Threat Database Fake Error Messages Toolbar.MyWebSearch

Toolbar.MyWebSearch

By GoldSparrow in Fake Error Messages
Translate To:

Threat Scorecard

Popularity Rank: 4,420
Threat Level: 50 % (Medium)
Infected Computers: 150,679
First Seen: July 24, 2009
Last Seen: May 26, 2026
OS(es) Affected: Windows

Toolbar.MyWebSearch, also called W32/Toolbar.MyWebSearch, is issued in fake security alerts and fake desktop pop-up windows, generated by the rogue anti-spyware application known as Antivirus XP 2008. This method is used to intimidate the user into believing that the computer has been compromised, and is then prompted to purchase and install the fake spyware remover Antivirus XP 2008 in order to solve the problem.

Aliases

15 security vendors flagged this file as malicious.

Antivirus Vendor Detection
Ikarus not-a-virus:AdWare.Win32
eTrust-Vet Win32/SillyBHO.GNX
Kaspersky not-a-virus:WebToolbar.Win32.MyWebSearch.mg
NOD32 a variant of Win32/Toolbar.MyWebSearch.Q
AVG Generic_r.CRO
Ikarus Application.ExqPage
Sophos Generic PUA DD
Kaspersky Trojan.Win32.Staser.fv
McAfee Artemis!56C4466FC3B4
AntiVir ADSPY/MyWebS.A.60.C
F-Secure Toolbar:W32/MyWebSearch.B
NOD32 Win32/Toolbar.MyWebSearch
Fortinet W32/AdInstaller
AhnLab-V3 PUP/Win32.FunWeb
Comodo ApplicUnwnt.Win32.AdWare.FunWeb.DA

SpyHunter Detects & Remove Toolbar.MyWebSearch

File System Details

Toolbar.MyWebSearch may create the following file(s):
# File Name MD5 Detections
1. mngr.exe ebba16a88f517bfb1b7681abf006c8b0 1,943
2. MWSOEMON.EXE d16afe4928c5686ade1e3e8553f3633b 237
3. n. 23e659658f22829a9f718e0e827a3ce0 31
4. L7_Start.exe 6f575d4c91ea22a23c993a52ce0ec82e 19
5. ScreenResolutionManager.exe 385fab9ea337a58c613eacc79383f3ae 17
6. setup.exe bf09329db30f9e3e3b11b04b90f2d249 16
7. czxgdkrtg.dll af44fa29756cd3fc27d60f01ef960e7b 14
8. wgsdgsdgdsgsd.exe 6bdb245eaf6b20c57fc012d7e0afbe1a 13
9. trojankiller.exe 5110b527283b5b3549b5dc65942f253c 11
10. kiki.sys fd592502d8871bad9eb2ef1d8135b386 10
11. WinVNC.exe ce13b222c925a6dc75be4b578fbd4d58 10
12. Nbt.exe 0e22d1901e7461e876f5e77508a4d0c3 9
13. hostc.exe d7255b2417f078ea324dcd8ed993d94f 6
14. HBLiteSA.exe 789f8a073c244a7957ac08afb630c92a 6
15. winini.exe 0615ccf5949d05b2dae2c6c87dc0acbc 5
16. c_2C_2.exe 1faaa43f4ea20c9a256d21ca7bc489c7 4
17. panmap.exe 38faf4975964aa84d098634e042c93bc 3
18. 6BED.exe 7fea8194a339d027cfe255d1ecfad08e 2
19. winlogon.exe f0f8665930c451a7fea811a1fe9e2caa 2
20. M3PLUGIN.DLL 7075cb51f200cfb073efe82e12c2f9d1 2
21. 8gquqFX0a.exe 47469a8a7ff8a67320c5d2a39d9870a3 2
22. bgamrgbw.exe 815c909a0a7061b2ac1ddb3cccc91203 2
23. FireFoxWH.dll 9179bef3040e1a98c93c90810df401ee 1
24. C600.exe 40e065a53f345c8fbe5c3da98c7bd9e6 1
25. 905290.exe 3a17734faf7d3d93de1c7cfd7bfad997 1
26. keywordtabhper.exe 690a7e735a832fc3f20eff0f6a22433c 1
27. hhFFWORCdGYZ.exe 0e95de79cab7c90f67eb1d7f3e063930 1
More files

Registry Details

Toolbar.MyWebSearch may create the following registry entry or registry entries:
CLSID
{01947140-417F-46B6-8751-A3A2B8345E1A}
{07B18EA9-A523-4961-B6BB-170DE4475CCA}
{07B18EAA-A523-4961-B6BB-170DE4475CCA}
{1093995A-BA37-41D2-836E-091067C4AD17}
{120927BF-1700-43BC-810F-FAB92549B390}
{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}
{1F52A5FA-A705-4415-B975-88503B291728}
{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}
{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}
{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
{3E1656ED-F60E-4597-B6AA-B6A58E171495}
{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}
{3E720451-B472-4954-B7AA-33069EB53906}
{3E720453-B472-4954-B7AA-33069EB53906}
{48586425-6bb7-4f51-8dc6-38c88e3ebb58}
{72EE7F04-15BD-4845-A005-D6711144D86A}
{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}
{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}
{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}
{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}
{7473D298-B7BB-4F24-AE82-7E2CE94BB6A9}
{819FFE21-35C7-4925-8CDA-4E0E2DB94302}
{8E9CF769-3D3B-40EB-9E2D-76E7A205E4D2}
{90449521-D834-4703-BB4E-D3AA44042FF8}
Software\AppDataLow\Software\mywebsearch
Software\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}
Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
SOFTWARE\mywebsearch
Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
SOFTWARE\Wow6432Node\MyWebSearch
SYSTEM\ControlSet001\services\eventlog\Application\WsysSvc
SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\{F921DE4A-6917-4EB4-8A1B-764259B8DB5E}
SYSTEM\ControlSet002\services\eventlog\Application\WsysSvc
SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\{F921DE4A-6917-4EB4-8A1B-764259B8DB5E}
SYSTEM\CurrentControlSet\services\eventlog\Application\WsysSvc
SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\{F921DE4A-6917-4EB4-8A1B-764259B8DB5E}

Directories

Toolbar.MyWebSearch may create the following directory or directories:

%PROGRAMFILES%\mywebsearch
%PROGRAMFILES(x86)%\mywebsearch
%UserProfile%\AppData\LocalLow\mywebsearch

URLs

Toolbar.MyWebSearch may call the following URLs:

https://hp.mywebsearch.com/

Analysis Report

General information

Family Name: MyWebSearch
Signature status: No Signature

Known Samples

MD5: 720d5f515e3eff6ea7ab6ca695ac0e07
SHA1: 430e255c96b23242e336166dd37a9e6fd21d715d
SHA256: 55AFAF16621B61F31AE641C723D6DA166485F90284601F4088F96F1D5B79A02C
File Size: 24.58 KB, 24576 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name MyWebSearch.com
File Description My Web Search Plugin Stub for 32-bit Windows
File Extents mws
File Open Name My Web Search Plugin Stub
File Version 1, 0, 0, 0
Internal Name MyWebSearchPluginStub
Legal Copyright Copyright © 2005
M I M E Type application/x-mws-mywebsearchplugin
Original Filename NPMyWebS.DLL
Product Name My Web Search Plugin Stub
Product Version 2, 1, 5, 0

File Traits

  • dll
  • x86

Block Information

Total Blocks: 10
Potentially Malicious Blocks: 4
Whitelisted Blocks: 6
Unknown Blocks: 0

Visual Map

x 0 0 0 0 0 x 0 x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\430e255c96b23242e336166dd37a9e6fd21d715d_0000024576.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...