Home Malware Programs Browser Hijackers Eminentsearchsystem.com

Eminentsearchsystem.com

Posted: November 15, 2011

With links for broad-interest subjects and a soothing blue-and-white background, Eminentsearchsystem.com tries to set your mind at ease, but this search engine isn't a site to let your guard down around. Like other CC Search sites, Eminentsearchsystem.com uses browser hijackers to force traffic to itself as part of a money-making search engine scam, and like these other sites, SpywareRemove.com malware researchers have found that Eminentsearchsystem.com doesn't offer real search results. Any contact with Eminentsearchsystem.com should be considered a potential infection vector for your PC, and if you find that your browser is beginning to redirect you to CC Search sites like Eminentsearchsystem.com, you should immediately scan your computer with an anti-malware application of good repute.

A Forecast for Eminentsearchsystem.com: Danger for Your PC

While Eminentsearchsystem.com may look like a search engine, Eminentsearchsystem.com doesn't attempt to 'search' for anything – Eminentsearchsystem.com brings up a list of links that are profitable for itself, without attempting to match up its links to your search queries. Dangers that are associated with Eminentsearchsystem.com and affiliated sites include:

  • Drive-by-download scripts that install malicious software without your permission (including Trojans, rootkits and browser hijackers).
  • Phishing sites that steal passwords, addresses and other forms of confidential data.
  • Scamware websites that install fake security software and other types of rogue programs (usually via inaccurate online scanner simulations).

At the very least, attempts to use Eminentsearchsystem.com like a normal search engine site will cause you to waste your time sorting through effectively-infinite heaps of irrelevant advertisement-based links, and SpywareRemove.com malware researchers recommend that you use more-trustworthy sites than Eminentsearchsystem.com for your online search purposes.

The Top Threat to Your PC That Eminentsearchsystem.com Can Present

Contact with Eminentsearchsystem.com and other variants of CC Search websites (such as Wonderfulserchsystem.com, Nailingsearchsystem.com, Uniquesearchsystem.com, Remarkablesearchsystem.com or Signalsearchsystem.com) may also result in your PC being infected by a browser hijacker. Although browser-hijacking is a function that can be contained in a variety of rootkits and Trojans, CC Search-specific browser hijackers will limit most of their functions to redirecting your web browser to Eminentsearchsystem.com and affiliated sites, whenever you try to use a search engine. You may also experience problems with security-related software and unusual web browser settings that reduce your online security.

SpywareRemove.com malware researchers have found that redirect attacks for Eminentsearchsystem.com are best cured by removing the relevant rootkit or Trojan, preferably with an anti-malware product. Once you've done this, you shouldn't have any other signs of Eminentsearchsystem.com attacks to worry about, other than the necessity of reversing any undesired changes to your browser or system settings. However, manual removal of a rootkit that's affiliated with Eminentsearchsystem.com may harm Windows, since CC Search-affiliated infections tend to alter baseline Windows components (and not just your web browser).

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%Windows%\system32\consrv.dll File name: %Windows%\system32\consrv.dll
File type: Dynamic link library
Mime Type: unknown/dll
%Windows%\system32\DRIVERS\mrxsmb.sys File name: %Windows%\system32\DRIVERS\mrxsmb.sys
File type: System file
Mime Type: unknown/sys

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}SubSystems: Windows = basesrv,1 winsrv:UserServerDllInitialization,3 consrv:ConServerDllInitialization,2 sxssrv,4
Loading...