internetguardsetup.exe

WebSearch Toolbar

WebSearch LLC

The application internetguardsetup.exe, “WebSearch Toolbar Setup ” by WebSearch has been detected as adware by 5 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from www.websearch.com.
Publisher:
WebSearch, LLC   (signed by WebSearch LLC)

Product:
WebSearch Toolbar

Description:
WebSearch Toolbar Setup

Version:
1.1.0.13

MD5:
630df9f6b1e6aa3cc2969d35aca4e18d

SHA-1:
ca509ce3942c4ac71473e83a8bb3b91958458775

SHA-256:
d185974f220035765023988df80ae681c79c5a81f408108b8b98978915af8ab4

Scanner detections:
5 / 68

Status:
Adware

Analysis date:
2/25/2025 1:49:51 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2015.0.3392

Clam AntiVirus
Win.Adware.PCFixSpeed
0.98/21411

McAfee
Artemis!630DF9F6B1E6
5600.7048

Reason Heuristics
PUP.WebSearch.Installer (M)
15.6.18.0

Trend Micro House Call
Suspicious_GEN.F47V0705
7.2.217

File size:
1.8 MB (1,860,472 bytes)

Product version:
1.1.0.13

Copyright:
copyright © WebSearch, LLC

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\internetguardsetup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/26/2013 7:00:00 PM

Valid to:
8/27/2014 6:59:59 PM

Subject:
CN=WebSearch LLC, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=WebSearch LLC, L=Boca Raton, S=Florida, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3973095592BCA3504FF9FFF6E2B0F381

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:G1GVXO7/P7fD2r5EghE5RgF5yebA5rOYiZnT:GS+LP6+gq5eFUebSivZnT

Entry address:
0xC1C0

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, C8, C0, 40, 00, E8, 60, 86, FF, FF, 33, C0, 55, 68, 85, C8, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 41, C8, 40, 00, 64, FF, 32, 64, 89, 22, A1, 60, E6, 40, 00, E8, 5E, FD, FF, FF, E8, C9, F8, FF, FF, 8D, 55, EC, 33, C0, E8, 93, CA, FF, FF, 8B, 55, EC, B8, 8C, F0, 40, 00, E8, 0A, 77, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 8C, F0, 40, 00, B2, 01...
 
[+]

Entropy:
7.9902

Developed / compiled with:
Microsoft Visual C++

Code size:
46.5 KB (47,616 bytes)

The file internetguardsetup.exe has been seen being distributed by the following URL.

Remove internetguardsetup.exe - Powered by Reason Core Security