Home Rogue Websites Classysearchserver.com

Classysearchserver.com

Posted: September 16, 2011

Classysearchserver.com is a bogus CC Search clone that uses browser hijackers to redirect your browser to the fake website and to inflate Classysearchserver.com's traffic. Like other CC Search mirrors, Classysearchserver.com pretends to be able to provide helpful search results, but SpywareRemove.com malware researchers have found that Classysearchserver.com doesn't make any real attempt to provide relevant links. Instead, Classysearchserver.com will provide adware and affiliate revenue-based links that give profit to the criminals in charge of the website, while being an impediment to Classysearchserver.com's hapless visitors. Because such browser hijacks are often correlated with the presence of rootkits, dropper Trojans and other types of advanced PC threats, SpywareRemove.com malware experts recommend that you use a competent anti-malware program to delete Classysearchserver.com infections, instead of trying to do so without assistance.

Classysearchserver.com: Just Another CC Search in Disguise

Classysearchserver.com is simply one of several domains that are used by the search engine that's known by the name of CC Search. Other examples of equivalent and identical sites include noblesearchserver.com, coolsearchserver.com, coolwebsearch.com and *dayoftheweek.com sites (such as 1dayoftheweek.com, 5dayoftheweek.com, etc).

Classysearchserver.com and Classysearchserver.com's relatives use browser hijacker infections to redirect your browser to their own sites and then offer links to advertisements, blank web pages and potentially hazardous sites. You should avoid having anything to do with any of these fake search results, since SpywareRemove.com malware experts haven't seen any indication that Classysearchserver.com can provide any links of genuine benefit.

Although a Classysearchserver.com redirect attack can appear at any time, the majority of these attacks occur only after you try to use a search engine like Google. Avoiding popular search engines may allow you to avoid the symptoms of a Classysearchserver.com infection, but the Classysearchserver.com infection itself should still be removed by an appropriate anti-malware program.

How to Get Rid of Classysearchserver.com and Get Back to Browsing Relevant Sites

Making alterations to your browser, such as changing its settings or re-installing it will not affect a Classysearchserver.com browser hijacker infection, since these infections operate to infect the Windows Registry and other non-browser aspects of Windows. SpywareRemove.com malware research team has also noted with mild alarm that Classysearchserver.com infections are often accompanied by the ZeroAccess rootkit.

Rootkits such as ZeroAccess, TDSS, and TDL3 will launch themselves automatically and should be considered active until you've taken steps to deactivate them. Safe Mode is the most easily-accessed method of stopping a Classysearchserver.com-related rootkit, although other measures may also be necessary for advanced infections. However, in all cases, appropriate security software that's been equipped with full threat definition updates can delete Classysearchserver.com, Classysearchserver.com's rootkit and related PC threats.

To protect your PC from Classysearchserver.com attacks in the future, keep your browser up-to-date, disable scripts for suspicious websites and only acquire software updates from sources that you trust.

Technical Details

File System Modifications

The following files were created in the system:



C:\Windows\system32\DRIVERS\mrxsmb.sys File name: C:\Windows\system32\DRIVERS\mrxsmb.sys
File type: System file
Mime Type: unknown/sys
C:\Windows\system32\consrv.dll File name: C:\Windows\system32\consrv.dll
File type: Dynamic link library
Mime Type: unknown/dll

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}SubSystems: Windows = basesrv,1 winsrv:UserServerDllInitialization,3 consrv:ConServerDllInitialization,2 sxssrv,4
Loading...