakerIE_28\bar\1.bin\28brmon.exe File name: 28brmon.exe
Size: 20.48 KB (20480 bytes)
MD5: e2db62956b14ceefb7b33987c7ce610f
Detection count: 646
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\OurBabyMakerIE_28\bar\1.bin
Group: Malware file
Last Updated: March 23, 2016
%PROGRAMFILES%\MyWebSearch\bar\1.bin\M3SRCHMN.EXE File name: M3SRCHMN.EXE
Size: 34.33 KB (34336 bytes)
MD5: 864a139fbd7beb081a68c8370c5cfdca
Detection count: 543
File type: Executable File
Mime Type: unknown/EXE
Path: %PROGRAMFILES%\MyWebSearch\bar\1.bin
Group: Malware file
Last Updated: March 23, 2016
%PROGRAMFILES(x86)%\PopularScreensavers_7i\bar\1.bin\AppIntegrator64.exe File name: AppIntegrator64.exe
Size: 485.96 KB (485960 bytes)
MD5: 81023fe149fb4393d3f333b78cdf2aa0
Detection count: 494
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\PopularScreensavers_7i\bar\1.bin
Group: Malware file
Last Updated: January 8, 2020
%PROGRAMFILES(x86)%\MyScrapNook_12\bar\1.bin\AppIntegrator.exe File name: AppIntegrator.exe
Size: 225.86 KB (225864 bytes)
MD5: 8436c5b7f8866dad1a956d95bf529c03
Detection count: 342
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\MyScrapNook_12\bar\1.bin
Group: Malware file
Last Updated: June 4, 2020
%APPDATA%\win32.exe File name: win32.exe
Size: 172.83 KB (172832 bytes)
MD5: 07c5192b7843b83d7ae8f70bc2e47ed6
Detection count: 192
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: March 25, 2016
%PROGRAMFILES%\PopularScreensavers_7i\bar\2.bin\7ibar.dll File name: 7ibar.dll
Size: 859.72 KB (859720 bytes)
MD5: 831ec56548b362259bf8e52513260051
Detection count: 96
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\PopularScreensavers_7i\bar\2.bin
Group: Malware file
Last Updated: May 19, 2014
%PROGRAMFILES(x86)%\TelevisionFanatic\bar\1.bin\64medint.exe File name: 64medint.exe
Size: 20.59 KB (20598 bytes)
MD5: 02dddedae31802fc7321248ad8aad700
Detection count: 59
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\TelevisionFanatic\bar\1.bin
Group: Malware file
Last Updated: March 8, 2020
D:\anti\TelevisionFanatic.exe File name: TelevisionFanatic.exe
Size: 270.87 KB (270872 bytes)
MD5: 25fa43e13f338833a5adb16241d18b40
Detection count: 56
File type: Executable File
Mime Type: unknown/exe
Path: D:\anti
Group: Malware file
Last Updated: July 4, 2014
%LOCALAPPDATA%\TelevisionFanatic\GLU32.dll File name: GLU32.dll
Size: 490.49 KB (490496 bytes)
MD5: e8abc0c21bb78dcc176c08ba63257481
Detection count: 44
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%\TelevisionFanatic
Group: Malware file
Last Updated: July 4, 2014
%PROGRAMFILES%\VideoDownloadConverter_4z\bar\1.bin\4zbarsvc.exe File name: 4zbarsvc.exe
Size: 120.32 KB (120328 bytes)
MD5: eccc46ecaf9a4ab62754c87c69fbf549
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\VideoDownloadConverter_4z\bar\1.bin
Group: Malware file
Last Updated: April 28, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

File name without pathhp.myway[1].xmlhttp_ext.ask.com_0.localstoragehttp_ext.ask.com_0.localstorage-journalhttp_ext.dl.tb.ask.com_0.localstoragehttp_ext.dl.tb.ask.com_0.localstorage-journalhttp_hp.myway.com_0.localstoragehttp_hp.myway.com_0.localstorage-journalHKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\MindsparkSoftware\Microsoft\Internet Explorer\BrowserStorage\DomainTrustStatus\myway.comSOFTWARE\Microsoft\Internet Explorer\DOMStorage\hp.myway.comSOFTWARE\Microsoft\Internet Explorer\DOMStorage\myway.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\hp.myway.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\myway.comSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cab\OpenWithProgids\euz.cabSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip\OpenWithProgids\euz.zipSOFTWARE\MindsparkSOFTWARE\Wow6432Node\Mindspark

Additional Information

The following directories were created:
%LOCALAPPDATA%\Mindspark%LOCALAPPDATA%\Mindspark_Interactive_Net%PROGRAMFILES%\FestiveBar_3g%PROGRAMFILES%\Mindspark%PROGRAMFILES(x86)%\FestiveBar_3g%PROGRAMFILES(x86)%\Mindspark%UserProfile%\Local Settings\Application Data\Mindspark%UserProfile%\Local Settings\Application Data\Mindspark_Interactive_Net
The following cookies were detected:
dl.myway.comhp.myway.commyway.comsearch.myway.com
The following URL's were detected:
"current":"Ask Web Sx-SAE@iacsearchandmedia.comMindspark_betterconverterpro.combetterconverterprotab.comdl.myway.comextensions.toolbar.mindsparkhttps://search.mysearch.com/web?q=https://search.myway.com/search/mindspark._mywebsearch.comnativemessagingHostName": "com.mindspark.search.myway.com
Loading...
Spywareremove.com uses cookies to provide you with a better browsing experience and analyze how users navigate and utilize the Site. By using this Site or clicking on "OK", you consent to the use of cookies. Learn more.