The Malware Dictionary

The Latest Computer Adware, Spyware, and Virus Info!

My Web Search Removal Tips

Tags: , , , , , , , ,

My Web Search is an Internet Explorer toolbar that is bundled with the Fun Web Products suite of applications. Other programs in the suite include Cursor Mania, My Mail Signature, My Mail Stationary, PopSwatter, My Way website portal, and Webfetti. My Web Search is sometimes labeled as Spyware, although a better categorization of the program is as a computer annoyance. All of the programs in the suite of products uses tracking cookies which could be exploited to obtain personally identifiable information about your computer usage. The utilities will also use computer resources when installed on your computer and are found by most of the current anti-spyware programs.

My Web Search will also “hi-jack” your default homepage attempting to have you use their default portal for the Internet Explorer homepage. The results returned to you when using the tool will force you to view responses from Ask.com’s search portal. Although, this practice is not directly considered adware, it is considered an aggressive tactic to drive the user to using a specific resource providers data and resulting advertisements.

My Web Search's Uninstall Screen. Steve Sims from Wikimedia Commons

My Web Search's Uninstall Screen. Steve Sims from Wikimedia Commons

How Do You Remove My Web Search?

The first step to removing My Web Search from your computer is through the add/remove programs feature of your operating system. To remove My Web Search:
1 – Select the Start menu on your computer and choose the “Control Panel” menu option.
2 – Choose the Add/Remove programs menu option and then find My Web Search on the list of installed programs.
3 – Single left click the add/remove program button beside My Web Search. If you see these programs listed from the Fun Web Products Suite you will also want to remove them from your computer:
My Way Speedbar (AOl, Yahoo, Outlook, Outlook Express, IncrediMail, or Smiley Central)
Search Assistant – My Way
4 – Restart your computer in Windows safe mode by depressing the F8 key during the rebooting process.
5 – Open your computer’s local or C drive in your file explorer. Then, open the Program files folder
6.- RIght click and delete the following folders: FunWebProducts, MyWebSearch.
7 – Restart your computer and My Web Search will be removed.

Files Associated with My Web Search

%program_fiels%\MyWebSearch
%program_files%\MyWebSearch\bar\1.bin\mwsbar.dll
%program_files%\MyWebSearch\bar\mwssetup.exe
%program_files%\MyWebSearch\srchastt\1.bin\mwssrcas.dll
%program_files%\MyWebSearch\srchastt\mwssrcsp.exe

Registry Values Associated with My Web Search

HKEY_CURRENT_USER\Control Panel\Desktop@^SCRNSAVE.EXE^=^C:\WINDOWS\system32\f3PSSavr.scr
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&Search@^http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZRxdm185YYIN
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar@^{F4D76F09-7896-458a-890F-E1F05C46069F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run@^MyWebSearch Plugin
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser@^{07B18EA9-A523-4961-B6BB-170DE4475CCA}
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser@^{37B85A29-692B-4205-9CAD-2626E4993404}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes@^DefaultScope^=^{56256A51-B582-467e-B8D4-7786EDA79AE0}
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks@^{9CB65206-89C4-402c-BA80-02D8C59F9B1D}
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser@^{FE063DB9-4EC0-403E-8DD8-394C54984B2C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar@^{FE063DB9-4EC0-403e-8DD8-394C54984B2C}
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks@^{0A94B116-4504-4e26-AB05-E61E474AA38B}
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes@^DefaultScope^=^{56256A51-B582-467e-B8D4-7786EDA79AE0}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar@^{8EAB99C9-F9EC-4b64-A4BA-D9BCAE8779C2}

Automatically Removing My Web Search from Your Computer

After you have taken manual action to remove My Web Search from your computer, you should run updated anti-spyware or anti-virus software to ensure you have fully removed the program automatically from your computer along with its associated registry entries.

Rogue Anti-Spyware Programs – Vista Antivirus 2008

Tags: , , , , , , ,

The Vista Antivirus 2008 program is one of the family of rogue or fake anti-spyware programs that are really computer spyware and are downloaded to computer user’s computers without their consent.

Vista Antivirus 2008 Description

The Vista Antivirus 2008 is installed many times by taking advantage of Security holes or flaws in the Internet Explorer web browser. It is normally a payload of a Trjoan Virus or Trojan Virus downloader. Once installed on your computer, Vista Antivirus 2008 will display a number of fake security threat messages to tell you that your computer is infected with Spyware. The ultimate goal of Vista Antivirus 2008 is to trick you into buying the commercial version of the software on your computer. If you do, then instead of fixing your problem, you have now paid a hacker to download additional computer malware and spyware onto the computer.

Indications that Your Computer is Infected with Vista Antivirus 2008

One of the hardest things to determine with modern-day spyware is if your computer is infected. If you have the Vista Antivirus 2008 spyware installed, then you will see a number of pop-up messages similar to the following:

-”Your system is infected with a dangerous Virus”

- “Warning! Spyware is detected on Your Computer”

- “Your computer is infected, Windows has detected spyware infection!”

Just by clicking on one of the warnings can result in additional malware being installed on your computer.

Other Actions by Vista Antivirus 2008

The rogue anti-spyware program Vista Antivirus 2008 mal also perform the following actions on your computer:

-         Download and execute additional computer malware and spyware

-         Continue to generate numerous fake security warnings

-         Significantly slow down your computer

-         Hijack your computer browser and take you to infected, malicious websites to download additional computer malware and spyware.

Vista Antivirus 2008 Files and Registry Entries

\Program Files\Antivirus 2008
\Program Files\Antivirus 2008\Antvrs.exe
\Documents and Settings\forensics\Start Menu\Antivirus
\Documents and Settings\forensics\Desktop\antvrs.exe
\Documents and Settings\forensics\Application Data\Antivirus
\Documents and Settings\forensics\Local Settings\Temporary Internet Files\Content.IE5\0L6FS9QR\instlog[1].htm
\Documents and Settings\forensics\Local Settings\Temporary Internet Files\Content.IE5\IQJ9X5GB\antvrs[1].exe

\Documents and Settings\forensics\Start Menu\Antivirus\Antivirus 2008.lnk
\Documents and Settings\forensics\Start Menu\Antivirus\Uninstall Antivirus.lnk

Associated Vista Antivirus 2008 Windows Registry Information:

HKEY_CURRENT_USER\Software\Antivirus
HKEY_LOCAL_MACHINE\SOFTWARE\Antivirus
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Antivirus”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Antivirus2008y”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce “3P_UDEC”

Vista Antivirus 2008 Removal Information

Vista Antivirus 2008 is complex and it is not recommended to attempt manual removal. Automatic removal using an updated anti-virus program is the recommended means for removal. If you are seeing what you believe to be “Fake” infection notifications, then your computer is likely already infected with the Spyware and the Trojan virus that deployed the malware.

What is a Keylogger?

Tags: , , , , , , ,

Keyloggers are the specialized computer Spyware programs, which are capable of recording everything you type on the computer’s keyboard. This malicious software will enable the creator to retrieve this information later and can help them in consequently discovering your passwords, account numbers, user names and other confidential and sensitive data. The creator can gather the entire knowledge of the user’s web surfing habits and can even read the personal emails. They are extremely powerful software applications that can lead to identity theft.

The level of sophistication of the Keyloggers has greatly increased in the recent times. They even have the capability to record the keystrokes even if you are not logged in. These programs will silently run in the background undetectably. They are capable spying on the active applications by taking their text snapshots. The latest Keyloggers can be turned on even remotely.

How Does Your Computer Gets Infected by KeyLoggers?

Downloading content from Internet is the major way of getting a Keylogger. The files you download from internet may have a keylogger or any other variety of malicious Spyware or other computer malware. These can also enter your system as attachments to an e-mail.

Keyloggers can be used for many ethical, legal and beneficial actions too. The keylogger programs can be used by the parents for keeping an eye on the online activities of kids. This can greatly help the parents in protecting the children from offensive content as well as predators.

You must somehow avoid being infected from this computer Spyware, as it is extremely malicious. You may not know even if your system is infected. You can avoid the attack of this spyware to a great extend by downloading music, software and other files from the trusted and reputed sites. You must also keep away from the email attachments from unknown senders. You must make its sure that the attachments are clean and safe before opening them even though they are from known sources. Installing a top quality anti spyware program can be a great thing to do in order to protect your system from Keyloggers and other malicious spyware. Anyhow, keeping your PC safe from spyware is important to keep you private data safe and avoiding identity theft.

Rogue Anti-Spyware Software- Malware Alarm

Tags: , , , , , , , , , ,

Malware Alarm is one of the numerous rogue anti-spyware programs on the Internet that are really a variant of computer spyware. Malware Alarm will attempt to trick you into purchasing the full commercial version of the product by displaying fake infection messages every time that you restart Windows. If you click “Ok” on one of the warning messages that Malware Alarm displays, it will automatically load the parent website of the malware in your Web Browser. It may or may not then automatically install the primary payload on your computer. Malware Alarm can be difficult to remove from your computer and will serve as a gateway to additional computer malware being downloaded to your computer. It is also known to be distributed as the payload of Trojan Viruses such as Zlob.

Malware Alarm Payload

Malware Alarm has been known to have done the following actions:

-         Install on your computer without consent via Web Browser exploit.

-         Serve as a gateway to additional computer spyware and adware.

-         Hijack your Web Browser and change the hosts file redirecting major website URL’s such as Google, Bing, and Yahoo

-         Display numerous advertising pop-ups on your computer

-         Violate your privacy and send personal information to remote web servers.

Malware Alarm Symptoms

You don’t necessarily know if you have Malware Alarm on your computer. Some of the potential symptoms you may see on your computer are:

-         Conspicuous firewall warnings for Malware Alarm attempting to communicate with remote web servers from your computer.

-         Significant increase in the number of advertisements displayed on your computer.

-         The default homepage for your web browser has changed to a site you are unfamiliar with and you are unable to change it back.

-         Your overall computer performance is significantly reduced.

Malware Alarm Files

If your computer is infected with the rogue anti-spyware program Malware Alarm, you will have the following files installed on your computer:

-         winter.exe

-         proper.exe

-         infos.exe

-         autos.exe

-         MalwareAlarmSetup[1].exe

-         MalwareAlarm.exe

-         MalwareAlarm3.dll

-         MalwareAlarm2.dll

-         MalwareAlarm1.dll

-         MalwareAlarm0.dll

Malware Alarm Removal Information

Malware Alarm is complex and it is not recommended to attempt manual removal. Automatic removal using an updated anti-virus program is the recommended means for removal. If you are seeing what you believe to be “Fake” infection notifications, then your computer is likely already infected with the Spyware and the Trojan virus that deployed it to your computer.

How Does Spyware Work?

Tags: , , , , , , ,

Computer Spyware infects a computer without the user’s permission. Spyware can be very dangerous to your personal privacy and can serve as a gateway to additional computer malware infection on your computer. Spyware by its nature does not self-replicate, but is used to exploit holes in the security on your computer. Recent trends have seen a significant rise in fake anti-spyware programs on the Internet that have been used to trick users into downloading additional spyware and malware to their computers.

Types of Computer Spyware

Four of the common types of computer spyware are: Adware, Browser Hijackers, Keyboard Loggers, and Modem Hijackers.

Adware

Not all Adware is bad. There is a growing population of Adware, however, that collect and send information to remote servers from your computer. This information includes web surfing history, advertisement clicks, etc. The rogue adware variants are also known to be bundled with other computer malware that could be installed on your computer.

Browser Hijack
A large amount of spyware will attempt to take over your web browser and modify the hosts file that determines what uniform resource locator is used to correlate to major search engine websites such as Yahoo, Bing, and Google. They will also force your browser to open rogue websites that pretend to be security centers of major providers online. The hijacked websites will then download computer malware to your computer and result in further infection.

Keyboard Logger
Keyboard loggers are one of the most dangerous variants of Spyware. Their sole purpose is to steal your private information and send it to a hacker for further use. This can be anything from your bank records, to email, to any other site that requires a login and password.

Modem Hijackers

Less prevalent today in the age of broadband connections, Modem Hijackers are still dangerous to computer users who have to use dial-up to connect to the Internet. A modem Hijacker will call a phone number that has a high per-minute charge and will run your phone bill up.

© 2009 The Malware Dictionary. All Rights Reserved.

This blog is powered by Wordpress and Magatheme by Bryan Helmig.