Jump to content

Welcome to Geeks to Go
Geeks to Go Welcome
Create Account Login to Account
Photo

Removal instructions for My Social Shortcut

- - - - - mindspark

  • Please log in to reply
No replies to this topic

#1
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 33,101 posts
Content is republished with permission from Malwarebytes.

What is My Social Shortcut?

The Malwarebytes research team has determined that My Social Shortcut is a browser NewTab. These so-called "NewTabs" can manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice.
My Social Shortcut is a member of the Mindspark/Ask family now known as IAC Applications.

How do I know if my computer is affected by My Social Shortcut?

You may see these browser extensions/add-ons:

warning5.png

warning6.png

these warnings during install:

main.png

warning1.png

warning2.png

You may see this entry in your list of installed software:

warning4.png

and this new homepage in the affected browsers:

startpage.png

How did My Social Shortcut get on my computer?

Browser hijackers use different methods for distributing themselves. This particular one was downloaded from their website.

website.png

How do I remove My Social Shortcut?

Our program Malwarebytes can detect and remove this potentially unwanted program.
You can use their own uninstall instructions first, but I would advise to follow the steps below anyway.
  • Please download Malwarebytes for Windows to your desktop.
  • Double-click MBSetup.exe and follow the prompts to install the program.
  • When your Malwarebytes for Windows installation completes, the program opens to the Welcome to Malwarebytes screen.
  • Click on the Get started button.
  • Click Scan to start a Threat Scan.
  • When the scan is finished click Quarantine to remove the found threats.
  • Reboot the system if prompted to complete the removal process.
Is there anything else I need to do to get rid of My Social Shortcut?
  • No, Malwarebytes' Anti-Malware removes My Social Shortcut completely.
  • If your browsers have been hijacked, you should read our Restore Browser page. You can read there how to fix additional browser redirect methods.
How would the full version of Malwarebytes help protect me?

We hope our application and this guide have helped you eradicate this hijacker.

As you can see below the full version of Malwarebytes would have protected you against the My Social Shortcut hijacker. It would have warned you before the hijacker could install itself, giving you a chance to stop it before it became too late.

protection1.png


and it blocks traffic to some of their domains:

protection2.png


Technical details for experts

Possible signs in a FRST log:

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://hp.myway.com/mysocialshortcut/ttab02/index.html?n={n}&p2={p2}&ptb={ptb}&coid={coid}
FF Homepage: Mozilla\Firefox\Profiles\{profile}.default -> moz-extension://6efd25d0-19d0-4d95-8143-1370478153a6/dynamicHomePage.html
FF HomepageOverride: Mozilla\Firefox\Profiles\{profile}.default -> Enabled: [email protected]
FF NewTabOverride: Mozilla\Firefox\Profiles\{profile}.default -> Enabled: [email protected]
FF Extension: (MySocialShortcut) - C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\Extensions\[email protected] [2020-04-02] [UpdateUrl:hxxps://updates.tb.ask.com/updateXpi.json?id=223553785&version=8.942.17.48010&track=TTAB03&trackRevision=1&fromId=_d1Membersttab03_%40free.mysocialshortcut.com&isBridgeExtension=false]
CHR NewTab: Default ->  Active:"chrome-extension://ognogdhldnmmaggmfoahbdnagnbhhlmj/ntp1.html"
CHR Extension: (MySocialShortcut) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ognogdhldnmmaggmfoahbdnagnbhhlmj [2020-04-02]
C:\Users\{username}\AppData\Local\MySocialShortcutTooltab

MySocialShortcut Internet Explorer Homepage and New Tab (HKCU\...\MySocialShortcutTooltab Uninstall Internet Explorer) (Version:  - Mindspark Interactive Network, Inc.) <==== ATTENTION
Significant changes made by the installers:

File system details [View: All details] (Selection)
---------------------------------------------------
    Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ognogdhldnmmaggmfoahbdnagnbhhlmj\13.924.17.40984_0
       Adds the file manifest.json"="4/2/2020 10:46 AM, 2551 bytes, A
       Adds the file ntp1.html"="3/17/2020 10:48 AM, 1434 bytes, A
    Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ognogdhldnmmaggmfoahbdnagnbhhlmj\13.924.17.40984_0\_locales
    Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ognogdhldnmmaggmfoahbdnagnbhhlmj\13.924.17.40984_0\_metadata
       Adds the file computed_hashes.json"="4/2/2020 10:46 AM, 7778 bytes, A
       Adds the file verified_contents.json"="3/17/2020 10:48 AM, 9197 bytes, A
    Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ognogdhldnmmaggmfoahbdnagnbhhlmj\13.924.17.40984_0\config
       Adds the file config.json"="3/17/2020 10:48 AM, 2239 bytes, A
    Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ognogdhldnmmaggmfoahbdnagnbhhlmj\13.924.17.40984_0\icons
       Adds the file icon128.png"="4/2/2020 10:46 AM, 5214 bytes, A
       Adds the file icon16.png"="4/2/2020 10:46 AM, 518 bytes, A
       Adds the file icon19disabled.png"="3/17/2020 10:48 AM, 1604 bytes, A
       Adds the file icon19on.png"="4/2/2020 10:46 AM, 588 bytes, A
       Adds the file icon48.png"="4/2/2020 10:46 AM, 1874 bytes, A
    Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ognogdhldnmmaggmfoahbdnagnbhhlmj\13.924.17.40984_0\js
       Adds the file ajax.js"="3/17/2020 10:48 AM, 3263 bytes, A
       Adds the file babAPI.js"="3/17/2020 10:48 AM, 5950 bytes, A
       Adds the file babClickHandler.js"="3/17/2020 10:48 AM, 3485 bytes, A
       Adds the file babContentScript.js"="3/17/2020 10:48 AM, 10509 bytes, A
       Adds the file babContentScriptAPI.js"="3/17/2020 10:48 AM, 13191 bytes, A
       Adds the file babRemoteConfigProcessor.js"="3/17/2020 10:48 AM, 4311 bytes, A
       Adds the file babTypeFactory.js"="3/17/2020 10:48 AM, 1999 bytes, A
       Adds the file babTypeInjectionEmbededPage.js"="3/17/2020 10:48 AM, 3383 bytes, A
       Adds the file babTypeInjectionIframe.js"="3/17/2020 10:48 AM, 2114 bytes, A
       Adds the file babTypeInjectionIframeAPIProxy.js"="3/17/2020 10:48 AM, 3160 bytes, A
       Adds the file babTypeInjectionScript.js"="3/17/2020 10:48 AM, 4111 bytes, A
       Adds the file background.js"="3/17/2020 10:48 AM, 25379 bytes, A
       Adds the file browserUtils.js"="3/17/2020 10:48 AM, 1892 bytes, A
       Adds the file chrome.js"="3/17/2020 10:48 AM, 146 bytes, A
       Adds the file contentScriptConnectionManager.js"="3/17/2020 10:48 AM, 23600 bytes, A
       Adds the file dateTimeUtils.js"="3/17/2020 10:48 AM, 1213 bytes, A
       Adds the file dlp.js"="3/17/2020 10:48 AM, 5852 bytes, A
       Adds the file dlpHelper.js"="3/17/2020 10:48 AM, 1835 bytes, A
       Adds the file extensionDetect.js"="3/17/2020 10:48 AM, 4357 bytes, A
       Adds the file index.js"="3/17/2020 10:48 AM, 49 bytes, A
       Adds the file localStorageContentScript.js"="3/17/2020 10:48 AM, 2237 bytes, A
       Adds the file logger.js"="3/17/2020 10:48 AM, 531 bytes, A
       Adds the file loggingLevelUtils.js"="3/17/2020 10:48 AM, 1976 bytes, A
       Adds the file meta.js"="3/17/2020 10:48 AM, 1697 bytes, A
       Adds the file newTabPageRedirectHandler.js"="3/17/2020 10:48 AM, 2902 bytes, A
       Adds the file notificationService.js"="3/17/2020 10:48 AM, 15355 bytes, A
       Adds the file offerService.js"="3/17/2020 10:48 AM, 17241 bytes, A
       Adds the file pageUtils.js"="3/17/2020 10:48 AM, 3132 bytes, A
       Adds the file PartnerId.js"="3/17/2020 10:48 AM, 16402 bytes, A
       Adds the file polyfill.js"="3/17/2020 10:48 AM, 875 bytes, A
       Adds the file product.js"="3/17/2020 10:48 AM, 8007 bytes, A
       Adds the file pTagService.js"="3/17/2020 10:48 AM, 7125 bytes, A
       Adds the file remoteConfigLoader.js"="3/17/2020 10:48 AM, 6179 bytes, A
       Adds the file scheduler.js"="3/17/2020 10:48 AM, 4130 bytes, A
       Adds the file searchBoxFocusSetterEdge.js"="3/17/2020 10:48 AM, 1648 bytes, A
       Adds the file splashPageRedirectHandler.js"="3/17/2020 10:48 AM, 2821 bytes, A
       Adds the file storageUtils.js"="3/17/2020 10:48 AM, 1718 bytes, A
       Adds the file surveyService.js"="3/17/2020 10:48 AM, 5401 bytes, A
       Adds the file templateParser.js"="3/17/2020 10:48 AM, 3153 bytes, A
       Adds the file ul.js"="3/17/2020 10:48 AM, 5856 bytes, A
       Adds the file urlFragmentActions.js"="3/17/2020 10:48 AM, 2453 bytes, A
       Adds the file urlUtils.js"="3/17/2020 10:48 AM, 5991 bytes, A
       Adds the file util.js"="3/17/2020 10:48 AM, 5402 bytes, A
       Adds the file watchExtensionsHandler.js"="3/17/2020 10:48 AM, 10297 bytes, A
       Adds the file webtooltabAPI.js"="3/17/2020 10:48 AM, 9786 bytes, A
       Adds the file webTooltabAPIProxy.js"="3/17/2020 10:48 AM, 8782 bytes, A
    Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ognogdhldnmmaggmfoahbdnagnbhhlmj
       Adds the file 000003.log"="4/2/2020 10:47 AM, 9823 bytes, A
       Adds the file CURRENT"="4/2/2020 10:46 AM, 16 bytes, A
       Adds the file LOCK"="4/2/2020 10:46 AM, 0 bytes, A
       Adds the file LOG"="4/2/2020 10:48 AM, 185 bytes, A
       Adds the file MANIFEST-000001"="4/2/2020 10:46 AM, 41 bytes, A
    Adds the folder C:\Users\{username}\AppData\Local\MySocialShortcutTooltab
       Adds the file TooltabExtension.dll"="11/21/2019 8:15 PM, 273008 bytes, A
    In the existing folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions
       Adds the file [email protected]"="4/2/2020 10:49 AM, 226458 bytes, A

Registry details [View: All details] (Selection)
------------------------------------------------
    [HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings]
       "ognogdhldnmmaggmfoahbdnagnbhhlmj"="REG_SZ", "B7DC2AFB9FEE8B79E5E8CA28C04303784F8973CE124A65BA2E5883514D6CE5E5"
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
       "Start Page" = REG_SZ, "https://hp.myway.com/mysocialshortcut/ttab02/index.html?n={n}&p2={p2}&ptb={ptb}&coid={coid}"
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\MySocialShortcutTooltab Uninstall Internet Explorer]
       "DisplayName"="REG_SZ", "MySocialShortcut Internet Explorer Homepage and New Tab"
       "HelpLink"="REG_SZ", "http://support.mindspark.com/"
       "Publisher"="REG_SZ", "Mindspark Interactive Network, Inc."
       "UninstallString"="REG_SZ", "Rundll32.exe "C:\Users\{username}\AppData\Local\MySocialShortcutTooltab\TooltabExtension.dll" U uninstall:MySocialShortcut"
       "URLInfoAbout"="REG_SZ", "http://support.mindspark.com/"
    [HKEY_CURRENT_USER\Software\MySocialShortcut]
       "Start Page"="REG_SZ", "https://hp.myway.com/mysocialshortcut/ttab02/index.html?n={n}&p2={p2}&ptb={ptb}&coid={coid}"
       "UnInstallSurveyUrl"="REG_SZ", "https://@{downloadDomain}.dl.myway.com/uninstall.jhtml?c={ptb}&ptb={p2}"
The Malwarebytes scan log:

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 4/2/20
Scan Time: 10:58 AM
Log File: 16b41158-74c0-11ea-8370-00ffdcc6fdfc.json

-Software Information-
Version: 4.1.0.56
Components Version: 1.0.859
Update Package Version: 1.0.21778
License: Premium

-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: {computername}\{username}

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 234055
Threats Detected: 23
Threats Quarantined: 23
Time Elapsed: 18 min, 42 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 0
(No malicious items detected)

Module: 1
PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\LOCAL\MySocialShortcutTooltab\TooltabExtension.dll, Quarantined, 1813, 356944, , , , 

Registry Key: 2
PUP.Optional.MindSpark.Generic, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\MySocialShortcutTooltab Uninstall Internet Explorer, Quarantined, 1813, 356944, , , , 
PUP.Optional.MindSpark.Generic, HKCU\SOFTWARE\MySocialShortcut, Quarantined, 1813, 444113, 1.0.21778, , ame, 

Registry Value: 4
PUP.Optional.MindSpark.Generic, HKCU\SOFTWARE\MySocialShortcut|START PAGE, Quarantined, 1813, 444113, 1.0.21778, , ame, 
PUP.Optional.MindSpark.Generic, HKCU\SOFTWARE\MySocialShortcut|UNINSTALLSURVEYURL, Quarantined, 1813, 769449, 1.0.21778, , ame, 
PUP.Optional.MindSpark, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\MySocialShortcutTooltab Uninstall Internet Explorer|PUBLISHER, Quarantined, 709, 352442, 1.0.21778, , ame, 
PUP.Optional.MindSpark.Generic, HKCU\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Default\extensions.settings|ognogdhldnmmaggmfoahbdnagnbhhlmj, Quarantined, 1813, 443121, , , , 

Registry Data: 1
PUP.Optional.MindSpark, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Replaced, 709, 293497, 1.0.21778, , ame, 

Data Stream: 0
(No malicious items detected)

Folder: 3
PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\LOCAL\MySocialShortcutTooltab, Quarantined, 1813, 356944, 1.0.21778, , ame, 
PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Local Extension Settings\ognogdhldnmmaggmfoahbdnagnbhhlmj, Quarantined, 1813, 443121, , , , 
PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\OGNOGDHLDNMMAGGMFOAHBDNAGNBHHLMJ, Quarantined, 1813, 443121, 1.0.21778, , ame, 

File: 12
PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\LOCAL\MySocialShortcutTooltab\TooltabExtension.dll, Quarantined, 1813, 356944, 1.0.21778, , ame, 
PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}.default\EXTENSIONS\[email protected], Quarantined, 1813, 782571, 1.0.21778, , ame, 
PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, 1813, 443121, , , , 
PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Replaced, 1813, 443121, , , , 
PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ognogdhldnmmaggmfoahbdnagnbhhlmj\000003.log, Quarantined, 1813, 443121, , , , 
PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ognogdhldnmmaggmfoahbdnagnbhhlmj\CURRENT, Quarantined, 1813, 443121, , , , 
PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ognogdhldnmmaggmfoahbdnagnbhhlmj\LOCK, Quarantined, 1813, 443121, , , , 
PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ognogdhldnmmaggmfoahbdnagnbhhlmj\LOG, Quarantined, 1813, 443121, , , , 
PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ognogdhldnmmaggmfoahbdnagnbhhlmj\MANIFEST-000001, Quarantined, 1813, 443121, , , , 
PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\OGNOGDHLDNMMAGGMFOAHBDNAGNBHHLMJ\13.924.17.40984_0\MANIFEST.JSON, Quarantined, 1813, 443121, 1.0.21778, , ame, 
PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\OGNOGDHLDNMMAGGMFOAHBDNAGNBHHLMJ\13.924.17.40984_0\CONFIG\CONFIG.JSON, Quarantined, 1813, 456842, 1.0.21778, , ame, 
PUP.Optional.MindSpark, C:\USERS\{username}\DESKTOP\MYSOCIALSHORTCUT.EXE, Quarantined, 709, 365288, 1.0.21778, , ame, 

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


(end)
As mentioned before the full version of Malwarebytes could have protected your computer against this threat.
We use different ways of protecting your computer(s):
  • Dynamically Blocks Malware Sites & Servers
  • Malware Execution Prevention
Save yourself the hassle and get protected.
  • 0

Advertisements






Also tagged with one or more of these keywords: mindspark

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

featured
Malware Removal How to Guides Windows 7 System Building Download Files Register welcome

Never used a forum? Learn how.