If your web browser’s homepage has been changed to Uppersearch.tk, then we want to inform you that your computer has been infected with a browser hijacker. Since a browser hijacker is considered malware, we recommend that you remove it as soon as you can. We urge you to do this quickly because it is used to promote highly unreliable web pages that can infect your PC with more malware. This malware can slow your computer down, and cause it to crash, among other things. It all depends on the type of malicious software it gets infected with. Therefore, we invite you to read this short description so that you get more in-depth information about this particular infection.
According to this hijacker’s Privacy Policy, “www.uppersearch.tk ("UpperSearch") is a website owned and operated by UpperSearch.” In actuality, this means that this infection’s developers are unknown. We know this because, for example, one of the clones of this browser hijacker called Safe-web.tk is (allegedly) owned and operated by SafeWeb Studio. We have found that, in total, Uppersearch.tk has seven clones, and we expect this number to increase further down the line. All of those clones, including Uppersearch.tk, are secondary hijackers because you get redirected to them when your browser’s homepage is changed to Globasearch.com/?serie=211&b=3&installkey=yQ1yAboNk0oLuP0yrFzh. Thus, it can be said that this hijacker comes from established malware developers that know what they are doing.
If you are wondering what is the purpose of hijacking you browser’s homepage, then let us clarify things for you. Browser hijackers, such as Uppersearch.tk are used to generate advertising revenue. If your computer has been infected with it, then you will notice that it features one banner ad that generates income when clicked. However, things can get a lot worse. While testing this hijacker, we were presented with a fake offer. We clicked this offer for testing purposes, and this action resulted in the installation of a shady browser extension called GoMovix Start for Firefox. Further testing has revealed that it can also install a similar extension on Chrome. At any rate, when you install this program, another application called Bang5Tao is installed secretly. Apart from that, this hijacker will generate pop-ups ads with fake messages, such as the typical “Click now to claim your prize,” “you are the millionth visitor, click here to claim,” and so on. Clicking messages such as these can result in your computer becoming infected with more malware, so please do not do that.
Note that if you enter a search query to Uppersearch.tk, then it will process it and redirect it to Google custom search. However, it presents the same search results as the regular Google.com, so we do not think that this hijacker includes malicious promotional links in them. Nevertheless, this does not mean that you should keep and use this browser hijacker because the pop-ups that appear on it can jeopardize your computer’s security by using trickery to infect your PC with malware.
We have found that Uppersearch.tk and by extension its primary browser hijacker (Globasearch.com/?serie=211&b=3&installkey=yQ1yAboNk0oLuP0yrFzh) are disseminated via malicious downloaders that use four servers (extrahosted.com, directhosted.org, thefilehost.org, and softdistribute.com). These kinds of downloaders are most likely featured on fake software-distributing websites that focus on disseminating malware. We have found that Uppersearch.tk is most popular in Algeria, Egypt, Indonesia, Thailand, and Saudi Arabia. Thus, it seems that this infection is featured on websites popular in the Middle East and the Asia-pacific regions. Nevertheless, very few infections are limited to a particular area, so your computer can become infected with this hijacker no matter where you are.
To recap, Uppersearch.tk is a browser hijacker dedicated to promoting unreliable software and other content via its main-page-based banners and pop-ups. Testing has shown that when installing certain software, your computer will be infected with additional malware. As a direct consequence, your computer’s security will be compromised. Therefore, we recommend that you remove this browser hijacker by resetting your browsers’ settings to default. For more information on how you can delete it, please consult the instructions below.
Google Chrome
Microsoft Internet Explorer
Mozilla Firefox