mwsBar.dll

My Web Search Bar for Internet Explorer, FireFox, email clients, and messenger clients

Fun Web Products

The module mwsBar.dll, “My Web Search Bar” by Fun Web Products has been detected as adware by 11 anti-malware scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘mwsBar BHO’.
Publisher:
MyWebSearch.com  (signed by Fun Web Products)

Product:
My Web Search Bar for Internet Explorer, FireFox, email clients, and messenger clients

Description:
My Web Search Bar

Version:
2, 3, 67, 3

MD5:
8c8c91053d9e5be488f4cc08556f8244

SHA-1:
00a1e7cbdc77add5f89dbd0266fa796af31e3c9f

SHA-256:
b3b037fefb2b998ecb75ddcfd20a5bf070d6ba0a195c985c0bcd610c810e933e

Scanner detections:
11 / 68

Status:
Adware

Explanation:
Part of the MyWebSearch/Mindspark/Ask web browser extension and toolbar.

Analysis date:
4/18/2024 6:56:48 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.MyWebSearch
2014.10.31

avast!
Win32:PUP-gen [PUP]
2014.9-151108

Boost by Reason
Optional.FunWebProducts.BHO
188838

Clam AntiVirus
Adware.FunWebProducts-5
0.98/21411

Comodo Security
Application.Win32.WebToolbar.MyWebSearch
19942

ESET NOD32
Win32/Toolbar.MyWebSearch
9.10644

Fortinet FortiGate
Riskware/MyWebSearch
11/8/2015

NANO AntiVirus
Riskware.Win32.FunWeb.gietl
0.28.6.62995

Reason Heuristics
PUP.MyWebSearch.Mindspark (M)
15.11.8.9

Vba32 AntiVirus
Trojan.BHORA.0900
3.12.26.3

VIPRE Antivirus
34366

File size:
741.5 KB (759,288 bytes)

Product version:
2, 3, 67, 3

Copyright:
Copyright © 2003, 2004, 2005, 2006, 2007, 2008, 2009, 2010

Original file name:
mwsBar.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\mywebsearch\bar\2.bin\mwsbar.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/19/2010 4:00:00 PM

Valid to:
1/20/2011 3:59:59 PM

Subject:
CN=Fun Web Products, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Fun Web Products, L=White Plains, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1F5E8AA6D425A4079DE388B7EF6D6904

File PE Metadata
Compilation timestamp:
3/18/2010 8:48:58 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:AWL/Cud70Mon0wx3QdYRoI7VUknzl53kf4xb:PL/B7hi1x3Qd/I7VUO2Qxb

Entry address:
0x1EABE

Entry point:
FF, 74, 24, 0C, FF, 74, 24, 0C, FF, 74, 24, 0C, E8, C2, F3, FE, FF, C2, 0C, 00, FF, 15, C0, 51, 04, 10, 33, C0, C3, A1, F0, FB, 04, 10, 56, 85, C0, 75, 13, FF, 74, 24, 08, 50, FF, 35, 90, FB, 04, 10, FF, 15, CC, 52, 04, 10, 5E, C3, 8B, 0D, F4, FB, 04, 10, 8B, 15, EC, FB, 04, 10, FF, 05, F4, FB, 04, 10, 23, D1, 8B, 34, 90, 8B, 44, 24, 08, 83, C0, 08, 50, 6A, 00, 56, FF, 15, CC, 52, 04, 10, 85, C0, 74, 07, 89, 30, 83, C0, 08, 5E, C3, 33, C0, 5E, C3, 8B, 44, 24, 04, 0F, AF, 44, 24, 08, 50, E8, 9D, FF, FF, FF...
 
[+]

Entropy:
6.0678

Code size:
272 KB (278,528 bytes)

Internet Explorer BHO
Display name:
mwsBar BHO

CLSID:
{07B18EA1-A523-4961-B6BB-170DE4475CCA}


Remove mwsBar.dll - Powered by Reason Core Security