Click on screenshot to zoom
Danger level 7
Type: Browser Hijackers
Common infection symptoms:
  • Hijacks homepage
  • Can't be uninstalled via Control Panel

We have recently witnessed an increase of browser hijacker releases that are tailored for specific regions and/or languages. is a new browser hijacker that targets web surfers who live is Portuguese speaking countries, such as Brazil. You probably want to remove this hijacker, because it obstructs your Internet browsing. The main purpose of this infection is to change your browser’s homepage and keep it that way. It will prevent you from changing your browser’s homepage back to how it was. Luckily, we have found ways to get rid of this pesky hijacker. It is not the easiest of tasks, but the most diligent users will pull it off successfully.

Your computer can become infected with if you are a frequent visitor of websites that feature pirated material. As far as we know, this hijacker can be found on Brazilian piracy websites. Of course, this hijacker cannot hijacker homepages on its own, because it is technically a search engine. This hijacker relies on custom installers to inject certain files and registry values into your system. might not be the only malicious application to enter your computer, because bad applications seldom travel by themselves. This hijacker might be bundled with other malicious applications and you might get your computer infected with them if you download pirated content via download managers.

The main purpose of is to generate revenue for its owners. This website receives approximately 25,000 unique visitors per day which should generate about $200 USD from advertising revenue. You might be surprised, but is actually worth an estimated $77,737.01 USD. But is any good at what it does as a search engine? Actually no, because all of its searches get redirected to The website, is therefore, utterly useless. There is no reason to use even if it did not take over your homepage by storm. This hijacker is likely to gather information about your browsing habits. This information will most certainly be used for analytical, advertising, and marketing purposes, so you may be presented with customized search results. Above all, this search engine is very poorly optimized so you might not even find what you are looking for.

Removing is not an easy objective. It cannot be removed via the Control Panel and it does not modify the browser’s Target line like most hijackers do. It relies on malicious files to keep everything under lock and key. Locating these files is impossible if you do not know where to look and knowing what exact file names you are looking for is crucial. Therefore, we have prepared a manual removal guide that will hopefully aid you in deleting the required files. In order to delete this hijacker, you must first uninstall ActSys, CashReminder, GOSafer, and WNet. After you have done that you have to delete certain files from the Drivers folder in System32. Only after you have done that you will be able to change your browser’s home page.

Uninstall malware

Windows 8/8.1

  1. Open the Start Screen.
  2. Type Uninstall in the search box and then go to Settings.
  3. In the search results, go to Uninstall a program.
  4. Locate the application and click Uninstall.

Windows 7/Vista

  1. Click Start and select Control Panel.
  2. Click Uninstall a program.
  3. Locate the malicious program and click Uninstall.

Windows XP

  1. Open the Start menu and click Control Panel.
  2. Select Add or Remove Programs.
  3. Locate the unwanted application and click Remove.

Delete files

  1. Open Windows Explorer or any other folder.
  2. Enter %windir%\system32\drivers in the address bar.
  3. Locate crfilterdrv.sys, gosaferdrv.sys, asfilterdrv.sys, ssfilterdrv.sys. and delete them.
  4. Done.
Download Spyware Removal Tool to Remove*
  • Quick & tested solution for removal.
  • 100% Free Scan for Windows

Post comment — WE NEED YOUR OPINION!

Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.