Announcement

Collapse
No announcement yet.

Hohosearch.com Browser Hijacker Removal Guide

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Hohosearch.com Browser Hijacker Removal Guide

    The Hohosearch.com program from the Adware/ShortcutHijacker family of browser hijackers that is bundled with other free software that you download off of the Internet. Once it is installed it will change your installed browser's home page and search engine to Hohosearch.com without your permission. This adware will also infect your web browser shortcuts by adding the http://www.hohosearch.com/?ts=[timestamp]&v=[version]&uid=[uid]&ptid=[unknown]&mode=[unknown] argument to them so that the Hohosearch.com site is opened every time you launch your browser. The method that they use to hijack your shortcuts makes it impossible to fix without specialized tools such as our Shortcut Cleaner.

    Hohosearch.com Browser Hijacker Removal Guide

    • Fri, 22 Apr 2016 16:32:02 EDT
    • Read 409 times








    The Hohosearch.com program from the Adware/ShortcutHijacker family of browser hijackers that is bundled with other free software that you download off of the Internet. Once it is installed it will change your installed browser's home page and search engine to Hohosearch.com without your permission. This adware will also infect your web browser shortcuts by adding the http://www.hohosearch.com/?ts=[timestamp]&v=[version]&uid=[uid]&ptid=[unknown]&mode=[unknown] argument to them so that the Hohosearch.com site is opened every time you launch your browser. The method that they use to hijack your shortcuts makes it impossible to fix without specialized tools such as our Shortcut Cleaner.

    When this is installed on a computer, victims easily become frustrated as when they remove the shortcuts from their browser links, they are mysteriously added back. This is because the Hohosearch.com program utilizes a Windows service that hijacks the shortcuts again when it detects if the shortcuts have been cleaned. This is why we first need to remove the program from the computer before we clean the shortcuts.
    How did the Hohosearch.com hijacker get on my computer?

    It is important to note that this program is installed by other programs that did not adequately disclose that other software would be installed along with it. Therefore, it is important that you pay attention to the license agreements and installation screens when installing anything off of the Internet. If an installation screen offers you Custom or Advanced installation options, it is a good idea to select these as they will typically disclose what other 3rd party software will also be installed. Furthermore, If the license agreement or installation screens state that they are going to install a toolbar or other unwanted adware, it is advised that you cancel the install and not use the free software.
    As you can see, the Hohosearch.com browser hijacker was created in a way that makes it difficult to clean up without specialized tools. In my opinion you should uninstall this program if you discover the symptoms listed above so that your computer and browsers can run properly. To remove the Hohosearch.com browser hijacker and clean the affected shortcuts, please use the removal guide below.
    Array
    View Associated Hohosearch.com Files C:\Program Files (x86)\Atagary\\ C:\Program Files (x86)\Atagary\Atgverfier.dll C:\Program Files (x86)\Atagary\Atgverfier.dll.json C:\Program Files (x86)\Atagary\{A16B1AF7-982D-40C3-B5C1-633E1A6A6678} C:\Program Files (x86)\Oyrrcfgbyra\ C:\Program Files (x86)\Oyrrcfgbyra\Drvcoresrv.exe C:\Program Files (x86)\Oyrrcfgbyra\Drvcoretsk.exe C:\Program Files (x86)\Oyrrcfgbyra\{A16B1AF7-982D-40C3-B5C1-633E1A6A6678} C:\Program Files (x86)\hohobnd\ C:\Program Files (x86)\hohobnd\@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924.xpi C:\Program Files (x86)\hohobnd\CCeuter.exe C:\Program Files (x86)\hohobnd\conf.json C:\Program Files (x86)\hohobnd\dmp\ C:\Program Files (x86)\hohobnd\dmp\CCeuter.exe\ C:\Program Files (x86)\hohobnd\dmp\Drvcoresrv.exe\ C:\Program Files (x86)\hohobnd\dmp\Drvcoretsk.exe\ C:\Program Files (x86)\hohobnd\dmp\reekge.exe\ C:\Program Files (x86)\hohobnd\dmp\weck.exe\ C:\Program Files (x86)\hohobnd\FFeuter.exe C:\Program Files (x86)\hohobnd\reekge.exe C:\Program Files (x86)\hohobnd\Uninst.exe C:\Program Files (x86)\hohobnd\weck.exe C:\Program Files (x86)\hohobnd\{A16B1AF7-982D-40C3-B5C1-633E1A6A6678} C:\Windows\System32\Tasks\Oyrrcfgbyra Core


    View Associated Hohosearch.com Registry Information HKCU\Software\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF} HKCU\Software\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}\hp http://www.hohosearch.com/?ts=[timestamp]&v=[version]&uid=[uid]&ptid=[affiliate_id]&mode=[unknown] HKCU\Software\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}\tab http://www.hohosearch.com/?ts=[timestamp]&v=[version]&uid=[uid]&ptid=[affiliate_id]&mode=[unknown] HKCU\Software\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}\sp http://www.hohosearch.com/chrome.php?uid=[uid]&ptid=[affiliate_id]&q={searchTerms}&ts=[timestamp]&v=[version]&mode=[unknown] HKCU\Software\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}\surl http://www.hohosearch.com/chrome.php?uid=[uid]&ptid=[affiliate_id]&ts=[timestamp]&v=[version]&mode=ffexttoolbar&q= HKCU\Software\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}\uid [uid] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{636f7069-6564-6672-6f6d-626c65657021}} HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{636f7069-6564-6672-6f6d-626c65657021}}\Path \Oyrrcfgbyra Core HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Oyrrcfgbyra Core HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Oyrrcfgbyra Core\Id {636f7069-6564-6672-6f6d-626c65657021}} HKLM\SOFTWARE\Mozilla\Firefox HKLM\SOFTWARE\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF} HKLM\SOFTWARE\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}\hp http://www.hohosearch.com/?ts=[timestamp]&v=[version]&uid=[uid]&ptid=[affiliate_id]&mode=[unknown] HKLM\SOFTWARE\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}\tab http://www.hohosearch.com/?ts=[timestamp]&v=[version]&uid=[uid]&ptid=[affiliate_id]&mode=[unknown] HKLM\SOFTWARE\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}\sp http://www.hohosearch.com/chrome.php?uid=[uid]&ptid=[affiliate_id]&q={searchTerms}&ts=[timestamp]&v=[version]&mode=[unknown] HKLM\SOFTWARE\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}\surl http://www.hohosearch.com/chrome.php?uid=[uid]&ptid=[affiliate_id]&ts=[timestamp]&v=[version]&mode=ffexttoolbar&q= HKLM\SOFTWARE\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}\uid [uid] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Uninstall - amz HKLM\SYSTEM\CurrentControlSet\services\Drvcoresrv HKLM\SYSTEM\CurrentControlSet\services\BugreportW\







    Click here to view the article.
Working...
X