Home Malware Programs Adware ToggleMark

ToggleMark

Posted: March 26, 2014

Threat Metric

Ranking: 17,033
Threat Level: 2/10
Infected PCs: 3,429
First Seen: March 26, 2014
Last Seen: July 22, 2023
OS(es) Affected: Windows


ToggleMark is an unwanted browser plug-in developed by SuperWeb LLC that may claim to enhance the computer user's Internet surfing experience by displaying related content including websites, allowing discount coupons, comparison shopping, and other similar functionalities. ToggleMark is considered to be adware. ToggleMark may use misleading marketing methods to distribute itself to computers. ToggleMark may spread and install itself on the PC bundled with other free applications that computer users can download from questionable download websites. ToggleMark may install itself on the computer as an additional program to free software that the computer user is downloading. Once installed, ToggleMark may generate and show numerous types of advertisements such as text link, interstitial, transitional, search, banner, and full page ads with the purpose to possibly generate advertising revenue.

Aliases

AdWare.SpadeCast [Ikarus]Trojan.BPlug.123 [DrWeb]

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{5B79DF26-5A4A-4A88-BFF4-FE188A4F223E}{C3715F93-4241-49F6-BA85-1D8151B277AF}{dc59a866-959c-4638-a191-c13177d0bd68}HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{dc59a866-959c-4638-a191-c13177d0bd68}SOFTWARE\Microsoft\Tracing\ToggleMark_RASAPI32SOFTWARE\Microsoft\Tracing\ToggleMark_RASMANCSSOFTWARE\Microsoft\Tracing\updateToggleMark_RASAPI32SOFTWARE\Microsoft\Tracing\updateToggleMark_RASMANCSSOFTWARE\Microsoft\Tracing\utilToggleMark_RASAPI32SOFTWARE\Microsoft\Tracing\utilToggleMark_RASMANCSSoftware\Microsoft\Windows\CurrentVersion\Ext\Settings\{dc59a866-959c-4638-a191-c13177d0bd68}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{dc59a866-959c-4638-a191-c13177d0bd68}Software\ToggleMarkSOFTWARE\Wow6432Node\Microsoft\Tracing\ToggleMark_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\ToggleMark_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\updateToggleMark_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateToggleMark_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\utilToggleMark_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\utilToggleMark_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{dc59a866-959c-4638-a191-c13177d0bd68}SOFTWARE\Wow6432Node\ToggleMarkSYSTEM\ControlSet001\services\eventlog\Application\Update ToggleMarkSYSTEM\ControlSet001\services\eventlog\Application\Util ToggleMarkSYSTEM\ControlSet001\services\Update ToggleMarkSYSTEM\ControlSet001\services\Util ToggleMarkSYSTEM\CurrentControlSet\services\eventlog\Application\Update ToggleMarkSYSTEM\CurrentControlSet\services\eventlog\Application\Util ToggleMarkSYSTEM\CurrentControlSet\services\Update ToggleMarkSYSTEM\CurrentControlSet\services\Util ToggleMarkHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}ToggleMark

Additional Information

The following directories were created:
%PROGRAMFILES%\ToggleMark%PROGRAMFILES(x86)%\ToggleMark
Loading...