Home Malware Programs Browser Hijackers GasGlance Toolbar

GasGlance Toolbar

Posted: October 12, 2015

Threat Metric

Threat Level: 2/10
Infected PCs: 403
First Seen: September 18, 2015
Last Seen: May 31, 2023
OS(es) Affected: Windows

GasGlance is a web toolbar that may cause you more issues than benefits. The name of the company that developed it is Mindspark Interactive Network. It is well-known to the cyber security industry because this firm is responsible for the creation of dozens of questionable applications. Just like the majority of them, GasGlance is adware that may overwhelm you with tons of unrequested ads. Many people wonder how this unreliable software found a way to enter their systems. Although its official site hosts it, the toolbar may arrive combined with other programs, whose license is typically free. The name of this approach is 'bundling.' It is an efficient tactic to spread questionable applications because unless you perform the installation process through the 'Advanced' menu, you may miss their presence. When the setup procedure is complete, you may notice GasGlance in all available web clients, including Google Chrome, Mozilla Firefox and Internet Explorer. The presence of the toolbar may be accompanied by quite a few other modifications. For example, you may notice another homepage and not the one that you have set. Mindspark may promote a manipulated version of the Ask search sites that may display links towards partner sites at the first few positions. The adware also generate may some additional commercial materials in the form of pop-ups, banners, interstitial ads and some videos that may launch without any interaction from the user. The nature of the displayed coupons, discounts and offers depends on your browsing history, so that they may attract your attention. However, you should be careful because some ads may lead to unsafe sites that may try to infect or lure you. You may be unable to delete GasGlance Toolbar in the normal way, so you should use credible security software.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files\gasglance_5i chrome extension\bar\GasGlanceCrxSetup.exe File name: C:\Program Files\gasglance_5i chrome extension\bar\GasGlanceCrxSetup.exe
MD5: b4b99f58685e084d7743c442dfce6a42
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\Program Files\GasGlance_5i Chrome Extension\bar\GasGlanceCrxSetup.exe /u File name: C:\Program Files\GasGlance_5i Chrome Extension\bar\GasGlanceCrxSetup.exe /u
Mime Type: unknown/exe /u
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

CLSID{076CAE79-591D-43FE-8EBE-BF0FB06275D9}{08D2138B-9D07-4E6C-A830-5F93DB16A0DD}{110116B5-F96B-4425-AAC9-17D4383E9C01}{17486831-58FD-47E4-9EAA-6926607C28E8}{297A4FA7-D27C-46BD-9694-5C48EEFE3025}{2a6d0334-deb2-41e2-9350-7181d8be4bf6}{30715044-A520-4C04-B9C3-5F0E6BAE13AC}{32f40a88-c3fe-4ffb-9ca6-ec6d5e80b8d9}{466f98aa-a8e0-41a0-9adb-bab6baadbe8d}{5806af45-491a-4080-b99e-d5045b11d21e}{5F26974F-6540-4F7E-B990-366799ACA573}{696B0A12-D0FE-4E9F-A1D3-5CFF2673E18F}{6D8C381A-4F27-4B85-8234-AE66EBF6AE38}{7e3508fd-6cf1-4457-977c-1586988d07b6}{801120a5-289d-4a31-9d09-3f1794681e02}{8D1EAB03-168A-4D05-A94F-A482B64CF3EF}{8D9D31F5-4002-437C-9061-F3F68177F87A}{8DD16469-F9CC-43AB-9775-8E3C9628BF99}{8FF6F59C-DB89-47AD-9AC2-41A44A587F4D}{9641d095-2c78-400e-bbb0-c20f3108358b}{9E50499E-AB9F-4B6A-9798-0C227AA26146}{A217A7FD-0542-45CC-B79B-58F7A74F6395}{a8116b30-b7fa-4092-ae25-e2d4d67e86e0}{AB2BFE44-B528-416E-A56F-EE9BBAA114A4}{AC590C4E-1B4A-4BDE-8B16-E7CB3742A935}{AD8C98AD-F931-41EA-8743-7C836FD020A9}{AE963A3D-6E65-43BE-BA03-99E2764CAAC5}{c74187ab-1909-4264-93ea-947344d58d02}{C8590002-2AA8-4F3D-B02E-934DDF58A646}{C9FD2311-0AE3-48A7-9455-55D3A22173C1}{CD0C027C-86B7-48DD-AEAD-3FDC9680563C}{D3E46107-CAA2-42F8-98DD-09BCA6FB1685}{D40B60BE-A62F-43EE-975B-CBBA72749C2B}{E1B89558-BA2B-44B0-B7B5-FFB04C9BEAD8}{e2f5dea9-1205-4ea8-9c99-a977c6240b01}{EA6F7E40-B3BF-47E5-8060-7EEF924D8CB0}{EF137DFB-60CF-4B37-8C2E-A552A659CF39}{F307288C-9A8C-4272-B811-162EAB27B1A9}HKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\GasGlance_5iSOFTWARE\GasGlance_5iSoftware\Microsoft\Internet Explorer\Approved Extensions\{865FC489-56EB-41FA-BB25-027900188070}Software\Microsoft\Internet Explorer\Approved Extensions\{9641D095-2C78-400E-BBB0-C20F3108358B}Software\Microsoft\Internet Explorer\Approved Extensions\{E1BFC11E-A392-4575-9EE7-27A96EB0DB90}Software\Microsoft\Internet Explorer\SearchScopes\{29c5f355-0907-4719-9f15-30ff0459607f}SOFTWARE\Microsoft\Windows\CurrentVersion\Run\GasGlance EPM SupportSOFTWARE\Microsoft\Windows\CurrentVersion\Run\GasGlance Toolbar AppIntegrator 32-bitSOFTWARE\Microsoft\Windows\CurrentVersion\Run\GasGlance Toolbar AppIntegrator 64-bitSOFTWARE\Microsoft\Windows\CurrentVersion\Run\GasGlance Toolbar EPM SupportSOFTWARE\Wow6432Node\GasGlance_5iSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{29c5f355-0907-4719-9f15-30ff0459607f}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\GasGlance EPM SupportSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\GasGlance Toolbar AppIntegrator 32-bitSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\GasGlance Toolbar AppIntegrator 64-bitSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\GasGlance Toolbar EPM SupportSYSTEM\ControlSet001\services\GasGlance_5iServiceSYSTEM\ControlSet002\services\GasGlance_5iServiceSYSTEM\CurrentControlSet\services\GasGlance_5iServiceHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}GasGlance_5ibar Uninstall Internet Explorer

Additional Information

The following directories were created:
%LOCALAPPDATA%\GasGlance_5i%PROGRAMFILES%\GasGlance_5i%PROGRAMFILES(x86)%\GasGlance_5i%USERPROFILE%\AppData\LocalLow\GasGlance_5i
The following URL's were detected:
search.mywebsearch.com/mywebsearch/default.jhtml
Loading...