Toolbar.MyWebSearch

Por GoldSparrow em Falsas Mensagens de Erro
Traduzir Para:

Cartão de pontuação de ameaças

Popularity Rank: 4,420
Nível da Ameaça: 50 % (Médio)
Computadores infectados: 150,679
Visto pela Primeira Vez: July 24, 2009
Visto pela Última Vez: May 26, 2026
SO (s) Afetados: Windows


O Toolbar.MyWebSearch, também chamado de W32/Toolbar.MyWebSearch, é exibido em alertas de segurança falsificados e em falsas janelas popup no desktop, geradas por um aplicativo anti-spyware nocivo, conhecido como Antivirus XP 2008. Esse método é usado para intimidar o usuário e faze-lo crer que o computador foi comprometido e, em seguida, convida-o a adquirir e instalar o falso removedor de spyware do Antivirus XP 2008, a fim de resolver esse problema.

Outros Nomes

15 fornecedores de segurança sinalizaram este arquivo como malicioso.

Antivirus Vendor Detecção
Ikarus not-a-virus:AdWare.Win32
eTrust-Vet Win32/SillyBHO.GNX
Kaspersky not-a-virus:WebToolbar.Win32.MyWebSearch.mg
NOD32 a variant of Win32/Toolbar.MyWebSearch.Q
AVG Generic_r.CRO
Ikarus Application.ExqPage
Sophos Generic PUA DD
Kaspersky Trojan.Win32.Staser.fv
McAfee Artemis!56C4466FC3B4
AntiVir ADSPY/MyWebS.A.60.C
F-Secure Toolbar:W32/MyWebSearch.B
NOD32 Win32/Toolbar.MyWebSearch
Fortinet W32/AdInstaller
AhnLab-V3 PUP/Win32.FunWeb
Comodo ApplicUnwnt.Win32.AdWare.FunWeb.DA

SpyHunter detecta e remove Toolbar.MyWebSearch

Detalhes Sobre os Arquivos do Sistema

Toolbar.MyWebSearch pode criar o(s) seguinte(s) arquivo(s):
# Nome do arquivo MD5 Detecções
1. mngr.exe ebba16a88f517bfb1b7681abf006c8b0 1,943
2. MWSOEMON.EXE d16afe4928c5686ade1e3e8553f3633b 237
3. n. 23e659658f22829a9f718e0e827a3ce0 31
4. L7_Start.exe 6f575d4c91ea22a23c993a52ce0ec82e 19
5. ScreenResolutionManager.exe 385fab9ea337a58c613eacc79383f3ae 17
6. setup.exe bf09329db30f9e3e3b11b04b90f2d249 16
7. czxgdkrtg.dll af44fa29756cd3fc27d60f01ef960e7b 14
8. wgsdgsdgdsgsd.exe 6bdb245eaf6b20c57fc012d7e0afbe1a 13
9. trojankiller.exe 5110b527283b5b3549b5dc65942f253c 11
10. kiki.sys fd592502d8871bad9eb2ef1d8135b386 10
11. WinVNC.exe ce13b222c925a6dc75be4b578fbd4d58 10
12. Nbt.exe 0e22d1901e7461e876f5e77508a4d0c3 9
13. hostc.exe d7255b2417f078ea324dcd8ed993d94f 6
14. HBLiteSA.exe 789f8a073c244a7957ac08afb630c92a 6
15. winini.exe 0615ccf5949d05b2dae2c6c87dc0acbc 5
16. c_2C_2.exe 1faaa43f4ea20c9a256d21ca7bc489c7 4
17. panmap.exe 38faf4975964aa84d098634e042c93bc 3
18. 6BED.exe 7fea8194a339d027cfe255d1ecfad08e 2
19. winlogon.exe f0f8665930c451a7fea811a1fe9e2caa 2
20. M3PLUGIN.DLL 7075cb51f200cfb073efe82e12c2f9d1 2
21. 8gquqFX0a.exe 47469a8a7ff8a67320c5d2a39d9870a3 2
22. bgamrgbw.exe 815c909a0a7061b2ac1ddb3cccc91203 2
23. FireFoxWH.dll 9179bef3040e1a98c93c90810df401ee 1
24. C600.exe 40e065a53f345c8fbe5c3da98c7bd9e6 1
25. 905290.exe 3a17734faf7d3d93de1c7cfd7bfad997 1
26. keywordtabhper.exe 690a7e735a832fc3f20eff0f6a22433c 1
27. hhFFWORCdGYZ.exe 0e95de79cab7c90f67eb1d7f3e063930 1
Arquivos Adicionais

Detalhes sobre o Registro

Toolbar.MyWebSearch pode criar a seguinte entrada de registro ou entradas de registro:
CLSID
{01947140-417F-46B6-8751-A3A2B8345E1A}
{07B18EA9-A523-4961-B6BB-170DE4475CCA}
{07B18EAA-A523-4961-B6BB-170DE4475CCA}
{1093995A-BA37-41D2-836E-091067C4AD17}
{120927BF-1700-43BC-810F-FAB92549B390}
{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}
{1F52A5FA-A705-4415-B975-88503B291728}
{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}
{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}
{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
{3E1656ED-F60E-4597-B6AA-B6A58E171495}
{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}
{3E720451-B472-4954-B7AA-33069EB53906}
{3E720453-B472-4954-B7AA-33069EB53906}
{48586425-6bb7-4f51-8dc6-38c88e3ebb58}
{72EE7F04-15BD-4845-A005-D6711144D86A}
{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}
{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}
{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}
{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}
{7473D298-B7BB-4F24-AE82-7E2CE94BB6A9}
{819FFE21-35C7-4925-8CDA-4E0E2DB94302}
{8E9CF769-3D3B-40EB-9E2D-76E7A205E4D2}
{90449521-D834-4703-BB4E-D3AA44042FF8}
Software\AppDataLow\Software\mywebsearch
Software\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}
Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
SOFTWARE\mywebsearch
Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
SOFTWARE\Wow6432Node\MyWebSearch
SYSTEM\ControlSet001\services\eventlog\Application\WsysSvc
SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\{F921DE4A-6917-4EB4-8A1B-764259B8DB5E}
SYSTEM\ControlSet002\services\eventlog\Application\WsysSvc
SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\{F921DE4A-6917-4EB4-8A1B-764259B8DB5E}
SYSTEM\CurrentControlSet\services\eventlog\Application\WsysSvc
SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\{F921DE4A-6917-4EB4-8A1B-764259B8DB5E}

Diretórios

Toolbar.MyWebSearch pode criar o seguinte diretório ou diretórios:

%PROGRAMFILES%\mywebsearch
%PROGRAMFILES(x86)%\mywebsearch
%UserProfile%\AppData\LocalLow\mywebsearch

URLs

Toolbar.MyWebSearch pode chamar os seguintes URLs:

https://hp.mywebsearch.com/

Relatório de análise

Informação geral

Family Name: MyWebSearch
Signature status: No Signature

Known Samples

MD5: 720d5f515e3eff6ea7ab6ca695ac0e07
SHA1: 430e255c96b23242e336166dd37a9e6fd21d715d
SHA256: 55AFAF16621B61F31AE641C723D6DA166485F90284601F4088F96F1D5B79A02C
Tamanho do Arquivo: 24.58 KB, 24576 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Nome Valor
Company Name MyWebSearch.com
File Description My Web Search Plugin Stub for 32-bit Windows
File Extents mws
File Open Name My Web Search Plugin Stub
File Version 1, 0, 0, 0
Internal Name MyWebSearchPluginStub
Legal Copyright Copyright © 2005
M I M E Type application/x-mws-mywebsearchplugin
Original Filename NPMyWebS.DLL
Product Name My Web Search Plugin Stub
Product Version 2, 1, 5, 0

File Traits

  • dll
  • x86

Block Information

Total Blocks: 10
Potentially Malicious Blocks: 4
Whitelisted Blocks: 6
Unknown Blocks: 0

Visual Map

x 0 0 0 0 0 x 0 x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\430e255c96b23242e336166dd37a9e6fd21d715d_0000024576.,LiQMAxHB

Tendendo

Mais visto

Carregando...