Thursday, August 4, 2011

Remove Searchqu 406 and 410 home page

Serchqu is a malicious program that pushes out your favorite pages in favor of its misleading web-search engine. The name of the rogue is conventional and indicates the name of the website promoted in the above way.
It might also intercept requests to browser typed into search bar without putting http or www at the beginning of the query.
A case has been described when the infection totally disabled Internet Explorer and set the following address:
www.searchqu/406
a home page for Firefox.
The home page of the browser could not be changed without removal of Serchqu malware.
Besides the browser capturer removal, it is reasonable to scan computer system for other infections, because the impact of the malicious modifier of browser settings and browser disabler makes computer system  extremely vulnerable to other hostile programs.
Click here to run free computer examination for viruses and trojans and get rid of Serchqu issue, as well as ensure thorough disinfection of your computer memory.

Serchqu screenshot:



Manual removal guide:
Delete infected files:

%AppData%\searchqutoolbar\coupons\categories.xml
 %AppData%\searchqutoolbar\coupons\merchants.xml
 %AppData%\searchqutoolbar\coupons\merchants2.xml
 %AppData%\searchqutoolbar\dtx.ini
 %AppData%\searchqutoolbar\guid.dat
 %AppData%\searchqutoolbar\log.txt
 %AppData%\searchqutoolbar\preferences.dat
 %AppData%\searchqutoolbar\stat.log
 %AppData%\searchqutoolbar\stats.dat
 %AppData%\searchqutoolbar\uninstallIE.dat
 %AppData%\searchqutoolbar\uninstallStatIE.dat
 %AppData%\searchqutoolbar\version.xml
 %AppData%\searchqutoolbar\
 %Temp%\searchqutoolbar-manifest.xml

Delete infected registry entries:

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\InprocServer32 "C:\PROGRA~1\WINDOW~4\ToolBar\searchqudtx.dll"
 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7} "Searchqu Toolbar"
 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\VersionIndependentProgID "SearchQUIEHelper.UrlHelper"
 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ProgID "SearchQUIEHelper.UrlHelper.1"
 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115} "UrlHelper Class"
 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard\CurVer
 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard\CLSID
 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard
 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard.1
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar "Searchqu Toolbar"
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079a25-328f-4bd4-be04-00955acaa0a7} "Searchqu Toolbar"

5 comments:

Perfect Vision Technologies said...

Hi guys - I found a simple way to resolve this issue:
...
Go into Control Panel
add/remove -- Remove an Apple program called Bonjour...
close it:
go to your Tools on your webpage and Change the Internet Webpage default to what you want it to be. It does work...cause I had to do the same....
Blake, FL

Perfect Vision Technologies said...

Better way to resolve the issue with Searchqu 406:
Go to your control Panel - Add/Remove - uninstall Bonjour - its an Apple program:
Now:
Go to your Tools - Internet Options and set the webpage default you want to use.
I used it myself and it definately worked.

Yoga, Bare said...

Thanks to Perfect Vision Technologies. Your solution worked for me! :)

msal said...

Okay...I did what was suggested in going to control panel and uninstalling "bonjour,"...problem: It was not in my control panel list of items. I attempted a search for "bonjour" and no file found. Any other suggestions? Thanks, El Paso, TX.

Perfect Vision Technologies said...

Msal - I am sorry you cannot find Bonjour on your Add/Remove contents. Maybe you do not have an apple product on your computer. Then just go to tools - webpage default and set what you want. I hope it works for you.