Threat Database Browser Hijackers Splendidsearchserver.com

Splendidsearchserver.com

By ESGI Advisor in Browser Hijackers

Splendidsearchserver.com is a rogue search engine with a number of similarly-named clones. Some of these clones include excellentsearchserver.com, Famoussearchserver.com, and classysearchserver.com. All of these websites mimic legitimate search engine websites (such as Yahoo, Windows Live Search, Google and Bing) in their outward interface. However, they have no search capabilities, instead returning any queries with search results from a list of malicious websites that have paid for the privilege. Splendidsearchserver.com and its clones are closely associated with the Google Redirect Virus, one of the most widespread browser hijackers in existence. According to ESG security researchers, this browser hijacker is also closely related to the TDSS Rootkit, widely considered one of the most dangerous and invasive malware threats in recent history.

Visits to the Splendidsearchserver.com Website Usually Mean Trouble

According to ESG malware analysts, almost all visitors to the Splendidsearchserver.com website are at risk for becoming infected with any number of different possible malware threats. This is because websites like Splendidsearchserver.com are at the center of malware distribution networks and act as infection hubs that can form a relationship between different, separate malware threats. Consider the following malware facts and how they relate to the Splendidsearchserver.com website:

  • Malware almost never appears as a lone, isolated infection.
  • The presence of one kind of malware is usually a sign of other malware that has been used to install it, malware that acts as a supporting element and malware that appears as a result of that infection.
  • The presence of redirects to the Splendidsearchserver.com website is a sign that your computer system is infected with a browser hijacker causing them in the first place. It also means that there is probably an underlying Trojan or rootkit infection hiding the browser hijacker and supporting it or that installed it in the first place.
  • Most importantly, the Splendidsearchserver.com website itself contains known malware components such as malicious advertisements, links to known malware sources and dangerous pop-up windows.

This means that the Splendidsearchserver.com website has the potential to cause the affected computer to become infected with additional malware problems, starting a cascade effect in which each new malware problem brings a host of new malware infections along with it. This is why ESG PC security researchers do not only recommend removing any signs of a browser hijacker infection, but doing so immediately, before more malware is installed.

File System Details

Splendidsearchserver.com may create the following file(s):
# File Name Detections
1. %Windows%\system32\DRIVERS\mrxsmb.sys
2. %Windows%\system32\consrv.dll
3. %windir%\system32\config\malicious file of splendidsearchserver.com
4. Globalroot\Device\svchost.exe\svchost.exe

Registry Details

Splendidsearchserver.com may create the following registry entry or registry entries:
HKEY_CURRENT_USER\\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS].exe"
HKEY_LOCAL_MACHINE &
SubSystems: Windows = basesrv,1 winsrv:UserServerDllInitialization,3 consrv:ConServerDllInitialization,2 sxssrv,4
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains of TDL4 Rootkit

Trending

Most Viewed

Loading...