Threat Database Adware Adware.MyWebSearch

Adware.MyWebSearch

By GoldSparrow in Adware

Threat Scorecard

Threat Level: 20 % (Normal)
Infected Computers: 1,608
First Seen: July 24, 2009
Last Seen: October 7, 2022
OS(es) Affected: Windows

Adware.MyWebSearch is a potentially unwanted advertising program. Adware.MyWebSearch can display advertisements in the form of pop-ups, pop-unders or banners. Adware.MyWebSearch can secretly infiltrate a system and gather internet related information that it sends to a remote server. The gathered information can be used to display advertisements according to a victim's browsing history or for criminal activities such as Identity Theft.

Aliases

15 security vendors flagged this file as malicious.

Antivirus Vendor Detection
AhnLab-V3 Win-Adware/FunWeb.210992.D
Comodo ApplicUnwnt.Win32.AdWare.FunWeb.DA
Kaspersky not-a-virus:HEUR:WebToolbar.Win32.MyWebSearch.gen
ClamAV Adware.FunWeb-10
Avast Win32:FunWeb-J [PUP]
Ikarus not-a-virus:AdWare.Win32.FunWeb
Kaspersky not-a-virus:AdWare.Win32.FunWeb.kd
CAT-QuickHeal Trojan.FunWeb.ci
AVG AdInstaller.FunWeb
Ikarus not-a-virus:AdWare.Win32
eTrust-Vet Win32/SillyBHO.GOR
Kaspersky not-a-virus:AdWare.Win32.FunWeb.ji
eSafe Win32.AdInstaller
McAfee Artemis!E2EF8C1E4425
AhnLab-V3 Win-Adware/FunWeb.149048

SpyHunter Detects & Remove Adware.MyWebSearch

File System Details

Adware.MyWebSearch may create the following file(s):
# File Name MD5 Detections
1. M3SRCHMN.EXE.vir 745893a76df42b09e8d5d22803c1d14e 446
2. MWSOEMON (2015_12_02 03_55_28 UTC).EXE a8e2d2429e86ee910cff9594f8adbec8 383
3. mwsoestb.dll 60fbc1fb8b39c41cf411b6df6a7fd13a 25
4. MWSSRCAS.DLL 2c41878da18c7ac9f65aec34a2ce5b4f 23
5. F3HTMLMU.DLL dd8a6ac438b15c37624cd3ea62d18c4c 8
6. A0226343.exe 1704bd8fa9b990f771ec9d10dbca55db 8
7. MWSBAR.DLL 0ce4508e8fc2298d968156ee18094c65 3
8. mwsoemon.exe f618d90e845ec46f8bd06f9e7748647c 0
More files

Analysis Report

General information

Family Name: MyWebSearch
Signature status: No Signature

Known Samples

MD5: 720d5f515e3eff6ea7ab6ca695ac0e07
SHA1: 430e255c96b23242e336166dd37a9e6fd21d715d
SHA256: 55AFAF16621B61F31AE641C723D6DA166485F90284601F4088F96F1D5B79A02C
File Size: 24.58 KB, 24576 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name MyWebSearch.com
File Description My Web Search Plugin Stub for 32-bit Windows
File Extents mws
File Open Name My Web Search Plugin Stub
File Version 1, 0, 0, 0
Internal Name MyWebSearchPluginStub
Legal Copyright Copyright © 2005
M I M E Type application/x-mws-mywebsearchplugin
Original Filename NPMyWebS.DLL
Product Name My Web Search Plugin Stub
Product Version 2, 1, 5, 0

File Traits

  • dll
  • x86

Block Information

Total Blocks: 10
Potentially Malicious Blocks: 4
Whitelisted Blocks: 6
Unknown Blocks: 0

Visual Map

x 0 0 0 0 0 x 0 x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\430e255c96b23242e336166dd37a9e6fd21d715d_0000024576.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...