HeadlineAlley Toolbar

HeadlineAlley Toolbar

Known Toolbar

by Mindspark Interactive Network

What is HeadlineAlley Toolbar?

HeadlineAlley Toolbar is software application developed by Mindspark Interactive Network. It is most commonly found on computers running Windows 7 with nearly 67.74% of installations running this operating system. HeadlineAlley Toolbar's installer is typically 9.00 MB in size and installs around 40 files.

HeadlineAlley Toolbar is most popular in the United States with 90.38% of installations residing in this country.

Multiple virus scanners have detected malware in HeadlineAlley Toolbar.

AppIntegrator64.exe (MD5: dde9c9b89b413a5868d7358511db5a6a) has been flagged by 10 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.MyWebSearch
avast! Win32:Mindspark-A [PUP]
AVG MyWebSearch
AVware MyWebSearch.J (v)
Baidu-International Adware.Win32.MyWebSearch.bQ
Kaspersky not-a-virus:WebToolbar.Win32.MyWebSearch.si
Malwarebytes PUP.Optional.MindSpark
Qihoo-360 Win32/Virus.WebToolbar.30b
Tencent Win32.Trojan.Falsesign.Wwof
VIPRE Antivirus MyWebSearch.J (v) (not malicious)
APPINTEGRATOR.EXE (MD5: b83db01d9e4bd53c9b65214806b54eb7) has been flagged by 16 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.MyWebSearch
avast! Win32:Mindspark-A [PUP]
AVG MyWebSearch
AVware MyWebSearch.J (v)
Baidu-International Adware.Win32.MyWebSearch.bQ
ESET-NOD32 a variant of Win32/Toolbar.MyWebSearch.AJ
Fortinet FortiGate Riskware/MyWebSearch
G Data Win32.Adware.Mindspark.C
Kaspersky not-a-virus:WebToolbar.Win32.MyWebSearch.si
Kingsoft AntiVirus Win32.Troj.MyWebSearch.si.(kcloud)
Malwarebytes PUP.Optional.MindSpark
Qihoo-360 Win32/Virus.WebToolbar.30b
Tencent Win32.Trojan.Falsesign.Pepp
TrendMicro-HouseCall Suspicious_GEN.F47V1106
VIPRE Antivirus MyWebSearch.J (v) (not malicious)
Zillya Adware.MyWebSearch.Win32.1695
29SrcAs.dll (MD5: aa5270eb6804dadda21905c65f2ab255) has been flagged by 17 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.MyWebSearch
Antiy-AVL RiskWare[WebToolbar:not-a-virus]/Win32.MyWebSearch
avast! Win32:Mindspark-A [PUP]
AVG MyWebSearch
AVware MyWebSearch.J (v)
Baidu-International Adware.Win32.MyWebSearch.bQ
ESET-NOD32 a variant of Win32/Toolbar.MyWebSearch.AK
Fortinet FortiGate Riskware/MyWebSearch
G Data Win32.Adware.Mindspark.C
Kaspersky not-a-virus:WebToolbar.Win32.MyWebSearch.si
Kingsoft AntiVirus Win32.Troj.MyWebSearch.si.(kcloud)
Malwarebytes PUP.Optional.MindSpark
Qihoo-360 Win32/Virus.WebToolbar.30b
Tencent Win32.Trojan.Falsesign.Lndy
TrendMicro-HouseCall Suspicious_GEN.F47V1106
VIPRE Antivirus MyWebSearch.J (v) (not malicious)
Zillya Adware.MyWebSearch.Win32.902
29barsvc.exe (MD5: eb0b3c1577773cb81ebc0a2507fccfdc) has been flagged by 14 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.MyWebSearch
avast! Win32:Mindspark-A [PUP]
AVG MyWebSearch
AVware MyWebSearch.J (v)
Baidu-International Adware.Win32.MyWebSearch.bQ
ESET-NOD32 a variant of Win32/Toolbar.MyWebSearch.AE
Fortinet FortiGate Riskware/MyWebSearch
G Data Win32.Adware.Mindspark.C
Kaspersky not-a-virus:WebToolbar.Win32.MyWebSearch.si
Kingsoft AntiVirus Win32.Troj.MyWebSearch.si.(kcloud)
Malwarebytes PUP.Optional.MindSpark
Qihoo-360 Win32/Virus.WebToolbar.30b
Tencent Win32.Trojan.Falsesign.Ajlj
VIPRE Antivirus MyWebSearch.J (v) (not malicious)
29medint.exe (MD5: 4de35f24efb8446518e0586fd54043b8) has been flagged by 15 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.MyWebSearch
avast! Win32:Mindspark-A [PUP]
AVG MyWebSearch
AVware MyWebSearch.J (v)
Baidu-International Adware.Win32.MyWebSearch.bQ
ESET-NOD32 a variant of Win32/Toolbar.MyWebSearch.AJ
Fortinet FortiGate Riskware/MyWebSearch
G Data Win32.Adware.Mindspark.C
Kaspersky not-a-virus:WebToolbar.Win32.MyWebSearch.si
Kingsoft AntiVirus Win32.Troj.MyWebSearch.si.(kcloud)
Malwarebytes PUP.Optional.MindSpark
Qihoo-360 Win32/Virus.WebToolbar.30b
Tencent Win32.Trojan.Falsesign.Pial
VIPRE Antivirus MyWebSearch.J (v) (not malicious)
Zillya Adware.MyWebSearch.Win32.1392

Software Behaviors

Services:
  • 29barsvc.exe runs as a service named 'InboxNowService' (InboxNow_drService).

Startup Entries

Startup tasks:
  • AppIntegrator64.exe is automatically launched at startup through a scheduled task named OnlineMapFinder AppIntegrator 64-bit_Reg_HKLMWow6432Run.
  • APPINTEGRATOR.EXE is automatically launched at startup through a scheduled task named OnlineMapFinder AppIntegrator 32-bit_Reg_HKLMWow6432Run.
Registry entries:
  • APPINTEGRATOR.EXE is loaded in the current user (HKCU) registry as an auto-starting executable named 'PowerSuite' and executes as "C:\Program Files1\Uniblue\POWERS~1\launcher.exe" delay 20000 -m.
  • AppIntegrator64.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'Hoolapp Android' and executes as "C:\users\user\appdata\Roaming\HOOLAP~1\Hoolapp.exe" /Minimized.

Software Details

URL:
https://search.mywebsearch.com/mywebsearch/default.jhtml
Support:
–
Installation path:
C:\Program Files\HeadlineAlley_29\bar\3.bin
Uninstaller:
rundll32 "C:\Program Files\HeadlineAlley_29\bar\3.bin\29Bar.dll",O mindsparktoolbarkey="HeadlineAlley_29"
Size:
9.00 MB
Language:
English

HeadlineAlley Toolbar Executable Details

Primary executable:
29bar.dll
Name:
HeadlineAlley Toolbar
Path:
C:\Program Files\HeadlineAlley_29\bar\3.bin\29bar.dll
MD5:
9bd7fb08514a6213b89f6969e31030e5
SHA-1:
–
SHA-256:
–
Files installed by HeadlineAlley Toolbar
File Type Filename MD5
DLL
6fc9a5a8850e13b4c18c1d5a23756fda
DLL
b16182105523b023b4a28f0196e83003
DLL
0f60cf9803fc7322939863d458cac46a
DLL
9cd47b752fe610e21ef22473a2f8f534
DLL
641f65b7f756e6bc9631fe12a9827c56
EXE
dde9c9b89b413a5868d7358511db5a6a
EXE
b83db01d9e4bd53c9b65214806b54eb7
EXE
1983adbec36385d0cedbb89881098684
DLL
aa5270eb6804dadda21905c65f2ab255
EXE
22eec005cc6a14f50ceceb93da5cf043