ADW_WEBSEARCH.GA
May 24, 2017
ALIASES:
not-a-virus:AdWare.Win32.SwiftBrowse.cz (Kaspersky), Adware.Whilokii.E (F-Secure)
PLATFORM:
Windows
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
INFORMATION EXPOSURE:

Threat Type: Adware
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Adware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
File Size:
65,304 bytes
File Type:
EXE
Memory Resident:
No
Initial Samples Received Date:
19 Oct 2013
Arrival Details
This Adware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Other System Modifications
This Adware also creates the following registry entry(ies) as part of its installation routine:
HKEY_USER\{SID}_CLASSES\keepmysearch\
instl\data
APPORDR = "6E1BE56A615ED1A"
Dropping Routine
This Adware drops the following files:
- {Current Adware Path}\app.ini
Other Details
This Adware connects to the following possibly malicious URL:
- http://api.{BLOCKED}ii.net/rs