Home Rogue Websites Search.yellowise.com

Search.yellowise.com

Posted: September 13, 2011

Search.yellowise.com is a recent entry into the chain of fake search engine websites that are cloned from the same simple template that's used by Find-fast-answers.com, icityfind.com, shopica.com, Findgala.com, find-answers-fast.com and other malicious search engine sites. Since SpywareRemove.com malware experts have found that Search.yellowise.com not only provides inaccurate and potentially harmful search results, but also utilizes browser hijackers to bloat its traffic artificially, it's strongly recommended that you avoid even the slightest contact with Search.yellowise.com. If you find your web browser under attack by a Search.yellowise.com hijacker, don't fritter your time away changing your browser's settings –Search.yellowise.com browser hijackers can only be removed by traditional anti-malware strategies and security applications.

Protecting Your PC from Search.yellowise.com Hijackers

Search.yellowise.com browser hijackers typically are installed by browser exploits from harmful websites or advertisements and may even be installed automatically after visiting Search.yellowise.com itself. Keeping your computer guarded against these attacks is as simple as avoiding risky sites, keeping your browser up-to-date and only browsing the web with strict security settings.

Nonetheless, since no defense can be totally impenetrable, SpywareRemove.com malware experts also advise you to be aware of the following signs of a Search.yellowise.com style browser hijacker:

  • Being redirected to Search.yellowise.com at random times or after you attempt to use a search engine.
  • Having your homepage set to Search.yellowise.com without your permission.
  • The appearance of pop-ups and other advertisements where they wouldn't ordinarily appear.

Because Search.yellowise.com browser hijackers will typically set up right in your Windows Registry, altering your web browser in any way will not truly fix the problem. Instead, you should turn to security applications that are able to scan your PC, find Search.yellowise.com's planted program and then delete Search.yellowise.com.

The Traps Served on the Side with Search.yellowise.com

Exposure to Search.yellowise.com should be avoided at all costs, since Search.yellowise.com can only provide search results that are valueless at best and harmful at worst. If you've been exposed to Search.yellowise.com and suspect that browser-based content on your PC may be influenced by Search.yellowise.com infections, look out for scams like the following:

  • Phishing scams such as the Facebook Birthday Free T-Shirt scam. These scams will try to acquire your account information and tend to target social networking websites or online banks. A standard phishing scam will claim that you've won a prize or will pretend to be a message from a friend and then ask for your login information.
  • Rogue software marketing. Scamware products like BlueFlare Antivirus and XP System Repair will market themselves in the form of helpful security programs but, if you install them, you'll find that their features are actually harmful. These types of fake programs specialize in stealing money and SpywareRemove.com malware experts advise that you only purchase software from a website that's trustworthy.
  • Fake software updates for video players or file codecs. These updates will tell you that your software is out of date and requires an update; such tactics will typically be used to install dropper Trojans. As long as you acquire your updates from reputable websites, you should be safe and Search.yellowise.com's fraudulent links and advertisements shouldn't be able to harm your PC.

Technical Details

File System Modifications

The following files were created in the system:



C:\Documents and Settings\<username>\Application Data\.exe File name: C:\Documents and Settings\<username>\Application Data\.exe
File type: Executable File
Mime Type: unknown/exe
C:\Windows\System32\Drivers\etc\hosts\malicious files File name: C:\Windows\System32\Drivers\etc\hosts\malicious files
C:\WINDOWS\system32\drivers\UAC.sys File name: C:\WINDOWS\system32\drivers\UAC.sys
File type: System file
Mime Type: unknown/sys
C:\Windows\System32\.exe of Search.yellowise.com File name: C:\Windows\System32\.exe of Search.yellowise.com
File type: Command, executable file
Mime Type: unknown/com

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\_VOIDd.sysHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS].exe"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Once\malicious key
Loading...