1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




Toolbar:W32/Mostofate

Name : Toolbar:W32/Mostofate
Detection Names : Dropped:Adware.Softomate.CD
Adware:W32/Mostofate
Adware.Win32.Mostofate
Aliases : Adware.CramToolbar (Symantec)
Category:Spyware
Type:Toolbar
Platform:W32

Summary

A browser plug-in which provides additional functionality not included in the standard browser. May introduce security risks not present in the standard browser.

Additional Details

This is the family description for the Toolbar:W32/Mostofate family of adware programs.

The Mostofate program is a Browser Helper Object (BHO), a type of browser plug-in 'added on' to web browser programs to provide additional functionality. Like many BHOs, Mostofate is a Microsoft Internet Explorer (IE) toolbar that offers limited search functionality and some utility functions.

Some variants and components in this family are also detected as Adware:W32/Mostofate
 

Installation

The toolbar is manually installed from an installer component that may be downloaded from the Internet.. The program is by default installed at:

  • C:\Program Files\FindFM Toolbar.

The installer allows the user to change the installation folder.

The following files are created by the installation:

  • C:\Program Files\FindFM Toolbar\toolbar.dll (toolbar component)
  • C:\Program FIles\FindFM Toolbar\1a.bmp
  • C:\Program FIles\FindFM Toolbar\icons.bmp
  • C:\Program FIles\FindFM Toolbar\toolbar.crc
  • C:\Program FIles\FindFM Toolbar\error.html
  • C:\Program FIles\FindFM Toolbar\inst.bat
  • C:\Program FIles\FindFM Toolbar\toolbar.inf
  • C:\Program FIles\FindFM Toolbar\newversion.txt
  • C:\Program FIles\FindFM Toolbar\version.txt
  • C:\Program FIles\FindFM Toolbar\basis.xml

Once installed, the program registers the toolbar in Internet Explorer. The toolbar can be uninstalled from the browser, but its files and registry entries have to be manually removed.


Activity

When first run, Mostofate attempts to update itself from the Internet. It will also set the default homepage to:

  • http://www.find.fm/

This site has the appearance of a search engine page, but most searches will return advertisements and links to porn sites. For example, typing the search terms 'adult education' in the search field resulted in the following search results being returned:



The toolbar allows users to clear the browser's search history, visited sites, etc. There is a risk that searches will be logged and used to deliver further targeted advertising.

The latest available installation package is also available as the following on the search engine page(s):

  • http://www.peakclick.com/toolbar/1/toolbar.exe

Registry

The malware creates numerous registry keys, notably:

  • HKCU\software\XBT04482\Toolbar\
  • HKCU\software\microsoft\internet explorer\toolbar\webbrowser\
  • HKCU\software\XBTB04482\

Note

Mostofate was created using software from Softomate, a development tool supplier. This is not a detection of Softomate's development tools, but rather is a detection of a Data Mining Toolbar created using Softomate's software.

Unfortunately, though Softomate (BestToolbars.net) offers legitimate development tools and source codes for creating customized toolbars, there have been a number of cases where their tools and codes have been used to create toolbars with such unwanted features as browser hijacking, advertisement pop-ups and data mining.