Home Malware Programs Browser Hijackers MindDabble Toolbar

MindDabble Toolbar

Posted: June 28, 2013

Threat Metric

Ranking: 14,738
Threat Level: 1/10
Infected PCs: 689
First Seen: June 28, 2013
Last Seen: October 14, 2023
OS(es) Affected: Windows

MindDabble is a browser hijacker, which is advertised via other freeware downloads (video recording/streaming, download-managers or PDF creators) that had bundled into their installation MindDabble, and once installed on an affected computer, it will insert the MindDabble Toolbar, and change the default browser homepage and default search engine to Mywebsearch.com. Mywebsearch will display annoying pop-up advertisements and sponsored links in search results of any legal search engine, and may gather search terms from a victimized Internet user's search queries. The MindDabble Toolbar is used to raise traffic of the certain website by using blackhat SEO and make money from click fraud. MindDabble is also categorized as a PUP (potentially unwanted program). MindDabble is also bundled within the custom installer on many download websites, such as CNET, Brothersoft or Softonic, so if the PC user has downloaded an application from these websites, MindDabble might have been installed during the application setup process.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{025D6190-6765-407F-BC7C-D748708FC795}{03975F40-DDFF-4061-93E4-9D4246F3018D}{0838a762-8d5e-4fbb-9ea9-44dbedaf3642}{0889C02C-E9A5-4248-BA4A-C542A08C8C32}{0D4BE4A8-53D1-46FE-9A00-CCE8A36F2745}{0DF2C26D-33BC-40DC-8E63-F1746D121C5D}{0FA9A98A-F3A6-4F8F-A22E-4B1BA1E15C8E}{203AD06C-FB5B-4195-9DCE-7DC830CA71D1}{22d1a59e-b36d-4802-addb-f09161eb2085}{279AEB4A-EAD4-497C-A433-42CA925BD496}{2ED25FF4-5642-4F09-968D-0AF2FC5E4CFA}{30ea28da-b2b8-4555-a80e-310d546d5f3d}{3120C992-D011-428B-A9A1-541F8D69C1C9}{3C1F4CFE-5035-4695-806F-11646487C623}{3CACEC93-4085-4A16-874F-15ECF784782F}{4101C16C-05EE-41A0-B78D-48C9BF4406D0}{4743bf10-db5f-449a-b43c-7db132560626}{4f901763-6c25-4cac-98fe-df3a55f5aeb4}{50AD5C46-636C-40F3-8387-CCE7A04463ED}{529E073B-A81F-4C83-814D-8D6DAA6E26AB}{5eec4ead-4c59-46eb-975c-1d9e3c6a308a}{612f1f86-3a05-49c8-bed2-9db18f90dc13}{63A6E12A-3D70-4286-906D-12895E60C9CF}{67E60D68-4D2C-4FA2-A8E8-340EFFD8A837}{68E9E564-E979-4827-AA7C-66A57820BFA8}{6CCE5B53-3FDC-4AFD-8E8D-4C943AE1717B}{6ed6bd05-113e-4dae-b268-646a9335c521}{72669E89-E464-4D97-A834-C2A5279C20A4}{799488CB-4C10-42CB-88FE-54632C387401}{79a4039e-0550-409d-a072-82b82f3c1924}{7ab1268b-b291-47fe-b699-c50bd3a090ec}{856136BB-FD9A-43D2-8664-131CE963F16A}{88B80696-C740-4C14-8C21-83B52FC947BB}{8e78b5b1-a7ec-4a48-b40c-d5177157aee3}{92E0A575-D457-4996-843A-24E96F8D855B}{93e6ca29-b4ed-4dde-90cf-f89a24756339}{94CD37D0-D27E-4873-8227-53525406D7BB}{9576A53F-3EB8-4B8D-8A10-82228A13B57B}{99853CE2-E415-412B-ACD2-13C00A9AFE67}{A7C7EA4D-0CA5-4B53-A4F7-1FD244EE5B2B}{A96C61FB-7AD9-401F-9EA1-8DB9798B7A92}{AB7C0368-9B14-486B-BC89-B35A0D0FB5D9}{B8F405E6-03CC-46ED-93E6-AD3493AD7673}{C0A02208-3815-413F-B366-C45D4A824F51}{C0E127CB-24B3-4DC7-9E8A-C0C7E941CE49}{c683cbf9-33f2-4d38-8daa-56ed16c1bbf1}{c6a49a40-c309-4173-8e6d-e01641134de5}{C9AC400D-1646-486F-8713-9FDD7289F14E}{D324ED7F-1273-4EB5-B9D5-542152DE9E27}{D40622C7-17D8-4CFC-BCAF-E23E69B90C98}{DE28DCC2-394F-4E0B-8269-4B313D451385}{e49b29de-a1b6-499a-b3e8-883b5c88e013}{e4a13bc5-1598-49fa-89d4-585bbb05748c}{E63B9643-80F6-45C6-9A82-77E1029B7FEE}{e88879cd-ed17-420c-8b09-cb9b3c1fa379}{ED7B9405-D31E-454A-A3A9-FDCEFE60ACA9}{ED8418C3-0D0A-4748-A013-1AA6B79C1EA5}{EE84F0FF-C55C-40A7-BB4B-2F24726EABCA}{F228B015-3994-4926-8B31-ABCD4EE33E1C}{FDAFE7E4-9E77-479E-9402-BBAF0D694AB8}HKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\MindDabble_4pSOFTWARE\Classes\MindDabble_4p.DynamicBarButtonSOFTWARE\Classes\MindDabble_4p.DynamicBarButton.1SOFTWARE\Classes\MindDabble_4p.FeedManagerSOFTWARE\Classes\MindDabble_4p.FeedManager.1SOFTWARE\Classes\MindDabble_4p.HTMLMenuSOFTWARE\Classes\MindDabble_4p.HTMLMenu.1SOFTWARE\Classes\MindDabble_4p.HTMLPanelSOFTWARE\Classes\MindDabble_4p.HTMLPanel.1SOFTWARE\Classes\MindDabble_4p.MultipleButtonSOFTWARE\Classes\MindDabble_4p.MultipleButton.1SOFTWARE\Classes\MindDabble_4p.PseudoTransparentPluginSOFTWARE\Classes\MindDabble_4p.PseudoTransparentPlugin.1SOFTWARE\Classes\MindDabble_4p.RadioSOFTWARE\Classes\MindDabble_4p.Radio.1SOFTWARE\Classes\MindDabble_4p.RadioSettingsSOFTWARE\Classes\MindDabble_4p.RadioSettings.1SOFTWARE\Classes\MindDabble_4p.ScriptButtonSOFTWARE\Classes\MindDabble_4p.ScriptButton.1SOFTWARE\Classes\MindDabble_4p.SettingsPluginSOFTWARE\Classes\MindDabble_4p.SettingsPlugin.1SOFTWARE\Classes\MindDabble_4p.SkinLauncherSOFTWARE\Classes\MindDabble_4p.SkinLauncher.1SOFTWARE\Classes\MindDabble_4p.SkinLauncherSettingsSOFTWARE\Classes\MindDabble_4p.SkinLauncherSettings.1SOFTWARE\Classes\MindDabble_4p.ThirdPartyInstallerSOFTWARE\Classes\MindDabble_4p.ThirdPartyInstaller.1SOFTWARE\Classes\MindDabble_4p.ToolbarProtectorSOFTWARE\Classes\MindDabble_4p.ToolbarProtector.1SOFTWARE\Classes\MindDabble_4p.UrlAlertButtonSOFTWARE\Classes\MindDabble_4p.UrlAlertButton.1SOFTWARE\Classes\MindDabble_4p.XMLSessionPluginSOFTWARE\Classes\MindDabble_4p.XMLSessionPlugin.1Software\Microsoft\Internet Explorer\Approved Extensions\{30EA28DA-B2B8-4555-A80E-310D546D5F3D}Software\Microsoft\Internet Explorer\Approved Extensions\{E88879CD-ED17-420C-8B09-CB9B3C1FA379}Software\Microsoft\Internet Explorer\Approved Extensions\{FDEAE01B-B015-4D75-A122-6250C871E77B}Software\Microsoft\Internet Explorer\SearchScopes\{38bc6857-67fa-4358-afae-28e0f9ad2128}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{30ea28da-b2b8-4555-a80e-310d546d5f3d}Software\Microsoft\Internet Explorer\URLSearchHooks\{22d1a59e-b36d-4802-addb-f09161eb2085}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{e88879cd-ed17-420c-8b09-cb9b3c1fa379}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{fdeae01b-b015-4d75-a122-6250c871e77b}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1adef423-42c9-4aa4-bca1-0c71cfc5809a}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4f901763-6c25-4cac-98fe-df3a55f5aeb4}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{79a4039e-0550-409d-a072-82b82f3c1924}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{82cc702b-cb01-4dbe-8e8e-24d720b77a7d}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{94CD37D0-D27E-4873-8227-53525406D7BB}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{c6a49a40-c309-4173-8e6d-e01641134de5}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e61f988f-451f-432f-8e85-e3f716c33302}Software\MindDabble_4pSOFTWARE\Mozilla\Firefox\Extensions\4pffxtbr@MindDabble_4p.comSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{38bc6857-67fa-4358-afae-28e0f9ad2128}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{30ea28da-b2b8-4555-a80e-310d546d5f3d}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{e88879cd-ed17-420c-8b09-cb9b3c1fa379}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{fdeae01b-b015-4d75-a122-6250c871e77b}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1adef423-42c9-4aa4-bca1-0c71cfc5809a}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4f901763-6c25-4cac-98fe-df3a55f5aeb4}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{79a4039e-0550-409d-a072-82b82f3c1924}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{82cc702b-cb01-4dbe-8e8e-24d720b77a7d}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{94CD37D0-D27E-4873-8227-53525406D7BB}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{c6a49a40-c309-4173-8e6d-e01641134de5}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e61f988f-451f-432f-8e85-e3f716c33302}SOFTWARE\Wow6432Node\MindDabble_4pSOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions\4pffxtbr@MindDabble_4p.com

Additional Information

The following directories were created:
%LOCALAPPDATA%\MindDabble_4p%PROGRAMFILES%\MindDabble_4p%PROGRAMFILES(x86)%\MindDabble_4p%USERPROFILE%\AppData\LocalLow\MindDabble_4p
The following URL's were detected:
MindDabble
Loading...