SpaceQuery.com

By LoneStar in Browser Hijackers

SpaceQuery.com Image

SpaceQuery.com is a fake website that poses as a trustworthy and legitimate search engine, but, in truth, it only aims at displaying spam and ads and spying on its victims. If you try to find anything online by using SpaceQuery.com, you won't get any safe search results except constant redirects to dubious websites full of bogus ads that bombard your PC. Annoying redirects to SpaceQuery.com are caused by browser hijackers and other malware threats such as ZeroAccess rootkit and Google Redirect Virus. These infections can take over your web browser and change its settings. They can change your default homepage or search engine without a possibility to change them back. Your search result links will be redirected to some unwanted or advertisement web pages. To avoid annoying redirects to SpaceQuery.com and other insecure websites, remove all browser hijackers and rootkits related to SpaceQuery.com that have infected your PC. Also, you can change your browser settings to block SpaceQuery.com from opening in your web browser.

File System Details

SpaceQuery.com may create the following file(s):
# File Name Detections
1. %AppData%[trojan name]toolbarlog.txt
2. %AppData%[trojan name]toolbarstats.dat
3. %Temp%[trojan name]toolbar-manifest.xml
4. %AppData%[trojan name]toolbarcouponsmerchants.xml
5. %AppData%[trojan name]toolbardtx.ini
6. %AppData%[trojan name]toolbarguid.dat
7. %AppData%[trojan name]toolbaruninstallStatIE.dat
8. %AppData%[trojan name]toolbarcouponscategories.xml
9. %AppData%[trojan name]toolbarstat.log
10. %AppData%[trojan name]toolbarpreferences.dat
11. %AppData%[trojan name]toolbaruninstallIE.dat
12. %AppData%[trojan name]toolbarversion.xml
13. %AppData%[trojan name]toolbarcouponsmerchants2.xml

Registry Details

SpaceQuery.com may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}InprocServer32 "C:PROGRA~1WINDOW~4ToolBar[trojan name]dtx.dll"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes[trojan name]IEHelper.DNSGuard
HKEY_LOCAL_MACHINE\SOFTWARE\Classes[trojan name]IEHelper.DNSGuardCLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115} "UrlHelper Class"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}VersionIndependentProgID "[trojan name]IEHelper.UrlHelper"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes[trojan name]IEHelper.DNSGuardCurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar "[trojan name] Toolbar"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}ProgID "[trojan name]IEHelper.UrlHelper.1"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7} "[trojan name] Toolbar"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes[trojan name]IEHelper.DNSGuard.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{99079a25-328f-4bd4-be04-00955acaa0a7} "[trojan name] Toolbar"

Trending

Most Viewed

Loading...