Content

Adware-Showsearch

Type
Program
SubType
Adware
Discovery Date
05/19/2004
Minimum DAT
4336 (03/10/2004)
Updated DAT
4587 (09/21/2005)
Minimum Engine
5.1.00
Description Added
04/26/2004
Description Modified
09/22/2004 3:15 PM (PT)

Tab Navigation

Characteristics

This is not a virus or trojan. It is a direct-marketing adware application. This application generates extra pop-up ads while using Internet Explorer.

This kind of application generally comes bundled with another program, which usually discloses the fact that it is ad-supported. Users agree to have the Adware installed in the license agreement, although they may not realise at first that this file was packaged with the product they installed.

Installation

Upon execution, the application installs itself into either the %WinDir% or %SysDir% directory as "mssearch.dll ".

(Where %Windir% is the Windows directory, for example C:\WINDOWS)
(Where %Sysdir% is the Windows System directory, for example C:\WINDOWS\SYSTEM)

For example:

c:\windows\mssearch.dll

The following Registry key(s) is/are added to hook system startup:

  • HKEY_CLASSES_ROOT\CLSID\{E2DDF680-9905-4dee-8C64-0A5DE7FE133C}\InprocServer32
    "(Default)" = "%Original file location)\mssearch.dll"
  • HKEY_CLASSES_ROOT\CLSID\{E2DDF680-9905-4dee-8C64-0A5DE7FE133C}\InprocServer32
    "ThreadingModel"= "Apartment"
  • HKEY_CLASSES_ROOT\CLSID\{E2DDF680-9905-4dee-8C64-0A5DE7FE133C}\ProgID
    "(Default)" = "ShowSearch.ViewSource.1"
  • HKEY_CLASSES_ROOT\CLSID\{E2DDF680-9905-4dee-8C64-0A5DE7FE133C}\TypeLib
    "(Default)" = "{CA3F4CA8-735D-4339-9EC2-BC0EDB077829}"
  • HKEY_CLASSES_ROOT\CLSID\{E2DDF680-9905-4dee-8C64-0A5DE7FE133C}\VersionIndependentProgID
    "(Default)" = "ShowSearch.ViewSource"
  • HKEY_CLASSES_ROOT\ShowSearch.ViewSource
    "(Default)" = "ViewSource Class"
  • HKEY_CLASSES_ROOT\ShowSearch.ViewSource\CLSID
    "(Default)" = "{E2DDF680-9905-4dee-8C64-0A5DE7FE133C}"
  • HKEY_CLASSES_ROOT\ShowSearch.ViewSource\CurVer
    "(Default)" = "ShowSearch.ViewSource.1"
  • HKEY_CLASSES_ROOT\ShowSearch.ViewSource.1
    "(Default)" = "ViewSource Class"
  • HKEY_CLASSES_ROOT\ShowSearch.ViewSource.1\CLSID
    "(Default)" = "{E2DDF680-9905-4dee-8C64-0A5DE7FE133C}"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E2DDF680-9905-4dee-8C64-0A5DE7FE133C}
    "(Default)" = "ShowSearch module"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShowSearch
    "DisplayName" = "MSSearch"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShowSearch
    "UninstallString" = "rundll32.exe %Original file location%\mssearch.dll,Uninstall"

Upon opening the IE web browser, the search side panel also opens.  A pop-up ad window will appear based on the context of the search performed.

Users who would like to check for the presence of potentially unwanted programs on their system should run the command line scanner with the /PROGRAM switch.
Please note that VirusScan 7, and higher, has an option that enables users to detect this kind of program automatically (see below).

Aliases

Aliases

    N/A