Home Malware Programs Adware WordShark Ads

WordShark Ads

Posted: June 11, 2015

Threat Metric

Ranking: 9,649
Threat Level: 2/10
Infected PCs: 7,520
First Seen: June 12, 2015
Last Seen: October 11, 2023
OS(es) Affected: Windows

WordShark is one of those annoying pieces of adware that overloads your web browsers with advertising materials. Computer Security experts warn users to stay focused when installing freeware or shareware as adware tends to travel bundled with it. Also, once your computer has been infected with WordShark, you may see ads by WordShark on each page you visit. Computer security experts explain that ads by WordShark may consume your PC's resources and make it run slower. It is also not recommended to click on ads by WordShark as you may be redirected to third-party websites and thus generate web traffic for them. Sometimes you may be redirected to questionable websites or ones that promote dubious applications. If you check the official website at wordshark.com, you will see that this is a marketing services domain that is most likely using questionable marketing methods to gain popularity.

Aliases

Generic.1E9 [AVG]BehavesLike.Win64.BadFile.qh [McAfee-GW-Edition]WS.Reputation.1 [Symantec]Artemis!724A427BFBBD [McAfee]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



c:\windows\system32\drivers\wsfd_1_10_0_19.sys File name: wsfd_1_10_0_19.sys
Size: 61.31 KB (61312 bytes)
MD5: 724a427bfbbd6bd9f202ad029bc777bb
Detection count: 105
File type: System file
Mime Type: unknown/sys
Path: c:\windows\system32\drivers\wsfd_1_10_0_19.sys
Group: Malware file
Last Updated: May 2, 2022
c:\windows\system32\drivers\wsfd_1_10_0_17.sys File name: wsfd_1_10_0_17.sys
Size: 58.24 KB (58240 bytes)
MD5: 137735d9e7152efda4ec3b6ec72d7272
Detection count: 59
File type: System file
Mime Type: unknown/sys
Path: c:\windows\system32\drivers\wsfd_1_10_0_17.sys
Group: Malware file
Last Updated: November 15, 2022
C:\Users\<username>\AppData\Local\Temp\c01e86d4-4bc5-4458-8483-f986a92e0aa9\wordshark-setup-1.10.0.20.exe File name: wordshark-setup-1.10.0.20.exe
Size: 1.18 MB (1185896 bytes)
MD5: dc2873b56986e04545409d3149f58939
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\c01e86d4-4bc5-4458-8483-f986a92e0aa9\wordshark-setup-1.10.0.20.exe
Group: Malware file
Last Updated: January 9, 2023
setup.exe File name: setup.exe
Size: 1.14 MB (1141456 bytes)
MD5: fec919904ca57b54358629294841ad04
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: November 15, 2022

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%WINDIR%\system32\Drivers\wsfd_1_10_0_[RANDOM CHARACTERS].sys%WINDIR%\system32\Drivers\wsfd_[RANDOM CHARACTERS]_1_10_0_[RANDOM CHARACTERS].sys%WINDIR%\system32\Drivers\wsfd_vt_1_10_0_[RANDOM CHARACTERS].sys%WINDIR%\System32\Tasks\WordShark Auto Updater[RANDOM CHARACTERS]HKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Tracing\WordSharkAutoUpdateClient_RASAPI32SOFTWARE\Microsoft\Tracing\WordSharkAutoUpdateClient_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\WordSharkAutoUpdateClient_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\WordSharkAutoUpdateClient_RASMANCSSYSTEM\ControlSet001\Enum\Root\LEGACY_WSFD_1_10_0_17SYSTEM\ControlSet002\Enum\Root\LEGACY_WSFD_1_10_0_17SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WSFD_1_10_0_17
Loading...