Home Malware Programs Potentially Unwanted Programs (PUPs) SafePCRepair Toolbar

SafePCRepair Toolbar

Posted: October 8, 2013

Threat Metric

Ranking: 1,825
Threat Level: 1/10
Infected PCs: 32,717
First Seen: October 8, 2013
Last Seen: October 17, 2023
OS(es) Affected: Windows

SafePCRepair Toolbar is a potentially unwanted program (PUP) that may be installed on web browser applications to display a toolbar that offers several function buttons or quick access buttons for PC fix functions. Use of the buttons on the SafePCRepair Toolbar may initialize the SafePCRepair application to offer system features for freeing up memory or repair the system registry. SafePCRepair Toolbar may also provide a method of searching the Internet using other Internet search engines. SafePCRepair tool is created and marketed by Mindspark Interactive Network and can be obtained on sites affiliated with Mindspark Interactive Network.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{0ABE162E-A121-4F56-A7DF-A94C95300943}{0BC5607D-DC04-410A-B137-73F2EE733596}{0c7d2cd6-27fb-46c4-8311-de0905048f1a}{10019e3c-1039-4c6a-8231-0c657afc4bc4}{154690A0-7778-41B5-A3AB-EB51E2482B74}{1fc509df-4b29-4ab3-96e6-47c178d60287}{2438F6B7-0532-4C8C-9C5C-B34935DD3D70}{2accb327-7218-4979-8eb7-0e653bc0ea66}{2E685A5C-6D12-4C22-AA7B-32E7467FD7A0}{2f8ae8d5-8f22-40e8-9c9d-b14f5fa9fbcf}{34930B93-003D-4FF8-BF64-6A6F27547B0E}{356E8E19-4DEB-4F01-8DB4-1A0C99129CE7}{35C03DE9-8BA0-4B87-B3D1-51944C349FF1}{394E9A2F-F433-43F1-9A2E-EAC2C6BB8D80}{3C6E6F5A-8105-423A-AD2C-892FDAC11F49}{41A55DD5-AF6C-482F-9FED-0F3326D71800}{43223489-51e1-4e5c-bbc4-3645dce39afe}{457C8D0E-3805-4860-B2CF-DC1CD664AD6B}{499616EC-7C3D-499E-95ED-5D37D7FC7A3F}{50066dbf-71b9-4489-b62e-4188d3048db2}{535062C7-0E84-4CD0-BEB2-59F41DD1A8F5}{565ABC73-E8CB-4261-8FDE-C281445CA53D}{5806dc83-95c8-4120-a305-cbce6260adf1}{590CFF64-4C98-4B32-887C-4F6BC8C89899}{59B4F810-41AC-40F0-9FF1-703EAD14C290}{5AB21B6C-9EAA-465D-9C21-A1F75981773C}{5d13bf91-ea09-4ed8-9acd-c6bad32617b9}{5ed1334e-4e55-40cd-accb-05ce52ad981d}{63498647-B3EF-4A8A-8C98-163ECF8048FE}{6C227856-D369-4B3F-A317-89E4B1CD1A83}{6E2A759A-C5FC-45BA-92B8-85A6131B1324}{76816fb7-2009-45ec-a3d7-0d45c67d5bd7}{79223c67-251e-4447-94fe-762be858d73e}{7D6E502F-02F7-46E9-AA46-D3364038B6F7}{7E84E65B-E911-4DC3-B316-E2E854343D1B}{816098C9-EC16-4106-9FF7-E19580B2C338}{88A26450-768B-4C55-BDCA-D5830E5856DD}{898E0428-E588-4945-8438-1CC2920D99F1}{8fe9cdec-ac53-463d-8ab0-9751e6f79c96}{943BEEA6-4A9B-4BBD-A3A4-9EE530425941}{95CD0B4B-5782-435E-993D-BA07B30710A6}{99e2e307-a956-4d7d-b1c2-b7448af6b33f}{9E0E974B-5E9C-4850-89AB-F7B9F189CCAD}{9e256edc-b241-4c5b-b949-c347f3b614fd}{9E6E74B8-655A-4E4E-B5E0-6930412A7D55}{A0222970-4A74-4E1D-B0B7-F83D42AEB676}{A42FD199-B78F-452F-B31F-5755D6105704}{A5935A23-63D1-4216-B6B3-7B392880EB21}{a8d7fcf9-a855-449b-aa9f-230ba62c4b4e}{A983B26D-76CB-41C6-947E-4EEFF0906747}{a9d9ea68-5d09-43ef-a0c5-6f6a6f82a0e1}{B24F3E66-6E22-456F-85F0-43BEF5784F6C}{B2A921D8-E831-468F-BBC6-16416342C0A7}{B4BCF535-178F-43C9-98B3-1C5447AAF153}{b5d376a7-0327-4265-bbcd-b8e3326e39c7}{b6de1d4c-f21b-4056-a99c-1727fd6400ce}{B98BE44D-266A-45FE-814D-DB708279E238}{BD821925-6AEE-4FFF-A8E8-7AB1F50B0F4F}{be823b8c-a7ec-4078-a321-0f8046cbb48a}{C78CCE0D-F991-44F4-B450-33C4FD189E38}{C889A354-08D6-46F5-8C68-C6481023D6DE}{CCB31621-E2C6-43E7-B5D8-2B161973D5C3}{E07714D8-5006-492B-A2B1-B433949D6B1D}{E07DD2E8-0B35-4F00-B311-1F079B94A1B4}{e81003f0-8f21-4a23-8142-403d821198ac}{F7B9F27C-2E1A-429C-972A-DA83F1165B74}{fe617740-9986-4a5b-a4a8-a66d64ce5e7d}{fe97fe9a-ef03-47e0-9df9-8ebb728c5d93}File name without pathhttp_safepcrepair.dl.myway.com_0.localstoragehttp_safepcrepair.dl.myway.com_0.localstorage-journalhttp_safepcrepair.dl.tb.ask.com_0.localstoragehttp_safepcrepair.dl.tb.ask.com_0.localstorage-journalsafepcrepair.dl.tb.ask[1].xmlHKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\Mindspark\SafePCRepairSoftware\AppDataLow\Software\SafePCRepair_89Software\Microsoft\Internet Explorer\Approved Extensions\{1FC509DF-4B29-4AB3-96E6-47C178D60287}Software\Microsoft\Internet Explorer\Approved Extensions\{5D13BF91-EA09-4ED8-9ACD-C6BAD32617B9}Software\Microsoft\Internet Explorer\Approved Extensions\{A9D9EA68-5D09-43EF-A0C5-6F6A6F82A0E1}Software\Microsoft\Internet Explorer\DOMStorage\safepcrepair.dl.tb.ask.comSOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0ddeae50-1858-4f3a-8fa9-4774f02eef86}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2438f6b7-0532-4c8c-9c5c-b34935dd3d70}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5ed1334e-4e55-40cd-accb-05ce52ad981d}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9e0e974b-5e9c-4850-89ab-f7b9f189ccad}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a983b26d-76cb-41c6-947e-4eeff0906747}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{c34c0e9f-c070-4b05-b912-563c3cff8555}SOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\safepcrepair.dl.myway.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\safepcrepair.dl.tb.ask.comSoftware\Microsoft\Internet Explorer\SearchScopes\{8684a7c7-3ade-4208-ad43-ad57a1af352c}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{a9d9ea68-5d09-43ef-a0c5-6f6a6f82a0e1}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{1fc509df-4b29-4ab3-96e6-47c178d60287}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{5d13bf91-ea09-4ed8-9acd-c6bad32617b9}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{50066dbf-71b9-4489-b62e-4188d3048db2}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5806dc83-95c8-4120-a305-cbce6260adf1}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{816098C9-EC16-4106-9FF7-E19580B2C338}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8fe9cdec-ac53-463d-8ab0-9751e6f79c96}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9e256edc-b241-4c5b-b949-c347f3b614fd}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e81003f0-8f21-4a23-8142-403d821198ac}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{fe97fe9a-ef03-47e0-9df9-8ebb728c5d93}SOFTWARE\MozillaPlugins\@SafePCRepair_89.com/PluginSOFTWARE\SafePCRepairSoftware\SafePCRepair_89SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0ddeae50-1858-4f3a-8fa9-4774f02eef86}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2438f6b7-0532-4c8c-9c5c-b34935dd3d70}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5ed1334e-4e55-40cd-accb-05ce52ad981d}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9e0e974b-5e9c-4850-89ab-f7b9f189ccad}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a983b26d-76cb-41c6-947e-4eeff0906747}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{c34c0e9f-c070-4b05-b912-563c3cff8555}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{8684a7c7-3ade-4208-ad43-ad57a1af352c}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{a9d9ea68-5d09-43ef-a0c5-6f6a6f82a0e1}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{1fc509df-4b29-4ab3-96e6-47c178d60287}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{5d13bf91-ea09-4ed8-9acd-c6bad32617b9}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{50066dbf-71b9-4489-b62e-4188d3048db2}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5806dc83-95c8-4120-a305-cbce6260adf1}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{816098C9-EC16-4106-9FF7-E19580B2C338}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8fe9cdec-ac53-463d-8ab0-9751e6f79c96}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9e256edc-b241-4c5b-b949-c347f3b614fd}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e81003f0-8f21-4a23-8142-403d821198ac}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{fe97fe9a-ef03-47e0-9df9-8ebb728c5d93}SOFTWARE\Wow6432Node\MozillaPlugins\@SafePCRepair_89.com/PluginSOFTWARE\Wow6432Node\SafePCRepair_89SYSTEM\ControlSet002\services\SafePCRepair_89ServiceSYSTEM\CurrentControlSet\services\SafePCRepair_89ServiceHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Mindspark SafePCRepairSafePCRepair_89bar Uninstall FirefoxSafePCRepair_89bar Uninstall Internet ExplorerSafePCRepairTooltab Uninstall Internet Explorer

Additional Information

The following directories were created:
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\mdfnjodbchpafccamndakjmgnfidihla%LOCALAPPDATA%\SafePCRepairTooltab%LOCALAPPDATA%\SafePCRepair_89%PROGRAMFILES%\SafePCRepair%PROGRAMFILES%\SafePCRepair_89%PROGRAMFILES(x86)%\SafePCRepair%PROGRAMFILES(x86)%\SafePCRepair_89%USERPROFILE%\AppData\LocalLow\SafePCRepair_89%USERPROFILE%\Application Data\SafePCRepair_89
The following URL's were detected:
SafePCRepair_89
Loading...