Home Malware Programs Browser Hijackers Searchput.net

Searchput.net

Posted: November 28, 2011

Searchput.net Screenshot 1Searchput.net is a malicious site that utilizes browser-hijacking rootkits to force visitors to flip through its profit-generating advertisements and links. Externally, Searchput.net may appear to be a harmless site with topical link databases and a search function, but all of its features are a thin veneer of legitimacy placed over an advertisement-delivery mechanism that may also expose you to hostile sites or infect your PC via drive-by-download exploits. If your browser has visited Searchput.net by accident or begins redirecting itself to Searchput.net for no apparent reason, chances are high that your PC is infected. In such instances, SpywareRemove.com malware researchers recommend that you remove your Searchput.net-affiliated browser hijacker by running a competent anti-malware scanner (ideally after disabling the rootkit in Safe Mode).

The Time-Wasting Nature of Searchput.net's Throughput

Like other types of fake search sites that profit off of browser-hijacking attacks (such as Smartwebsearch.com, Swelldavinciserver.com, Nailingsearchsystem.com or Uniquesearchsystem.com), Searchput.net is happy to provide you with a multitude of seemingly-harmless links, but these links will redirect you to advertisements or to other forms of malicious sites, including sites that sell rogue anti-virus programs and phishing websites. Because Searchput.net's content is utterly non-beneficial to browse through, SpywareRemove.com malware experts discourage any contact with Searchput.net or Searchput.net-based links, since they may expose your PC to other attacks.

The most prominent risk that's associated with Searchput.net is the possibility of your PC being infected by a browser hijacker for Searchput.net. Browser-hijacking functions are often contained in rootkits and Trojans that are installed by Flash or Java-based web browser attacks. Although you may first notice the symptoms of a browser hijacker infection in a particular web browser, the majority of browser hijackers for Searchput.net and similar sites base their components in the Registry and other areas of Windows that aren't specific to a particular web-browsing application.

Searching for Searchput.net's Pit Trap Before Your PC Falls Into It

Although you can take measures to diminish the risk of a Searchput.net attack by using up-to-date scripts, keeping secure browser settings and having active anti-malware programs, zero day exploits may still be able to infect your PC with a Searchput.net-related rootkit or Trojan. Signs of browser hijacks that are linked to Searchput.net can include:

  • Being redirected to Searchput.net once you click on a result link from another search engine.
  • Being unable to change your web browser settings.
  • An altered homepage that loads Searchput.net or a similarly-fraudulent site.

Before you try to remove a browser hijacker for Searchput.net, SpywareRemove.com malware analysts encourage a Safe Mode boot (an option that's available in all versions of Windows) to disable the infection to prevent Searchput.net from defending itself. After you've turned off your Searchput.net browser hijacker, you can remove Searchput.net with a suitable anti-malware scanner, although you may need to update your threat database to be sure of identifying all infected components. Be careful to avoid any contact with Searchput.net during this process, since Searchput.net may simply reinfect your PC with another drive-by-download attack.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%Windows%\system32\consrv.dll File name: %Windows%\system32\consrv.dll
File type: Dynamic link library
Mime Type: unknown/dll
%Windows%\system32\DRIVERS\mrxsmb.sys File name: %Windows%\system32\DRIVERS\mrxsmb.sys
File type: System file
Mime Type: unknown/sys

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}SubSystems: Windows = basesrv,1 winsrv:UserServerDllInitialization,3 consrv:ConServerDllInitialization,2 sxssrv,4
Loading...