6xEzSetp.DLL

ReadingFanatic Easy Installer

Mindspark Interactive Network

This library is part of the Mindspark toolbar which uses the Ask.com search property to install a web browser extension and modify the browser's search, home and new tab features in order to redirect web searches to the IAC property. The module 6xEzSetp.DLL by Mindspark Interactive Network has been detected as a potentially unwanted program by 17 anti-malware scanners.
Publisher:
ReadingFanatic  (signed by Mindspark Interactive Network)

Product:
ReadingFanatic Easy Installer

Version:
1, 2, 11, 3

MD5:
2f49f194a68adc4130358221b0e6d772

SHA-1:
9f572c0266705634dba56eedbb9c1e41524cc9b4

SHA-256:
088358ccbcdf35b271758cb149aa72592c4e090ee34f576ca2266a0e972d741b

Scanner detections:
17 / 68

Status:
Potentially unwanted

Explanation:
Part of the MyWebSearch/Mindspark/Ask web browser extension and toolbar.

Analysis date:
4/25/2024 10:18:43 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Toolbar.MyWebSearch
7.1.1

avast!
Win32:Mindspark-A [PUP]
2014.9-150201

AVG
MyWebSearch
2016.0.3212

Baidu Antivirus
Adware.Win32.MyWebSearch
4.0.3.1521

Comodo Security
ApplicUnwnt.Win32.AdWare.FunWeb.DA
16713

Dr.Web
9.0.1.032

ESET NOD32
Win32/Toolbar.MyWebSearch.AC (variant)
9.10696

Fortinet FortiGate
Riskware/Toolbar_MyWebSearch
2/1/2015

G Data
Win32.Adware.Mindspark
15.2.24

Kaspersky
not-a-virus:WebToolbar.Win32.MyWebSearch
14.0.0.2554

NANO AntiVirus
Riskware.Win32.WebSearch.ddutde
0.28.6.62995

Panda Antivirus
Adware/WebSearch
15.02.01.05

Qihoo 360 Security
Win32/Virus.WebToolbar.ce0
1.0.0.1015

Reason Heuristics
PUP.Installer.Mindspark
15.2.1.5

SUPERAntiSpyware
Trojan.Agent/Gen-MyWebSearch
10081

VIPRE Antivirus
34640

Zillya! Antivirus
2.0.0.1977

File size:
798.9 KB (818,056 bytes)

Product version:
1, 2, 11, 3

Copyright:
Copyright © 2003, 2004, 2005, 2006, 2007, 2008, 2009, 2010, 2011, 2012, 2013

Original file name:
6xEzSetp.DLL

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\readingfanatic_6xei\installr\1.bin\6xezsetp.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/10/2012 1:00:00 AM

Valid to:
5/7/2015 12:59:59 AM

Subject:
CN=Mindspark Interactive Network, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Mindspark Interactive Network, L=White Plains, S=NewYork, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
098417F7EA6406EC7B320590E17A65B7

File PE Metadata
Compilation timestamp:
11/19/2013 8:58:41 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:ocxEMa0+O57B55+hDHSQoGCUQFwszC2Zr3LysDBiH1gpcySSbAxj:Tl+O5NCsV0QFnLDiH1HySSbK

Entry address:
0x1AC77

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, D4, 3B, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, E8, 38, 1B, 00, 00, 85, C0, 74, 07, 50, E8, F0, 1C, 00, 00, 59, FF, 75, 08, FF, 15, FC, 41, 02, 10, CC, 6A, 0C, 68, 18, C7, 02, 10, E8, 5B, 09, 00, 00, E8, 8B, 1B, 00, 00, 83, 65, FC, 00, FF, 70, 58, FF, 50, 54, 50, E8, C0, FF, FF, FF, 8B, 45, EC, 8B, 08, 8B, 09, 89, 4D, E4, 50, 51, E8, 06, 3A, 00, 00, 59, 59, C3, 8B, 65, E8, FF, 75, E4, E8, E0, 08...
 
[+]

Entropy:
6.7332

Code size:
136.5 KB (139,776 bytes)

Remove 6xEzSetp.DLL - Powered by Reason Core Security