Main Menu
Home
Bookmark
Contact Us



 
Winshow Browser Hijacker Information

Name: Winshow
Category: Browser Hijacker
Alias: - Alias: PowerSearch toolbar
Advice: Remove
Risk: Elevated Risk Elevated threats are usually threats that fall into the range of adware in which data about a user's habits are tracked and sent back to a server for analysis without your consent or knowledge.
Description: Winshow is a browser helper object (BHO) for Internet Explorer designed to change (hijack) your home page without your permission, change your default search settings to direct them to one of its controlling servers, and to open pop-up ads controlled

Winshow modifies the Internet Explorer home page, so that when the browser is opened, it will, by default, load the advertising Web site.

Winshow modifies the Internet Explorer default search settings, so that any default search attempt would be directed to a particular controlling server, which is often affiliated with the advertiser.

When Winshow finds a selected word or phrase in a web page that IE is displaying, it may open a popup ad related to that term. Ads are served by 00hq.com and 8ad.com.

Winshow is installed via MSUpdater.exe, a 20,480 byte file that runs silently and retrieves additional components. This may be delivered via a VBScript from a web page, or from a JAR file.

When a JAR file containing the downloader is run, it uses the Microsoft Internet Explorer VerifierBug vulnerability to gain full privileges, escaping Java's intended security. The VerifierBug allows the downloader to run and download winshow.dll, and then register it with regsvr32. As a browser helper object, Winshow.dll is then run when you run IE.

Signatures: process: msupdater.exe: MD5 Hash: ... process: javale.exe: MD5 Hash: 2c70ecd4ffe5a0e3dbd... process: msupdater.exe: MD5 Hash: ..
Type: Browser Hijacker - Adware is generally software that displays advertisements. Some advertisers may covertly install adware on your system and generate a stream of unsolicited advertisements that can clutter your desktop and affect your productivity. The advertisements may also contain pornographic or other material that you might find inappropriate. The extra processing required to track you or to display advertisements can tax your computer and hurt your system performance.



Top Browser Hijacker Visited Pages:
SuperSpider - Alias: Network Security Guard, Melcosoft - 323 visits
Spyass.com - 65 visits
Tubby - Alias: MakeMeSearch, CoolWebSearch.Tubby, Spyware.Arau, Trojan.Win32.StartPage.ih, Trojan.StartPage-FJ - 54 visits
CoolWebSearch - Alias: CWS, Cool Web Serach, CoolWwwSearch - 50 visits
CrackSpider - Alias: Troj/Favadd-D - 49 visits
SecurityToolbar.DesktopScam - 45 visits
Paytime - 40 visits
Trojan.StartPage - Alias: SearchCentral - 37 visits
Search3 Hijacker - 30 visits
SBSoft - 30 visits

Random Browser Hijacker Pages:
CoolWebSearch.Control - Alias: CWS variant
Frsk
Trojan.MSConfig.BHO
WurldMedia - Alias: BuyersPort, Buyer's Port, Morpheus Shopping Club, WURLD Shopping Community
CWS_Hputi
Tubby - Alias: MakeMeSearch, CoolWebSearch.Tubby, Spyware.Arau, Trojan.Win32.StartPage.ih, Trojan.StartPage-FJ
Spyware.Hijacker.mcicdb - Alias: mcicdb
IGetNet - Alias: INetSpeak
SecurityToolbar.DesktopScam
PowerSearch - Alias: PowerSearch toolbar


 


© 2006-2008 spyware32.com - Privacy Policy