MapsGalaxy Toolbar

MapsGalaxy Toolbar

Known Toolbar

by Mindspark Interactive Network

What is MapsGalaxy Toolbar?

MapsGalaxy Toolbar is software application developed by Mindspark Interactive Network. It is most commonly found on computers running Windows 7 with nearly 66.29% of installations running this operating system. MapsGalaxy Toolbar's installer is typically 11.00 MB in size and installs around 42 files.

MapsGalaxy Toolbar is most popular in the United States with 74.06% of installations residing in this country.

MapsGalaxy Toolbar adds 1 scheduled task to the Windows Task Scheduler launching the program at randomly scheduled times.

About MapsGalaxy Toolbar?

The software features the installation of a Mindspark toolbar into the user's web browser, facilitating the collection and storage of web browsing habits. This information is then transmitted to Mindspark for the purpose of providing targeted services and advertisements through the toolbar.

Multiple virus scanners have detected malware in MapsGalaxy Toolbar.

AppIntegrator64.exe (MD5: f68778b356218f4cbfd5c2c19419c0a0) has been flagged by 4 scanners:
Scanner Software Result
avast! Win32:Mindspark-A [PUP]
AVG Zango
ESET-NOD32 a variant of Win64/Toolbar.MyWebSearch.A
VIPRE Antivirus MyWebSearch.J (v) (not malicious)
APPINTEGRATOR.EXE (MD5: 660d435be4a48b8d941e5dcf30ac1974) has been flagged by 10 scanners:
Scanner Software Result
avast! Win32:Mindspark-A [PUP]
AVG Zango
Baidu-International Adware.Win32.Mindspark.81
Panda Antivirus Adware/WebSearch
Tencent Win32.Trojan.Falsesign.Wlzh
TrendMicro-HouseCall TROJ_GEN.F47V0404
VIPRE Antivirus MyWebSearch.J (v) (not malicious)
Malwarebytes PUP.Optional.AudioToAudioToolBar.A
NANO AntiVirus Trojan.Win32.FUbu2.cudmon
ESET-NOD32 a variant of Win64/Toolbar.MyWebSearch.A
39brmon.exe (MD5: 2c0a45683112082493b1fb3c09c60184) has been flagged by 6 scanners:
Scanner Software Result
avast! Win32:Mindspark-A [PUP]
AVG Zango
Malwarebytes PUP.Optional.MindSpark.A
VIPRE Antivirus MyWebSearch.J (v) (not malicious)
TrendMicro-HouseCall TROJ_GEN.F47V0404
ESET-NOD32 a variant of Win64/Toolbar.MyWebSearch.A
39SrchMn.exe (MD5: 466af3fbfdd028b3d90238425c367b7e) has been flagged by 14 scanners:
Scanner Software Result
AhnLab-V3 Trojan/Win32.Buzus
avast! Win32:Mindspark-A [PUP]
AVG Zango
Kingsoft AntiVirus Win32.Troj.Undef.(kcloud)
McAfee Artemis!466AF3FBFDD0
McAfee-GW-Edition Artemis!466AF3FBFDD0
TrendMicro-HouseCall TROJ_GEN.F47V0404
VIPRE Antivirus MyWebSearch.J (v) (not malicious)
Baidu-International Adware.Win32.Mindspark.45
Panda Antivirus Adware/WebSearch
Tencent Win32.Trojan.Falsesign.Lkxk
Malwarebytes PUP.Optional.AudioToAudioToolBar.A
NANO AntiVirus Trojan.Win32.FUbu2.cudmon
ESET-NOD32 a variant of Win64/Toolbar.MyWebSearch.A
39SrcAs.dll (MD5: 31f0fd888f41c6e4b05a8a26a6257bbb) has been flagged by 10 scanners:
Scanner Software Result
avast! Win32:Mindspark-A [PUP]
AVG Zango
Baidu-International Adware.Win32.Mindspark.45
Panda Antivirus Adware/WebSearch
Tencent Win32.Trojan.Falsesign.Lkxk
TrendMicro-HouseCall TROJ_GEN.F47V0404
VIPRE Antivirus MyWebSearch.J (v) (not malicious)
Malwarebytes PUP.Optional.AudioToAudioToolBar.A
NANO AntiVirus Trojan.Win32.FUbu2.cudmon
ESET-NOD32 a variant of Win64/Toolbar.MyWebSearch.A

Software Behaviors

Services:
  • 39barsvc.exe runs as a service named 'WebfettiService' (Webfetti_52Service).
Scheduled tasks:
  • AppIntegrator64.exe is scheduled as a task named 'Price Fountain' (runs daily at 4:45 PM).

Startup Entries

Startup tasks:
  • AppIntegrator64.exe is automatically launched at startup through a scheduled task named 7.
  • 39SrchMn.exe is automatically launched at startup through a scheduled task named 3.
  • 39medint.exe is automatically launched at startup through a scheduled task named 2.
  • 39brmon64.exe is automatically launched at startup through a scheduled task named 5.
  • 39brmon.exe is automatically launched at startup through a scheduled task named 4.

Software Details

URL:
https://search.mywebsearch.com/mywebsearch/default.jhtml
Support:
Installation path:
C:\Program Files\MapsGalaxy_39\bar\2.bin
Uninstaller:
rundll32 C:\Program Files2\MAPSGA~2\bar\1.bin\39Bar.dll,O
Size:
11.00 MB
Language:
English

MapsGalaxy Toolbar Executable Details

Primary executable:
39bar.dll
Name:
MapsGalaxy Toolbar
Path:
C:\Program Files\MapsGalaxy_39\bar\2.bin\39bar.dll
MD5:
96a060cf33a2c42617cf13224a47db07
SHA-1:
SHA-256:
Files installed by MapsGalaxy Toolbar
File Type Filename MD5
DLL
99314afe1aa7f154766c7b10b1b7e90d
DLL
aedf3f97b88562ce2d5128c9422718c1
DLL
a842b26aee3d1312bda37096c8490b39
DLL
bef81913920b66f99cce1b8b94d2335d
EXE
c9fecbc3ec683b4b60cf45ebae9abfcd
DLL
9f1f27aaedca28c35f7ec1484c53b6e5
EXE
466af3fbfdd028b3d90238425c367b7e
DLL
31f0fd888f41c6e4b05a8a26a6257bbb
EXE
f59ea63eaa060998c359fcbfdbc8c7d7
DLL
2fd72a0a4fc75b4371f22252e443b245