Home Malware Programs Potentially Unwanted Programs (PUPs) HeadlineAlley Toolbar

HeadlineAlley Toolbar

Posted: January 16, 2012

Threat Metric

Ranking: 1,707
Threat Level: 1/10
Infected PCs: 87,143
First Seen: January 16, 2012
Last Seen: October 16, 2023
OS(es) Affected: Windows

HeadlineAlley Toolbar is a potentially unwanted program (PUP) that was created and marketed by Mindspark Interactive Network Inc. Computer users may utilize HeadlineAlley Toolbar as a means of finding headline news stories over the Internet. Additionally, HeadlineAlley Toolbar may be used to quickly access certain headline news sites that it offers in its quick function buttons displayed directly on the toolbar. While the utilization of the HeadlineAlley Toolbar is not harmful to a PC, it changes a web browser's start page, new tab page, or homepage. Users who don't find HeadlineAlley Toolbar's news sources important may wish to remove this software from their computer. HeadlineAlley Toolbar's removal can be taken care of by uninstalling the browser extensions associated with it.

Aliases

Suspicious file [Panda]Heuristic.LooksLike.Win32.Suspicious.E [McAfee-GW-Edition]TR/Crypt.XPACK.Gen [AntiVir]HEUR:Trojan.Win32.Generic [Kaspersky]Trj/CI.A [Panda]Suspicion: unknown virus [AVG]W32/Adware_fam.NB [Fortinet]not-a-virus:AdWare.Win32.SmartPops [Ikarus]PUP/Win32.SmartPop [AhnLab-V3]Trojan/win32.agent.gen [Antiy-AVL]Adware/SmartPops.s [AntiVir]DLOADER.Trojan [DrWeb]UnclassifiedMalware [Comodo]not-a-virus:AdWare.Win32.SmartPops.w [Kaspersky]WS.Reputation.1 [Symantec]
More aliases (48)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\HeadlineAlley_29\bar\1.bin\29SrcAs.dll File name: 29SrcAs.dll
Size: 53.24 KB (53248 bytes)
MD5: 3362c9e383ae8c6ec7c403df8d474c71
Detection count: 2,611
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\HeadlineAlley_29\bar\1.bin
Group: Malware file
Last Updated: April 24, 2013
%PROGRAMFILES%\HeadlineAlley_29\bar\1.bin\29bar.dll File name: 29bar.dll
Size: 675.84 KB (675840 bytes)
MD5: 81360e41834e89627a930cbc9d50d656
Detection count: 2,600
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\HeadlineAlley_29\bar\1.bin
Group: Malware file
Last Updated: April 24, 2013
%PROGRAMFILES%\HeadlineAlley_29\bar\1.bin\29highin.exe File name: 29highin.exe
Size: 22.04 KB (22048 bytes)
MD5: 6689d8f62f860178685496ef45520967
Detection count: 20
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\HeadlineAlley_29\bar\1.bin
Group: Malware file
Last Updated: April 25, 2013
%ALLUSERSPROFILE%\Application Data\amsecure.exe File name: amsecure.exe
Size: 825.34 KB (825344 bytes)
MD5: 0739d8449b32fd3910482137d25dc8fb
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Application Data
Group: Malware file
Last Updated: April 29, 2013

Registry Modifications

The following newly produced Registry Values are:

CLSID{011BB8C9-5B2C-449E-B26C-7D7D489E2C6D}{03818361-D0A0-4C89-8B0A-3320FA74158F}{07686242-e711-4ade-804f-7b91600e071e}{08f9937e-0a4f-48cf-94e7-827223daec1d}{13119113-0854-469d-807A-171568457991}{14955909-6b2d-4a8b-bf1e-497d4ad7f794}{18B539A0-26A0-4D0B-85CE-9B726C3C3DC6}{1F2316ED-10F9-4DE5-86E6-1AA53A633DD1}{23119123-0854-469D-807A-171568457991}{298E6072-44DE-4B02-9194-53977B19222F}{2a7560c0-8bc4-4087-bbb0-d307c8f7e95e}{2C4A366F-2830-423C-BCC5-FEFF73BA0AD4}{2d081902-5ca0-4645-b767-cd5fb0ac06b5}{2f929a33-87fe-42a6-ab43-8ef920a34c2a}{33119133-0854-469d-807A-171568457991}{331770FF-B8C8-46AC-BD9F-CCEB4D222EC9}{37B3AC7D-AC04-4640-A554-F566F317E63C}{3CCF7447-D257-4552-B693-F995281F9E19}{3F98963D-1277-48FD-802E-6CA1A4DC9622}{433ae6bf-a1fd-4a51-858e-6c26c7cd64db}{444FA7B2-C5C5-4739-973E-4211D4A8FDD9}{4465e725-ed03-4227-995a-c2e51ac5bc54}{46C2A50F-39BF-4344-82CD-F0F032F246A6}{4AE2915E-2E0F-4BEC-BBDA-69BD2F95EA90}{530E1961-8D61-4C07-981E-36611C9E8AF5}{55566AA7-0CBC-4D19-BFBF-3BD77C84A048}{5BF14132-D493-4866-ACB4-3BB2861A321B}{6170566B-0E22-47DE-A68B-B854DB9D4EE6}{6946FB9E-ED71-4EAE-AAE7-68FF89C62D96}{6B67147C-4666-44A0-A57F-855A05215AAE}{6BC35620-2E92-4E13-9889-55643CCE8BD8}{6E95D1D3-A691-44AC-AB5B-731312C2D69D}{724e9f12-9c72-4475-b963-fe290934dc66}{7ad4c0aa-a484-4330-862c-74a40f587cbc}{7F50FCA3-2F15-4506-9E76-7E7969E2CF30}{86e3ef9b-685b-4a16-8552-0e0a646c65cd}{8f61e414-ea79-4559-8bb6-61d956f70306}{91530325-8BFA-4C9D-8581-3046FB599169}{94A0986F-2DD3-4A55-8AD0-2DE46AA9268B}{9B2FB732-5D3C-4C2A-A53B-DC1BEDFD8B00}{9c8de6c1-88f6-4515-9e81-6a280bb35349}{9dc134b0-9913-4d9b-b8ab-69eda881a4bc}{A2C11415-E270-493B-9C89-EF9E348A05A2}{A441C22D-839F-43D6-9B3A-AE2301CD7764}{a6b53354-4f5e-46d3-b722-9f2620ad3758}{B35E972E-A888-447A-8272-B2114C866735}{B46B1675-EA32-47FA-B6A4-F6B75C0DAA44}{B5025785-47CC-463D-AA96-07DFB989A726}{BB548C84-4EA2-4790-807A-FDF5F7F5AA96}{bc5d2791-ed53-427a-8915-0dab12b9b42c}{BEE1DBD3-D64D-4F0D-A4CF-86083B046D20}{BEE4E929-4A4A-4F2A-91E3-26654A2294B6}{BF1626C4-9782-4911-97A8-003D97E0196D}{bf49b0a2-8252-4656-8ccc-aae14cde8c10}{C0399D3E-A8A3-41C3-A2D2-EBF178A31278}{C26C99E3-A2AE-4FA4-9AE1-C26456AF0133}{c40cb9d6-d375-46fe-997b-cac7af3bef9c}{C48AEA59-780E-43E0-A3A8-AAD34B635D07}{D110789B-63D2-4CD5-A11E-40726B711404}{D2024392-8943-4FED-B862-0AAF3FEB4AEB}{D353AA2B-4AC9-4EDD-8D94-1267C63607A8}{da974ecc-1b4f-49ce-967a-0e4261fa3292}{DB409D94-9141-47FA-BF12-30B00788F6E4}{DB74EA0A-6AD3-4884-87F5-6FFC220FA3BF}{E3C2CEFB-FB77-4258-A94E-2BA27CD8E67A}{E82C1803-3EBF-4209-952A-A4C5FDBBF9F3}{F61ABA1F-F45C-4774-8048-4C1CD440F4D4}{f8acf502-727b-4d05-9994-9eab5691e439}{FBBD3485-7B7A-4B33-A239-8C4E374F4517}File name without pathheadlinealley.dl.myway[1].xmlhttp_headlinealley.dl.tb.ask.com_0.localstoragehttp_headlinealley.dl.tb.ask.com_0.localstorage-journalHKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\HeadlineAlley_29SOFTWARE\Classes\HeadlineAlley_29.DynamicBarButtonSOFTWARE\Classes\HeadlineAlley_29.DynamicBarButton.1SOFTWARE\Classes\HeadlineAlley_29.FeedManagerSOFTWARE\Classes\HeadlineAlley_29.FeedManager.1SOFTWARE\Classes\HeadlineAlley_29.HTMLMenuSOFTWARE\Classes\HeadlineAlley_29.HTMLMenu.1SOFTWARE\Classes\HeadlineAlley_29.HTMLPanelSOFTWARE\Classes\HeadlineAlley_29.HTMLPanel.1SOFTWARE\Classes\HeadlineAlley_29.MultipleButtonSOFTWARE\Classes\HeadlineAlley_29.MultipleButton.1SOFTWARE\Classes\HeadlineAlley_29.PseudoTransparentPluginSOFTWARE\Classes\HeadlineAlley_29.PseudoTransparentPlugin.1SOFTWARE\Classes\HeadlineAlley_29.RadioSOFTWARE\Classes\HeadlineAlley_29.Radio.1SOFTWARE\Classes\HeadlineAlley_29.RadioSettingsSOFTWARE\Classes\HeadlineAlley_29.RadioSettings.1SOFTWARE\Classes\HeadlineAlley_29.ScriptButtonSOFTWARE\Classes\HeadlineAlley_29.ScriptButton.1SOFTWARE\Classes\HeadlineAlley_29.SettingsPluginSOFTWARE\Classes\HeadlineAlley_29.SettingsPlugin.1SOFTWARE\Classes\HeadlineAlley_29.SkinLauncherSOFTWARE\Classes\HeadlineAlley_29.SkinLauncher.1SOFTWARE\Classes\HeadlineAlley_29.SkinLauncherSettingsSOFTWARE\Classes\HeadlineAlley_29.SkinLauncherSettings.1SOFTWARE\Classes\HeadlineAlley_29.ThirdPartyInstallerSOFTWARE\Classes\HeadlineAlley_29.ThirdPartyInstaller.1SOFTWARE\Classes\HeadlineAlley_29.ToolbarProtectorSOFTWARE\Classes\HeadlineAlley_29.ToolbarProtector.1SOFTWARE\Classes\HeadlineAlley_29.UrlAlertButtonSOFTWARE\Classes\HeadlineAlley_29.XMLSessionPluginSOFTWARE\Classes\HeadlineAlley_29.XMLSessionPlugin.1SOFTWARE\HeadlineAlleySoftware\HeadlineAlley_29Software\Microsoft\Internet Explorer\Approved Extensions\{9C8DE6C1-88F6-4515-9E81-6A280BB35349}SOFTWARE\Microsoft\Internet Explorer\DOMStorage\headlinealley.comSOFTWARE\Microsoft\Internet Explorer\DOMStorage\www.headlinealley.comSoftware\Microsoft\Internet Explorer\SearchScopes\{9a2d7aa7-c5a9-4eb1-9e08-c6aaa7538b55}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9C8DE6C1-88F6-4515-9E81-6A280BB35349}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{14955909-6B2D-4A8B-BF1E-497D4AD7F794}SOFTWARE\MozillaPlugins\@HeadlineAlley_29.com/PluginSOFTWARE\Wow6432Node\HeadlineAlley_29SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9a2d7aa7-c5a9-4eb1-9e08-c6aaa7538b55}SOFTWARE\Wow6432Node\MozillaPlugins\@HeadlineAlley_29.com/PluginSYSTEM\ControlSet001\services\HeadlineAlley_29ServiceSYSTEM\ControlSet002\services\HeadlineAlley_29ServiceSYSTEM\CurrentControlSet\services\HeadlineAlley_29ServiceHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}HeadlineAlley_29bar UninstallHeadlineAlley_29bar Uninstall FirefoxHeadlineAlley_29bar Uninstall Internet ExplorerHeadlineAlleyTooltab Uninstall Internet Explorer

Additional Information

The following directories were created:
%APPDATA%\HeadlineAlley_29%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\jdcoaiglgbabaidnjgejfgebhmcapcea%LOCALAPPDATA%\HeadlineAlleyTooltab%LOCALAPPDATA%\HeadlineAlley_29%PROGRAMFILES%\HeadlineAlley_29%PROGRAMFILES(x86)%\HeadlineAlley_29%USERPROFILE%\AppData\LocalLow\HeadlineAlley_29
Loading...