What is the is an unreasonable redirect virus, forcibly capturing user’s browser search service and change it to its own. It pretended to be a useful platform so that to satisfy user’s shopping demands but in fact was with the evil purpose of coaxing the masses of innocent users to make transactions and defraud their money. Normally, the always providing the commercial information about the latest listing of products with incredible but preferential price. In this case, most of the users could not resist the temptation and blindly click on each advertising link to have a look, hoping to gain advantages but resulting in being cheated and losing a lot of money.

Because can freely make modifications about the browser, and not just the default homepage has been reset but more. The cunning redirect virus would secretly put the browser guard down and make it wide open for various baleful attacks. Under this circumstance, the compromised browser will be defenseless, giving the chances for all the unwanted threats including virus, Trojans, worms and malware to install in it without user’s awareness and corrupt it gradually. With such a terrible beginning, the compromised browser was equivalent to a high-risk vulnerability so that more and more virus and malware will seize the chance to invade into the computer system and destroy it. can bring no end of trouble for the future. As the browser was broken through by the redirect virus and other mighty attacks, cyber criminals and hackers will easily take control of targeted computer remotely. In that case, user’s online activities will be monitored without authorization and their important data will be revealed. Hackers are always so treacherous and skilled, they can stealthily record user’s keyboard log and crack the confidential information such as user’s login passwords, online banking transaction authentication codes, personal identification codes, etc. Which must pose a serious threat to user’s personal assets and also a violation for user’s personal privacy. More than that, hackers would also delete or destroy users important files to cause them irreparable losses. So it is strongly recommended that users have to remove immediately before everything falling apart.

How to Remove Completely

Step 1: Clean all the traces of from the browser

Internet Explorer

1. Start the Internet Explorer, click on Tools in the menu bar then select the Internet Options in the drop-down list.

2. Click on the Advanced tab, check the needed items under the browser settings section and click on the Reset button.

3. Click on the General tab, type a new address in the homepage box and save the changes.

4. Restart the Internet Explorer.

Mozilla Firefox

1. Open the Mozilla Firefox, locate the Help under the Firefox menu then click on the Troubleshooting Information in the list.

2. In the showing page, click on the Reset Firefox button and conform the reset.

3. Close the current pages and click on the Firefox button and locate the Options and click on the Options.

4. Click on the General tab in the showing window, type a new address in the homepage box then save the changes.

5. Restart the Mozilla Firefox.

Google Chrome

1. Launch the Google Chrome then click on the wrench icon, choose Settings in the drop-down list.

2. In the showing Settings page, click on Show advanced settings.
3. Click on Reset browser settings button.

4. In the Appearance section, click on the Show Home button then click on the Change link, type a new address in the box and save the changes.

5. Restart Google Chrome.

Step 2: Remove from the Control Panel

1. Open the Start menu then search for the Control Panel open it.

2. Find out the Programs in the panel, then click on the Uninstall a program link under it.

3. Search for the in the showing programs list, then highlight them and click on the Uninstall to remove them all.

4. Confirm the uninstall request then follow the wizard to complete the removal.
5. Refresh the list to make sure if the was removed.

Step 3: Remove all the leftovers of

1. Click on the Start button and open the Run Command box, type “regedit” in it then press the Enter key.

*for Windows 8 users, type “regedit” in the Apps search bar , then click on the Registry Editor in the search results.

2. Find out all the registry entries of in the Registry Editor window and delete them carefully.

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “Hidden” = ’0′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = 1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run: [avsdsvc] %CommonAppData%\ifdstore\security_defender.exe /min
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “ShowSuperHidden” = 0′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\InternetSettings “CertificateRevocation”=0

3. Show up all the hidden files.
1) Open the Control Panel and click on the Appearance and Personalization, then click on the Folder Options.

2) Click on the View tab. Select the item: Show hidden files, folders and drives and remove the default check from the item: Hide protected operating system files(Recommended).
3) Click on the OK button to save the changes.
%AllUsersProfile%\Application Data\
%AllUsersProfile%\Application Data\.exe
%UserProfile%\Start Menu\Programs\random.lnk
%AllUsersProfile%\Application Data\~r
%AllUsersProfile%\Application Data\.dll

4. Search for the files of in the system and delete them.
5. Reboot the computer immediately.


Just as the usually got away with it and freely hijacked user’s browser with improper ways, users have to learn for more effective ways to prevent from being infected with the cunning redirect virus. For example, users have to stop downloading freeware or shareware from random sites which might be corrupted by cyber criminals. In most cases, this kind of websites are filled up with plenty of viruses and malware, once any user wandering around the pages, the browser and computer will be seriously infected. And the freeware is also a trap for users. Because most of the malware would love to be bundled with it and installed together into the targeted system, the consequences would be disastrous.
