Home Malware Programs Bad Toolbars Webfetti

Webfetti

Posted: February 1, 2011

Threat Metric

Ranking: 12,262
Threat Level: 1/10
Infected PCs: 2,127
First Seen: February 1, 2011
Last Seen: October 16, 2023
OS(es) Affected: Windows

Aliases

Toolbar.MyWebSearch.AS [AVG]Toolbar.MyWebSearch.Y [AVG]Win32.Adware.Mindspark.C [GData]MyWebSearch [AVG]Riskware/MyWebSearch [Fortinet]PUP/Win32.MyWebSearch [AhnLab-V3]RiskWare[WebToolbar]/Win32.MyWebSearch.si [Antiy-AVL]Adware.MyWebSearch.82 [DrWeb]not-a-virus:WebToolbar.Win32.MyWebSearch.si [Kaspersky]Win32:Mindspark-A [PUP] [Avast]W64/Mywebsearch.L.gen!Eldorado [F-Prot]PUA.Webwatcher.OD9 [CAT-QuickHeal]WS.Reputation.1 [Symantec]

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{0245f767-d631-48e1-90fe-d1480bafb400}{0526BC20-B55E-4C8E-8A24-EF55F8EB18D0}{0F637868-BD05-4655-877F-A372F38B7587}{0FB868F2-23D2-4C89-9FBD-966D63800279}{0FC010B5-1FA1-46C4-8C45-FA5B5FD993E3}{119689AA-00D3-4AF5-94FC-E60AD64C0767}{137547B0-9846-4B17-869B-CCB390A81821}{21120E41-1C8F-4A29-9AF5-A48D7B5719CE}{2A793196-FF06-43AD-BB99-BB8CDD76BB06}{33A1A608-7363-4B7A-B3B0-D3CC3EFFB193}{35402A4B-56F7-4BAD-B22B-A271F28BDF10}{3A437A7B-1890-4385-A8E4-E8D95ACBCD95}{4376B407-9480-4FB5-8E3A-8E6730023F4F}{482c2143-8424-417c-be8e-a3e5e3471434}{48426BB3-2FCD-4C4A-B202-86BBBA3E727D}{4C426A1A-2A6E-42A3-960E-02FD4C0DCFF7}{4D8B3259-941B-4C32-AB18-27771ED64202}{529A871B-5D1A-4982-8E13-6C0F105D50DE}{544c72e2-a279-4350-8d4c-c8155afb838c}{54a2c9dc-5f89-4e0e-881c-9d085db825fe}{5d8b6666-cab9-43be-b3a0-52c8d4ebd808}{626EC92B-F04A-466D-A0E7-EB31BDEE89E0}{78EFC8E0-11A8-4425-BB0F-2CE20FAD2FFD}{8F106B81-326A-4D48-B2F8-DE7AA3E93968}{925156ef-5598-476c-808e-91361df41bc2}{93fad456-5260-4336-a8f3-d3fb2b6e588f}{9ea325ce-de51-4986-890e-f42cef044810}{A1DB749F-5B5C-49AA-8C0B-83D301DD9EEE}{B2687F04-D41A-470B-AF0F-1EFAF9C286FE}{B8711748-C923-4D3B-BAB5-8BF2AC519C48}{BBE38021-1402-4C18-930E-411C76225621}{C8025EE0-B722-4F37-A057-B7BF49306C71}{CC581899-D841-4E6D-9CD0-BA562F2EA8EC}{CC6CEF90-D8FB-4B84-920F-254EB8295B67}{cd528b94-1b57-4bd4-b53c-e9556cf12ffe}{cebad05d-17ca-4581-8bac-4f74cff1ce91}{CF97FB73-9BDA-4EF5-B3F3-02C6CD43B963}{D01A11AC-8448-42C2-A2B3-4DDE0C44D573}{D1CE52A0-B595-40BC-946F-9E06648F578F}{D3D15C2D-C893-4DF4-8979-0AFEDBB7F4B2}{D499FF20-FC53-4EF0-A2A8-B30D8276CBCC}{DF13A59D-2C40-4C06-B099-0E12E04C34F7}{E5CA6EC7-BF77-415C-AFB5-9538807EDDDC}{E6A75EEA-FA46-4E55-ADA4-005F827B7511}{EC293FDE-0849-43DA-8DFB-575BD649D9E4}{ED32911E-6A24-42CA-8638-C4EA3E26388C}{EEA9FACD-E1AF-422A-BAF0-C879A97EB84A}{F6D41509-EEAF-4370-9717-FEA84601147B}{f97ca2a9-243c-4620-b844-359ac5d52ac7}{FC78EE6D-5A4A-47D1-90AB-A16A1953D7A0}{fcf204da-f2f8-4788-9298-6098d544f93c}{FEE0FDB9-DB08-415E-8257-10D45C25D3AD}{FF1AB4DC-4476-468E-9C08-EE72BB76F953}HKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59948926-35c9-494a-adaf-bef419b1a60e}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7978d9fa-50de-4c38-b7e0-821545dc2c46}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{c10284b4-91ad-45c2-b818-7dce51a39234}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{dbdc7d45-f399-43e1-94f8-3f56afa50636}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{dbf0f9a4-a83e-49df-a75e-91906163b4c1}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f7f23974-e100-42bd-9694-feba0f1df93c}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59948926-35c9-494a-adaf-bef419b1a60e}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7978d9fa-50de-4c38-b7e0-821545dc2c46}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{c10284b4-91ad-45c2-b818-7dce51a39234}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{dbdc7d45-f399-43e1-94f8-3f56afa50636}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{dbf0f9a4-a83e-49df-a75e-91906163b4c1}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f7f23974-e100-42bd-9694-feba0f1df93c}
Loading...