Home Malware Programs Browser Hijackers Questdns.com

Questdns.com

Posted: November 7, 2011

Questdns.com (AKA QuestDNS) is a fake search engine website that pretends to offer relevant search results, but in reality, prefers to share links that will pay kickbacks to Questdns.com as a reward for the traffic flow. SpywareRemove.com malware researchers have also connected Questdns.com to other types of fake search engines that duplicate its scam, as well as to Trojans that cause browser redirect attacks (with the inevitable destination being, of course, Questdns.com). If you experience browser redirects to Questdns.com or other symptoms of a browser hijacker's presence, you should try to limit exposure to Questdns.com and remove the browser hijacker with an up-to-date anti-malware scanner.

Questdns.com – a Global Search Engine Threat

The streamlined interface that Questdns.com uses is a copy, with minor tweaks, of the interfaces of other types of fake search engine sites that run the same scam – by pretending to offer you relevant results, Questdns.com and its relatives have an easy excuse to redirect you to profitable advertisements and outright hostile sites. SpywareRemove.com malware researchers encourage you to avoid any contact with Questdns.com, QueryExplorer.com, BarQuery.com, Ziniky.com, SeekDNS.com, Zumie.com and Searchqu.com, since they all engage in similar attacks on any browser that happens to visit them.

The most common attack by Questdns.com and related websites is the installation of browser-redirecting Trojans that behave similarly to the Google Redirect Virus. Since these Trojans can be installed by drive-by-download scripts without your permission, even a brief crossing with Questdns.com can turn into a high-level threat to your PC. Symptoms of the presence of browser hijackers for Questdns.com can extend to:

  • Having your browser's homepage set to Questdns.com. This can also extend to non-homepage new windows and tabs.
  • Being redirected to Questdns.com when you tried to use an unrelated site. Search engine websites are especially vulnerable to being used to trigger these redirect attacks, but shouldn't be considered the sole potential triggers.
  • Experiencing worsened web browser performance, lag or slow loading times.
  • Pop-ups that expose you to irrelevant advertisements, fake system scanners or phishing scams (including fake surveys and contests).

The Trick to Refusing the Call to Questdns.com

Although you may be able to remove a browser hijacker for Questdns.com by normal methods (such as through the Control Panel's program list), this is strongly likely to leave behind components of the guilty Trojan that may cause other farms of damage to your PC. Accordingly, SpywareRemove.com malware experts recommend that you remove any Questdns.com-aligned infection by using qualified anti-malware programs to scan your PC, so that it can detect all infected components, including malicious Registry entries.

You should never attempt to remove a browser hijacker for Questdns.com by deleting your web browser, since Questdns.com redirect attacks can occur in Chrome, Firefox or Internet Explorer until the relevant Trojan is deleted. Even changes to your browser's security settings can be undone until the original infection is removed, which is why it's recommended that you get rid of any software that's affiliated with Questdns.com in good haste.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%Temp%QuestDNStoolbar-manifest.xml File name: %Temp%QuestDNStoolbar-manifest.xml
Mime Type: unknown/xml
%AppData%QuestDNStoolbardtx.ini File name: %AppData%QuestDNStoolbardtx.ini
Mime Type: unknown/ini
%AppData%QuestDNStoolbarstat.log File name: %AppData%QuestDNStoolbarstat.log
Mime Type: unknown/log
%AppData%QuestDNStoolbarstats.dat File name: %AppData%QuestDNStoolbarstats.dat
File type: Data file
Mime Type: unknown/dat
%AppData%QuestDNStoolbaruninstallIE.dat File name: %AppData%QuestDNStoolbaruninstallIE.dat
File type: Data file
Mime Type: unknown/dat
%AppData%QuestDNStoolbaruninstallStatIE.dat File name: %AppData%QuestDNStoolbaruninstallStatIE.dat
File type: Data file
Mime Type: unknown/dat
%AppData%QuestDNStoolbarguid.dat File name: %AppData%QuestDNStoolbarguid.dat
File type: Data file
Mime Type: unknown/dat
%AppData%QuestDNStoolbarlog.txt File name: %AppData%QuestDNStoolbarlog.txt
Mime Type: unknown/txt
%AppData%QuestDNStoolbarpreferences.dat File name: %AppData%QuestDNStoolbarpreferences.dat
Mime Type: unknown/dat
%AppData%QuestDNStoolbarversion.xml File name: %AppData%QuestDNStoolbarversion.xml
Mime Type: unknown/xml
%AppData%QuestDNStoolbarcouponscategories.xml File name: %AppData%QuestDNStoolbarcouponscategories.xml
Mime Type: unknown/xml
%AppData%QuestDNStoolbarcouponsmerchants.xml File name: %AppData%QuestDNStoolbarcouponsmerchants.xml
Mime Type: unknown/xml
%AppData%QuestDNStoolbarcouponsmerchants2.xml File name: %AppData%QuestDNStoolbarcouponsmerchants2.xml
Mime Type: unknown/xml

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}ProgID "QuestDNSIEHelper.UrlHelper.1"HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{A40DC6C5-79D0-4ca8-A185-8FF989AF1115} "UrlHelper Class"HKEY_LOCAL_MACHINESOFTWAREClassesQuestDNSIEHelper.DNSGuardCurVerHKEY_LOCAL_MACHINESOFTWAREClassesCLSID{99079a25-328f-4bd4-be04-00955acaa0a7}InprocServer32 "C:PROGRA~1WINDOW~4ToolBarQuestDNSdtx.dll"HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{99079a25-328f-4bd4-be04-00955acaa0a7} "QuestDNS Toolbar"HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}VersionIndependentProgID "QuestDNSIEHelper.UrlHelper"HKEY_LOCAL_MACHINESOFTWAREClassesQuestDNSIEHelper.DNSGuardCLSIDHKEY_LOCAL_MACHINESOFTWAREClassesQuestDNSIEHelper.DNSGuardHKEY_LOCAL_MACHINESOFTWAREClassesQuestDNSIEHelper.DNSGuard.1HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar "QuestDNS Toolbar"HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{99079a25-328f-4bd4-be04-00955acaa0a7} "QuestDNS QuestDNS Toolbar"
Loading...