Home Malware Programs Browser Hijackers SearchNew

SearchNew

Posted: March 28, 2006

SearchNew is a browser hijacker that changes Internet Explorer default home and search pages and blocks access to Microsoft search engine. It also adds bookmarks to the web browser's Favorites menu. The threat is bundled with some ad-supported software. It can also be manually installed. SearchNew automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 msapp.exe
    2 winupd.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainDefault_Search_URL=[siteaddress]HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainSearchBar=[siteaddress]HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainSearchPage=[siteaddress]HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainStartPage=[siteaddress]HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerSearch=[siteaddress]HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerSearchCustomizeSearch=[siteaddress]HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerSearchSearchAssistant=[siteaddress]HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerSearchURL=[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerMainDefault_Search_URL==[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerMainSearchBar==[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerMainSearchPage==[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerMainStartPage==[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerSearch==[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerSearchCustomizeSearch==[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerSearchSearchAssistant==[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerSearchURL==[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunwinapp32=masapp.exeHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunwinupd=%System%winupd.exeHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionyun

Related Posts

Loading...