Home Malware Programs Adware HighlightSearches

HighlightSearches

Posted: July 14, 2015

Threat Metric

Ranking: 3,757
Threat Level: 2/10
Infected PCs: 16,840
First Seen: May 27, 2015
Last Seen: October 16, 2023
OS(es) Affected: Windows

HighlightSearches is a Web-browsing application that may provide additional interface options for your Web searches but also may deliver advertisements for revenue. Because of the minimal utility of its features and additional security issues, HighlightSearches is classified as a Potentially Unwanted Program. Like most PUPs, uninstalling HighlightSearches via the Control Panel may give HighlightSearches the opportunity to reinstall itself or continue delivering advertisements, all of which should be resolved by removing HighlightSearches with a good anti-adware program.

The Downside of Highlighting Your Web Searches

HighlightSearches is adware based on a multiple browser platform that may modify Internet Explorer, Firefox or Chrome simultaneously. However, this platform, Abengine.exe, isn't installed from the HighlightSearches website (HighlightSearches.com). Malware analysts eventually isolated installers for HighlightSearches and its underlying platform distributing themselves in bundles with other, equally free software, such as third-party codec packages. PC users using these installers also found most installed browsers changed by HighlightSearches automatically.

HighlightSearches may include two primary, separate modifications:

  • HighlightSearches may inject additional user interface elements for Web page navigation (a HighlightSearches-specific 'next page' button). These elements may be confined to popular search engines.
  • HighlightSearches also may add its own, promoted search result links into most Web searches. These results may label themselves as being delivered by HighlightSearches and provide third-party affiliate offers, rather than the relevancy of their content.

Since HighlightSearches may use a semi-universal Abengine-based platform to make these changes, PC users are unable to delete HighlightSearches or its browser changes from their local browser's extensions menu or add-on manager. At this time, malware analysts have found no cases of HighlightSearches serving corrupted advertising content, although they also have noted that HighlightSearches excludes control options for disabling its advertisements easily.

Concluding the Search for Removing HighlightSearches

While the HighlightSearches website does offer generic uninstall instructions, malware analysts found most samples of HighlightSearches failing to delete itself appropriately during the procedure. They also confirmed instances of HighlightSearches being reinstalled automatically after a system reboot. Restoring your Web browser's settings while leaving HighlightSearches installed is a possible security risk, and, as with most adware, not a recommended solution.

For deleting HighlightSearches entirely, malware analysts advise restarting in Safe Mode, which you can find in the boot options menu by pressing F8 while your PC reboots. Updated anti-adware programs and equivalent security tools should have no problems in detecting and then removing HighlightSearches from any computer. Afterward, any remaining symptoms of HighlightSearches advertising should be eliminated, although clearing your browser's cache and settings also may be needed.

Malware analysts have yet to finish tracing the original sources of installer bundles for HighlightSearches. However, most similar adware products may exploit general freeware domains or illicit torrent uploads as a primary means of circulation.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



D:\Program Files\HighlightSearches\fres3005.exe File name: fres3005.exe
Size: 59.48 KB (59488 bytes)
MD5: 5677ba7efe34c8abab840a7bc7165c73
Detection count: 4,747
File type: Executable File
Mime Type: unknown/exe
Path: D:\Program Files\HighlightSearches\fres3005.exe
Group: Malware file
Last Updated: September 6, 2020
%PROGRAMFILES(x86)%\HighlightSearches\abengine.exe File name: abengine.exe
Size: 1.77 MB (1775248 bytes)
MD5: 758f224c7d70516ebcd7f8737ce4a0b7
Detection count: 2,056
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\HighlightSearches
Group: Malware file
Last Updated: August 11, 2019
C:\Program Files (x86)\HighlightSearches\uninstall.exe File name: uninstall.exe
Size: 65.69 KB (65694 bytes)
MD5: 23aeb808a0ab76ae7f2efb518956965c
Detection count: 215
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\HighlightSearches\uninstall.exe
Group: Malware file
Last Updated: December 27, 2022
C:\Program Files (x86)\HighlightSearches\lengine64.exe File name: lengine64.exe
Size: 345.98 KB (345984 bytes)
MD5: d0342dabf5c9efcd0b0d6efe67bc418a
Detection count: 192
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\HighlightSearches\lengine64.exe
Group: Malware file
Last Updated: December 27, 2022
C:\AdwCleaner\Quarantine\C\Program Files (x86)\HighlightSearches\abengine.exe.vir File name: abengine.exe.vir
Size: 2.32 MB (2329600 bytes)
MD5: 7bb84746407a35025c3bd4583030f7d3
Detection count: 141
Mime Type: unknown/vir
Path: C:\AdwCleaner\Quarantine\C\Program Files (x86)\HighlightSearches\abengine.exe.vir
Group: Malware file
Last Updated: December 27, 2022
C:\Program Files (x86)\HighlightSearches\iren3006.exe File name: iren3006.exe
Size: 59.98 KB (59986 bytes)
MD5: 2db4e2907d04fee2633bcd6ae9cdd0be
Detection count: 117
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\HighlightSearches\iren3006.exe
Group: Malware file
Last Updated: December 27, 2022
C:\AdwCleaner\Quarantine\C\Program Files (x86)\HighlightSearches\lengine.exe.vir File name: lengine.exe.vir
Size: 398.16 KB (398160 bytes)
MD5: f107f7d79b750fca106ac8ace7781e5d
Detection count: 117
Mime Type: unknown/vir
Path: C:\AdwCleaner\Quarantine\C\Program Files (x86)\HighlightSearches\lengine.exe.vir
Group: Malware file
Last Updated: December 27, 2022
%PROGRAMFILES(x86)%\HighlightSearches\fres3005.exe File name: fres3005.exe
Size: 59.48 KB (59488 bytes)
MD5: de07885a3eee967ac22df0978f6d3605
Detection count: 36
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\HighlightSearches
Group: Malware file
Last Updated: May 27, 2015
%PROGRAMFILES(x86)%\HighlightSearches\dc.exe File name: dc.exe
Size: 95.74 KB (95744 bytes)
MD5: 77b6c586b96a0b2d545478950ba99a72
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\HighlightSearches
Group: Malware file
Last Updated: January 16, 2020
%PROGRAMFILES(x86)%\HighlightSearches\abengine.exe File name: abengine.exe
Size: 2.32 MB (2329600 bytes)
MD5: 261b110740337f46744b415c07c666bf
Detection count: 15
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\HighlightSearches
Group: Malware file
Last Updated: May 27, 2015
C:\Users\<username>\AppData\Local\Temp\setuptn_4435.exe File name: setuptn_4435.exe
Size: 5.79 MB (5793523 bytes)
MD5: 578130cabe5c432599e3e78ea7c10dad
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\setuptn_4435.exe
Group: Malware file
Last Updated: April 11, 2021
%PROGRAMFILES%\HighlightSearches\lengine.exe File name: lengine.exe
Size: 295.15 KB (295152 bytes)
MD5: eaf44eaead26073ef003bddd9becef17
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\HighlightSearches
Group: Malware file
Last Updated: May 27, 2015
%PROGRAMFILES(x86)%\HighlightSearches\lengine64.exe File name: lengine64.exe
Size: 345.44 KB (345440 bytes)
MD5: 450610b82ce6518d7421e17b2eb87a09
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\HighlightSearches
Group: Malware file
Last Updated: May 27, 2015
%PROGRAMFILES(x86)%\HighlightSearches\abengine.exe File name: abengine.exe
Size: 1.77 MB (1775248 bytes)
MD5: 6e78be5ced55f457b5ee380416289caa
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\HighlightSearches
Group: Malware file
Last Updated: May 27, 2015
%PROGRAMFILES(x86)%\HighlightSearches\njs.exe File name: njs.exe
Size: 164.35 KB (164352 bytes)
MD5: 64f2513967a2b9cf6f3f7f3980ec326e
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\HighlightSearches
Group: Malware file
Last Updated: May 27, 2015
%PROGRAMFILES(x86)%\HighlightSearches\iren3006.exe File name: iren3006.exe
Size: 59.98 KB (59986 bytes)
MD5: df2ae361867bf91c5f8f4ee205af7f04
Detection count: 0
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\HighlightSearches
Group: Malware file
Last Updated: May 27, 2015

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}SYSTEM\ControlSet001\services\abengineSYSTEM\ControlSet002\services\abengineSYSTEM\CurrentControlSet\services\abengine

Additional Information

The following directories were created:
%PROGRAMFILES%\HighlightSearches%PROGRAMFILES(x86)%\HighlightSearches
Loading...