Home Malware Programs Browser Hijackers Discover-facts.com

Discover-facts.com

Posted: April 25, 2012

Discover-facts.com Screenshot 1Discover-facts.com is a search engine that fills its results with advertisements and unrelated links that benefit its web masters, as opposed to sorting results according to how relevant they are to your search terms. Although this merely places Discover-facts.com in the realm of a mild nuisance, there have been instances of browser hijackers promoting Discover-facts.com with browser redirects. In cases of your browser redirecting itself to Discover-facts.com recurrently, probably your PC has been infected by a PC threat with browser-hijacking functions, although any given browser hijacker may also be capable of other attacks that could be serious threats to your computer's security. With these facts in mind, removing browser hijackers that promote Discover-facts.com should be considered a basic matter of computer safety to be performed ASAP, and, preferably, with suitable anti-malware programs.

Discovering What Lies at the End of a Discover-facts.com Search

Discover-facts.com hasn't been noted as a host for malicious software or other PC attacks by any PC security company, and can be considered a safe destination except insofar as Discover-facts.com may inadvertently expose you to risky websites in the same way that any search engine may accidentally do. Although visits to Discover-facts.com, by themselves, can be safe, SpywareRemove.com malware researchers do encourage you to have a modicum of caution while interacting with search results from Discover-facts.com, since Discover-facts.com hasn't been confirmed to use the same safeguards that more popular search engines than itself use as a matter of course.

Discover-facts.com's search results are especially noted to include advertisements and other forms of 'spammy' content that, instead of providing relevant content, provide the linking website's web masters PPC revenue and similar benefits. Thusly, as of the time of this article's writing, searches at Discover-facts.com aren't likely to provide worthwhile content for your time, although they are also unlikely to be directly dangerous to your computer. All of this, unfortunately, falls somewhat to the wayside compared to the typical means of accidental Discover-facts.com encounters, which SpywareRemove.com malware analysts have noticed to be ever-prolific browser hijackers.

Discover-facts.com can also be considered a clone of similar search engine sites that share its appearance, tag line and search methodology. Examples of Discover-facts.com clones include Search-Images.com, IdentifyPlaces.com, LocalFindInfo.com, FindSearchEngineResults.com, Expand-Search-Goals.com, Extensive-Search.com and Search-Feature.com.

What to Do About Constant Discover-facts.com Redirects

Discover-facts.com would have remained out of the limelight and well out of the scope of most PC security companies if not for its promotion by malicious software with browser-hijacking attacks. Typical browser hijacks for Discover-facts.com can involve:

  • Having your homepage locked on Discover-facts.com (regardless of what changes you make to your homepage settings).
  • Being redirected to Discover-facts.com when you were trying to navigate to a different search engine.
  • Having your online searches redirected through Discover-facts.com.
  • The appearance of pop-ups or new tabs that display Discover-facts.com by default.

Browser hijackers for Discover-facts.com have been noted as far back as 2009, but are still an ongoing threat that you should protect your PC against whenever possible. While changes to your browser settings are unlikely to solve a Discover-facts.com-redirecting problem, SpywareRemove.com malware experts suggest using anti-malware software to detect and delete all Discover-facts.com-promoting browser hijackers easily and quickly.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%AppData%[trojan name]toolbarstat.log File name: %AppData%[trojan name]toolbarstat.log
Mime Type: unknown/log
%AppData%[trojan name]toolbarlog.txt File name: %AppData%[trojan name]toolbarlog.txt
Mime Type: unknown/txt
%AppData%[trojan name]toolbardtx.ini File name: %AppData%[trojan name]toolbardtx.ini
Mime Type: unknown/ini
%AppData%[trojan name]toolbarpreferences.dat File name: %AppData%[trojan name]toolbarpreferences.dat
File type: Data file
Mime Type: unknown/dat
%AppData%[trojan name]toolbarguid.dat File name: %AppData%[trojan name]toolbarguid.dat
File type: Data file
Mime Type: unknown/dat
%AppData%[trojan name]toolbaruninstallStatIE.dat File name: %AppData%[trojan name]toolbaruninstallStatIE.dat
File type: Data file
Mime Type: unknown/dat
%AppData%[trojan name]toolbaruninstallIE.dat File name: %AppData%[trojan name]toolbaruninstallIE.dat
File type: Data file
Mime Type: unknown/dat
%AppData%[trojan name]toolbarstats.dat File name: %AppData%[trojan name]toolbarstats.dat
File type: Data file
Mime Type: unknown/dat
%AppData%[trojan name]toolbarcouponsmerchants.xml File name: %AppData%[trojan name]toolbarcouponsmerchants.xml
Mime Type: unknown/xml
%AppData%[trojan name]toolbarcouponscategories.xml File name: %AppData%[trojan name]toolbarcouponscategories.xml
Mime Type: unknown/xml
%AppData%[trojan name]toolbarcouponsmerchants2.xml File name: %AppData%[trojan name]toolbarcouponsmerchants2.xml
Mime Type: unknown/xml
%AppData%[trojan name]toolbarversion.xml File name: %AppData%[trojan name]toolbarversion.xml
Mime Type: unknown/xml
%Temp%[trojan name]toolbar-manifest.xml File name: %Temp%[trojan name]toolbar-manifest.xml
Mime Type: unknown/xml

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}VersionIndependentProgID "[trojan name]IEHelper.UrlHelper"HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{99079a25-328f-4bd4-be04-00955acaa0a7}InprocServer32 "C:PROGRA~1WINDOW~4ToolBar[trojan name]dtx.dll"HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{99079a25-328f-4bd4-be04-00955acaa0a7} "[trojan name] Toolbar"HKEY_LOCAL_MACHINESOFTWAREClasses[trojan name]IEHelper.DNSGuardHKEY_LOCAL_MACHINESOFTWAREClasses[trojan name]IEHelper.DNSGuard.1HKEY_LOCAL_MACHINESOFTWAREClasses[trojan name]IEHelper.DNSGuardCurVerHKEY_LOCAL_MACHINESOFTWAREClasses[trojan name]IEHelper.DNSGuardCLSIDHKEY_LOCAL_MACHINESOFTWAREClassesCLSID{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}ProgID "[trojan name]IEHelper.UrlHelper.1"HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{99079a25-328f-4bd4-be04-00955acaa0a7} "[trojan name] Toolbar"HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{A40DC6C5-79D0-4ca8-A185-8FF989AF1115} "UrlHelper Class"HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar "[trojan name] Toolbar"
Loading...