Tuesday, July 2, 2013

Remove Goonsearch.com hijack. Fix redirect virus

Goonsearch.com is a fake search engine that uses browser hijack malwares to get promoted. Once Goonsearch virus redirect has been executed on a PC, it immediately applies its corrupt settings to the Firefox, Chrome, Internet explorer or any web browser installed on the infected PC. All the process of this virus is very stealth, even its download cannot be notices because it comes either as bundled with freeware programs or gets dropped into a machine by trojans (from hacked domains). At first user notices that Google search results are redirecting to http://Goonsearch.com or when trying to access Google.com, it leads to Goonsearch engine. At the time you,ll realize that home page also has been set to that unwanted website while you did not change it. Some other common things you might notice are, strange popup ads or ads by Goonsearch appearing on all websites accessed from infected PC, slow down system performance and browser crashes, etc. Goonsearch redirect malware can be a responsible for identity theft as such programs are designed to spy on infected computers and collect sensitive user information. You are advised to get rid of Goonsearch.com hijack virus right now.



Disadvantages and risks of having GoonSearch.com:
  • It may change & corrupt default settings of browsers like Firefox, Chrome or Internet explorer
  • Changes home page and displays unwanted pop-ups advertisements
  • Causes frequent web redirects to wrong websites, hijacks search engine settings and leads to unexpected webpages
  • Keeps record of browsing activities and interests
  • Collects Personal user information which may include sensitive financial data such as logins, usernames, accounts
  • It may bring further infections are direct the user to infectious sites
  • Makes the browser run slow, uses a big part of system resources
Want to get rid of Browser Hijack GoonSearch.com?:
To manually remove GoonSearch.com, follow the instructions.
First of all, Uninstall the program. (Skip to the next step if the application is not listed in Control Panel).
“Start > Settings > Control Panel. Now Locate and open “Add or Remove Programs” or “PROGRAMS AND FEATURES”. Find “GoonSearch.com”. Now click Uninstall/Remove.
Now remove the program from Browser.
Internet Explorer users:
Click “Tools” (if on Internet Explorer 9, click gear icon), Then “Manage Add-ons”. Look for GoonSearch.com. Disable if found any.
Block pop-ups of GoonSearch.com
To stop pop-ups from malware,
Click on TOOLS > POP-UP BLOCKER, then click TURN ON POP-UP BLOCKER. and then go to POP-UP BLOCKER SETTINGS. (Type any website you wish to block popups from)
 Firefox users:
Go to “Tools” (at the top), > “Add-ons” > “Extensions” and disable “GoonSearch.com”
 Chrome Users:
Click “Tools/Settings” (Wrench incon), > “Add-ons” > “Extensions” and disable any file associate with malware.


Still Spyware GoonSearch.com lurking in the system? Remove manually
Stop processes of this malware:
Open Task Manager to stop processes.
Remove associated registry settings:
HKEY_CLASSES_ROOT\urlsearchhook.toolbarurlsearchhook
HKEY_LOCAL_MACHINE\software\classes\urlsearchhook.toolbarurlsearchhook
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions,
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnonBadCertRecving” = ’0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop “NoChangingWallPaper” = ’1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = ’1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = ’1
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “CheckExeSignatures” = ‘no’
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main “Use FormSuggest” = ‘yes’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “ShowSuperHidden” = 0
Delete GoonSearch.com infected files:
%Profile%\Local Settings\Temp\
%ProgramFiles%\
%UserProfile%\

No comments:

Post a Comment