Click on screenshot to zoom
Danger level 7
Type: Browser Hijackers
Common infection symptoms:
  • Hijacks homepage
  • Changes default search engine is a website that is set on Internet Explorer and Google Chrome browsers without a user’s consent. Once it makes the necessary changes, it causes redirections to a suspicious page looking like a search tool: Since Russian search results and ads are provided for users, specialists believe that should be called a Russian browser hijacker. Even though it targets Russian-speaking users primarily, it does not mean that you are safe – this infection might enter any computer because it is spread using illegal methods of distribution and can sneak onto computers unnoticed. Have you already become a victim of If the answer is yes, what you need to do today is to go to remove this browser hijacker from your computer so that you could set the preferred website as a homepage. The removal of this threat will not be an easy process because it makes quite many modifications on the infected computer, e.g. it changes the Value data of several different Values, it creates files in certain directories, and, finally, it modifies three files of Google Chrome so that it could set itself on this browser.

Users do not understand immediately that it is better to get rid of because it opens a website that looks like a decent search engine. It is a huge mistake to judge the book by its cover, especially when we talk about software or tools for searching the web. It is because many programs and search tools are made to look trustworthy, but, in reality, they have only been created to serve their authors, e.g. generate the revenue for them. Unfortunately, the same can be said about the search page redirects users to when they open their Internet Explorer or Google Chrome browsers. It looks like a genuine search provider at first glance, but the truth is that it is a platform for displaying advertisements. These ads are located on the right side of the page, but it is not their one and only location. Researchers at, who have thoroughly tested the browser hijacker, have noticed that ads might appear on the search results page too, meaning that users might encounter them if they use the search tool opened for them as the main tool for searching the web. Clicking on these commercials might be quite dangerous since they might cause harm. We do not say that malicious software will be immediately downloaded to your computer; however, using the dubious search tool promoted by the browser hijacker might really result in problems associated with the security because visiting suspicious websites every day (users might be immediately taken to them after clicking on a commercial advertisement) is a risky activity. Problems associated with the privacy might quickly arise too because the information about you will be recorded. This browser hijacker does not have a Privacy Policy accessible for anyone interested, but specialists suspect that it might not only record non-personally identifiable information, but might also be interested in various personal details about users. Evidently, the website causes redirections to is not a trustworthy tool for searching the web. It will no longer be visible only if is fully removed.

According to researchers, users who see set on their browsers, most probably, intended to download a free crack from the web. In most cases, such malicious cracks are located on file-sharing and similar third-party websites. Actually, browser hijackers are not the only threats that might sneak onto your PC together with free applications. Therefore, the installation of a reputable security application should be your top priority now. Keep in mind that you still cannot act carelessly on the web even though a security tool is installed and activated on your PC.

Because of all the modifications the browser hijacker makes on the infected computer, we cannot promise that it will be easy to make it gone from browsers. Of course, we really want to make it easier for you to get rid of this computer infection. Therefore, we asked our researchers to prepare the step-by-step removal guide for you. You are welcome to use it, but if it happens that you do not have enough experience in malware removal to perform the manual deletion of this browser hijacker, you should let SpyHunter do this job for you. It is a quicker and easier process – a user’s only job is to install a scanner and then launch it.

Delete manually

  1. Press Win+R.
  2. Type regedit and press Enter.
  3. Move to HKLM\SOFTWARE\Policies\Google\Chrome.
  4. Delete the Value data field of two Values located there (right-click on the Value and select Modify): DefaultSearchProviderInstantURL and DefaultSearchProviderSuggestURL.
  5. Open HKLM\SOFTWARE\Wow6432Node\Policies\Google\Chrome.
  6. Repeat the 4th step.
  7. Go to HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Search.
  8. Locate CustomizeSearch and SearchAssistant Values.
  9. Delete their Value data fields (right-click on the Value and then click Modify).
  10. Open the HKLM\SOFTWARE\Microsoft\Internet Explorer\Search registry key.
  11. Clean the Value data of CustomizeSearch and SearchAssistant Values.
  12. Open HKCU\Software\Microsoft\Windows\CurrentVersion\Run.
  13. Find the C Value and remove it.
  14. Close the Registry Editor.
  15. Find R and Registry.pol files in the following directories and delete them:
  • %WINDIR%\System32\GroupPolicy\Machine
  • %WINDIR%\System32\GroupPolicy\User
  • %WINDIR%\SysWOW64\GroupPolicy\Machine
  • %WINDIR%\SysWOW64\GroupPolicy\User
  1. Locate Secure Preferences, Preferences, and Web Data files in %LocalAppData%\Google\Chrome\User Data\Default and %USERPROFILE%\Local Settings\Application Data\Google\Chrome\User Data\Default.
  2. Open these files with Notepad (right-click on a file, select Open with, and choose Notepad).
  3. Replace all instances of inside these files with the preferred website, e.g. and save them.
Download Spyware Removal Tool to Remove*
  • Quick & tested solution for removal.
  • 100% Free Scan for Windows

Post comment — WE NEED YOUR OPINION!

Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.