The Malware Dictionary

The Latest Computer Adware, Spyware, and Virus Info!

My Web Search Removal Tips

Tags: , , , , , , , ,

My Web Search is an Internet Explorer toolbar that is bundled with the Fun Web Products suite of applications. Other programs in the suite include Cursor Mania, My Mail Signature, My Mail Stationary, PopSwatter, My Way website portal, and Webfetti. My Web Search is sometimes labeled as Spyware, although a better categorization of the program is as a computer annoyance. All of the programs in the suite of products uses tracking cookies which could be exploited to obtain personally identifiable information about your computer usage. The utilities will also use computer resources when installed on your computer and are found by most of the current anti-spyware programs.

My Web Search will also “hi-jack” your default homepage attempting to have you use their default portal for the Internet Explorer homepage. The results returned to you when using the tool will force you to view responses from Ask.com’s search portal. Although, this practice is not directly considered adware, it is considered an aggressive tactic to drive the user to using a specific resource providers data and resulting advertisements.

My Web Search's Uninstall Screen. Steve Sims from Wikimedia Commons

My Web Search's Uninstall Screen. Steve Sims from Wikimedia Commons

How Do You Remove My Web Search?

The first step to removing My Web Search from your computer is through the add/remove programs feature of your operating system. To remove My Web Search:
1 – Select the Start menu on your computer and choose the “Control Panel” menu option.
2 – Choose the Add/Remove programs menu option and then find My Web Search on the list of installed programs.
3 – Single left click the add/remove program button beside My Web Search. If you see these programs listed from the Fun Web Products Suite you will also want to remove them from your computer:
My Way Speedbar (AOl, Yahoo, Outlook, Outlook Express, IncrediMail, or Smiley Central)
Search Assistant – My Way
4 – Restart your computer in Windows safe mode by depressing the F8 key during the rebooting process.
5 – Open your computer’s local or C drive in your file explorer. Then, open the Program files folder
6.- RIght click and delete the following folders: FunWebProducts, MyWebSearch.
7 – Restart your computer and My Web Search will be removed.

Files Associated with My Web Search

%program_fiels%\MyWebSearch
%program_files%\MyWebSearch\bar\1.bin\mwsbar.dll
%program_files%\MyWebSearch\bar\mwssetup.exe
%program_files%\MyWebSearch\srchastt\1.bin\mwssrcas.dll
%program_files%\MyWebSearch\srchastt\mwssrcsp.exe

Registry Values Associated with My Web Search

HKEY_CURRENT_USER\Control Panel\Desktop@^SCRNSAVE.EXE^=^C:\WINDOWS\system32\f3PSSavr.scr
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&Search@^http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZRxdm185YYIN
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar@^{F4D76F09-7896-458a-890F-E1F05C46069F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run@^MyWebSearch Plugin
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser@^{07B18EA9-A523-4961-B6BB-170DE4475CCA}
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser@^{37B85A29-692B-4205-9CAD-2626E4993404}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes@^DefaultScope^=^{56256A51-B582-467e-B8D4-7786EDA79AE0}
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks@^{9CB65206-89C4-402c-BA80-02D8C59F9B1D}
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser@^{FE063DB9-4EC0-403E-8DD8-394C54984B2C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar@^{FE063DB9-4EC0-403e-8DD8-394C54984B2C}
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks@^{0A94B116-4504-4e26-AB05-E61E474AA38B}
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes@^DefaultScope^=^{56256A51-B582-467e-B8D4-7786EDA79AE0}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar@^{8EAB99C9-F9EC-4b64-A4BA-D9BCAE8779C2}

Automatically Removing My Web Search from Your Computer

After you have taken manual action to remove My Web Search from your computer, you should run updated anti-spyware or anti-virus software to ensure you have fully removed the program automatically from your computer along with its associated registry entries.

How Does Tabjacking Work?

Tags: , , , , , ,

Mozilla’s FireFox made Internet Browser tabs popular and Internet Explorer followed suit with quicking adopting tabs into their web browser. As with all technology, a new threat that emerged was “Tabjacking”. Tabjacking emerged as a threat in early 2007. It refers to hackers introducing malicious code into your computer’s borwser where one of the browser tbas will fall under their control and be directed to a potentially malicious website. They can also use the hijacking or tabjacking to display adware and other annoyances on your computer.

Internet Browser Tabs

Mozilla Firefox made web surfing with multiple tabs popular with Internet surfers. Firefox was the first browser to incorporate tabs and Microsoft’s Internet Explorer followed suit with IE 7. It reduces the number of browser windows that you have to open on your computer when surfing across multiple websites and can take up less memory on your computer by not opening as many concurrent computer processes.

How Tabjackers Gain Control of Your Browser’s Tab

Internet Browser tabs are another potential Internet Browser exploitation target. If a hacker can gain control of a browser tab on your computer’s Internet Browser, then they can use the “Tabjacked” tab to load computer malware on your computer, or display variants of “pop-under” or “pop-up” advertisements. This type of ad doesn’t have a unique name yet…maybe “tabvertisement”? This is just an annoyance, however, as the real danger lies in opening a malicious website that can inject malicious code on your computer such as Spyware or Trojan virus downloaders than can serve as gateways to additional computer malware being installed on your computer without your permission. Tabjackers could also display “fake” webpages for commonly used banking and other websites where you might be tricked into entering your credit card or other financial information. Tabjacking normally occurs from hackers taking advantage of Browser security vulnerabilities on computers that are not running up-to-date anti-virus software or out of date operating systems.

How to Defend Against Tabjacking

The best way to defend against Tabjacking is to keep your Operating System and Web Browser up to date with all current software updates and to run current anti-virus protection. Once you are infected, you will likely notice an increase in adware and spyware being run on your computer which requires a greater level of effort to remove than keeping your browser from being tabjacked in the first place.

How Does Adware Work?

Tags: , , , , , , , ,

Adware is considered to be any computer software that will display, download, or automatically play advertisements on your computer while the parent application is being used. Some adware is designed to violate your privacy and acts as a benign form of Spyware and is considered privacy-invasive. Many variants of Adware can also bog down your computer with the number of advertisements and increased bandwidth usage if they are designed to display contextual advertisements on your computer as well as work in conjunction with other computer malware to negatively impact your computer. 

Adware Applications

Adware is typically bundled with other software that you want to use. Developers that include adware with their applications use it as a means to help make additional money on the cost of making the software and many say it allows them to reduce the cost of their product. Many users see adware as an uninvited interruption or distraction from their computer work. This is even after a lot of adware embedded applications include in their End-User License Agreement a statement to the effect that the user agrees to the installation and display of advertisements with the software product.
Adverse Effects of Removing Adware
Before you start removing all adware on your computer, you need to take a look at what application is the culprit for the ads. If it is a free, or low cost version of you favorite program, putting up with the Ads may be the “cost of war” for using the reduced cost version of the product. Conducting a basic search on Malware Dictionary or Google to see if the Adware is listed as a rogue program or not. If it is benign, you may find it more useful to keep using the shareware with the Ads than to lose the program altogether. Many bundled applications will cease to work if you remove their Adware component. Good adware will also typically let you remove it through the “Add/Remove Programs” feature in Microsoft Windows.

Computer Malware, Types of Spyware

Tags: , , , , , , , , , , , , , , ,

Computer Spyware is computer malware that infects a user’s computer without their permission. It can be used to steal your private information to a remote computer server and is known to change settings to include: 1 – The Default Search Engine Home Page, 2 – The computer’s default home page, and 3 – Serve as a means to further infect the computer with additional malware. Unlike other computer viruses, Spyware is not normally designed to self-replicate, but rather is made to exploit security vulnerabilities on your computer. Recent developments in computer spyware have seen fake anti-spyware programs deployed in order to trick a user into downloading additional spyware to their computer.

Types of Computer Spyware

Adware

Adware is one of the most common types of spyware on the Internet. Adware normally waits for the user to go online and then displays unsolicited advertisements in the form of pop-up, pop-under, and pop-over advertisements. It also records what websites you visit and sends back to remote computer servers. Some adware variants are knowingly installed by computer users while others are not.

Browser Hijack
Many variants of spyware will hijack your web browser and change your default homepage to one determined by the author of the spyware. Many will also hijack the uniform resource locator (URL) for the major search engines so that your browser is redirected to fake search sites chosen by the spyware author. Browser hijackers will also display unsolicited advertisements upon opening the web browser and send records of your web browser to a remote web server.

Keyboard Logger
Keyboard loggers are designed in order to steal your private information. They are capable of recording the information used to access your bank records, email, and any other website that you use a password or pin number to access. Keyboard loggers are one of the most dangerous variants of computer Spyware due to their ability to steal your private information.

Modem Hijackers

Although these are becoming less prevalent with the migration of Internet users to broadband Internet connections, modem hijacking Spyware still exists. This variant of spyware normally infects your computer as a payload of a Trojan virus or through a peer-to-peer file sharing network. They are also referred to as “Dialers.” Once your computer is infected with a Dialer, the Spyware will dial long distance, premium rated phone numbers that cost you a significant amount of money if not detected early.

Win32.ZangoShoppingReports Adware

Tags: , , , , , , , ,

 

Description of ZangoShoppingreports Adware

ZangoShoppingReports is an adware that pops up the ads to the infected system. It is a kind of unethical adware, which displays ads and even without the consent of the users, it directs the user to e-commerce and business websites. This adware is designed in such a way that it is difficult to uninstall it. This adware will display the targeted advertising into the infected systems while the user is browsing the internet and it will be based on the search items that are entered in to search engines.

Installation of ZangoShoppingreports Adware

When ZangoShoppingreports is installed on the computer, it will perform the actions such as:

Creating the folders like ‘%ProgramFiles%\shoppingreport’ and %APPDATA%\shoppingreport’ and creates the files such as ‘%ProgramFiles%\shoppingreport\cs\persist.dbs’ and ‘%APPDATA%\shoppingreport\cs\persist.dbs’

Characteristics of ZangoShoppingreports Adware

Displays advertisements

Records personal keystrokes or data

Hijacks the internet browser

Downloads files that are unsolicited

Allows remote influence

Disables system or programs that are running

Exploits the security flaw

Unauthorized phone calls are made

Distributes various threats

Using the cookies, it tracks the browsing activity

With the help of installed applications, it tracks the browsing activity

Without the user consent, installs programs

Inadequate uninstall procedures  

Excessive resources of the system is used

Insufficiency privacy consent and disclosure

Performs silent updates

Fraudulent claims are made regarding the spyware detection and removal as well.

Symptoms of ZangoShoppingreports Adware

Some of the following changes in the computer will indicate the presence of the ZangoShoppingreports.

Presence of the folders such as ‘%ProgramFiles%\shoppingreport’ and ‘%APPDATA%\shoppingreport’ and presence of the files such as %ProgramFiles%\shoppingreport\cs\persist.dbs’ and %APPDATA%\shoppingreport\cs\persist.dbs’

Zango ShoppingReports Adware Removal Steps

Zango Shopping Reports Adware will significantly slow down your computer. As a result, you should remove Zango Shopping Reports Adware using an anti-spyware program if you are not savvy with registry modifications and computer security. Click here for automatic removal instructions for removing Zango Shopping Reports.

© 2009 The Malware Dictionary. All Rights Reserved.

This blog is powered by Wordpress and Magatheme by Bryan Helmig.