Home Malware Programs Browser Hijackers SmartSearch

SmartSearch

Posted: March 28, 2006

SmartSearch is a browser hijacker that changes Internet Explorer default home and search pages to undesirable web sites and modifies related search settings. The threat also sends the web browser to unsolicited Internet resources every time the user enters a site address without the "http://" prefix. SmartSearch is able to automatically update itself via the Internet. The threat runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 accesss.exe
    2 directx.exe
    3 explore.exe
    4 funny.exe
    5 helpcvs.exe
    6 internet.exe
    7 systeem.exe
    8 systemcritical.exe
    9 wmplayer.exe
    10 y.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainDefault_Page_URL=[siteaddress]HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainDefault_Search_URL=[siteaddress]HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainSearchPage=[siteaddress]HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainStartPage=[siteaddress]HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerSearch=[siteaddress]HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerSearchURL=[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerMainDefault_Page_URL=[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerMainDefault_Search=[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerMainSearchBar=[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerMainSearchPage=[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerMainStartPage=[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerSearch=[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerSearchCustomizeSearch=[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerSearchSearchAssistant=[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerSearchURL=[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunSystemEmergencyHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionURLDefaultPrefix(Default)=[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionURLPrefixeswww=[siteaddress]

Related Posts

Loading...