F3WPHOOK.DLL – Adware MyWebSearch

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

F3WPHOOK.DLL – Adware MyWebSearch removal

FileMD5Virus Alias
F3WPHOOK.DLL cee57e05eccf470e751689ded838b7d2 Adware MyWebSearch
F3WPHOOK.DLL cee57e05eccf470e751689ded838b7d2 Adware FunWeb
F3WPHOOK.DLL cee57e05eccf470e751689ded838b7d2 Trojan Agent

F3WPHOOK.DLL size: 20480 bytes
F3WPHOOK.DLL hash: CEE57E05ECCF470E751689DED838B7D2

Created files:

%Program Files%\MyWebSearch\bar\1.bin\F3CJPEG.DLL
%Program Files%\MyWebSearch\bar\1.bin\F3DTACTL.DLL
%Program Files%\MyWebSearch\bar\1.bin\F3HISTSW.DLL
%Program Files%\MyWebSearch\bar\1.bin\F3HKSTUB.DLL
%Program Files%\MyWebSearch\bar\1.bin\F3HTMLMU.DLL
%Program Files%\MyWebSearch\bar\1.bin\F3HTTPCT.DLL
%Program Files%\MyWebSearch\bar\1.bin\F3IMSTUB.DLL
%Program Files%\MyWebSearch\bar\1.bin\F3POPSWT.DLL
%Program Files%\MyWebSearch\bar\1.bin\F3PSSAVR.SCR
%Program Files%\MyWebSearch\bar\1.bin\F3REGHK.DLL
%Program Files%\MyWebSearch\bar\1.bin\F3REPROX.DLL
%Program Files%\MyWebSearch\bar\1.bin\F3RESTUB.DLL
%Program Files%\MyWebSearch\bar\1.bin\F3SCHMON.EXE
%Program Files%\MyWebSearch\bar\1.bin\F3SCRCTR.DLL
%Program Files%\MyWebSearch\bar\1.bin\F3SPACER.WMV
%Program Files%\MyWebSearch\bar\1.bin\F3WPHOOK.DLL
%Program Files%\MyWebSearch\bar\1.bin\M3AUXSTB.DLL
%Program Files%\MyWebSearch\bar\1.bin\M3DLGHK.DLL
%Program Files%\MyWebSearch\bar\1.bin\M3FFXTBR.JAR
%Program Files%\MyWebSearch\bar\1.bin\M3HIGHIN.EXE
%Program Files%\MyWebSearch\bar\1.bin\M3HTML.DLL
%Program Files%\MyWebSearch\bar\1.bin\M3IDLE.DLL
%Program Files%\MyWebSearch\bar\1.bin\M3IMPIPE.EXE
%Program Files%\MyWebSearch\bar\1.bin\M3MEDINT.EXE
%Program Files%\MyWebSearch\bar\1.bin\M3MSG.DLL
%Program Files%\MyWebSearch\bar\1.bin\M3NTSTBR.JAR
%Program Files%\MyWebSearch\bar\1.bin\M3OUTLCN.DLL
%Program Files%\MyWebSearch\bar\1.bin\M3PLUGIN.DLL
%Program Files%\MyWebSearch\bar\1.bin\M3SKIN.DLL
%Program Files%\MyWebSearch\bar\1.bin\M3SKPLAY.EXE
%Program Files%\MyWebSearch\bar\1.bin\M3SLSRCH.EXE
%Program Files%\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
%Program Files%\MyWebSearch\bar\1.bin\MWSBAR.DLL
%Program Files%\MyWebSearch\bar\1.bin\MWSOEMON.EXE
%Program Files%\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
%Program Files%\MyWebSearch\bar\1.bin\MWSOESTB.DLL
%Program Files%\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
%Program Files%\MyWebSearch\bar\1.bin\MWSSVC.EXE
%Program Files%\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
%Program Files%\MyWebSearch\bar\Avatar\COMMON.F3S
%Program Files%\MyWebSearch\bar\Game\CHECKERS.F3S
%Program Files%\MyWebSearch\bar\Game\CHESS.F3S
%Program Files%\MyWebSearch\bar\Game\REVERSI.F3S
%Program Files%\MyWebSearch\bar\Message\COMMON.F3S
%Program Files%\MyWebSearch\bar\Notifier\COMMON.F3S
%Program Files%\MyWebSearch\bar\Notifier\DOG.F3S
%Program Files%\MyWebSearch\bar\Notifier\FISH.F3S
%Program Files%\MyWebSearch\bar\Notifier\KUNGFU.F3S
%Program Files%\MyWebSearch\bar\Notifier\LIFEGARD.F3S
%Program Files%\MyWebSearch\bar\Notifier\MAID.F3S
%Program Files%\MyWebSearch\bar\Notifier\MAILBOX.F3S
%Program Files%\MyWebSearch\bar\Notifier\OPERA.F3S
%Program Files%\MyWebSearch\bar\Notifier\ROBOT.F3S
%Program Files%\MyWebSearch\bar\Notifier\SEDUCT.F3S
%Program Files%\MyWebSearch\bar\Notifier\SURFER.F3S
%SysDir%\f3PSSavr.scr
%Temp%\MWSSETUP.EXE
%Temp%\MWSSETUP.EX_

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\MyWebSearch Plugin: rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\My Web Search Bar Search Scope Monitor: “C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe” /m=2 /w /h
HKLM\System\CurrentControlSet\Services\MyWebSearchService\Type: 10000000
HKLM\System\CurrentControlSet\Services\MyWebSearchService\Start: 02000000
HKLM\System\CurrentControlSet\Services\MyWebSearchService\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\MyWebSearchService\DisplayName: My Web Search Service
HKLM\System\CurrentControlSet\Services\MyWebSearchService\ImagePath: %Program Files%\MyWebSearch\bar\1.bin\MWSSVC.EXE

Detected by UnHackMe:

F3WPHOOK.DLL
Default location: %PROGRAM FILES%\MYWEBSEARCH\BAR\1.BIN\F3WPHOOK.DLL

Dropper information:
MD5: e365078a058faaa2270f2319cceafba0
File size: 2528720 bytes

Leave a Reply