QueryService.net

By Sumo3000 in Browser Hijackers

QueryService.net is an insecure website which pretends to be a genuine web search engine and is related to browser hijackers, rootkits and Trojans such as Google Redirect Virus and ZeroAcces rootkit. Browser hijackers, rootkits and Trojans can change your default web browser and homepage, and even if you try to restore them, QueryService.net occurs again. Browser hijacking Trojans and rootkits associated with QueryService.net are able to hijack your web browser and change its settings. They can also change your search results and divert you to QueryService.net and other dubious websites full of fake advertisements generated by cybercriminals to earn money and raise traffic of the particular website. To stop diversions to QueryService.net, remove all browser hijackers and rootkits connected with QueryService.net, and change your browser settings to block QueryService.net from opening in your web browser.

File System Details

QueryService.net may create the following file(s):
# File Name Detections
1. %AppData%[trojan name]toolbarlog.txt
2. %AppData%[trojan name]toolbarstats.dat
3. %Temp%[trojan name]toolbar-manifest.xml
4. %AppData%[trojan name]toolbarcouponsmerchants.xml
5. %AppData%[trojan name]toolbardtx.ini
6. %AppData%[trojan name]toolbarguid.dat
7. %AppData%[trojan name]toolbaruninstallStatIE.dat
8. %AppData%[trojan name]toolbarcouponscategories.xml
9. %AppData%[trojan name]toolbarstat.log
10. %AppData%[trojan name]toolbarpreferences.dat
11. %AppData%[trojan name]toolbaruninstallIE.dat
12. %AppData%[trojan name]toolbarversion.xml
13. %AppData%[trojan name]toolbarcouponsmerchants2.xml

Registry Details

QueryService.net may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}InprocServer32 "C:PROGRA~1WINDOW~4ToolBar[trojan name]dtx.dll"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes[trojan name]IEHelper.DNSGuard
HKEY_LOCAL_MACHINE\SOFTWARE\Classes[trojan name]IEHelper.DNSGuardCLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115} "UrlHelper Class"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}VersionIndependentProgID "[trojan name]IEHelper.UrlHelper"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes[trojan name]IEHelper.DNSGuardCurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar "[trojan name] Toolbar"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}ProgID "[trojan name]IEHelper.UrlHelper.1"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7} "[trojan name] Toolbar"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes[trojan name]IEHelper.DNSGuard.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{99079a25-328f-4bd4-be04-00955acaa0a7} "[trojan name] Toolbar"

Trending

Most Viewed

Loading...