Toolbar:W32/Mostofate

Classification

Category :

Spyware

Type :

Toolbar

Aliases :

Toolbar:W32/Mostofate, Dropped:Adware.Softomate.CD, Adware:W32/Mostofate, Adware.Win32.Mostofate, Adware.CramToolbar (Symantec

Summary

A browser plug-in which provides additional functionality not included in the standard browser. May introduce security risks not present in the standard browser.

Removal

Based on the settings of your F-Secure security product, it may block the file from running, move it to the quarantine where it cannot spread or cause harm, or ask you to select an action.

A False Positive is when a file is incorrectly detected as harmful, usually because its code or behavior resembles known harmful programs. A False Positive will usually be fixed in a subsequent database update without any action needed on your part. If you wish, you may also:

  • Check for the latest database updates

    First check if your F-Secure security program is using the latest updates, then try scanning the file again.

  • Submit a sample

    After checking, if you still believe the file is incorrectly detected, you can submit a sample of it for re-analysis.

    Note: If the file was moved to quarantine, you need to collect the file from quarantine before you can submit it.

  • Exclude a file from further scanning

    If you are certain that the file is safe and want to continue using it, you can exclude it from further scanning by the F-Secure security product.

    Note: You need administrative rights to change the settings.

Technical Details

This is the family description for the Toolbar:W32/Mostofate family of adware programs.

The Mostofate program is a Browser Helper Object (BHO), a type of browser plug-in 'added on' to web browser programs to provide additional functionality. Like many BHOs, Mostofate is a Microsoft Internet Explorer (IE) toolbar that offers limited search functionality and some utility functions.

Some variants and components in this family are also detected as Adware:W32/Mostofate.

Installation

The toolbar is manually installed from an installer component that may be downloaded from the Internet.. The program is by default installed at:

  • C:\Program Files\FindFM Toolbar.

The installer allows the user to change the installation folder.

The following files are created by the installation:

  • C:\Program Files\FindFM Toolbar\toolbar.dll (toolbar component)
  • C:\Program FIles\FindFM Toolbar\1a.bmp
  • C:\Program FIles\FindFM Toolbar\icons.bmp
  • C:\Program FIles\FindFM Toolbar\toolbar.crc
  • C:\Program FIles\FindFM Toolbar\error.html
  • C:\Program FIles\FindFM Toolbar\inst.bat
  • C:\Program FIles\FindFM Toolbar\toolbar.inf
  • C:\Program FIles\FindFM Toolbar\newversion.txt
  • C:\Program FIles\FindFM Toolbar\version.txt
  • C:\Program FIles\FindFM Toolbar\basis.xml

Once installed, the program registers the toolbar in Internet Explorer. The toolbar can be uninstalled from the browser, but its files and registry entries have to be manually removed.

Activity

When first run, Mostofate attempts to update itself from the Internet. It will also set the default homepage to:

  • https://www.find.fm/

This site has the appearance of a search engine page, but most searches will return advertisements and links to porn sites. For example, typing the search terms 'adult education' in the search field resulted in the following search results being returned:

The toolbar allows users to clear the browser's search history, visited sites, etc. There is a risk that searches will be logged and used to deliver further targeted advertising.

The latest available installation package is also available as the following on the search engine page(s):

  • https://www.peakclick.com/toolbar/1/toolbar.exe

Registry

The malware creates numerous registry keys, notably:

  • HKCU\software\XBT04482\Toolbar\
  • HKCU\software\microsoft\internet explorer\toolbar\webbrowser\
  • HKCU\software\XBTB04482\

Note

Mostofate was created using software from Softomate, a development tool supplier. This is nota detection of Softomate's development tools, but rather is a detection of a Data Mining Toolbar created using Softomate's software.