ADW_WEBSEARCH.GB
HEUR:AdWare.Win32.Agent.gen(Kaspersky)
Windows
Threat Type: Adware
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Adware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
However, as of this writing, the said sites are inaccessible.
TECHNICAL DETAILS
381,792 bytes
EXE
Yes
23 May 2018
Arrival Details
This Adware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Adware drops the following files:
- %AppDataLocal%\MyNewsGuideTooltab\TooltabExtension.dll
- %User Temp%\nsz{4-Random Character}.tmp\secondary_accept.png
- %User Temp%\nsz{4-Random Character}.tmp\secondary_bg.png
- %User Temp%\nsz{4-Random Character}.tmp\secondary_decline.png
(Note: %AppDataLocal% is the Local Application Data folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Application Data on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Local on Windows Vista, 7, and 8.. %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Local\Temp on Windows Vista, 7, and 8.)
It creates the following folders:
- %AppDataLocal%\MyNewsGuideTooltab
- %User Temp%\nsz{4-Random Character}.tmp
(Note: %AppDataLocal% is the Local Application Data folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Application Data on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Local on Windows Vista, 7, and 8.. %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Local\Temp on Windows Vista, 7, and 8.)
Other System Modifications
This Adware adds the following registry entries as part of its installation routine:
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Main
Start Page = "http://hp.{BLOCKED}y.com/mynewsguide/ttab02/index.html?n=C0760ED&p2=^BXZ^mni000^TTAB02&ptb=22F86B53-C1F3-4305-B7E0-2E821BA98A78&coid=89551634c0674c6cbe1414d79a83ac78"
HKEY_CURRENT_USER\Software\MyNewsGuide
Start Page = "http://hp.{BLOCKED}y.com/mynewsguide/ttab02/index.html?n=C0760ED&p2=^BXZ^mni000^TTAB02&ptb=22F86B53-C1F3-4305-B7E0-2E821BA98A78&coid=89551634c0674c6cbe1414d79a83ac78"
HKEY_CURRENT_USER\Software\MyNewsGuide
UnInstallSurveyUrl = http://@{downloadDomain}.dl.{BLOCKED}y.com/uninstall.jhtml?surveyUrl=http%3A%2F%2Fwww.research.net%2Fr%2FHYSCVNM%3Fc%3D22F86B53-C1F3-4305-B7E0-2E821BA98A78%26ptb%3D^BXZ^mni000^TTAB02"
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\TabbedBrowsing
NewTabPageShow = "1"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Uninstall\
MyNewsGuideTooltab Uninstall Internet Explorer
DisplayName = "MyNewsGuide Internet Explorer Homepage and New Tab"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Uninstall\
MyNewsGuideTooltab Uninstall Internet Explorer
UninstallString = "Rundll32.exe "C:\Users\dyituser_732\AppData\Local\MyNewsGuideTooltab\TooltabExtension.dll" U uninstall:MyNewsGuide"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Uninstall\
MyNewsGuideTooltab Uninstall Internet Explorer
Publisher = "Mindspark Interactive Network, Inc."
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Uninstall\
MyNewsGuideTooltab Uninstall Internet Explorer
HelpLink = "http://support.{BLOCKED}ark.com/"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Uninstall\
MyNewsGuideTooltab Uninstall Internet Explorer
URLInfoAbout = "http://support.{BLOCKED}ark.com/"
Other Details
This Adware connects to the following possibly malicious URL:
- anx.{BLOCKED}ark.com
- http://hp.{BLOCKED}y.com/mynewsguide/ttab02/index.html?n=C0760ED&p2=^BXZ^mni000^TTAB02&ptb=22F86B53-C1F3-4305-B7E0-2E821BA98A78&coid=89551634c0674c6cbe1414d79a83ac78
- http://anx.tb.{BLOCKED}k.com/anx.gif?anxuu=A71BFC6F-CD51-40F1-88EA-7AD7ED85D3D1&anxa=WebTooltab&anxv=webtooltab-2.1.1&anxd=-&anxsn=&anxu=http%3A%2F%2Fhp.myway.com%2Fmynewsguide%2Fttab02%2Findex.html&anxl=en&anxlv=0&anxrd=none&anxrp=-&anxrk=-&anxrm=-&anxrb=-&anxrc=-&anxrs=-&anxsq=2&anxt=22F86B53-C1F3-4305-B7E0-2E821BA98A78&anxp=%5EBXZ%5Emni000%5ETTAB02&anxsi=&buid=17cd1617-932e-44af-a8ea-1a6f8456e564&pageType=tab&productData=%7B%22coid%22%3A%2289551634c0674c6cbe1414d79a83ac78%22%2C%22pageLoad%22%3A1%7D&anxe=Heartbeat&anxr=378732657
However, as of this writing, the said sites are inaccessible.