Hitpush.com

By ZulaZuza in Browser Hijackers

Hitpush.com is part of a very large family of search engines that tend to feature minimalist web page designs with a search box in the center of the screen. This batch of bogus search engines tends to feature a logo designed to resemble a globe, gray lettering and neon green highlights all on a white background. In the case of bogus search engines like Hitpush.com, less is often more. One mistake criminals tend to make with these fake search engines is to cram too much into their web page designs, quickly tipping off computer users of the true nature of the page in question. However, Hitpush.com's minimalist design makes Hitpush.com resemble dozens of legitimate websites with this kind of aesthetic, making it possible for Hitpush.com to scam computer users that may be relatively more experienced. Hitpush.com belongs to a highly-known online scam designed to take advantage of inexperienced computer users by taking over their computers in order to profit from advertising revenue. In this regard, Hitpush.com plays an interesting role. Hitpush.com is a threat to your computer's security despite the fact that the Hitpush.com website itself is not particularly dangerous. This is because Hitpush.com has a dual relationship with malware that makes it highly likely that any contact with Hitpush.com results in a severe malware infection.

How Hitpush.com is Connected to Dangerous Malware

As was mentioned above, Hitpush.com has a close relationship with malware that will usually result in victims becoming infected with malware in relation to the Hitpush.com website. The vast majority of computer users visiting Hitpush.com do so because of a browser hijacker infection on their computer. Hitpush.com has been connected to the Google Redirect Virus, a Trojan infection that will change how the victim's computer connects to the Internet in order to control which websites it visits without the computer user's authorization. This Trojan in particular changes the results on Google searches so that they link to Hitpush.com instead of to their respective web pages. Another link between Hitpush.com and malware lies in its fake search results. Inexperienced computer users will often attempt their search again on Hitpush.com, which will always result in a large list of fake results composed of spam and links to websites known to host malware or to actively participate in known online scams.

File System Details

Hitpush.com may create the following file(s):
# File Name Detections
1. %AppData%[trojan name]toolbardtx.ini
2. %AppData%[trojan name]toolbarguid.dat
3. %AppData%[trojan name]toolbaruninstallIE.dat
4. %AppData%[trojan name]toolbaruninstallStatIE.dat
5. %AppData%[trojan name]toolbarcouponsmerchants2.xml
6. %AppData%[trojan name]toolbarcouponsmerchants.xml
7. %AppData%[trojan name]toolbarstats.dat
8. %AppData%[trojan name]toolbarstat.log
9. %Temp%[trojan name]toolbar-manifest.xml
10. %AppData%[trojan name]toolbarcouponscategories.xml
11. %AppData%[trojan name]toolbarlog.txt
12. %AppData%[trojan name]toolbarpreferences.dat
13. %AppData%[trojan name]toolbarversion.xml

Registry Details

Hitpush.com may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{99079a25-328f-4bd4-be04-00955acaa0a7}InprocServer32 "C:PROGRA~1WINDOW~4ToolBar[trojan name]dtx.dll"
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}VersionIndependentProgID "[trojan name]IEHelper.UrlHelper"
HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar "[trojan name] Toolbar"
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{A40DC6C5-79D0-4ca8-A185-8FF989AF1115} "UrlHelper Class"
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{99079a25-328f-4bd4-be04-00955acaa0a7} "[trojan name] Toolbar"
HKEY_LOCAL_MACHINESOFTWAREClasses[trojan name]IEHelper.DNSGuardCLSID
HKEY_LOCAL_MACHINESOFTWAREClasses[trojan name]IEHelper.DNSGuard.1
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}ProgID "[trojan name]IEHelper.UrlHelper.1"
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{99079a25-328f-4bd4-be04-00955acaa0a7} "[trojan name] Toolbar"
HKEY_LOCAL_MACHINESOFTWAREClasses[trojan name]IEHelper.DNSGuardCurVer
HKEY_LOCAL_MACHINESOFTWAREClasses[trojan name]IEHelper.DNSGuard

Trending

Most Viewed

Loading...