mwsBar.dll

My Web Search Bar for Internet Explorer, FireFox, email clients, and messenger clients

Fun Web Products

The module mwsBar.dll, “My Web Search Bar” by Fun Web Products has been detected as adware by 16 anti-malware scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘mwsBar BHO’.
Publisher:
MyWebSearch.com  (signed by Fun Web Products)

Product:
My Web Search Bar for Internet Explorer, FireFox, email clients, and messenger clients

Description:
My Web Search Bar

Version:
2, 3, 66, 4

MD5:
10df6beef6997fdecad17237a1d2bc81

SHA-1:
e794990416683ad15b6aab8a6be470e314a4b538

SHA-256:
a5e25ff7e59b1e1c546f6f83b55f6eb29ea2066b8ab99c9cb34414eb7434dfcd

Scanner detections:
16 / 68

Status:
Adware

Explanation:
Part of the MyWebSearch/Mindspark/Ask web browser extension and toolbar.

Analysis date:
4/26/2024 10:40:06 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.MyWebSearch
2013.04.08

avast!
Win32:PUP-gen [PUP]
2014.9-160214

Clam AntiVirus
Adware.FunWebProducts-5
0.98/18155

Comodo Security
Application.Win32.WebToolbar.MyWebSearch
15859

ESET NOD32
Win32/Toolbar.MyWebSearch
10.8205

Fortinet FortiGate
Riskware/MyWebSearch
2/14/2016

F-Prot
W32/Mywebsearch.B.gen
v6.4.6.2.117

F-Secure
Adware:W32/MyWebSearch
11.2016-14-02_1

K7 AntiVirus
Unwanted-Program
13.67.2865

McAfee
Artemis!4AB68688D89F
5600.6490

NANO AntiVirus
Riskware.Win32.FunWeb.gietl
0.24.0.51813

Prevx
Low Risk Adware
3.0

Reason Heuristics
PUP.MyWebSearch.Mindspark (M)
16.2.14.3

SUPERAntiSpyware
PUP.MyWebSearch
9325

Vba32 AntiVirus
Trojan.BHORA.0900
3.12.20.2

VIPRE Antivirus
16672

File size:
445.5 KB (456,184 bytes)

Product version:
2, 3, 66, 4

Copyright:
Copyright © 2003, 2004, 2005, 2006, 2007, 2008, 2009, 2010

Original file name:
mwsBar.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\mywebsearch\bar\1.bin\mwsbar.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/19/2010 7:00:00 PM

Valid to:
1/20/2011 6:59:59 PM

Subject:
CN=Fun Web Products, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Fun Web Products, L=White Plains, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1F5E8AA6D425A4079DE388B7EF6D6904

File PE Metadata
Compilation timestamp:
2/4/2010 6:18:35 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:6ZpTCw16vVDh0KLdRiuMCnRHoIdd6lmdHgwP21o8Jqxa:KpTv6vtq8dECZoId35Jxa

Entry address:
0x1E5AB

Entry point:
FF, 74, 24, 0C, FF, 74, 24, 0C, FF, 74, 24, 0C, E8, 02, F6, FE, FF, C2, 0C, 00, FF, 15, C0, 41, 04, 10, 33, C0, C3, A1, 28, EB, 04, 10, 56, 85, C0, 75, 13, FF, 74, 24, 08, 50, FF, 35, C8, EA, 04, 10, FF, 15, 68, 41, 04, 10, 5E, C3, 8B, 0D, 2C, EB, 04, 10, 8B, 15, 24, EB, 04, 10, FF, 05, 2C, EB, 04, 10, 23, D1, 8B, 34, 90, 8B, 44, 24, 08, 83, C0, 08, 50, 6A, 00, 56, FF, 15, 68, 41, 04, 10, 85, C0, 74, 07, 89, 30, 83, C0, 08, 5E, C3, 33, C0, 5E, C3, 8B, 44, 24, 04, 0F, AF, 44, 24, 08, 50, E8, 9D, FF, FF, FF...
 
[+]

Entropy:
6.2324

Code size:
268 KB (274,432 bytes)

Internet Explorer BHO
Display name:
mwsBar BHO

CLSID:
{07B18EA1-A523-4961-B6BB-170DE4475CCA}


Remove mwsBar.dll - Powered by Reason Core Security