HeadlineAlley Toolbar

HeadlineAlley Toolbar

Known Toolbar

by Mindspark Interactive Network

What is HeadlineAlley Toolbar?

HeadlineAlley Toolbar is software application developed by Mindspark Interactive Network. It is most commonly found on computers running Windows 7 with nearly 67.74% of installations running this operating system. HeadlineAlley Toolbar's installer is typically 9.00 MB in size and installs around 40 files.

HeadlineAlley Toolbar is most popular in the United States with 90.38% of installations residing in this country.

Multiple virus scanners have detected malware in HeadlineAlley Toolbar.

AppIntegrator64.exe (MD5: dde9c9b89b413a5868d7358511db5a6a) has been flagged by 10 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.MyWebSearch
avast! Win32:Mindspark-A [PUP]
AVG MyWebSearch
AVware MyWebSearch.J (v)
Baidu-International Adware.Win32.MyWebSearch.bQ
Kaspersky not-a-virus:WebToolbar.Win32.MyWebSearch.si
Malwarebytes PUP.Optional.MindSpark
Qihoo-360 Win32/Virus.WebToolbar.30b
Tencent Win32.Trojan.Falsesign.Wwof
VIPRE Antivirus MyWebSearch.J (v) (not malicious)
APPINTEGRATOR.EXE (MD5: b83db01d9e4bd53c9b65214806b54eb7) has been flagged by 16 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.MyWebSearch
avast! Win32:Mindspark-A [PUP]
AVG MyWebSearch
AVware MyWebSearch.J (v)
Baidu-International Adware.Win32.MyWebSearch.bQ
ESET-NOD32 a variant of Win32/Toolbar.MyWebSearch.AJ
Fortinet FortiGate Riskware/MyWebSearch
G Data Win32.Adware.Mindspark.C
Kaspersky not-a-virus:WebToolbar.Win32.MyWebSearch.si
Kingsoft AntiVirus Win32.Troj.MyWebSearch.si.(kcloud)
Malwarebytes PUP.Optional.MindSpark
Qihoo-360 Win32/Virus.WebToolbar.30b
Tencent Win32.Trojan.Falsesign.Pepp
TrendMicro-HouseCall Suspicious_GEN.F47V1106
VIPRE Antivirus MyWebSearch.J (v) (not malicious)
Zillya Adware.MyWebSearch.Win32.1695
29SrcAs.dll (MD5: aa5270eb6804dadda21905c65f2ab255) has been flagged by 17 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.MyWebSearch
Antiy-AVL RiskWare[WebToolbar:not-a-virus]/Win32.MyWebSearch
avast! Win32:Mindspark-A [PUP]
AVG MyWebSearch
AVware MyWebSearch.J (v)
Baidu-International Adware.Win32.MyWebSearch.bQ
ESET-NOD32 a variant of Win32/Toolbar.MyWebSearch.AK
Fortinet FortiGate Riskware/MyWebSearch
G Data Win32.Adware.Mindspark.C
Kaspersky not-a-virus:WebToolbar.Win32.MyWebSearch.si
Kingsoft AntiVirus Win32.Troj.MyWebSearch.si.(kcloud)
Malwarebytes PUP.Optional.MindSpark
Qihoo-360 Win32/Virus.WebToolbar.30b
Tencent Win32.Trojan.Falsesign.Lndy
TrendMicro-HouseCall Suspicious_GEN.F47V1106
VIPRE Antivirus MyWebSearch.J (v) (not malicious)
Zillya Adware.MyWebSearch.Win32.902
29barsvc.exe (MD5: eb0b3c1577773cb81ebc0a2507fccfdc) has been flagged by 14 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.MyWebSearch
avast! Win32:Mindspark-A [PUP]
AVG MyWebSearch
AVware MyWebSearch.J (v)
Baidu-International Adware.Win32.MyWebSearch.bQ
ESET-NOD32 a variant of Win32/Toolbar.MyWebSearch.AE
Fortinet FortiGate Riskware/MyWebSearch
G Data Win32.Adware.Mindspark.C
Kaspersky not-a-virus:WebToolbar.Win32.MyWebSearch.si
Kingsoft AntiVirus Win32.Troj.MyWebSearch.si.(kcloud)
Malwarebytes PUP.Optional.MindSpark
Qihoo-360 Win32/Virus.WebToolbar.30b
Tencent Win32.Trojan.Falsesign.Ajlj
VIPRE Antivirus MyWebSearch.J (v) (not malicious)
29medint.exe (MD5: 4de35f24efb8446518e0586fd54043b8) has been flagged by 15 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.MyWebSearch
avast! Win32:Mindspark-A [PUP]
AVG MyWebSearch
AVware MyWebSearch.J (v)
Baidu-International Adware.Win32.MyWebSearch.bQ
ESET-NOD32 a variant of Win32/Toolbar.MyWebSearch.AJ
Fortinet FortiGate Riskware/MyWebSearch
G Data Win32.Adware.Mindspark.C
Kaspersky not-a-virus:WebToolbar.Win32.MyWebSearch.si
Kingsoft AntiVirus Win32.Troj.MyWebSearch.si.(kcloud)
Malwarebytes PUP.Optional.MindSpark
Qihoo-360 Win32/Virus.WebToolbar.30b
Tencent Win32.Trojan.Falsesign.Pial
VIPRE Antivirus MyWebSearch.J (v) (not malicious)
Zillya Adware.MyWebSearch.Win32.1392

Software Behaviors

Services:
  • 29barsvc.exe runs as a service named 'InboxNowService' (InboxNow_drService).

Startup Entries

Startup tasks:
  • AppIntegrator64.exe is automatically launched at startup through a scheduled task named OnlineMapFinder AppIntegrator 64-bit_Reg_HKLMWow6432Run.
  • APPINTEGRATOR.EXE is automatically launched at startup through a scheduled task named OnlineMapFinder AppIntegrator 32-bit_Reg_HKLMWow6432Run.
Registry entries:
  • APPINTEGRATOR.EXE is loaded in the current user (HKCU) registry as an auto-starting executable named 'PowerSuite' and executes as "C:\Program Files1\Uniblue\POWERS~1\launcher.exe" delay 20000 -m.
  • AppIntegrator64.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'Hoolapp Android' and executes as "C:\users\user\appdata\Roaming\HOOLAP~1\Hoolapp.exe" /Minimized.

Software Details

URL:
https://search.mywebsearch.com/mywebsearch/default.jhtml
Support:
–
Installation path:
C:\Program Files\HeadlineAlley_29\bar\3.bin
Uninstaller:
rundll32 "C:\Program Files\HeadlineAlley_29\bar\3.bin\29Bar.dll",O mindsparktoolbarkey="HeadlineAlley_29"
Size:
9.00 MB
Language:
English

HeadlineAlley Toolbar Executable Details

Primary executable:
29bar.dll
Name:
HeadlineAlley Toolbar
Path:
C:\Program Files\HeadlineAlley_29\bar\3.bin\29bar.dll
MD5:
9bd7fb08514a6213b89f6969e31030e5
SHA-1:
–
SHA-256:
–
Files installed by HeadlineAlley Toolbar
File Type Filename MD5
DLL
298bfa5c34ce7cb9bfcc4bcc3966daee
DLL
93da07f94d74c54c75d6000090799f70
EXE
eb0b3c1577773cb81ebc0a2507fccfdc
DLL
08fef020b225248df46a3bb78ed3bd58
DLL
51d3c41e27f7589bd63e6bd588073dfc
DLL
6b4eb4f6694fc5592a7a59dad0a33950
EXE
4de35f24efb8446518e0586fd54043b8
EXE
5a2c29f369c710af4b57f84b5688475c
DLL
9bd7fb08514a6213b89f6969e31030e5
DLL
cf0646bb879911192c833e314e0afc57