Click on screenshot to zoom
Danger level 7
Type: Browser Hijackers
Common infection symptoms:
  • Changes default search engine
  • Hijacks homepage

Browser hijackers are increasing in numbers every day as most of them are clones of each other. is a hijacker that belongs to the Websearch family. You should want to remove it because it is distributed using a clandestine and dishonest manner, so if you have it on your PC, then you most likely got it unintentionally. In this article, we are going to cover this infection’s dissemination methods, and functions and purposes. Lastly, we are going to provide you with the means to delete it from your web browser, so please continue reading.

Browser hijackers are considered as computer infections because they are distributed in such a manner that requires them to be injected to a computer without the user knowing about it. We have tested this infection and found that it can affect Microsoft Internet Explorer, Google Chrome, and Mozilla Firefox. It is set to replace the homepage of Internet Explorer and Firefox and the new tab page of Google Chrome. However, it does not change the search provider of either of these web browsers. The reason for performing this malicious activity is to redirect web traffic to

Testing has shown that when you enter a search term to, then it will redirect you to a shady search engine that features three search results that are claimed to have come from Clicking on anyone one of those search results will redirect you to This search engine is the final stop, and it is this search engine that gives you the final search results. We have found that often contains links that promote certain third-party websites. Some of them redirect to other search engines, such as, while others redirect to sites.

We want to stress that you cannot be certain whether the promoted websites are legitimate since and the search engines it redirects to are not legitimate whatsoever. Furthermore, this browser hijacker is currently configured to advertise a shady program on its main page. The name of this program is Reimage. This program is very familiar to us since it has been around for some time now. We are aware of it precisely because it is shady and has been classified as a potentially unwanted program that is paid, but does not perform useful functions.

We are not surprised in the least because this browser hijacker comes from a well-known group of browser hijackers that we refer to as the Websearch browser hijacker family. Indeed, you can recognize a hijacker from the family be looking at the URL. For example, some of’s clones are called,, and They all come from the same group of developers. However, we do not know the name of the company because their browser hijackers were not signed by anyone. This is indicative of the fact that Websearch’s browser hijackers are malicious because a legitimate company would not hide in the shadows.

As far as’s dissemination methods go, we want to inform you that it is being distributed in a very dishonest manner. Our research has revealed that it comes bundled with InstallRex installers that also bundle potentially unwanted programs such as LightningDownloader and Optimizer Pro. So in addition to having your web browser infected with a browser hijacker, you might also shady apps installed on your PC. We have found that such bundles are advertised on various torrent websites that you can install by clicking a fake download torrent button. Nevertheless, we believe that these malicious software bundles are not limited to torrent sites and can be found elsewhere. However, currently, we have no additional information about other websites they might be featured on.

We hope that you found the information we have provided enlightening. As you can see, only poses as a legitimate search engine while in reality it is used to generate advertising revenue for its developers and their clients. As a search engine, this hijacker is very annoying as it redirects you to other shady search engines which make performing Internet searches a real pain. So we invite you to remove and uninstall any additional software that it may have come with.

How to remove this browser hijacker from your web browser

Mozilla Firefox

  1. Press Windows+E keys.
  2. Enter C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\{Unique mozilla user ID} in the address bar.
  3. Locate prefs.js and open it with Notepad.
  4. Replace the homepage address in the string user_pref("browser.startup.homepage", "");

Google Chrome

  1. Press Windows+E keys.
  2. Enter C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default in the address bar.
  3. Find Preferences, Secure Preferences and Web Data files.
  4. Open them with Notepad and replace another homepage address.

Microsoft Internet Explorer

  1. Press Windows+R keys.
  2. Enter regedit in the resulting dialog box and click OK.
  3. In the Registry Editor, go to HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
  4. Find Start Page string, right-click on it and click Modify.
  5. Enter new homepage address in the Value data line.
Download Spyware Removal Tool to Remove*
  • Quick & tested solution for removal.
  • 100% Free Scan for Windows

Post comment — WE NEED YOUR OPINION!

Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.