Home Malware Programs Bad Toolbars Winload Toolbar

Winload Toolbar

Posted: July 24, 2013

Threat Metric

Ranking: 3,520
Threat Level: 5/10
Infected PCs: 31,323
First Seen: July 24, 2013
Last Seen: October 17, 2023
OS(es) Affected: Windows

Winload Toolbar is a browser add-on that promotes itself as a tool, which is able to improve a PC user's web browsing experience when it is installed onto Internet Explorer, Mozilla Firefox, and Google Chrome Internet browsers. Frequently, many web users consider Winload Toolbar to be a browser hijacker, although it is not. Winload Toolbar is an adware application that Internet users may unknowingly install on the computer when downloading freeware and shareware applications. Winload Toolbar modifies the default home page and default search engine with a dubious search engine. Winload Toolbar takes control of the affected computer system and, thus, seems to appear a security threat. Winload Toolbar can also be used by scammers in advertising campaigns to make money. Winload Toolbar keeps track on how the target computer user browses the web and keeps the collected data for malicious purposes. Winload Toolbar records all information that might be valuable for the aim of cybercriminals to push ads in numerous advertising websites. Winload Toolbar results in annoying browser redirects to suspicious advertising websites.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\AppData\Roaming\Windows Net Data\uninstaller.exe File name: uninstaller.exe
Size: 1.11 MB (1117184 bytes)
MD5: 692a36a91ec83bbb0fbcf6c024394713
Detection count: 7,335
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\Windows Net Data\uninstaller.exe
Group: Malware file
Last Updated: September 27, 2023
Winload-Toolbar-Setup.exe File name: Winload-Toolbar-Setup.exe
Size: 577.28 KB (577280 bytes)
MD5: b8b6e302f3b0c1075fbfcfd431901584
Detection count: 31
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 8, 2020

Registry Modifications

The following newly produced Registry Values are:

CLSID{40C3CC16-7269-4B32-9531-17F2950FB06F}HKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\WinloadSoftware\AppDataLow\Toolbar\RegisteredSources\CT2319825SOFTWARE\Classes\Toolbar.CT2319825SOFTWARE\WinloadSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{30F9B915-B755-4826-820B-08FBA6BD249D}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{40c3cc16-7269-4b32-9531-17f2950fb06f}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}SOFTWARE\Wow6432Node\WinloadHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}BrowseToolE0191 ToolbarVISWinload Toolbar

Additional Information

The following directories were created:
%APPDATA%\Windows Net Data%ProgramFiles%\Winload%ProgramFiles(x86)%\Winload%USERPROFILE%\AppData\LocalLow\Winload
The following URL's were detected:
Spartipps
Loading...