Home Malware Programs Browser Hijackers Yoursite123.com

Yoursite123.com

Posted: November 24, 2015

Threat Metric

Ranking: 6,250
Threat Level: 5/10
Infected PCs: 33,448
First Seen: November 24, 2015
Last Seen: October 12, 2023
OS(es) Affected: Windows


Yoursite123.com is a website associated with campaigns that may hijack your Web browser and force it to load URLs automatically. Although Yoursite123.com has no history of facilitating threatening or illicit acts, unwanted software or threats may promote Yoursite123.com traffic to increase Web traffic-based revenue. As there are no benefits to allowing your browser to load Yoursite123.com automatically, malware researchers suggest common anti-malware protocols for removing Yoursite123.com hijackers or 'viruses' from all Web browsers.

When All Sites Turn into 'Your Site'

Yoursite123.com is a currently down website without any historical record of hosting or redirecting traffic to threat installers, phishing tactics or any other type of harmful Web content. Normally, malware researchers have minimal investment in such websites. However, occasionally even these 'non-threatening' sites like Yoursite123.com may become embroiled in browser-hijacking campaigns. Such campaigns may launch themselves through genuine threats, such as backdoor Trojans, but may just be the telltale signs of the installation of a Potentially Unwanted Program (PUP).

Since their campaign is significantly more recent than the registration of the Yoursite123.com domain, Yoursite123.com hijackers are still under examination for details on their preferred distribution methods. However, malware researchers did verify that Yoursite123.com hijackers limited themselves to modifying the Chrome browser. Hijackings may use any of several formats, such as:

  • Loading Yoursite123.com as your new homepage.
  • Forcing your Web searches to use Yoursite123.com.
  • Opening new Yoursite123.com tabs.
  • Redirecting your browser away from unrelated Web pages towards Yoursite123.com.
  • Creating new Yoursite123.com windows or pop-ups.

The Yoursite123.com hijacking campaign is far from the only one to target Chrome users; malware researchers also see similar efforts for corrupted sites like Upstaradown.com and various adware apps like AdFreeApp. However, unlike in most such events, the Yoursite123.com hijacker has no known ties with visible toolbars, browser extensions or other software products making themselves visible by brand names of some description.

A One-Two-Three Method out of Yoursite123.com Hijackings

There's no available evidence for Yoursite123.com being a threat domain, but malware researchers would recommend using script blockers and similar protection when visiting any unknown website. Despite that caveat, there are no advantages had from letting a concealed program determine which websites your browser is loading. Even assuming perfect safety on the part of Yoursite123.com's administrators and affiliates, such functions also may be re-purposed for redirecting computer users to copycat bank login tactics or forcing the loading of scripts for installing threats. There are few, if any, situations under which should you ever allow a browser hijacker to remain on your PC, even when the promoted site, like Yoursite123.com, is harmless.

Standard anti-malware and anti-adware programs should be able to identify most Yoursite123.com hijackers and uninstall them without any issues. Some PC users also may need to take other actions for removing Yoursite123.com redirects afterward, including resetting the Chrome's cache. From your Chrome customization menu, select 'More Tools' followed by 'Clear browsing data.' Alternately, press and hold your Control, Shift and Delete keys.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

File name without pathwww.yoursites123[1].xmlRegexp file mask%HOMEDRIVE%\yoursites123.xmlHKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.yoursites123.comSOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\yoursites123.comSOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.yoursites123.comSOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\yoursites123.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\yoursites123.comSOFTWARE\Wow6432Node\yoursites123SoftwareSOFTWARE\yoursites123Software
Loading...