Home Malware Programs Browser Hijackers Easy Search

Easy Search

Posted: March 28, 2006

Threat Metric

Ranking: 5,147
Threat Level: 1/10
Infected PCs: 7,535
First Seen: March 8, 2016
Last Seen: October 17, 2023
OS(es) Affected: Windows

Easy Search is a simple but aggressive browser hijacker that may compromise Google Chrome, Mozilla Firefox and Internet Explorer. This application may hook towards all available Web clients as an extension, but it is much more stubborn than the legit plugins. The main function of the browser hijacker is to promote easysearch.com. This plain site contains only a small search field on top of the screen. There are no additional page elements besides the search box. If you type your terms there, you may not find reliable results. Easy Search relies on the database of Google for part of its results, but the majority of links that you will see may lead to third-party partner pages. Some of them may be unsafe, so it is not advisable to use easysearch.com. Since the results that this domain generates are not the most accurate ones, you may lose precious time visiting irrelevant pages. The browser hijacker may make this suspicious site your default homepage. As long as the unwanted extension stays on your PC, you may be unable to revert the modification made by it. Easy Search also may set its low-quality search engine as your default search provider. As a consequence, typing your terms in the URL bar may bring the results from easysearch.com. This harmful add-on may be suggested to the PC users by third-party freeware, which is an approach called bundling. Its description may be misleading – you may assume that the extension will optimize your searches or improve the overall surfing experience. In the majority of cases, however, computer users remain totally unaware that they are about to install Easy Search. The commonly used 'Quick' menu may not show details about additional components alongside the main software, so you should use the 'Advanced' Guide instead. Once the unwanted extension settles in, you should use a credible security program for its removal.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 iau.exe
    2 lssas.exe
    3 mservice.exe
    4 msqdevl.exe
    5 runwin32.exe
    6 stisvsq.exe
    7 svshost.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainStartPage=[siteaddress]HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternetSettingsProxyOverride=[local]HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternetSettingsProxyServer=[IPaddress]HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunGamesAccelerationHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunInternetConnectionWizardHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunInternetMailandNewsHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunMicrosoftInternetAcceleratorHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunMicrosoftManagementConsoleHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunMultimediaExtensionsHKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerMainStartPage=[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunGamesAccelerationHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunInternetConnectionWizardHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunInternetMailandNewsHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunMicrosoftInternetAcceleratorHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunMicrosoftManagementConsoleHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunMultimediaExtensions
Loading...