Home Browser Helper Object Resulturl

Resulturl

Posted: August 8, 2011

Resulturl is a fake search engine-enhancing product that's spread throughout the Internet by the same criminal minds that are responsible for ResultBar, Findxplorer and similar types of adware. Although the Resulturl website will pretend to offer Resulturl as a useful and time-saving program, Resulturl's search results are padded with advertisements and other methods of artificially generating revenue for Resulturl's maintainers. The main signs of a Resulturl infection are browser hijacks that force you to use Resulturl when you're attempting to visit or use an unrelated website. Since Resulturl has no relevant features and can redirect you to highly dangerous websites, SpywareRemove.com malware researchers can find no reason why you shouldn't delete Resulturl with any good anti-malware application that's available.

Staying Alert for Resulturl's Browser Break-Ins

 Resulturl uses browser-based adware such as not-a-virus:AdWare.Win32.Relevant, Adware-OneStep.k and BrowserModifier:Win32/Zwangi to infect your PC. The same types of adware may also install other malicious programs from the same family as Resulturl, including Resultbar, Findxplorer, QuestURL, ZinkSeek, BrowserZinc and BrowserQuest. The behavior between these Resulturl clones may vary slightly, but the overall attack methods and goals are the same, as shown below:

  • Resulturl will attempt to redirect you to Resulturl-powered links and advertisements whenever you try to use your web browser. These redirects may limit themselves to taking place only in certain circumstances, such as when you try to use a search engine, although SpywareRemove.com malware analysts have also seen some Resulturl variants redirecting during URL navigation.
  • Resulturl will be installed without your permission as one part of an overarching Trojan infection that may have other functions, including keylogging, installing other harmful programs without your consent or attacking your security settings. Many of these infections have been linked to Windows 7 themes packages.
  • Resulturl will not try to hide its folder, files or its memory process. However, Resulturl also will launch itself without permission, will not allow you to shut down Resulturl's processes and will resist any attempts to uninstall Resulturl.

Getting Rid of Resulturl to Get the Results That You Really Want

Deleting Resulturl should use appropriate threat-removal software, since any other method may allow deep-seated system changes to remain in place. SpywareRemove.com malware researchers have found that files that are related to Resulturl infections have been known to engage in such serious attacks as opening network ports, downloading files without permission, concealing malicious files in a variety of locations (such as the Windows directory and the Temp directory) and updating themselves automatically.
 
Since Resulturl will not ask permission to launch itself and will not allow itself to be closed, the safest way to remove  Resulturl is by using a Safe Mode-based system boot. This can be accessed by tapping F8 during a boot, but before Windows has begun to load. Once in Safe Mode, you can verify whether your version of Resulturl is still active or not by opening Task Manager with Ctrl+Alt+Del. If Resulturl is still active, you may want to try booting from an external device, such as a USB drive or CD, to insure that Resulturl will not interfere with the deletion process.

Technical Details

File System Modifications

The following files were created in the system:



C:\Program Files\ResultUrl\ResultUrl_deleted_\resulturl.exe File name: C:\Program Files\ResultUrl\ResultUrl_deleted_\resulturl.exe
File type: Executable File
Mime Type: unknown/exe
C:\Program Files\ResultUrl\ResultUrl_deleted_\resulturl.dll File name: C:\Program Files\ResultUrl\ResultUrl_deleted_\resulturl.dll
File type: Dynamic link library
Mime Type: unknown/dll
C:\Program Files\ResultUrl File name: C:\Program Files\ResultUrl
C:\Documents and Settings\<username>\Application Data\ResultUrl\resulturl191.exe File name: C:\Documents and Settings\<username>\Application Data\ResultUrl\resulturl191.exe
File type: Executable File
Mime Type: unknown/exe
C:\Program Files\ResultUrl\uninstall.exe File name: C:\Program Files\ResultUrl\uninstall.exe
File type: Executable File
Mime Type: unknown/exe
C:\Program Files\ResultUrl\resulturl.exe File name: C:\Program Files\ResultUrl\resulturl.exe
File type: Executable File
Mime Type: unknown/exe
C:\Program Files\ResultUrl\resulturl.dll File name: C:\Program Files\ResultUrl\resulturl.dll
File type: Dynamic link library
Mime Type: unknown/dll

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ResultUrl ServiceHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RESULTURL_SERVICEHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ResultUrlHKEY_LOCAL_MACHINE\SOFTWARE\ResultUrlHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ResultUrl ServiceHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RESULTURL_SERVIC
Loading...