Threat Description

Adware: ​W32/WSearch


Category: Spyware
Type: Adware
Platform: W32


This program delivers advertising content to the user. It is usually annoying but harmless, unless it is combined with spyware or trackware.


Automatic action

Once detected, the F-Secure security product will automatically quarantine the suspect file and prompt the user to select a further desired action.

Quarantine is a safe repository for files that may be harmful. A quarantined file can be restored or, if you decide so, deleted.

Excluding a file from scanning

If you are aware of and accept any potential risk associated with this program, you can configure the F-Secure security product to exclude it from scanning.

Suspect a False Alarm?

If you suspect a file has been incorrectly identified as malicious, (that is, it is a False Alarm or a False Positive), please first ensure your F-Secure security program is up-to-date with the latest detection database updates, then rescan the suspect file.

If you continue to suspect a False Alarm, you may submit a sample of the suspect file to our Security Labs for further analysis via the Sample Analysis System (SAS).

More scanning & removal options

More information on scanning or removal options is available in the documentation for your F-Secure security product on the Downloads section of our Home - Global site.

You may also refer to the Knowledge Base on the F-Secure Community site for more information.

Contact Support

For further assistance, F-Secure customers can request support online via the Request support or the Chat forms on our Home - Global site.

Technical Details

This is the family description for the Adware:W32/WSearch adware family.

The WSearch adware family appears to be related to the Zhongsou Chinese Search Engine. While active and connected to the Internet, WSearch adware may display additional targeted pop-up advertisements and communicate with Zhongsou servers.


When a WSearch adware program's installer is executed, the program is silently installed. No end user license agreement (EULA) is displayed during the installation.&

The adware is installed to:

  • %programfiles%\DeskAdTop\

Network Connections

Attempts to connect with HTTP to:



WSearch adware can be uninstalled from the Add/Remove Programs menu. The uninstallation process requires the user to complete a CAPTCHA test (Completely Automated Public Turing Test to Tell Computers and Humans Apart).

Once the program is uninstalled, its folder still needs to be manually deleted.

Description Created: 2009-03-24 05:17:49.0

Description Last Modified: 2009-03-24 08:11:22.0


Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Submit a sample

Wondering if a file or URL is malicious Submit a sample to our Lab for analysis via the Sample Analysis System (SAS)

Learn More

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More