Home Malware Programs Adware Value Apps

Value Apps

Posted: June 11, 2013

Threat Metric

Ranking: 2,341
Threat Level: 2/10
Infected PCs: 51,639
First Seen: June 11, 2013
Last Seen: October 17, 2023
OS(es) Affected: Windows

One of the latest progeny of the far-too-fecund Conduit Ltd company, Value Apps is another browser add-on that may install itself without permission and promote its services without allowing you to uninstall Value Apps easily. Unlike many other Conduit-built Potentially Unwanted Programs, Value Apps is a PUP that primarily restricts itself to displaying a limited number of pop-ups and an accompanying toolbar icon. While Value Apps is not quite as irritating as the average PUP, Value Apps still includes functions that shouldn't be tolerated by any PC user, as well as questionable benefits to counterbalance its drawbacks. SpywareRemove.com malware experts usually recommend deleting Conduit toolbars with a reliable anti-malware program, and they recommend the same for Value Apps, since removing Value Apps by normal methods usually fails to disinfect your PC entirely.

The Lack of Value for Users in Value Apps

One of the mid-2013 members of the Conduit family of toolbars, Value Apps is marketed as an online shopping assistant, but its functions are most well-known throughout the Web for involving unwanted pop-up windows. Value Apps pop-up windows usually are formatted to lack a border or any visible means of closing them, which is a small trick that SpywareRemove.com malware researchers also have seen being abused by many types of ransomware Trojans (Ukash Viruses, LockScreen Trojans, etc.). Besides simply being annoyed, Value Apps's pop-ups have the notable disadvantage of often preventing you from accessing the original site you were trying to load.

The only other side effect linked to Value Apps is its icon. Trying to delete the Value Apps interface without removing all of Value Apps will cause Value Apps to reinstall any deleted components at the next opportunity (usually, as soon as you reboot your PC). SpywareRemove.com malware experts classify Value Apps as a low-level threat that can be considered adware or a PUP, and encourage deleting Value Apps, just as they encourage the removal of all Conduit toolbars.

Getting the Most Value Out of Your Time Spent Removing Value Apps

In some cases, Value Apps only may be installed for specific browsers, such as Chrome. Disabling these browsers may allow you to use the Web without Value Apps's pop-ups appearing, but you should be conscious of Value Apps still being installed on your computer. The same goes for other members of Value Apps's family of widespread toolbars, which SpywareRemove.com malware experts have found to include such colorful browser plugins as:

  • KeyBar Toolbar
  • Adware.2YourFace
  • FLV Runner Toolbar
  • Delta Search Toolbar
  • Internet Helper Toolbar
  • Vuze Toolbar
  • WiseConvert Community Toolbar
  • Produtools
  • IsoBuster Toolbar
  • Internet Helper Toolbar
  • Vaf Music Toolbar
  • If your browser starts showing Value Apps pop-ups or other Value Apps-related issues, you should immediately restart in Safe Mode and use any accessible anti-malware software to make certain of removing Value Apps completely. As long as you react with a reasonable degree of promptness, SpywareRemove.com malware experts don't consider Value Apps a major threat to your computer's safety or privacy.

    Technical Details

    File System Modifications

    Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

    The following files were created in the system:



    C:\Users\<username>\AppData\Local\Conduit\ValueApps\IE\ValueApps.exe File name: ValueApps.exe
    Size: 1.08 MB (1089536 bytes)
    MD5: 7d2ec3601a4125c8e2540059ba73210b
    Detection count: 630
    File type: Executable File
    Mime Type: unknown/exe
    Path: C:\Users\<username>\AppData\Local\Conduit\ValueApps\IE\ValueApps.exe
    Group: Malware file
    Last Updated: August 3, 2023
    C:\Users\<username>\AppData\Roaming\ValueApps\IE\uninstaller.exe File name: uninstaller.exe
    Size: 76.4 KB (76406 bytes)
    MD5: 025429136fd5f1da5d485360eadec9b3
    Detection count: 237
    File type: Executable File
    Mime Type: unknown/exe
    Path: C:\Users\<username>\AppData\Roaming\ValueApps\IE\uninstaller.exe
    Group: Malware file
    Last Updated: August 10, 2022
    C:\Users\<username>\AppData\Local\Conduit\ValueApps\IE\64\MonPrx.dll File name: MonPrx.dll
    Size: 196.6 KB (196608 bytes)
    MD5: 69880a8e18ca941f1022e2dfc305c621
    Detection count: 126
    File type: Dynamic link library
    Mime Type: unknown/dll
    Path: C:\Users\<username>\AppData\Local\Conduit\ValueApps\IE\64\MonPrx.dll
    Group: Malware file
    Last Updated: August 3, 2023
    %LOCALAPPDATA%\Conduit\ValueApps\IE\64\MonPrx.dll File name: MonPrx.dll
    Size: 211.23 KB (211232 bytes)
    MD5: 398d450647bb0fa5fb5f67b5d506d8c3
    Detection count: 46
    File type: Dynamic link library
    Mime Type: unknown/dll
    Path: %LOCALAPPDATA%\Conduit\ValueApps\IE\64
    Group: Malware file
    Last Updated: March 23, 2016
    %APPDATA%\ValueApps\IE\ValueApps.exe File name: ValueApps.exe
    Size: 435.2 KB (435200 bytes)
    MD5: 72c4fb246d7dafba9de1b593fe581dc8
    Detection count: 41
    File type: Executable File
    Mime Type: unknown/exe
    Path: %APPDATA%\ValueApps\IE
    Group: Malware file
    Last Updated: November 14, 2013
    %APPDATA%\ValueApps\IE\ValueApps.exe File name: ValueApps.exe
    Size: 420.86 KB (420864 bytes)
    MD5: 1450f61df8572cd1c6641e6c1cd081d5
    Detection count: 37
    File type: Executable File
    Mime Type: unknown/exe
    Path: %APPDATA%\ValueApps\IE
    Group: Malware file
    Last Updated: March 31, 2020
    %APPDATA%\ValueApps\IE\MonPrx.dll File name: MonPrx.dll
    Size: 168.22 KB (168224 bytes)
    MD5: e2956b592d4a7e50bdd3b749d57c138b
    Detection count: 16
    File type: Dynamic link library
    Mime Type: unknown/dll
    Path: %APPDATA%\ValueApps\IE
    Group: Malware file
    Last Updated: November 14, 2013
    %APPDATA%\ValueApps\IE\ValueApps.exe File name: ValueApps.exe
    Size: 1.22 MB (1229274 bytes)
    MD5: 11472354f7726d215e559dcca558767b
    Detection count: 15
    File type: Executable File
    Mime Type: unknown/exe
    Path: %APPDATA%\ValueApps\IE
    Group: Malware file
    Last Updated: March 30, 2016
    %LOCALAPPDATA%\Conduit\ValueApps\IE\ValueApps.exe File name: ValueApps.exe
    Size: 1.1 MB (1100064 bytes)
    MD5: 901cc59313284366c4ba290e976c7853
    Detection count: 10
    File type: Executable File
    Mime Type: unknown/exe
    Path: %LOCALAPPDATA%\Conduit\ValueApps\IE
    Group: Malware file
    Last Updated: March 30, 2016

    Registry Modifications

    The following newly produced Registry Values are:

    CLSID{4A36AF02-3E2F-47DD-A102-784D22E8C2B8}{68FD483F-A55D-4B78-AE10-48EF2BBE317E}{8050556E-4AD3-40BD-B338-7DBB0D5C10C8}{9011F634-B91C-400D-8CA2-E9E9A1FCC725}{939A0D04-0E07-48FE-A463-6623B70C3A96}{93DBF2BB-A2B3-4683-A92E-57E60751F346}{B71BC738-1C95-4784-B6AF-5B0964B895D9}{C9A54DFE-051F-49C5-9FC7-ECB81DC6C69F}{DD7858C7-889A-42E4-9863-E4AA3A0BFE65}{DEBFDDD0-96AA-400F-B77A-69003A94018B}{E171D5FB-6763-4100-87CD-5F918979FBEA}{F63AAEDC-3602-49EF-AA45-262380A98980}Regexp file mask%WINDIR%\System32\ValueApps.ini%WINDIR%\System32\ValueApps64.dll%WINDIR%\System32\ValueAppsOff.ini%WINDIR%\SysWoW64\ValueAppsOff.iniHKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\AppID\ValueApps.exeSOFTWARE\Classes\Wow6432Node\AppID\ValueApps.exeSoftware\Microsoft\Internet Explorer\Approved Extensions\{93DBF2BB-A2B3-4683-A92E-57E60751F346}Software\Microsoft\Internet Explorer\Approved Extensions\{F63AAEDC-3602-49EF-AA45-262380A98980}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{93DBF2BB-A2B3-4683-A92E-57E60751F346}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD7858C7-889A-42E4-9863-E4AA3A0BFE65}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F63AAEDC-3602-49EF-AA45-262380A98980}SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\ValueApps.exeSoftware\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{93DBF2BB-A2B3-4683-A92E-57E60751F346}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{F63AAEDC-3602-49EF-AA45-262380A98980}Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F63AAEDC-3602-49EF-AA45-262380A98980}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{93DBF2BB-A2B3-4683-A92E-57E60751F346}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F63AAEDC-3602-49EF-AA45-262380A98980}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{93DBF2BB-A2B3-4683-A92E-57E60751F346}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F63AAEDC-3602-49EF-AA45-262380A98980}SOFTWARE\ValueAppsSOFTWARE\Wow6432Node\Classes\AppID\ValueApps.exeSOFTWARE\Wow6432Node\mamverifier\toolbar\{94cd2cc3-083f-49ba-a218-4cda4b4829fd}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Approved Extensions\{F63AAEDC-3602-49EF-AA45-262380A98980}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{93DBF2BB-A2B3-4683-A92E-57E60751F346}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD7858C7-889A-42E4-9863-E4AA3A0BFE65}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F63AAEDC-3602-49EF-AA45-262380A98980}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\ValueApps.exeSoftware\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{93DBF2BB-A2B3-4683-A92E-57E60751F346}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{F63AAEDC-3602-49EF-AA45-262380A98980}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F63AAEDC-3602-49EF-AA45-262380A98980}SOFTWARE\Wow6432Node\ValueAppsHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}ValueApps

    Additional Information

    The following directories were created:
    %ALLUSERSPROFILE%\ValueApps%AppData%\ValueApps%Homedrive%\ValueApps%LOCALAPPDATA%\ValueApps%PROGRAMFILES%\ValueApps%PROGRAMFILES(x86)%\ValueApps%USERPROFILE%\Local Settings\Application Data\ValueApps
    The following URL's were detected:
    Value AppsValue apps
Loading...