Home Malware Programs Browser Hijackers Smartinf.ru

Smartinf.ru

Posted: June 5, 2015

Threat Metric

Ranking: 3,229
Threat Level: 5/10
Infected PCs: 96,520
First Seen: June 5, 2015
Last Seen: October 16, 2023
OS(es) Affected: Windows


Smartinf.ru is designed as a homepage for Russian-speaking users. Smartinf.ru has links to popular services like Yandex Mail, Facebook, Instagram and Pinterest. Smartinf.ru may include news from your vicinity and provide content from news outlets like Sputniknews.com, Themoscowtimes.com and Rt.com. However, the Smartinf.ru page is associated with a browser hijacker that is deployed to users via freeware packages globally. Moreover, the Smartinf.ru is not trusted and is blacklisted by most Web filters among which are Google Safe Browsing, Mozilla Phishing Protection and Cisco Cloud Web Security. The 185.50.24.124 IP address of Smartinf.ru is related to the Infinity Exploit Kit.

The browser hijacker at hand is programmed to change the user's start page to Smartinf.ru and the functionality of the address bar, the Omnibar and the search bar of browsers like Google Chrome, Opera, Internet Explorer and Mozilla Firefox. The Smartinf.ru browser hijacker may redirect users to affiliated pages, promotional materials and phishing portals. The links on Smartinf.ru may lead users to download potentially hazardous software like FixPCOptimizer and CpuMiner. The Smartinf.ru browser hijacker may slow down your Internet client, and open new tabs with vouchers and offers from untrusted merchants when you look at items on Amazon, Best Buy and Walmart. The Smartinf.ru browser hijacker may be listed in the Windows Task Manager as a browser service, and run as long as your PC is turned on. Security researchers note that the Smartinf.ru browser hijacker may have made modifications to the group policy of your Windows OS and hide its files from third-party applications and manual removal. Computer users are advised to seek the help of a trusted anti-malware tool to eradicate the Smartinf.ru browser hijacker and secure their machines.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

File name without pathhttp_smartinf.ru_0.localstoragehttp_smartinf.ru_0.localstorage-journalHKEY..\..\..\..{RegistryKeys}Software\Microsoft\favorites\2inf_favoritesSoftware\Microsoft\hsetSOFTWARE\Microsoft\pinnedtabs\2inf_pinnedtabsSoftware\Microsoft\shortcutmakerSOFTWARE\Microsoft\shortcutmaker\2inf_iconSOFTWARE\Microsoft\shortcutmaker\2inf_launchSoftware\Microsoft\speeddialmakerSoftware\Microsoft\StartlinkSoftware\Microsoft\Startlink\2inf_startlinkSOFTWARE\Microsoft\startpage\2inf_startpageSoftware\Microsoft\uouaPluginSoftware\speeddialmaker

Additional Information

The following URL's were detected:
//thatmi.ru/ovteve.ru/2inf.netdcura.rudeal-big.ruforetuned.comhttps://smartinf.ruhttps://smartinf.ru/lenife.rungiregi.rusimsimotkroysia.rutumuri.ruvyitikho.ruyakubala.ru
Loading...