Home Malware Programs Adware WebSparkle

WebSparkle

Posted: October 3, 2013

Threat Metric

Threat Level: 2/10
Infected PCs: 1,904
First Seen: October 3, 2013
Last Seen: July 1, 2024
OS(es) Affected: Windows

WebSparkle Screenshot 1WebSparkle is adware that may display annoying pop-up ads within Internet Explorer, Mozilla Firefox and Google Chrome. WebSparkle pop-up ads may be displayed regardless of the web browser or search engine, and if a PC user is seeing ads from WebSparkle whenever he is performing an online search in any legal search provider or is visiting a certain commercial website, then the computer may be infected with adware or other PC threats. WebSparkle may be created by attackers specifically to earn money from click fraud and raised website traffic. WebSparkle may boost web traffic by forced redirects, gather sales leads for other tricky websites, and show pop-up advertisements, sponsored links and coupons within the targeted web browser. WebSparkle may be spread stealthily through infected websites, or genuine websites that have been hijacked. WebSparkle may also proliferate via malicious spam email attachments, which contain attachments or links to insecure websites. WebSparkle may also be downloaded manually by fooling Internet user into thinking they are installing a beneficial software product. WebSparkle may also be distributed via peer-to-peer file sharing websites and is often packaged with pirated or illegitimately acquired tools.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



file.exe File name: file.exe
Size: 1.9 MB (1909328 bytes)
MD5: ccf5fda6c32b0f6386f7b4b0086e8abb
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: August 17, 2022

Registry Modifications

The following newly produced Registry Values are:

CLSID{1BCCADB8-680C-41A0-9789-19D566FBAC16}{6832C453-2F06-4A9F-9080-5DDECF242856}{6935FA3E-0771-4B2F-A668-8C9CC50A7C90}{9f56bab3-2739-40ed-a8d0-1451657a9742}HKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Tracing\updateWebSparkle_RASAPI32SOFTWARE\Microsoft\Tracing\updateWebSparkle_RASMANCSSoftware\WebSparkleSOFTWARE\Wow6432Node\Microsoft\Tracing\updateWebSparkle_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateWebSparkle_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\WebSparkle_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\WebSparkle_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{9f56bab3-2739-40ed-a8d0-1451657a9742}SOFTWARE\Wow6432Node\WebSparkleSYSTEM\ControlSet001\services\eventlog\Application\Update WebSparkleSYSTEM\ControlSet001\services\Update WebSparkleSYSTEM\CurrentControlSet\services\eventlog\Application\Update WebSparkleSYSTEM\CurrentControlSet\services\Update WebSparkleHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}WebSparkle

Additional Information

The following directories were created:
%ProgramFiles%\WebSparkle%ProgramFiles(x86)%\WebSparkle
The following URL's were detected:
WebSparkle

Related Posts

Loading...