Home Malware Programs Adware Fastsearchweb

Fastsearchweb

Posted: March 28, 2006

Fastsearchweb is an adware spyware that shows undesirable commercial advertisements and modifies essential Internet Explorer settings. The threat can get into the computer while visiting some insecure web sites. Fastsearchweb registers itself as a web browser add-on and therefore runs every time the user starts Internet Explorer.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 iecust.dll
    2 protect32.dll
    3 rcpie.dll
    4 subsys.exe
    5 susbsys.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainDefault_Page_URL=[blankpage]HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainDefault_Search_Page=[blankpage]HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainSearchBar=[longstring]HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainSearchPage=[longstring]HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainStartPage=[blankpage]HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainUseCustomSearchURL=0x1HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainUseSearchAsst=noHKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerSearchCustomize_Search=[blankpage]HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerSearchDefault_Search_URL=[blankpage]HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerSearchSearchAssistant=[longstring]HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerMainSearchBar=[longstring]HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerMainSearchPage=[longstring]HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerMainStartPage=[blankpage]HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerMainUseCustomSearchURL=0x1HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerMainUseSearchAsst=noHKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerSearchSearchAssistant=[longstring]
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}0EC7A55C-77D4-40E9-A4A0-9463B12B31E5D825EF86-59BB-46EA-924F-12088D928D6C69063189-5F20-4361-BB5F-30EF8526284D19E25DD9-89F9-49FD-A5FC-1B7862BB816706ABAA2D-34AB-4902-A326-409BD9B9A7A5
Loading...