Home Malware Programs Adware JoomiWeb

JoomiWeb

Posted: December 16, 2013

Threat Metric

Threat Level: 2/10
Infected PCs: 23
First Seen: December 18, 2013
Last Seen: August 23, 2021
OS(es) Affected: Windows

JoomiWeb is an adware ad–on that provides advertisements in your browser as its primary function. Because JoomiWeb is cloned from a family of similar adware products that include BeepieBear and Larparus, JoomiWeb has few functions that are out of the mainstream for adware, but still may be a potential security problem and an almost certain quality of life issue for any affected PC. Unintentional JoomiWeb installations through typical means, such as a software bundle from a free software site, always should be reversed by deleting JoomiWeb with a good anti-malware or similar security product, which should be able to remove any browser symptoms, as well.

JoomiWeb: Why Adware Never Travels Alone

Adware programs often are defined by a few central but non-advantageous features that are shared broadly between many minor variants of these products. However, new brands of adware often are being developed, providing a new vehicle for installing easy advertising revenue, and JoomiWeb is one of the newest of these. Since JoomiWeb can be updated automatically, its features are somewhat in a state of flux, but malware experts have observed several basic adware issues related to JoomiWeb's history. These issues may encompass:

  • Modified Web pages that are made to host JoomiWeb through injected banners, text links, product comparisons, etc.
  • Pop-up advertising windows (or pop-under windows, a similar advertisement that loads beneath, rather than atop of your browser).
  • Various tweaks to browser settings to enable JoomiWeb to optimize its advertisements. Fortunately, security-related settings aren't altered – at least, not in current versions of JoomiWeb. Two of the most noticeable of these changes are related to your online searches: instant or 'predictive' searches are disabled, and search results automatically are forced to open new tabs, rather than using the already-open tab.

JoomiWeb's own installers are anticipated to be using the same general software bundles as many other adware programs, such as Larparus and BeepieBear. Avoiding sites with histories of distributing adware bundles, and scanning a possible bundle with anti-malware tools prior to launching it, provide the most accessible defenses against these kinds of Potentially Unwanted Programs.

Building a World Wide Web with Fewer JoomiWeb Advertisements in It

Security also is a concern for dealing with JoomiWeb after JoomiWeb is already landed on whatever PC a bundle may have targeted. Since JoomiWeb advertisements aren't likely to be monitored strenuously for maintaining content security, they also may be direct dangers to your computer, as well as simple annoyances. Disguised installers for high-level PC threats, such as fake Registry cleaners or banking Trojans, are particularly common on poorly-secured advertisement networks, and may use social engineering techniques to encourage you to download them. Occasionally, automatic downloads that use software exploits to install threats from any victims also are observed.

Removing JoomiWeb may be what's best for your online safety and simple performance, but the uninstallation advice provided on JoomiWeb's website has proven less than helpful, due to being copy-pasted from previous adware sites. Instead of spending your time on the questionable proposition of removing JoomiWeb without any assistance, malware researchers would encourage using anti-malware tools to remove JoomiWeb whenever a PC security professional is unavailable.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}Software\JoomiWebSOFTWARE\Microsoft\Tracing\updateJoomiWeb_RASAPI32SOFTWARE\Microsoft\Tracing\updateJoomiWeb_RASMANCSSOFTWARE\Microsoft\Tracing\utilJoomiWeb_RASAPI32SOFTWARE\Microsoft\Tracing\utilJoomiWeb_RASMANCS

Additional Information

The following directories were created:
%PROGRAMFILES%\JoomiWeb%PROGRAMFILES(x86)%\JoomiWeb
Loading...