tmp000000029c9eb6b3d2562d7e

My Web Search Bar for Internet Explorer, email clients, and messenger clients

Mindspark Interactive Network

The file tmp000000029c9eb6b3d2562d7e, “My Web Search Plugin Loader” by Mindspark Interactive Network has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
MyWebSearch.com  (signed by Mindspark Interactive Network)

Product:
My Web Search Bar for Internet Explorer, email clients, and messenger clients

Description:
My Web Search Plugin Loader

Version:
1,2,2,7

MD5:
fabf3218576b7f291fd1e81ad5f51804

SHA-1:
b6cc2a4115715bfe6b6a4c8792f3d32b78754ac5

SHA-256:
c28b94f4216d3eb633e33ef38f8cdbb428deee5721fc1dc637d2a7b31b1bbcf0

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 12:40:47 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Mindspark (M)
17.3.3.1

File size:
512 KB (524,288 bytes)

Product version:
2,3,0,0

Copyright:
Copyright © 2003-2007 MyWebSearch.com

Original file name:
mwsoemon.exe

Language:
English (United States)

Common path:
C:\windows\temp\tmp000000029c9eb6b3d2562d7e

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/30/2010 7:00:00 PM

Valid to:
5/6/2012 6:59:59 PM

Subject:
CN=Mindspark Interactive Network, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Mindspark Interactive Network, L=White Plains, S=NewYork, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
41730EB0E6D92A476E16628A0DBEFB36

File PE Metadata
Compilation timestamp:
3/5/2010 3:39:46 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x2398

Entry point:
55, 8B, EC, 83, EC, 44, 53, 56, 6A, 00, FF, 15, 6C, 50, 40, 00, A3, 64, 68, 40, 00, FF, 15, 68, 50, 40, 00, 8B, 1D, 64, 50, 40, 00, 8B, F0, 85, F6, 75, 04, 6A, FF, FF, D3, 8A, 06, 57, 8B, 3D, 34, 51, 40, 00, 3C, 22, 75, 1B, 56, FF, D7, 8B, F0, 8A, 06, 3C, 22, 74, 04, 84, C0, 75, F1, 80, 3E, 22, 75, 15, 56, FF, D7, 8B, F0, EB, 0E, 3C, 20, 7E, 0A, 56, FF, D7, 8B, F0, 80, 3E, 20, 7F, F6, 8A, 06, 84, C0, 74, 04, 3C, 20, 7E, E1, 83, 65, E8, 00, 8D, 45, BC, 50, FF, 15, 60, 50, 40, 00, E8, 2D, 00, 00, 00, F6, 45...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
16 KB (16,384 bytes)

Remove tmp000000029c9eb6b3d2562d7e - Powered by Reason Core Security