Home Malware Programs Browser Hijackers Searchqu

Searchqu

Posted: May 26, 2011

Threat Metric

Ranking: 2,406
Threat Level: 5/10
Infected PCs: 318,149
First Seen: July 31, 2012
Last Seen: October 17, 2023
OS(es) Affected: Windows

Searchqu Screenshot 1Searchqu is an unwanted installation, which is added to a content the users actually intended to download. Searchqu does not spread via a computer trojan or worm application. Searchqu is not also a software program that adds its components onto a targeted computer system. Searchqu resets browser's homepage to searchqu.com and adds a toolbar to a web browser. Searchqu tries to replace popular search engines hindering access to them and offering its own search tool. Since Searchqu is not specified in the Add/Remove Programs menu, it cannot be merely uninstalled this way. To remove Searchqu, if it's really annoying, delete its entries. You may also uninstall Searchqu in your web browser's menu, but using ultimate technique of the Searchqu removal is preferable to guarantee it is eliminated completely.


Searchqu Screenshot 2

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\searchqutoolbar\
    2 %AppData%\searchqutoolbar\coupons\categories.xml
    3 %AppData%\searchqutoolbar\coupons\merchants.xml
    4 %AppData%\searchqutoolbar\coupons\merchants2.xml
    5 %AppData%\searchqutoolbar\dtx.ini
    6 %AppData%\searchqutoolbar\guid.dat
    7 %AppData%\searchqutoolbar\log.txt
    8 %AppData%\searchqutoolbar\preferences.dat
    9 %AppData%\searchqutoolbar\stat.log
    10 %AppData%\searchqutoolbar\stats.dat
    11 %AppData%\searchqutoolbar\uninstallIE.dat
    12 %AppData%\searchqutoolbar\uninstallStatIE.dat
    13 %AppData%\searchqutoolbar\version.xml
    14 %Temp%\searchqutoolbar-manifest.xml

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\ClassesHKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7} "Searchqu Toolbar"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\InprocServer32 "C:\PROGRA~1\WINDOW~4\ToolBar\searchqudtx.dll"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115} "UrlHelper Class"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ProgID "SearchQUIEHelper.UrlHelper.1"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\VersionIndependentProgID "SearchQUIEHelper.UrlHelper"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard.1HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard\CLSIDHKEY_LOCAL_MACHINE\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard\CurVerHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar "Searchqu Toolbar"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079a25-328f-4bd4-be04-00955acaa0a7} "Searchqu Toolbar"HKEY..\..\..\..{RegistryKeys}\SearchQUIEHelper.DNSGuard

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ALLUSERSPROFILE%\Application Data\Wincert\win32cert.dll File name: win32cert.dll
Size: 7.16 KB (7168 bytes)
MD5: 4ab92ef53f4b5c0663d3fff00d59cc81
Detection count: 52,465
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\Application Data\Wincert\win32cert.dll
Group: Malware file
Last Updated: August 2, 2023
%ALLUSERSPROFILE%\Wincert\win32cert.dll File name: win32cert.dll
Size: 7.16 KB (7168 bytes)
MD5: 1ac563ef1ff9e5daf6570d5e413f0a0c
Detection count: 35,637
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\Wincert\win32cert.dll
Group: Malware file
Last Updated: October 15, 2023
C:\ProgramData\Wincert\win64cert.dll File name: win64cert.dll
Size: 8.7 KB (8704 bytes)
MD5: 991f56da93a49baacf5fcfa2f96a920f
Detection count: 10,933
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\ProgramData\Wincert\win64cert.dll
Group: Malware file
Last Updated: June 26, 2023
D:\Daten alte Festplatte\Dokumente und Einstellungen\All Users\Anwendungsdaten\Wincert\win32cert.dll File name: win32cert.dll
Size: 6.65 KB (6656 bytes)
MD5: 97c82474f36e378b3a98e92a5c27aee9
Detection count: 7,347
File type: Dynamic link library
Mime Type: unknown/dll
Path: D:\Daten alte Festplatte\Dokumente und Einstellungen\All Users\Anwendungsdaten\Wincert\win32cert.dll
Group: Malware file
Last Updated: March 9, 2023
C:\Documents and Settings\<username>\Bureau\Temp de JAPON\datamngrUI.exe.3118734 File name: datamngrUI.exe.3118734
Size: 796.6 KB (796608 bytes)
MD5: 1600fccbe1f8b062fafa82bdba2bba63
Detection count: 347
Mime Type: unknown/3118734
Path: C:\Documents and Settings\<username>\Bureau\Temp de JAPON\datamngrUI.exe.3118734
Group: Malware file
Last Updated: April 13, 2023
%PROGRAMFILES(x86)%\Search Results Toolbar\Datamngr\DatamngrCoordinator.exe File name: DatamngrCoordinator.exe
Size: 4.45 MB (4454912 bytes)
MD5: 0b77a81da0124a1f9ff415d15f110548
Detection count: 295
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Search Results Toolbar\Datamngr
Group: Malware file
Last Updated: May 26, 2017
C:\Program Files (x86)\Music Toolbar\Datamngr\SRTOOL~1\IE\__searchresultsDx.dll File name: __searchresultsDx.dll
Size: 92.59 KB (92592 bytes)
MD5: 85daab2fb836f70e9200967dd270d3b6
Detection count: 283
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Program Files (x86)\Music Toolbar\Datamngr\SRTOOL~1\IE\__searchresultsDx.dll
Group: Malware file
Last Updated: April 5, 2022
%PROGRAMFILES(x86)%\Search Results Toolbar\Datamngr\DatamngrCoordinator.exe File name: DatamngrCoordinator.exe
Size: 4.55 MB (4557312 bytes)
MD5: 00b59a1ecf1009c3abbf12ef0321f50c
Detection count: 222
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Search Results Toolbar\Datamngr
Group: Malware file
Last Updated: May 26, 2017
%PROGRAMFILES%\Search Results Toolbar\Datamngr\DatamngrCoordinator.exe File name: DatamngrCoordinator.exe
Size: 4.55 MB (4552192 bytes)
MD5: 37f682ddcdf7f40cc1a36658f61a302c
Detection count: 208
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Search Results Toolbar\Datamngr
Group: Malware file
Last Updated: May 26, 2017
%PROGRAMFILES%\Windows Searchqu Toolbar\Datamngr\datamngrUI.exe File name: datamngrUI.exe
Size: 1.61 MB (1616784 bytes)
MD5: 6d22910188808d0fcb90ff7e3da6c2a5
Detection count: 47
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Windows Searchqu Toolbar\Datamngr
Group: Malware file
Last Updated: December 4, 2012
%PROGRAMFILES%\Music Toolbar\Datamngr\SRTOOL~1\IE\searchresultsDx.dll File name: searchresultsDx.dll
Size: 115.66 KB (115664 bytes)
MD5: 1fb0d205be47c0e0ab23e8406d285691
Detection count: 35
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Music Toolbar\Datamngr\SRTOOL~1\IE
Group: Malware file
Last Updated: May 31, 2021
C:\Program Files (x86)\searchresults7\searchresultsDx.dll File name: searchresultsDx.dll
Size: 87 KB (87008 bytes)
MD5: e040fd5cddb2be30a2038fc57c2e9936
Detection count: 26
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Program Files (x86)\searchresults7\searchresultsDx.dll
Group: Malware file
Last Updated: August 28, 2021
%PROGRAMFILES%\Music App\Datamngr\SRTOOL~1\IE\searchresultsDx.dll File name: searchresultsDx.dll
Size: 115.58 KB (115584 bytes)
MD5: 306c370c7770a19e53dd1e9c34a5ebef
Detection count: 16
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Music App\Datamngr\SRTOOL~1\IE
Group: Malware file
Last Updated: May 25, 2017
%PROGRAMFILES%\searchresults\searchresultsDx.dll File name: searchresultsDx.dll
Size: 87 KB (87008 bytes)
MD5: dd6b65d1d6be4820a97be286389a7582
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\searchresults
Group: Malware file
Last Updated: May 25, 2017

Registry Modifications

The following newly produced Registry Values are:

CLSID{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}{f34c9277-6577-4dff-b2d7-7d58092f272f}Regexp file mask%PROGRAMFILES%\Mozilla Firefox\searchplugins\Search_Results.xml%PROGRAMFILES(x86)%\Mozilla Firefox\searchplugins\Search_Results.xmlHKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2101}SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1ED9DA0-AFD0-4b90-AC6A-D3874F591014}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1ED9DA0-AFD0-4b90-AC6A-D3874F591014}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Searchqu Toolbar

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Application Data\Wincert%ALLUSERSPROFILE%\Wincert%PROGRAMFILES%\Search Results Toolbar%PROGRAMFILES%\Windows Searchqu Toolbar%PROGRAMFILES%\searchresults%PROGRAMFILES%\searchresults7%PROGRAMFILES(x86)%\Search Results Toolbar%PROGRAMFILES(x86)%\Windows Searchqu Toolbar%PROGRAMFILES(x86)%\searchresults%PROGRAMFILES(x86)%\searchresults7%UserProfile%\AppData\LocalLow\searchresultstb
The following URL's were detected:
http://www1.search-results.com/webhttps://dts.search-results.com/sr?o=

Related Posts

Loading...