RingtoneFanatic Internet Explorer Toolbar

RingtoneFanatic Internet Explorer Toolbar

Known Toolbar

by Mindspark Interactive Network

What is RingtoneFanatic Internet Explorer Toolbar?

RingtoneFanatic Internet Explorer Toolbar is software application developed by Mindspark Interactive Network. It is most commonly found on computers running Windows 10 with nearly 48.72% of installations running this operating system. RingtoneFanatic Internet Explorer Toolbar's installer is typically 11.00 MB in size and installs around 49 files.

RingtoneFanatic Internet Explorer Toolbar is most popular in the United States with 84.75% of installations residing in this country.

RingtoneFanatic Internet Explorer Toolbar adds 1 scheduled task to the Windows Task Scheduler launching the program at randomly scheduled times.

About RingtoneFanatic Internet Explorer Toolbar?

The RingtoneFanatic Internet Explorer Toolbar is a web browser toolbar supported by advertising that has the ability to make adjustments to the browser's home page, search provider, and new tab pages. These modifications may include changing the default home page and new tab settings, as well as altering the default search engine in the Internet Browser. Additionally, it may incorporate alternative error page functionality, such as "Page Not Found."

Multiple virus scanners have detected malware in RingtoneFanatic Internet Explorer Toolbar.

AppIntegrator64.exe (MD5: 143d634f4f93155d3a4d430c2cf60d11) has been flagged by 12 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.MyWebSearch
Antiy-AVL RiskWare[WebToolbar:not-a-virus]/Win32.MyWebSearch
avast! Win32:Mindspark-A [PUP]
AVG Zango
Baidu-International Adware.Win32.MyWebSearch.Aki
Fortinet FortiGate Riskware/MyWebSearch
Kaspersky not-a-virus:WebToolbar.Win32.MyWebSearch.si
Malwarebytes PUP.Optional.MindSpark
Panda Antivirus Adware/WebSearch
Qihoo-360 Win32/Virus.WebToolbar.30b
Tencent Win32.Trojan.Falsesign.Dvqb
VIPRE Antivirus MyWebSearch.J (v) (not malicious)
APPINTEGRATOR.EXE (MD5: b6940fe9d6fc34ef59f1028ae6018fe1) has been flagged by 18 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.MyWebSearch
Antiy-AVL RiskWare[WebToolbar:not-a-virus]/Win32.MyWebSearch
avast! Win32:Mindspark-A [PUP]
AVG MyWebSearch
AVware MyWebSearch.J (v)
Baidu-International Adware.Win32.MyWebSearch.am
ESET-NOD32 a variant of Win32/Toolbar.MyWebSearch.AJ
Fortinet FortiGate Riskware/MyWebSearch
G Data Win32.Adware.Mindspark.C
Kaspersky not-a-virus:WebToolbar.Win32.MyWebSearch.si
Kingsoft AntiVirus Win32.Troj.MyWebSearch.si.(kcloud)
Malwarebytes PUP.Optional.MindSpark
Qihoo-360 Win32/Virus.WebToolbar.30b
Tencent Win32.Trojan.Falsesign.Pgcq
TrendMicro-HouseCall Suspicious_GEN.F47V0812
VIPRE Antivirus MyWebSearch.J (v) (not malicious)
Zillya Adware.MyWebSearch.Win32.1392
Panda Antivirus Adware/WebSearch
b0SrchMn.exe (MD5: 3c93215de9cc97c60b1892ad8dbe4411) has been flagged by 18 scanners:
Scanner Software Result
AhnLab-V3 Trojan/Win32.Buzus
Antiy-AVL RiskWare[WebToolbar:not-a-virus]/Win32.MyWebSearch
avast! Win32:Mindspark-A [PUP]
AVG MyWebSearch
AVware MyWebSearch.J (v)
Baidu-International Adware.Win32.MyWebSearch.abZ
ESET-NOD32 a variant of Win32/Toolbar.MyWebSearch.AJ
Fortinet FortiGate Riskware/MyWebSearch
G Data Win32.Adware.Mindspark.C
Kaspersky not-a-virus:WebToolbar.Win32.MyWebSearch.si
Kingsoft AntiVirus Win32.Troj.MyWebSearch.si.(kcloud)
Malwarebytes PUP.Optional.MindSpark
Qihoo-360 Win32/Virus.WebToolbar.30b
Tencent Win32.Trojan.Falsesign.Lmut
VIPRE Antivirus MyWebSearch.J (v) (not malicious)
Zillya Adware.MyWebSearch.Win32.1351
TrendMicro-HouseCall Suspicious_GEN.F47V0812
Panda Antivirus Adware/WebSearch
b0SrcAs.dll (MD5: 779662595f6b51bb86f96eccc230f13c) has been flagged by 20 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.MyWebSearch
Antiy-AVL RiskWare[WebToolbar:not-a-virus]/Win32.MyWebSearch
avast! Win32:Mindspark-A [PUP]
AVG MyWebSearch
AVware MyWebSearch.J (v)
Baidu-International Adware.Win32.MyWebSearch.aRmS
ESET-NOD32 a variant of Win32/Toolbar.MyWebSearch.AC
Fortinet FortiGate Riskware/MyWebSearch
G Data Win32.Adware.Mindspark.C
Kaspersky not-a-virus:WebToolbar.Win32.MyWebSearch.si
Kingsoft AntiVirus Win32.Troj.MyWebSearch.si.(kcloud)
Malwarebytes PUP.Optional.MindSpark
NANO AntiVirus Riskware.Win32.Toolbar.dfqike
Qihoo-360 Win32/Virus.WebToolbar.30b
Tencent Win32.Trojan.Falsesign.Aisc
TrendMicro-HouseCall Suspicious_GEN.F47V0812
VIPRE Antivirus MyWebSearch.J (v) (not malicious)
Zillya Adware.MyWebSearch.Win32.902
Agnitum Outpost PUA.Toolbar.MyWebSearch!
Panda Antivirus Adware/WebSearch
b0medint.exe (MD5: 4de35f24efb8446518e0586fd54043b8) has been flagged by 17 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.MyWebSearch
avast! Win32:Mindspark-A [PUP]
AVG MyWebSearch
AVware MyWebSearch.J (v)
Baidu-International Adware.Win32.MyWebSearch.bQ
ESET-NOD32 a variant of Win32/Toolbar.MyWebSearch.AJ
Fortinet FortiGate Riskware/MyWebSearch
G Data Win32.Adware.Mindspark.C
Kaspersky not-a-virus:WebToolbar.Win32.MyWebSearch.si
Kingsoft AntiVirus Win32.Troj.MyWebSearch.si.(kcloud)
Malwarebytes PUP.Optional.MindSpark
Qihoo-360 Win32/Virus.WebToolbar.30b
Tencent Win32.Trojan.Falsesign.Pial
VIPRE Antivirus MyWebSearch.J (v) (not malicious)
Zillya Adware.MyWebSearch.Win32.1392
Antiy-AVL RiskWare[WebToolbar:not-a-virus]/Win32.MyWebSearch
Panda Antivirus Adware/WebSearch

Software Behaviors

Services:
  • b0barsvc.exe runs as a service named 'InboxNowService' (InboxNow_drService).
Scheduled tasks:
  • AppIntegrator64.exe is scheduled as a task named 'Price Fountain' (runs daily at 4:45 PM).

Startup Entries

Startup tasks:
  • AppIntegrator64.exe is automatically launched at startup through a scheduled task named 7.
  • b0SrchMn.exe is automatically launched at startup through a scheduled task named 3.
  • b0medint.exe is automatically launched at startup through a scheduled task named 2.
  • APPINTEGRATOR.EXE is automatically launched at startup through a scheduled task named OnlineMapFinder AppIntegrator 32-bit_Reg_HKLMWow6432Run.
Registry entries:
  • APPINTEGRATOR.EXE is loaded in the current user (HKCU) registry as an auto-starting executable named 'PowerSuite' and executes as "C:\Program Files1\Uniblue\POWERS~1\launcher.exe" delay 20000 -m.
  • AppIntegrator64.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'Hoolapp Android' and executes as "C:\users\user\appdata\Roaming\HOOLAP~1\Hoolapp.exe" /Minimized.

Software Details

URL:
https://support.mindspark.com
Support:
–
Installation path:
C:\Program Files\RingtoneFanatic_b0\bar\1.bin
Uninstaller:
rundll32 "C:\Program Files\RingtoneFanatic_b0\bar\1.bin\b0Bar.dll",O mindsparktoolbarkey="RingtoneFanatic_b0" uninstalltype=IE
Size:
11.00 MB
Language:
English

RingtoneFanatic Internet Explorer Toolbar Executable Details

Primary executable:
b0bar.dll
Name:
RingtoneFanatic Internet Explorer Toolbar
Path:
C:\Program Files\RingtoneFanatic_b0\bar\1.bin\b0bar.dll
MD5:
96a060cf33a2c42617cf13224a47db07
SHA-1:
–
SHA-256:
–
Files installed by RingtoneFanatic Internet Explorer Toolbar
File Type Filename MD5
DLL
a90bf4411ebff8b342c21c1a647b513b
DLL
298bfa5c34ce7cb9bfcc4bcc3966daee
DLL
93da07f94d74c54c75d6000090799f70
EXE
b3dae11b5316528e6853a94d39e141e3
DLL
b92c71d0ba7098f565520266e6b987d9
DLL
e0d399dfb42ca6a24c40b4d38d0db3a3
DLL
b927852e2e860edbc4d2ec2b436cfaba
DLL
05e7f2c19ae83dd990a6960a19755752
DLL
96a060cf33a2c42617cf13224a47db07