Should I block it?

98%
Yes, 98% block recommendation.
Possible reasons:
Multiple malware detections
Performance resource utilization

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegQueryValueExA, RegFlushKey, RegEnumValueA, RegQueryInfoKeyA, RegSetValueExA, RegEnumKeyExA, RegOpenKeyExA, RegCloseKey, RegDeleteValueA, RegCreateKeyExA, RegDeleteKeyA, RegEnumKeyA
gdi32.dll
CreateDIBitmap, CreateCompatibleBitmap, GetDeviceCaps, CreateRectRgnIndirect, CreateRectRgn, DPtoLP, SelectClipRgn, CreateCompatibleDC, SelectObject, GetMapMode, SetMapMode, BitBlt, DeleteDC, RestoreDC, SetViewportOrgEx, SetWindowOrgEx, SaveDC, LPtoDP, CreateDCA, GetTextMetricsA, CreateFontIndirectA, ModifyWorldTransform, SetGraphicsMode, SetBkMode, SetTextColor, CreateSolidBrush, EqualRgn, OffsetRgn, CombineRgn, SetRectRgn, PtInRegion, CreateEllipticRgn, GetStockObject, DeleteObject, GetObjectA
kernel32.dll
FindResourceA, GetLastError, IsDBCSLeadByte, HeapDestroy, GetCurrentThreadId, ReadFile, SetThreadPriority, GetThreadPriority, GetCurrentThread, GetPrivateProfileStringA, WritePrivateProfileStringA, GetCurrentDirectoryA, GetLocalTime, WaitForMultipleObjects, SetLastError, lstrcmpA, FindNextFileA, GetFileAttributesA, GetLogicalDrives, FindClose, FindFirstFileA, GlobalUnlock, GlobalLock, DebugBreak, HeapReAlloc, LoadResource, CreateFileMappingA, WriteFile, GetFileSize, CreateFileA, UnmapViewOfFile, CreateDirectoryA, SetEndOfFile, SetFilePointer, SetFileAttributesA, FlushFileBuffers, SizeofResource, WideCharToMultiByte, GetModuleHandleA, GetSystemDirectoryA, GetVersion, HeapCreate, GetVersionExA, GetSystemInfo, HeapAlloc, DisableThreadLibraryCalls, EnterCriticalSection, LeaveCriticalSection, CreateThread, DeleteCriticalSection, InitializeCriticalSection, GetCurrentProcess, FlushInstructionCache, VirtualQuery, VirtualProtect, MultiByteToWideChar, lstrlenW, OpenProcess, ResetEvent, LocalFree, GlobalAlloc, GetPriorityClass, ResumeThread, MulDiv, GetFileTime, GetCommandLineA, GetDriveTypeA, SetCurrentDirectoryA, WritePrivateProfileSectionA, GetPrivateProfileIntA, OpenFileMappingA, HeapFree, GetProcessHeap, FreeLibrary, InterlockedDecrement, InterlockedIncrement, LoadLibraryExA, LoadLibraryA, GetProcAddress, lstrcmpiA, GetTickCount, ReleaseMutex, CreateMutexA, CreateEventA, GetModuleFileNameA, GetShortPathNameA, CreateProcessA, lstrcpynA, CopyFileA, WaitForSingleObject, lstrcpyA, OpenEventA, SetEvent, CloseHandle, lstrlenA, lstrcatA, DeleteFileA, MapViewOfFile, GetCurrentProcessId
msvfw32.dll
DrawDibOpen, DrawDibClose, DrawDibDraw
ole32.dll
OleRegGetUserType, OleRegEnumVerbs, CoTaskMemRealloc, CoTaskMemAlloc, StringFromCLSID, OleRegGetMiscStatus, OleInitialize, OleUninitialize, CreateStreamOnHGlobal, CLSIDFromProgID, CLSIDFromString, OleLockRunning, CoCreateInstance, CreateOleAdviseHolder, ReleaseStgMedium, CoLoadLibrary, CoTaskMemFree
shell32.dll
SHGetDesktopFolder, SHGetFileInfoA, SHGetMalloc, SHGetSpecialFolderLocation, SHGetPathFromIDListA, SHLoadInProc
user32.dll
SetWindowRgn, SetWindowPos, DestroyWindow, GetFocus, GetClassInfoExA, LoadCursorA, RegisterClassExA, OffsetRect, EqualRect, IntersectRect, EndPaint, GetClientRect, BeginPaint, UnhookWindowsHookEx, PostQuitMessage, SendMessageA, KillTimer, SetTimer, AdjustWindowRect, GetWindowRect, GetDesktopWindow, RegisterWindowMessageA, PostMessageA, GetClassNameA, IsWindowVisible, GetParent, SystemParametersInfoA, CallNextHookEx, TranslateMessage, GetMessageA, SetWindowsHookExA, ShowWindow, SetFocus, FillRect, CopyImage, RegisterClipboardFormatA, CreateWindowExA, UnionRect, MoveWindow, PtInRect, GetKeyState, DefWindowProcA, CharNextA, GetWindowLongW, GetWindowLongA, IsWindowUnicode, SetWindowLongW, SetWindowLongA, CallWindowProcA, CallWindowProcW, DefWindowProcW, wsprintfA, keybd_event, IsChild, PeekMessageA, GetKeyboardType, UnregisterClassA, GetKeyboardState, ShowCursor, GetWindow, DrawTextA, CopyRect, SetRect, CloseClipboard, EmptyClipboard, OpenClipboard, SetWindowTextA, GetSysColor, RedrawWindow, CreateAcceleratorTableA, ReleaseCapture, SetCapture, InvalidateRgn, GetDlgItem, ScrollDC, GetWindowThreadProcessId, GetDC, ReleaseDC, InvalidateRect, UpdateWindow, EnumWindows, IsWindow, EnumChildWindows, GetWindowTextLengthA, GetWindowTextA, SendMessageTimeoutA, DispatchMessageA
version.dll
GetFileVersionInfoSizeA, GetFileVersionInfoA, VerQueryValueA
Export table
DllCanUnloadNow
DllGetClassObject
DllRegisterServer
DllUnregisterServer
LES
SSD
Update
WMCreateStreamForURL

f3ScrCtr.dll

Popular Screensavers by Mindspark Interactive Network (Signed)

Remove f3ScrCtr.dll
Version:   1, 0, 2, 15
MD5:   3835ce080353193215e97c11a9edac37
SHA1:   e89851a1a2caf68c2fbf03870f902bb34fdd0d68
SHA256:   1ae5e950823f99ca3508941a93a1db032e71b353d86cfe026e7f8e4ddb2fbec2
Warning 10 antivirus scanners has detected malware.

What is f3ScrCtr.dll?

Popular Screensavers by the Mindspark Interactive Network is a browser toolbar, part of the Fun Web Products suite of potentially unwanted applications such as Smiley Central, Cursor Mania, Popular Screensavers and others. The toolbar provides access to search engine results and a 404 Error Redirector among other things to your browser. The My Web Search toolbar could slow down your PC and uses cookies to track your web surfing usage and habits.

About f3ScrCtr.dll (from Mindspark Interactive Network)

MyWebSearch brings together the most comprehensive collection of search tools available to provide you with the information you need when you need it.

Overview

f3scrctr.dll is malware that is loaded as dynamic link library that runs in the context of a process. It is set to be run when the PC boots and the user logs into Windows (added to the Run registry key for the current user). The file is digitally signed by Mindspark Interactive Network which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:f3scrctr.dll
Publisher:FunWebProducts.com
Product name:Popular Screensavers
Description:Popular Screensavers Tools
Typical file path:C:\Program Files\mywebsearch\bar\1.bin\f3scrctr.dll
File version:1, 0, 2, 15
Product version:2, 3, 0, 0
Size:301.42 KB (308,656 bytes)
Certificate
Issued to:Mindspark Interactive Network
Authority (CA):VeriSign
Effective date:Sunday, May 30, 2010
Expiration date:Sunday, May 6, 2012
Digital DNA
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'PopularScreensaversWallpaper' → rundll32 C:\Program Files2\MYWEBS~1\bar\1.bin\F3SCRCTR.DLL,LES

MalwareMalware detections

Based on 40+ industry antivirus scanners, 10 of them detected the following malware.
Antivirus engineEngine versionDetection
AhnLab V3 Internet Security 2013.03.16 Win-PUP/Toolbar.FunWeb.308656
avast! 6.0.1289.0 Win32:FunWeb-B [PUP]
AVG 2014.0.3629 AdInstaller.FunWeb
Clam AntiVirus 0.97.3.0 Adware.FunWebProducts-5
eSafe 7.0.17.0 Win32.Toolbar.MyWebS
ESET NOD32 7.8122 Win32/Toolbar.MyWebSearch.P
Kingsoft 2013.1.8.219 Win32.Troj.Generic.(kcloud)
Norman 7.00.22 Suspicious_Gen2.QQTSF
SUPERAntiSpyware 5.6.0.1008 PUP.MyWebSearch/FunWebProducts
VIPRE Antivirus 16080 MyWebSearch.J (v) (not malicious)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 50.00%
Windows 7 Home Premium 50.00%

Distribution by countryDistribution by country

MU installs about 50.00% of Popular Screensavers.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
GIGABYTE 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE