|
|
|
|
CoolWebSearch.msaps Spyware/Adware Definition
| Name: |
CoolWebSearch.msaps |
| Category: |
Browser Hijacker |
| Alias: |
StartPage-FJ |
| Advice: |
Remove |
| Risk: |
Elevated Risk
Elevated threats are usually threats that fall into the range of adware in which data about a user's habits are tracked and sent back to a server for analysis without your consent or knowledge. |
| Description:
|
CoolWebSearch.msaps modifies the start and search page in Internet Explorer.
CoolWebSearch.msaps changes Internet Explorer's Search Page, Start Page, Default_Page_URL and Local Page to "res://msaps.dll/search.html" or "res://msaps.dll/index.html.
When executed, this trojan modifies the following registry settings:
HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerMain "Local Page" = "res://msaps.dll/index.html"
HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerMain "Search Page" = "res://msaps.dll/search.html"
HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerMain "Start Page" = "res://msaps.dll/index.html"
HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerAboutURLs "blank" = "res://msaps.dll/index.html"
HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerAboutURLs "NavigationCanceled"="res://msaps.dll/index.html"
HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerAboutURLs "NavigationFailure" = "res://msaps.dll/index.html"
HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerMain "Default_Page_URL" = "res://msaps.dll/index.html"
HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerMain "Default_Search_URL" = "res://msaps.dll/search.html"
HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerMain "Default_Page_URL" = "res://msaps.dll/index.html"
HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerMain "Default_Search_URL" = "res://msaps.dll/search.html"
|
| Type: |
Browser Hijacker - Spyware's primary purpose is to collect demographic and usage information from your computer, usually for advertising purposes. Spyware usually that 'sneaks' onto a system or performs other activities hidden to the user. Spyware programs are usually bundled as a hidden component and downloaded from the Internet. These modules are almost always installed on the system secretively and try to run secretively as well. |
|
Top Browser Hijacker Visited Pages:
2nd Thought
2nd-thought
2nsSearch
ActualNames
AdBlock
Adpowerzone.BHO
Adw.Afris.Downloader
Adw.CWS.Hotoffers
Adw.KlikFind.Hijacker
Adw.Melkosoft.SuperSpider
Adw.SearchFast.Toolbar
Adw.SystemExplorer
Adware.24t
Americlicks
AproposMedia
|
|