Whatseek.com

By JubileeX in Browser Hijackers

Whatseek.com Image

Whatseek.com is a search engine that is associated with browser hijackers. At first sight, this website appears to be one more web page in the same vein as Google, Yahoo or MSN search. This fake search engine has an orange color theme, and its layout is broken up into several compartments reminiscent of the design of the Yahoo search engine (Whatseek.com even comes with a news feed). Appearances are not everything! While Whatseek.com may externally seem to be a search engine, this web page is actually designed to display advertisements instead of legitimate search results. Whenever a computer user enters a search in the Whatseek.com search engine the results will mostly be irrelevant, advertising various websites.

If Whatseek.com limited itself to being a search engine in order to generate advertisement revenue, Whatseek.com would not be a problem. Computer users would simply be able to stay away from Whatseek.com and carry out their online searches on legitimate search engines instead. However, criminals take this scam one step further by using dangerous browser hijackers. A browser hijacker is a malware infection that is designed to take over the victim's web browser and force it to carry out various tasks, for example, a browser hijacker may force a web browser to visit Whatseek.com repeatedly, display a pop-up window containing the Whatseek.com website or change the web browser's settings such as its homepage or security preferences. Browser hijackers associated with Whatseek.com will not affect one particular web browser. Rather, these are extremely dangerous Trojans that fundamentally change how the victim's computer connects to websites. Once infected, the victim's computer will visit Whatseek.com repeatedly and searches carried out on legitimate search engines will be altered so that results link to Whatseek.com.

File System Details

Whatseek.com may create the following file(s):
# File Name Detections
1. %AppData%[trojan name]toolbarcouponsmerchants2.xml
2. %AppData%[trojan name]toolbarlog.txt
3. %AppData%[trojan name]toolbarguid.dat
4. %AppData%[trojan name]toolbarstat.log
5. %Temp%[trojan name]toolbar-manifest.xml
6. %AppData%[trojan name]toolbarcouponsmerchants.xml
7. %AppData%[trojan name]toolbardtx.ini
8. %AppData%[trojan name]toolbaruninstallStatIE.dat
9. %AppData%[trojan name]toolbarversion.xml
10. %AppData%[trojan name]toolbarcouponscategories.xml
11. %AppData%[trojan name]toolbarpreferences.dat
12. %AppData%[trojan name]toolbaruninstallIE.dat
13. %AppData%[trojan name]toolbarstats.dat

Registry Details

Whatseek.com may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{99079a25-328f-4bd4-be04-00955acaa0a7}InprocServer32 "C:PROGRA~1WINDOW~4ToolBar[trojan name]dtx.dll"
HKEY_LOCAL_MACHINESOFTWAREClasses[trojan name]IEHelper.DNSGuardCurVer
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{99079a25-328f-4bd4-be04-00955acaa0a7} "[trojan name] Toolbar"
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}ProgID "[trojan name]IEHelper.UrlHelper.1"
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{A40DC6C5-79D0-4ca8-A185-8FF989AF1115} "UrlHelper Class"
HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar "[trojan name] Toolbar"
HKEY_LOCAL_MACHINESOFTWAREClasses[trojan name]IEHelper.DNSGuard.1
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}VersionIndependentProgID "[trojan name]IEHelper.UrlHelper"
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{99079a25-328f-4bd4-be04-00955acaa0a7} "[trojan name] Toolbar"
HKEY_LOCAL_MACHINESOFTWAREClasses[trojan name]IEHelper.DNSGuardCLSID
HKEY_LOCAL_MACHINESOFTWAREClasses[trojan name]IEHelper.DNSGuard

Trending

Most Viewed

Loading...