Home Malware Programs Browser Hijackers Swellsearchsystem.com

Swellsearchsystem.com

Posted: October 19, 2011

Swellsearchsystem.com Screenshot 1Swellsearchsystem.com is a fake search engine website that's affiliated with ZeroAccess rootkit-based browser hijackers and attempts to corrupt your search results to drive advertisement-based revenue to itself. As just one member of a burgeoning family of CC Search scam search engines, Swellsearchsystem.com is, like Swellsearchsystem.com's brethren, incapable of providing you with real search results and will only delay your searches by inserting irrelevant content and redirecting your browser without your permission. SpywareRemove.com malware researchers have noted that redirect attacks for Swellsearchsystem.com and related websites have a strong tendency to occur when you attempt to use unrelated search engines (such as Google). Because removal or even detection of Swellsearchsystem.com's browser-hijacking rootkit can be extremely difficult to do without assistance, it's strongly encouraged for you to use a competent anti-malware program to delete a Swellsearchsystem.com infection for you.

The Not-So-Swell Truth About Swellsearchsystem.com Searching Features

Swellsearchsystem.com is a member of the CC Search family of search engine scam sites, a string of sites that use ZeroAccess rootkits and Trojans to forcibly redirect web browsers to Swellsearchsystem.com, marveloussearchsystem.com, strikingsearchsystem.com, wickedsearchsystem.com, noblesearchsystem.com, raresearchsystem.com and neatsearchsystem.com. Browser hijacks may redirect you to one of these websites, such as Swellsearchsystem.com, consistently, or they may redirect you to any given CC Search site at random.

Although Swellsearchsystem.com and its brethren's kin pretend to offer you viable search engine functions and relevant links for topics that are of broad interest, SpywareRemove.com malware experts have found that Swellsearchsystem.com, like all its brethren's kind, doesn't have the best interests of brethren's visitors at heart. Instead of providing real search results or safe websites, Swellsearchsystem.com redirects you towards advertisement-based sites that hand money back to Swellsearchsystem.com in return for the favor.

Contact with Swellsearchsystem.com, any other CC Search site or any of their affiliated sites is strongly discouraged, since they can be sources of infection by a variety of PC threats, including their very own ZeroAccess rootkit-based browser hijacker.

What to Do When Swellsearchsystem.com Has Your Search Engine in Its Grip

If you suspect that your PC has become the next victim of a Swellsearchsystem.com browser hijacker, you can watch for the following symptoms to verify or debunk that possibility:

  • Most Swellsearchsystem.com browser hijackers always trigger after you click another search engine link. Instead of being directed to the right site, you'll be directed to Swellsearchsystem.com (which you'll be able to note by the 'waiting on swellsearchsystem.com' line at the bottom of your browser's window), which will take you to an advertisement instead of to your original destination.
  • In some cases, Swellsearchsystem.com browser hijacks may also force new tabs to display Swellsearchsystem.com or a Swellsearchsystem.com-affiliated site.
  • Some Swellsearchsystem.com victims have also reported variants of Swellsearchsystem.com browser hijackers redirecting them to Swellsearchsystem.com at random, even if they try to avoid using search engines like Google or Bing.
  • These redirects can also cause a noticeable and excessive delay in the loading time for websites, even if you eventually end up at the website that you intended to visit.
  • If your browser settings have been changed and either refuse to change back or revert after a reboot, you may be suffering from a browser hijacker, such as Swellsearchsystem.com's ZeroAccess Trojan.

Once you've identified a Swellsearchsystem.com-aligned infection, you can remove the ZeroAccess rootkit and any related PC threats by scanning your computer with an appropriate anti-malware application. Since ZeroAccess rootkit is able to stay active with minimal signs of being present, you should be ready to use standard safety procedures, like Safe Mode, and be prepared to scan several times to be certain that you've completely removed your Swellsearchsystem.com problem.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%Windows%\system32\consrv.dll File name: %Windows%\system32\consrv.dll
File type: Dynamic link library
Mime Type: unknown/dll
%Windows%\system32\DRIVERS\mrxsmb.sys File name: %Windows%\system32\DRIVERS\mrxsmb.sys
File type: System file
Mime Type: unknown/sys

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}SubSystems: Windows = basesrv,1 winsrv:UserServerDllInitialization,3 consrv:ConServerDllInitialization,2 sxssrv,4
Loading...