Home Malware Programs Browser Hijackers Redisearch.com

Redisearch.com

Posted: October 31, 2017

Threat Metric

Ranking: 10,050
Threat Level: 5/10
Infected PCs: 11,504
First Seen: October 31, 2017
Last Seen: October 6, 2023
OS(es) Affected: Windows


Redisearch.com is a browser hijacker that usually swaps your search engine with its own and changes your homepage to redisearch.com. Redisearch.com targets all commonly used Web browsers, including Chrome, Mozilla Firefox, Internet Explorer, and the newer Edge browser from Microsoft. Redisearch.com can infect a browser through one of many vectors, including software bundle installers, as well as voluntary installation from the users who do not fully understand what they are allowing on their machines. Once Redisearch.com finds its home in a browser, it may change the homepage to show redisearch.com – a search portal skinned and themed to visually resemble an old Google homepage design from around the year 2011.

One might argue that Redisearch is not that threatening because it simply redirects the users searches through google.com currently, and brings up a new tab or window, containing the original Google search results eventually. However, there’s no way to know where Redisearch.com is storing the information about the user browsing habits and search history and whether this information is forwarded or sold to third parties. The hijacker presents a privacy issue first and foremost, and even though it’s not a threat, it should not be ignored.

The best way to prevent such Potentially Unwanted Programs (PUPs) from getting on your system in the first place, is to use a fully-featured, robust anti-malware suite that can stop similar parasite types in their tracks. Anticipation is always a better strategy than the subsequent cleaning of a system that has already been infected.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

File name without pathredisearch[1].xmlHKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\DOMStorage\redisearch.com

Additional Information

The following URL's were detected:
redisearch.com
Loading...