Home Malware Programs Potentially Unwanted Programs (PUPs) Gaming Assassin Toolbar

Gaming Assassin Toolbar

Posted: August 3, 2016

Threat Metric

Threat Level: 2/10
Infected PCs: 201
First Seen: May 5, 2015
Last Seen: May 2, 2022
OS(es) Affected: Windows

Mindspark Interactive Network is a software publisher whose name is often linked to dubious toolbars that may change a Web browser's behavior automatically. The Gaming Assassin Toolbar is one of the pieces of software developed and published by Mindspark Interactive Network, and it does same things that Mindspark's products are ill-famed for – modifying a Web browser's settings, injecting marketing content, and gathering Web browser usage statistics anonymously. However, the Gaming Assassin Toolbar's dubious behavior is never mentioned in the installation notes, and Mindspark Interactive Network promotes its product as a useful browser utility that allows users to discover and access hundreds of free-to-play online games quickly. The Gaming Assassin Toolbar does, in fact, lead users to reliable online gaming pages, but it also carries out background operations that aren't considered user-friendly.

When the Gaming Assassin Toolbar is first installed, it may change the configuration of affected Web browsers, so that they will have their homepage changed to hxxp://hp.myway.com/gamingassassin. This is a low-quality search engine which is affiliated to Mindspark Interactive Network and may be used to distribute marketing content, sponsored search results, and software download offers that may lead users to potentially unsafe Web destinations. The changes that the Gaming Assassin Toolbar brings can't be reverted without removing the toolbar first, and many users might be stuck with using hxxp://hp.myway.com/gamingassassin unless they remove the toolbar first.

The removal of the Gaming Assassin Toolbar is strongly recommended because this utility may not bring any necessary or useful features. Instead, it focuses on promoting dubious Web pages and advertising content that may cause performance issues or expose users to unsafe Web content.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files\GamingAssassin_4s\bar\1.bin\4sBar.dll File name: C:\Program Files\GamingAssassin_4s\bar\1.bin\4sBar.dll
MD5: f86336c978311761bc3e2a80b08d46bc
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
"C:\Program Files\GamingAssassin_4s\bar\1.bin\4sBar.dll",O mindsparktoolbarkey="GamingAssassin_4s" uninstalltype="FF" File name: "C:\Program Files\GamingAssassin_4s\bar\1.bin\4sBar.dll",O mindsparktoolbarkey="GamingAssassin_4s" uninstalltype="FF"
Mime Type: unknown/dll",O mindsparktoolbarkey="GamingAssassin_4s" uninstalltype="FF"
Group: Malware file
4shkstub.dll File name: 4shkstub.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
4sreghk.dll File name: 4sreghk.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
4sSrcAs.dll File name: 4sSrcAs.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
4sSrchMn.exe File name: 4sSrchMn.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
NP4sStub.dll File name: NP4sStub.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
T8HTML.DLL File name: T8HTML.DLL
File type: Dynamic link library
Mime Type: unknown/DLL
Group: Malware file
4sPlugin.dll File name: 4sPlugin.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
4sbprtct.dll File name: 4sbprtct.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
4sdlghk.dll File name: 4sdlghk.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
T8TICKER.DLL File name: T8TICKER.DLL
File type: Dynamic link library
Mime Type: unknown/DLL
Group: Malware file
4ssknlcr.dll File name: 4ssknlcr.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
4simpipe.exe File name: 4simpipe.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
4stpinst.dll File name: 4stpinst.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
T8EXTEX.DLL File name: T8EXTEX.DLL
File type: Dynamic link library
Mime Type: unknown/DLL
Group: Malware file
T8EXTPEX.DLL File name: T8EXTPEX.DLL
File type: Dynamic link library
Mime Type: unknown/DLL
Group: Malware file
T8RES.DLL File name: T8RES.DLL
File type: Dynamic link library
Mime Type: unknown/DLL
Group: Malware file
4shtmlmu.dll File name: 4shtmlmu.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
AppIntegrator64.exe File name: AppIntegrator64.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
AppIntegratorStub64.dll File name: AppIntegratorStub64.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
BOOTSTRAP.JS File name: BOOTSTRAP.JS
File type: JavaScript file
Mime Type: unknown/JS
Group: Malware file
CREXT.DLL File name: CREXT.DLL
File type: Dynamic link library
Mime Type: unknown/DLL
Group: Malware file
CrExtP4s.exe File name: CrExtP4s.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
DPNMNGR.DLL File name: DPNMNGR.DLL
File type: Dynamic link library
Mime Type: unknown/DLL
Group: Malware file
EXEMANAGER.DLL File name: EXEMANAGER.DLL
File type: Dynamic link library
Mime Type: unknown/DLL
Group: Malware file
Hpg64.dll File name: Hpg64.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
INSTALL.RDF File name: INSTALL.RDF
Mime Type: unknown/RDF
Group: Malware file
installKeys.js File name: installKeys.js
File type: JavaScript file
Mime Type: unknown/js
Group: Malware file
VERIFY.DLL File name: VERIFY.DLL
File type: Dynamic link library
Mime Type: unknown/DLL
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Gaming Assassin Search Scope MonitorSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Gaming Assassin Search Scope Monitor

Additional Information

The following URL's were detected:
support.mindspark.com
Loading...