Home Malware Programs Adware WebSpades

WebSpades

Posted: March 25, 2014

Threat Metric

Ranking: 8,997
Threat Level: 2/10
Infected PCs: 7,937
First Seen: March 25, 2014
Last Seen: October 16, 2023
OS(es) Affected: Windows


WebSpades is considered to be adware that may access the PC through packaged free software. WebSpades may be added into Internet Explorer, Mozilla Firefox or Google Chrome Web browsers and reduce the overall PC's performance. WebSpades may show a variety of annoying pop-up advertisements, which may claim to be sent to PC users by WebSpades Deals or WebSpades Ads. WebSpades may forcibly divert computer users to suspicious websites if they click on ads. Thus, PC users may undergo repeated diversions to unwanted websites whenever they use any Web browser. The main aim of WebSpades may be to raise traffic of the questionable website and benefit from clicks on links and ads. To evade installation of WebSpades, computer users should be attentive to the free tools they are installing to their PCs and always read the steps of installation. Then, they can see if free tools carry extra software, and they may be able not to download additional applications. WebSpades may trace the PC user's browsing habits and transfer collected information to third-parties possibly for the purpose of targeted advertising.

Aliases

Webpade [AVG]AdWare.SpadeCast [Ikarus]Trojan/Win32.TSGeneric [Antiy-AVL]BrowseSmart [Sophos]Artemis!53CF0796C727 [McAfee]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



system32\drivers\{2635ac50-5488-40bf-9bfd-accb158f8f3f}t64.sys File name: {2635ac50-5488-40bf-9bfd-accb158f8f3f}t64.sys
Size: 60.09 KB (60096 bytes)
MD5: 1973cd2b1d86c782a3537125b79a8fa1
Detection count: 96
File type: System file
Mime Type: unknown/sys
Path: system32\drivers
Group: Malware file
Last Updated: July 18, 2014
system32\drivers\{2635ac50-5488-40bf-9bfd-accb158f8f3f}t64.sys File name: {2635ac50-5488-40bf-9bfd-accb158f8f3f}t64.sys
Size: 60.09 KB (60096 bytes)
MD5: 0d23294772b6941c2a6d8d47e8068e83
Detection count: 86
File type: System file
Mime Type: unknown/sys
Path: system32\drivers
Group: Malware file
Last Updated: July 18, 2014
system32\drivers\{2635ac50-5488-40bf-9bfd-accb158f8f3f}t64.sys File name: {2635ac50-5488-40bf-9bfd-accb158f8f3f}t64.sys
Size: 60.09 KB (60096 bytes)
MD5: 8abb99610a2fa571530058f6585bce7f
Detection count: 72
File type: System file
Mime Type: unknown/sys
Path: system32\drivers
Group: Malware file
Last Updated: July 18, 2014
system32\drivers\{2635ac50-5488-40bf-9bfd-accb158f8f3f}t64.sys File name: {2635ac50-5488-40bf-9bfd-accb158f8f3f}t64.sys
Size: 60.09 KB (60096 bytes)
MD5: a5d3bc5cac6586a3220b1a8d7539c07c
Detection count: 70
File type: System file
Mime Type: unknown/sys
Path: system32\drivers
Group: Malware file
Last Updated: July 18, 2014
system32\drivers\{2635ac50-5488-40bf-9bfd-accb158f8f3f}Gw64.sys File name: {2635ac50-5488-40bf-9bfd-accb158f8f3f}Gw64.sys
Size: 61.12 KB (61120 bytes)
MD5: 3925da84ed744f80535e3c2ce208feeb
Detection count: 26
File type: System file
Mime Type: unknown/sys
Path: system32\drivers
Group: Malware file
Last Updated: July 18, 2014
system32\drivers\{ed7eb956-75ed-460d-8f69-29a93b07afd1}t64.sys File name: {ed7eb956-75ed-460d-8f69-29a93b07afd1}t64.sys
Size: 60.09 KB (60096 bytes)
MD5: 3c8e6e5865e199e0882513cbcdb4751c
Detection count: 10
File type: System file
Mime Type: unknown/sys
Path: system32\drivers
Group: Malware file
Last Updated: July 18, 2014
system32\drivers\{2635ac50-5488-40bf-9bfd-accb158f8f3f}t64.sys File name: {2635ac50-5488-40bf-9bfd-accb158f8f3f}t64.sys
Size: 60.09 KB (60096 bytes)
MD5: 0bd139bf8ba198e7920bdf0de5dfc8d3
Detection count: 7
File type: System file
Mime Type: unknown/sys
Path: system32\drivers
Group: Malware file
Last Updated: July 18, 2014
%WINDIR%\System32\drivers\{2635ac50-5488-40bf-9bfd-accb158f8f3f}Gw.sys File name: {2635ac50-5488-40bf-9bfd-accb158f8f3f}Gw.sys
Size: 52.92 KB (52928 bytes)
MD5: c1c616a7e7499b11b9f327f18beb36d4
Detection count: 5
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: July 18, 2014

Registry Modifications

The following newly produced Registry Values are:

CLSID{0D17D945-4EB1-4370-B3B0-E566D5014B0A}{26C67489-D15D-4C39-9D38-DB3C33FCF199}{43867D46-E907-46D4-94C0-B50ABF479A59}{49E31EE4-051E-49D7-B77B-05462B1E91D3}{57FE6A0E-F47C-40E7-B9A5-D77D752CAD5E}{5fb66911-2787-49cf-8f96-265e34893e40}{863499e9-9257-4f5d-a356-496258ab93c8}{92E43F88-F1A5-442E-94C3-F35E01D075ED}{c919d8b2-11e4-43c7-a2c2-9294fd2c4106}HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{5FB66911-2787-49CF-8F96-265E34893E40}Software\Microsoft\Internet Explorer\Approved Extensions\{863499E9-9257-4F5D-A356-496258AB93C8}Software\Microsoft\Internet Explorer\Approved Extensions\{C919D8B2-11E4-43C7-A2C2-9294FD2C4106}SOFTWARE\Microsoft\Tracing\updateWebSpades_RASAPI32SOFTWARE\Microsoft\Tracing\updateWebSpades_RASMANCSSOFTWARE\Microsoft\Tracing\WebSpades_RASAPI32SOFTWARE\Microsoft\Tracing\WebSpades_RASMANCSSoftware\Microsoft\Windows\CurrentVersion\Ext\Settings\{5FB66911-2787-49CF-8F96-265E34893E40}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{863499E9-9257-4F5D-A356-496258AB93C8}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C919D8B2-11E4-43C7-A2C2-9294FD2C4106}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5FB66911-2787-49CF-8F96-265E34893E40}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{863499E9-9257-4F5D-A356-496258AB93C8}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C919D8B2-11E4-43C7-A2C2-9294FD2C4106}Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{5fb66911-2787-49cf-8f96-265e34893e40}Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{c919d8b2-11e4-43c7-a2c2-9294fd2c4106}Software\WebSpadesSOFTWARE\Wow6432Node\Microsoft\Tracing\updateWebSpades_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateWebSpades_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\utilWebSpades_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\utilWebSpades_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\WebSpades_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\WebSpades_RASMANCSSOFTWARE\Wow6432Node\WebSpadesSYSTEM\ControlSet001\services\eventlog\Application\Update WebSpadesSYSTEM\ControlSet001\services\eventlog\Application\Util WebSpadesSYSTEM\ControlSet001\services\Update WebSpadesSYSTEM\ControlSet001\Services\UpdaterSvcWebSpadesSYSTEM\ControlSet001\Services\Util WebSpadesSYSTEM\ControlSet002\services\eventlog\Application\Update WebSpadesSYSTEM\ControlSet002\services\eventlog\Application\Util WebSpadesSYSTEM\ControlSet002\services\Update WebSpadesSYSTEM\ControlSet002\Services\Util WebSpadesSYSTEM\CurrentControlSet\services\eventlog\Application\Update WebSpadesSYSTEM\CurrentControlSet\services\eventlog\Application\Util WebSpadesSYSTEM\CurrentControlSet\services\Update WebSpadesSYSTEM\CurrentControlSet\Services\UpdaterSvcWebSpadesSYSTEM\CurrentControlSet\Services\Util WebSpadesHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}WebSpades

Additional Information

The following directories were created:
%PROGRAMFILES%\WebSpades%PROGRAMFILES(x86)%\WebSpades%TEMP%\WebSpades
The following URL's were detected:
WebSpades
Loading...