Home Malware Programs Potentially Unwanted Programs (PUPs) UnzipApp Toolbar

UnzipApp Toolbar

Posted: July 14, 2015

Threat Metric

Ranking: 14,890
Threat Level: 1/10
Infected PCs: 508
First Seen: June 9, 2015
Last Seen: October 5, 2023
OS(es) Affected: Windows

The UnzipApp Toolbar, considered as a Potentially Unwanted Program (PUP), is speculated to change the homepage of the user to a customized version of http://hp.myway.com and welcome users to benefit from extended search options. The UnzipApp Toolbar that is developed by Mindspark Interactive Network, Inc. The UnzipApp Toolbar was configured to work only if the user has agreed to use http://hp.myway.com as their home page. The customized version of http://hp.myway.com had useful links to services like www.zipshare.com, pdfcompressor.com, and www.files2zip.com but UnZipp took over the user's Internet settings, and that was not welcomed. The behavior of the UnzipApp Toolbar was the reason for security scanners to detect the program as Toolbar.MyWebSearch.AO, Win32:Mindspark-A [PUP] and W32/Mywebsearch.K.gen!Eldorado. Researchers note that apps like UnzipApp may leave residual data that can be cleaned with a reliable anti-spyware tool.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{0BA82E27-87A4-4023-8305-17408CE08424}{355A3170-6755-4FA6-A8A2-4DE247F9D9D0}{5D11D31A-0CAE-411A-B212-90D00D0DE1FA}{6DBB69C5-21CE-4823-AB71-9A13BD85C3DD}{780DAF26-1FB6-4967-85D7-00E91A50CC6B}{906B0A3D-67F6-4E5E-84A7-019787AAE7E5}File name without pathhttp_UnzipApp.dl.myway.com_0.localstoragehttp_UnzipApp.dl.myway.com_0.localstorage-journalhttp_UnzipApp.dl.tb.ask.com_0.localstoragehttp_UnzipApp.dl.tb.ask.com_0.localstorage-journalUnzipApp.lnkUnzipAppSetup.exeHKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\UnzipApp_dtSoftware\Microsoft\Internet Explorer\Approved Extensions\{0E51BD29-6D41-4405-BCCE-B3AB260A9DDA}Software\Microsoft\Internet Explorer\Approved Extensions\{B3325E5E-51AB-4F28-977D-8A9D836BAD9A}Software\Microsoft\Internet Explorer\Approved Extensions\{BBEDE69E-6340-4D50-8B44-5FF4FE07933B}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{B3325E5E-51AB-4F28-977D-8A9D836BAD9A}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{B3325E5E-51AB-4F28-977D-8A9D836BAD9A}

Additional Information

The following directories were created:
%APPDATA%\Microsoft\Windows\Start Menu\Programs\UnzipApp
Loading...