Home Malware Programs Browser Hijackers MySearch

MySearch

Posted: April 2, 2005

MySearch is a Potentially Unwanted Program that resets your browser's settings to promote its affiliated search site. Browser hijackers like MySearch may use marketing that describes them as beneficial to your browser. However, malware experts easily determined that MySearch offers no benefits and should not, in normal situations, be allowed to stay on your computer. Deleting MySearch should use PC security utilities that have good records for combating browser toolbars, adware and all other forms of unwanted programs.

Why Your Searches Become the Choice of MySearch

MindSpark LLC is a company that has had a lengthy history for promoting browser toolbars and related add-ons that hijack their users' Web browsers. MySearch is one of the latest members of this add-on family to be examined by malware researchers, although there are numerous other examples, such as the Utility Chest Toolbar, MindDabble and the Hughes Toolbar. These browser add-ons, including MySearch, are designed to redirect your browser to MindSpark-affiliated search sites.

Search results by MySearch are not necessarily threatening to your PC, and, based on the latest analyses, are borrowed from other, popular search sites. However, additional sponsored results and advertisements may be included, which pose the same risks to your Web browser as that of standard adware.

In addition to the search results MySearch shows, MySearch also modifies your browser's homepage, new tab page and default search page. These modifications are renewed automatically even after your browser's settings are reset, which allows MySearch to continue hijacking your Web-surfing activities indefinitely. This form of artificial traffic redirection, while insufficient to classify MySearch as a Trojan, does warrant its classification as a PUP whose removal always is as an ideal response.

Making Your Web Searches Your Decision Again

By allowing MySearch to choose which sites your browser loads by default, you put your PC at risk for exposure to attacks from insecure advertising sources and similar threats. Even though the MindSpark Limited Liability Company is not an illicit institution, avoiding its software is more likely to benefit than PC's safety and stability than doing otherwise. As a general standard, malware experts recommend uninstalling any add-on that subverts your personal control over your Web-browsing software, including seemingly minor settings, such as your choice of your homepage.

MySearch may affect more than one Web browser at a time, and its browser hijacks may continue even if you remove the original software that caused its browser redirects. Deleting MySearch and the settings changes caused by MySearch always should use appropriate security solutions as they're available. While most anti-adware and anti-PUP programs should be sufficient for removing this low-level threat, in the worst cases, you may wish to consider scanning your hard drive with full-fledged anti-malware software.

www.MySearch.com

File System Modifications

  • The following files were created in the system:
    # File Name
    1 adinstalle.exe
    2 aj[1].exe
    3 files.ini
    4 mysearchpluginproxy.class
    5 mysrchas.dll
    6 npmysrch.dll
    7 pagerevisor.dll
    8 prevcfg.htm
    9 s42ns.exe
    10 s4bar.dll
    11 s4ezsetp.dll
    12 s4ffxtbr.jar
    13 s4plugin.dll
    14 s4popswt.dll
    15 s4sept.exe
    16 soproc.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\software\microsoft\internetexplorer\menuext\webrebates.HKEY_CURRENT_USER\software\microsoft\internetexplorer\newwindows\allowwww.mysearch.comHKEY_LOCAL_MACHINE\software\microsoft\codestoredatabase\distributionHKEY..\..\..\..{RegistryKeys}85204a50-6997-4543-9ff8-d9bbcb9108f5\1.0HKEY_CLASSES_ROOT\mysearch.popswatterbarbuttonHKEY_CLASSES_ROOT\mysearch.popswatterbarbutton.1HKEY_CLASSES_ROOT\mysearch.popswatterbarbutton.1\clsidHKEY_CLASSES_ROOT\mysearch.popswatterbarbutton\clsidHKEY_CLASSES_ROOT\mysearch.popswatterbarbutton\curverHKEY_CLASSES_ROOT\mysearch.popswattersettingscontrolHKEY_CLASSES_ROOT\mysearch.popswattersettingscontrol.1HKEY_CLASSES_ROOT\mysearchtoolbar.netscapeshutdownHKEY_CLASSES_ROOT\mysearchtoolbar.netscapeshutdown.1HKEY_CLASSES_ROOT\mysearchtoolbar.netscapestartupHKEY_CLASSES_ROOT\mysearchtoolbar.netscapestartup.1HKEY_CLASSES_ROOT\mysearchtoolbar.netscapestartup\curverHKEY_CLASSES_ROOT\mysearchtoolbar.settingspluginHKEY_CLASSES_ROOT\mysearchtoolbar.settingsplugin.1HKEY_CLASSES_ROOT\mysearchtoolbar.settingsplugin\clsid
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}58f0b492-a42e-435a-bcbf-c6b2608077ba014da6c1-189f-421a-88cd-07cfe51cff1004079856-5845-4dea-848c-3ecd647aa554014da6c9-189f-421a-88cd-07cfe51cff1085204a50-6997-4543-9ff8-d9bbcb9108f5014da6c0-189f-421a-88cd-07cfe51cff10

Related Posts

Loading...