QueryExplorer is a software usually installed without your knowledge with the download of freeware. In fact some sites use the method of repackaging. This is an operation that is to redo the module software installation by adding download options. These options allow to add other software as for example toolbars browser, or potentially unwanted software. The addition of these new programs can decrease the performance of the system but also slow or redirect internet surfing. As a general rule, should focus on the author’s official site to download your software.
Identified : 07/08/2015.


– It belongs to a family of PUP (Potentially Unwanted Program).
– An Adware is a program that adds other programs without the knowledge of the user.
– A polluteware is a software that pollutes storage and/or the Base of registers.
– Vendor : PUP.Optional


– It installs as a process launched at startup of the system (RP),
– It installs as a service to be launched each time the system (O23),(SS/SR),
– It installs as a program (O42),
– It creates to many registry keys ‘Software’,
– It creates additional folders (O43),
– It moved to the Windows prefetcher folder (O45),
– It creates a Legacy pointing to a malware service, key in the registry. (O64),
– It changes the Internet research provider (O69),


[MD5.342FB22D685077DE2A40211ACEB48E92] – (…) — C:\Users\Coolman\Application Data\QueryExplorer\queryexplorer119.exe [61720] [MD5.342FB22D685077DE2A40211ACEB48E92] – (…) — C:\Program Files\QueryExplorer\queryexplorer.exe [61720] O23 – Service: (QueryExplorer Service) . (…) – C:\Users\Coolman\Application Data\QueryExplorer\queryexplorer119.exe
O42 – Logiciel: QueryExplorer 1.0 build 119 – (…) [HKLM] — QueryExplorer
O42 – Logiciel: QueryExplorer 1.0 build 143 powered by FIRST SEARCHBAR – (…) [HKLM] — QueryExplorer[HKLM\Software\QueryExplorer] O43 – CFD: 17/11/2010 – 11:33:40 —-D- C:\Program Files\QueryExplorer
O64 – Services: CurCS – “C:\Users\Coolman\Application Data\QueryExplorer\queryexplorer119.exe (.not file.) – QueryExplorer Service (QueryExplorer Service) .(…) – LEGACY_QUERYEXPLORER_SERVICE
O69 – SBI: SearchScopes [HKUS\.DEFAULT] {C34A3EC2-C7F1-4F62-A549-DCE7F7322A79} – (QueryExplorer) – http://www.queryexplorer.com
O69 – SBI: SearchScopes [HKUS\S-1-5-18] {C34A3EC2-C7F1-4F62-A549-DCE7F7322A79} – (QueryExplorer) – http://www.queryexplorer.com[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\QueryExplorer] [HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\QueryExplorer] [HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C34A3EC2-C7F1-4F62-A549-DCE7F7322A79}] [HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_QUERYEXPLORER_SERVICE] [HKLM\SYSTEM\CurrentControlSet\Services\QueryExplorer Service] C:\Program Files\Mozilla Firefox\Extensions\{27E679CC-6AAB-4B2A-BB87-096FE4178464}
C:\Program Files\QueryExplorer
C:\Users\Coolman\Application Data\QueryExplorer


Adware.QueryExplorer [ Malwarebytes Antimalware ] Adware.Zwangi [Bitdefender] Adware/OneStep [Panda Antivirus]


– Remove software in Windows Configuration Panel,
Remove with ZHPcleaner
Diagnose with ZHPDiag

2016-12-30T07:34:17+00:00 Categories: Adware, Polluteware, PUP|Tags: , , |Comments Off on PUP.Optional.QueryExplorer