Home Malware Programs Potentially Unwanted Programs (PUPs) Translation Buddy Toolbar

Translation Buddy Toolbar

Posted: January 15, 2016

Threat Metric

Ranking: 2,651
Threat Level: 2/10
Infected PCs: 73,092
First Seen: October 22, 2014
Last Seen: October 17, 2023
OS(es) Affected: Windows

TranslationBuddy is a Web toolbar made by Mindspark Interactive Network that is compatible with Google Chrome, Mozilla Firefox and Internet Explorer. Initially, this tiny application may seem handy, but you should not install TranslationBuddy because it is a Potentially Unwanted Program (PUP). This toolbar claims that it can translate to and from 50 different languages, including Russian, German, French, Spanish, Chinese, Italian, etc. Allegedly, this way, you will be able to read sites that would otherwise remain foreign to you. While this feature may work, there are compelling reasons to keep the PUP away. First, the popular browsers already have a module that allows you to translate websites into your native language. Second, TranslationBuddy has adware capabilities, so it may inject different commercial materials in the pages that you open. This behavior is typical for the Mindspark products, which is the reason this company doesn't have a good reputation. The marketing elements that you may encounter after the installation of the toolbar may come in various shapes. You may detect pop-ups, banners, interstitial ads, transitional ads, in-text ads, etc. Some of the most resource-consuming ads are videos and eye-catching gifs that may launch right after your browser loads the page. These new commercial materials may trouble the performance of the Web clients. The common issues that may disturb some PC users are occasional freezes and crashes, or an overall sluggish functionality. Some of the ads may be corrupt, which means that they may transfer you to unsafe platforms. If you cannot recall downloading TranslationBuddy intentionally, then it probably found a way into your system as an addition towards third-party freeware. Once TranslationBuddy creates an extension in your browsers, the removal process may require a credible anti-malware application.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{03fc47fc-a1f4-4f98-a956-ce57200a2ebc}{102DDF44-88F8-4EDC-B430-F687A80B56AC}{109c517b-9f73-4f90-9adc-b9cb52f89872}{1456ac9b-13e8-4355-bf47-6847832f68e0}{151e0e34-9665-43b7-8584-4d482bf3ca59}{19E0B507-A625-4319-B5B8-134EA78D4B24}{24568B44-2A80-4ECD-9A22-5F8DFD68E326}{2867A954-147A-4C0B-8D81-63549C79CED3}{28D55821-5D33-46B2-951E-1AB5D55B3FA9}{3103924D-4372-4F67-96A7-D6D655AC29ED}{412EC2B3-6321-4D4A-8B83-CC8F97F7EF11}{4A158A0A-9482-468E-8A6C-38FC0E65BF76}{53ED0F4C-293D-4B11-BF43-E189371DE2E1}{549A6E42-4522-43BC-8B6C-37F4D3BB0253}{585353e6-45f5-4dcf-b9f2-4d080794cb3c}{5931AB5D-4895-4A39-A917-ED6A81B0CA23}{5D10C8B7-73A4-4EDB-AC24-78904B7FE6D4}{61EC7A07-0BF6-4E5A-8724-E73CFF86D1F6}{675EB9F5-F281-4622-90DA-BA9760EAAF8D}{687E6A9A-5B2F-4821-9EF5-0B71FB644DB3}{72e9afe7-100b-43ff-b102-c01a6e268b7e}{7C809DE4-E73D-4509-85D6-2E0239C831B3}{8086777A-916B-4707-8742-65687E0D129C}{8be84445-bc1a-47d9-a9f7-f3daab615a89}{8d28b450-b378-448a-a02f-c893bc7ed416}{8D80F670-F6D7-4CA0-8F2B-921150100E77}{9345d411-009f-4cf8-8a9d-48b989f305c0}{9567301B-01D7-4511-B87A-F2176B23A21B}{95F21E41-293F-445A-8423-B686A30AC05C}{9891d91c-5172-4c8a-8669-2066ca997c43}{A007B01E-2A70-4D1E-8DA9-49B9E858319D}{a3c5f699-f046-47e7-8011-06269bc6ed24}{A6F78A25-0959-4A45-B241-6DD54043BE67}{a90a3936-db11-4102-9371-79a73f8a9bed}{A9E3975F-5C0C-4D62-BD57-63CB63D1418E}{B0EDD3AC-F223-4A67-9668-FB626E33928E}{B55A4B1D-068E-4865-A594-9079CE939DD6}{b5d21176-3524-4619-ab58-34cd2bec03aa}{B943A324-8057-4214-95C2-A21B790C6935}{BC68EEE4-C39E-40F3-AE33-F9CBB135980E}{C1CEC7A7-A738-4603-82E8-29E3403D4877}{C6942CC5-A278-47E9-BF3E-14328C64A233}{ca18db8d-17b0-4f8b-8afb-2583d982f1d1}{CA390083-368F-4A80-92D7-C67D709A5877}{CC8EE593-3803-4FB1-8439-2AF3FD3BE0DB}{d9ae0ed3-fedd-40b4-ade8-fdd70c447e7f}{DA798068-9008-475F-929E-7A34D96FE6D7}{dafcc24f-ff8f-4df8-a6d8-c4f8111181df}{def235fc-9507-4374-9daa-459538061e52}{E6901DC6-D4C3-4B6C-9C62-B50687785F37}{EB8866B8-373A-4AFC-9D84-4A314F9D5DD5}{EBA16011-DBCC-497E-ACE2-B9B803132712}File name without pathhttp_translationbuddy.dl.myway.com_0.localstoragehttp_translationbuddy.dl.myway.com_0.localstorage-journalhttp_translationbuddy.dl.tb.ask.com_0.localstoragehttp_translationbuddy.dl.tb.ask.com_0.localstorage-journaltranslationbuddy.dl.myway[1].xmltranslationbuddy.dl.tb.ask[1].xmlHKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\TranslationBuddy_5eSoftware\Microsoft\Internet Explorer\DOMStorage\translationbuddy.dl.myway.comSoftware\Microsoft\Internet Explorer\DOMStorage\translationbuddy.dl.tb.ask.comSOFTWARE\Microsoft\Internet Explorer\Toolbar\{a3c5f699-f046-47e7-8011-06269bc6ed24}SOFTWARE\Microsoft\Windows\CurrentVersion\Run\TranslationBuddy AppIntegrator 32-bitSOFTWARE\Microsoft\Windows\CurrentVersion\Run\TranslationBuddy AppIntegrator 64-bitSOFTWARE\Microsoft\Windows\CurrentVersion\Run\TranslationBuddy EPM SupportSOFTWARE\Microsoft\Windows\CurrentVersion\Run\TranslationBuddy Search Scope MonitorSOFTWARE\Translation BuddySoftware\TranslationBuddy_5eSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{a3c5f699-f046-47e7-8011-06269bc6ed24}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\TranslationBuddy AppIntegrator 32-bitSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\TranslationBuddy AppIntegrator 64-bitSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\TranslationBuddy EPM SupportSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\TranslationBuddy Search Scope MonitorSYSTEM\ControlSet001\services\TranslationBuddy_5eServiceSYSTEM\ControlSet002\services\TranslationBuddy_5eServiceSYSTEM\CurrentControlSet\services\TranslationBuddy_5eServiceHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Translation BuddyTooltab Uninstall Internet Explorer

Additional Information

The following directories were created:
%LOCALAPPDATA%\Translation BuddyTooltab%PROGRAMFILES%\TranslationBuddy_5eEI%PROGRAMFILES%\translationbuddy_5e%PROGRAMFILES(x86)%\TranslationBuddy_5eEI%PROGRAMFILES(x86)%\translationbuddy_5e
Loading...