Home Malware Programs Potentially Unwanted Programs (PUPs) HowToSuite Toolbar

HowToSuite Toolbar

Posted: November 30, 2015

Threat Metric

Ranking: 1,807
Threat Level: 2/10
Infected PCs: 93,166
First Seen: November 13, 2015
Last Seen: October 17, 2023
OS(es) Affected: Windows

HowToSuite is a questionable toolbar that targets mature PC users. This application promises the clients access to over hundreds of educational videos, life hacks, recipes and ways to improve their homes. While 'do-it-yourself' guides may be helpful, you should not rely on HowToSuite to access these sites. The HowToSuite Toolbar is a Potentially Unwanted Program (PUP) that may overwhelm browsers with new advertising elements. The developer of this questionable application is well-known to cyber security experts. The company that stands behind HowToSuite is called Mindspark Interactive Network. It has created and keeps releasing dozens of suspicious Web toolbars that often leave the clients dissatisfied.

Although it may be difficult to find, the HowToSuite Toolbar has an official product page. The Chrome Web Store also offers it, but the PUP may get access to the PC in software bundles. This delivery tactic may be problematic because the checkbox of the suspicious application is marked in advance. Unless the user unchecks it manually, the toolbar will enter together with the main program. If it does, you may notice it in Google Chrome, Mozilla Firefox and Internet Explorer immediately. You should know that all Mindspark products promote Ask-based search engines, which you may notice as your homepage. They may not be reliable because the results that you will face may be sponsored links to its partners. The ads that the PUP generates may come in different types, but most noticeable and troublesome are usually the pop-ups, banners, interstitial ads and videos. The fact that they come in large quantities may lead to speed drops of the browsers. If you wish to remove HowToSuite toolbar from your Web clients, you should use a special anti-malware solution.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

File name without pathhowtosuite.dl.myway[1].xmlhowtosuite.dl.tb.ask[1].xmlhttp_free.howtosuite.com_0.localstorage-journalhttp_howtosuite.dl.myway.com_0.localstoragehttp_howtosuite.dl.myway.com_0.localstorage-journalhttp_howtosuite.dl.tb.ask.com_0.localstoragehttp_howtosuite.dl.tb.ask.com_0.localstorage-journalHKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\HowToSuite_fwSOFTWARE\HowToSuiteSoftware\HowToSuite_fwSoftware\Microsoft\Internet Explorer\Approved Extensions\{24C3E2A5-54B3-4901-8C87-D178E6B756C1}Software\Microsoft\Internet Explorer\Approved Extensions\{2F06E199-4985-4AAA-8639-78404D5DA516}Software\Microsoft\Internet Explorer\Approved Extensions\{5465B327-DC50-4026-8EEB-DCCB70290B62}SOFTWARE\Microsoft\Internet Explorer\DOMStorage\howtosuite.dl.myway.comSOFTWARE\Microsoft\Tracing\HowToSuite_RASAPI32SOFTWARE\Microsoft\Tracing\HowToSuite_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\Run\HowToSuiteSOFTWARE\Microsoft\Windows\CurrentVersion\Run\HowToSuite AppIntegrator 32-bitSOFTWARE\Microsoft\Windows\CurrentVersion\Run\HowToSuite AppIntegrator 64-bitSOFTWARE\Microsoft\Windows\CurrentVersion\Run\HowToSuite EPM SupportSOFTWARE\Microsoft\Windows\CurrentVersion\Run\HowToSuite Search Scope MonitorSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\HowToSuiteSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\HowToSuite AppIntegrator 32-bitSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\HowToSuite AppIntegrator 64-bitSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\HowToSuite EPM SupportSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\HowToSuite Search Scope MonitorHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}HowToSuiteTooltab Uninstall Internet Explorer

Additional Information

The following directories were created:
%LOCALAPPDATA%\HowToSuiteTooltab%LOCALAPPDATA%\HowToSuite_fw%PROGRAMFILES%\HowToSuite_fw%PROGRAMFILES(x86)%\HowToSuite_fw%USERPROFILE%\AppData\LocalLow\HowToSuite_fw
Loading...