Information: is not a real search engine at all, as it’s created for some bad goal but not helping you somehow. We have discussed many similar problems before, such as Virus and Virus. Though they look differently, they have the same hijacker feature. Cyber criminals want to make money on pay-per-click industry. That’s to say, they need to attract lots of traffic and make them click on the ads on their websites. Of course, they will not apply regular SEO means to grow traffic. So they resort to an automatic way, that’s ZeroAccess Rootkit. When this rootkit succeeds in entering your workstation, it will impact the way you search. The problem will happen when you search on some well-known search engines like Yahoo! and Google etc. This rootkit do not stop you visting them, entering the phrase and getting the real search results. But you will be surprised to end up on rather than other website URLs you clicked. No matter which link that you click, it will all take you to the The more click to, the more money hackers can get.

To solve this problem, you need to remove ZeroAccess Rootkit. There is removal guide that can help you out of this mess. Screenshot: Manual Removal

Note: If you are not proficient with computer, it’s advised that you backup your system before manually removing virus. And double check the files that you are going to delete, or your computer can’t work for missing some files.

Step 1: Delete the following registery files:

HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{99079a25-328f-4bd4-be04-00955acaa0a7}InprocServer32 “C:PROGRA~1WINDOW~4ToolBar[trojan name]dtx.dll”

HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}VersionIndependentProgID “[trojan name]IEHelper.UrlHelper”

HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{A40DC6C5-79D0-4ca8-A185-8FF989AF1115} “UrlHelper Class”


HKEY_LOCAL_MACHINESOFTWAREClasses[trojan name]IEHelper.DNSGuard.1

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects

Step 2: Delete the following files:

%AppData%[trojan name]toolbarcouponscategories.xml

%AppData%[trojan name]toolbarcouponsmerchants2.xml

%AppData%[trojan name]toolbarguid.dat

%AppData%[trojan name]toolbarpreferences.dat

%AppData%[trojan name]toolbaruninstallStatIE.dat

%Temp%[trojan name]toolbar-manifest.xml

Please, note that manual removal of virus is a procedure with high complexity and can not always guarantee a full removal of the virus, due to the fact that some objects can stay hidden or may become reanimated automatically after incomplete removal. What’s more, lack of the required skills and even the slightest deviation from the removal guides may result in irreparable system corruption. That’s the reason it’s strongly adviced automatic removal of virus, which will save your time and avoid any system corruptions and ensure the desired result.

Automatic virus Removal:

Step 2: Click & download the trusted virus Automatic Removal Utility.

Tips: In case you can’t install the removal utility, please download this correction script, unzip it and then double click to execute it. It can correct the system settings that the spyware has distorted.

Step 6: Perform a Full Scan of your system to detect virus or other malware.


Published by Cruze Albert