Home Malware Programs Potentially Unwanted Programs (PUPs) Elite Unzip Toolbar

Elite Unzip Toolbar

Posted: August 11, 2015

Threat Metric

Ranking: 777
Threat Level: 1/10
Infected PCs: 89,827
First Seen: November 17, 2014
Last Seen: October 17, 2023
OS(es) Affected: Windows

Elite Unzip Toolbar is an add-on that is considered to be a potentially unwanted program (PUP) by computer security experts. Elite Unzip Toolbar is a web browser component that may be added to your browser application by downloading directly from a specific website. Much like other well-known toolbar add-ons, Elite Unzip Toolbar is developed and offered by Mindspark Interactive Network, Inc. Through the use of the myway.com search site aggregator, Elite Unzip Toolbar offers quick methods to search the Internet through its toolbar search feature. However, while MyWay.com may prove to be useful in certain situations, some users may not be happy with the fact that MyWay.com replaced their favorite new tab page. If this seems like an issue to you and you wish to remove the Elite Unzip Toolbar, then you may do this by uninstalling the 'Elite Unzip Toolbar' browser extension.

Aliases

ApplicUnwnt [Comodo]PUP/Win32.Mindspark [AhnLab-V3]GrayWare[WebToolbar:not-a-virus]/Win32.MyWebSearch [Antiy-AVL]Adware.MyWebSearch.85 [DrWeb]not-a-virus:WebToolbar.Win32.MyWebSearch.sw [Kaspersky]Trojan ( 000052ba1 ) [K7AntiVirus]PUA.MSJDGBTIR.OD5 [CAT-QuickHeal]Riskware/MyWebSearch [Fortinet]PUP/Win32.MyWebSearch [AhnLab-V3]RiskWare[WebToolbar:not-a-virus]/Win32.MyWebSearch [Antiy-AVL]not-a-virus:WebToolbar.Win32.MyWebSearch.si [Kaspersky]MyWebSearch [AVG]Win32.Adware.Mindspark.C [GData]Win32:Mindspark-A [PUP] [Avast]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files\EliteUnzip\EliteUnzip.exe File name: C:\Program Files\EliteUnzip\EliteUnzip.exe
MD5: 1981980e56ce5cacb6433b9a164f9d15
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
lua5.1.dll File name: lua5.1.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
LogicNP.ShComboBox.WPF.dll File name: LogicNP.ShComboBox.WPF.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
LogicNP.FolderView.WPF.dll File name: LogicNP.FolderView.WPF.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
LogicNP.FileView.WPF.dll File name: LogicNP.FileView.WPF.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
7z64.dll File name: 7z64.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
7z.dll File name: 7z.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
SevenZipSharp.dll File name: SevenZipSharp.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
UnifiedLogging.dll File name: UnifiedLogging.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
IAC.Helpers.dll File name: IAC.Helpers.dll
Mime Type: unknown/dll
Group: Malware file
IAC.UnifiedLogging.dll File name: IAC.UnifiedLogging.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
DesktopSdk.dll File name: DesktopSdk.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
RebootRequired.exe File name: RebootRequired.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

CLSID{09498152-17e5-4100-9116-bc386231a44c}{1A3F8C09-E6F9-41F6-91CE-9F16530F144B}{1af33c13-6c63-488c-9dea-17b0e7829de5}{233E4207-02F7-49F3-8EB1-2A9669EA69D4}{277BA79D-741F-4190-B573-BB963235A17F}{2facf966-7eba-4300-a012-7ed28c52c428}{30EEAA8C-6918-4975-93C1-63949A16C77D}{382929c8-bba2-4938-b5b6-8002016aee0f}{38FD445C-C802-4BED-9AC5-9EBC436D6620}{3b4b7e67-b97e-4ac2-b67f-67f45a620e64}{3D9B1790-63DA-464A-AB42-855398023504}{439D8B19-B2CA-429D-93C3-08100A304387}{473B0471-4A6B-4ED6-85EC-192FFDA754A1}{481BC3A1-ECB6-48A9-BB89-54592815F42F}{4A82DADB-0D80-4E18-8A8F-69793B7E0CD4}{4CC00B40-C831-4DE8-9D23-23F854A6393E}{591D8476-DE4F-4804-8D2B-4501A45C9E85}{5BEB51A1-9E60-4ECD-8621-54184927BD48}{5C3EDE4B-782F-4431-8F09-22819A15742D}{5F3CADB7-0472-4198-890B-B159DCF600F5}{77177E2C-52FE-456A-8DA0-88A042B38CAA}{7EA7C8BD-DC70-42BE-8A0D-D9BAA8BBF342}{8358a5f6-e352-4677-8386-9704aa8ad899}{8538002b-d91f-4242-9fea-b397ab3ee6f9}{8704213b-8013-4f69-8e19-9ef25610128d}{8B7F149C-7573-4793-BE30-B03F3E591508}{8BA04565-22EE-4F92-935C-28F8BCF8F09A}{90fa0e29-aa8f-42f6-83ec-fddf0df144ff}{95969FA6-C35A-4552-A1FE-34C45FE13799}{96d6a54a-32fe-496f-87ab-7e08a39ff1bc}{97CE1707-67E1-4758-A14C-04CE2205D975}{99054213-9DDB-4D98-A83D-BFB698659179}{a62ea21a-a6a0-4de1-8a93-adfc39c1e442}{AB884D81-E21B-4E8B-B883-3E74DAE6381E}{B95EB44F-5177-4A6E-AF98-300C2FBB27B0}{BAD67FD3-E2C8-4ED9-B280-F1606E542937}{bbf72817-58fe-4372-a430-47a74ed49764}{bd4622da-5525-4235-8f9e-5a60cc276b83}{BDA8D29D-FC82-4D3B-889E-AD5228FFABEF}{C649D7F3-4451-4406-8445-E8AE56E0D109}{C7C95C40-05B2-45BA-8582-36B37CA592B0}{c8372612-302d-4dee-9188-51f104040765}{CD47593D-1F30-4B75-9E86-85B90D499B83}{D1EF1547-79A0-43AB-8704-5D7426F79877}{d68ae9dc-6103-4867-a205-a3a9e738fe86}{D9FE87DE-92E6-41FF-8DEE-8B6E99D8F86A}{da5d70b2-0a92-4b43-b068-a0dd02898c56}{DB6274DB-8FA7-4CD4-BC7F-35925689576C}{EEF2CA16-902A-46D0-9CCC-9F010C61D3F0}{ef55cb9f-2729-4bff-afe5-ee59593b16e8}{F229256B-4818-4FD0-9720-BC49C216EEB0}{F31A8B54-DC1B-4334-8585-9F8A269F5622}{F469D53A-5818-47E1-90E5-0F262BB59258}{FBFBD788-FAD3-437E-AAAB-3141D3F72001}{FF1BA25F-C7BB-4282-8887-4D9E040A08FC}File name without pathElite Unzip.lnkhttp_EliteUnzip.dl.tb.ask.com_0.localstoragehttp_EliteUnzip.dl.tb.ask.com_0.localstorage-journalRegexp file mask%PROGRAMFILES(x86)%\aaUninstall Elite Unzip.dllHKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\EliteUnzip_aaSoftware\EliteUnzip_aaSOFTWARE\Microsoft\Internet Explorer\Toolbar\{ef55cb9f-2729-4bff-afe5-ee59593b16e8}SOFTWARE\Microsoft\Windows\CurrentVersion\Run\EliteUnzip AppIntegrator 32-bitSOFTWARE\Microsoft\Windows\CurrentVersion\Run\EliteUnzip AppIntegrator 64-bitSOFTWARE\Microsoft\Windows\CurrentVersion\Run\EliteUnzip EPM SupportSOFTWARE\Microsoft\Windows\CurrentVersion\Run\EliteUnzip Search Scope MonitorSOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\EliteUnzip_aabar UninstallSOFTWARE\Mindspark\EliteUnzipSOFTWARE\Wow6432Node\EliteUnzip_aaSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{ef55cb9f-2729-4bff-afe5-ee59593b16e8}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\EliteUnzip AppIntegrator 32-bitSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\EliteUnzip AppIntegrator 64-bitSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\EliteUnzip EPM SupportSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\EliteUnzip Search Scope MonitorSOFTWARE\Wow6432Node\Mindspark\EliteUnzipSYSTEM\ControlSet001\services\EliteUnzip_aaServiceSYSTEM\ControlSet002\services\EliteUnzip_aaServiceSYSTEM\CurrentControlSet\services\EliteUnzip_aaService

Additional Information

The following directories were created:
%LOCALAPPDATA%\EliteUnzip_aa%PROGRAMFILES%\EliteUnzip_aaEI%PROGRAMFILES(x86)%\EliteUnzip_aaEI%USERPROFILE%\AppData\LocalLow\EliteUnzip_aa%USERPROFILE%\Application Data\EliteUnzip_aa
The following URL's were detected:
www.mindspark.com
Loading...