How to remove ads in the browser (virus): step by step instructions

Table of contents:

How to remove ads in the browser (virus): step by step instructions
How to remove ads in the browser (virus): step by step instructions

Without the Internet, the life of a modern person is impossible to imagine. However, it is fraught with many dangers associated with the penetration of all kinds of virus applets onto user computers or mobile devices. Some of them can steal personal data or confidential information, others harm the operating system or encrypt user files, demanding considerable sums of money for decryption, others flood the browsers used in the process of Internet surfing with advertising or spontaneously redirect users to advertising sites or virus-containing resources. Next, let's focus on the appearance of ads in the browser. Not everyone knows how to remove a virus of such an action (Malware, Adware, Hijackers), so below is a brief practical guide, which in most caseswill quickly and completely get rid of all known threats of this nature.

Ad viruses: what are they and how do they work?

To begin with, it is worth saying a few words about the viruses themselves, which open browsers with ads. Conventionally, they can be divided into several main categories. The first can be attributed only to those that are launched exclusively during the operation of browsers. Most often, such threats in the system can be found either in the form of separately installed applications that are not completely masked from the user's eyes, or in the form of additional extensions integrated into browsers.

The second group should include viruses that once penetrated the system through gaps in browsers or through the fault of the user himself, who ignored antivirus warnings and entered a potentially dangerous page, and flooded the entire system with ads, regardless of whether browser program at the moment or not. In this case, pop-up messages and notifications appear on the "Desktop" or in the system tray, since such applets require only an active Internet connection.

In addition, many threats of this type replace the default search engines and start pages that open when browsers start. Sometimes the load on system resources or traffic consumption may increase. Thus, as soon as you, God forbid, notice the first symptoms of such behavior of your own system, immediately start eliminating threats! But how to remove virus-advertising in the browser? ForFrom the beginning, the best solution would be to use specialized portable anti-virus programs. In no case do not rely on regular antiviruses, as they have already missed the threats!

Cleaning your computer with Dr. Web CureIt

This scanner is considered one of the most powerful tools to recognize, neutralize or remove most known threats, including adware. If you have pop-up ads in your browser, the portable scanner may not know the virus, so it is highly recommended to update the anti-virus databases immediately after launching the application.

Dr. antivirus Web CureIt!
Dr. antivirus Web CureIt!

You can leave the default settings unchanged. Next, simply run a scan and select the action to take when a threat is detected. Alas, in practice everything is not so perfect. The problem is that the scanner detects some programs as potentially dangerous or unwanted software (in particular, we are talking about iObit software products), and then removes or “heals” them. But it is impossible to disable such actions in the antivirus itself.

AdwCleaner program

Now let's see how to remove adware from the browser using AdwCleaner. It is believed that this utility, so to speak, is "sharpened" just for all kinds of advertising applets.

Antivirus scanner AdwCleaner
Antivirus scanner AdwCleaner

In most cases, unless the virus has penetrated too deeply into the system, the application finds all known threats and removes them eitherautomatically or after your confirmation. But you cannot rely on the capabilities of this applet alone.

Malwarebytes Anti-malware Scanner

If you figure out how to remove virus-advertising in the browser using another related application from the same developer, then the field of activity is much wider. The only difference is that this package is shareware and sometimes it detects threats, but for some reason, even in the trial version, it does not want to completely remove it.

Malwarebytes Anti-malware
Malwarebytes Anti-malware

However, the information obtained using this program may be useful when performing manual removal of virus objects, which will be discussed separately.

HitmanPro app

Now let's see how to remove the browser ad-opening virus using another shareware product (Shareware) with a trial period of thirty days.

HitmanPro Scanner Settings
HitmanPro Scanner Settings

In general, this period may not be observed, and when starting the application, immediately mark the item stating that you will use the program only once. After that, the scan will start automatically. The result will not be long in coming, since many experts call this applet one of the most effective in the fight against advertising threats.

Warning: never use the highly advertised SpyHunter package. Firstly, although he finds viruses, but without the obligatory purchase of a license (which,By the way, it is very expensive) does absolutely nothing with them. Secondly, it will not be possible to get rid of the software package itself without the necessary skills and abilities manually (even if you try to remove it with the system starting in safe mode).

How to detect virus process activity?

Now let's assume that the anti-virus programs described above did not give the proper result, or you did not have them at hand at the right time. How to remove virus-advertising in the browser in such a situation? You can do this, but you have to sweat, as they say. First you need to identify the activity of the viral process.

To do this, you can use the most common "Task Manager", sort all active processes either by CPU load, or by RAM consumption, or by network or Internet connection usage parameters. If you have some unfamiliar (and non-system) service in front of you, right-click to navigate to the file location to locate the virus objects on your hard drive.

Locating a Suspicious Process File
Locating a Suspicious Process File

Also look at the username it is running as (usually not "SYSTEM", LOCAL SERVICE or NETWORK SERVICE, but the user account) in the details section. This will come in handy later.

Adware in the Programs and Features section
Adware in the Programs and Features section

Now call the Programs and Features section from the Control Panel, sort the applications by installation date and look at thoseapplets that have been installed in recent days. If you see an unfamiliar application in the list or know for sure that it was not installed (it may even have some kind of abstract name or contain meaningless character sets in the name), you will have to get rid of this program yourself.

Advertising pops up in the browser: how to remove the virus manually?

Try to remove the selected suspicious applet from the open list using the standard method of clicking the delete/change button at the top.

Search for virus keys in the registry
Search for virus keys in the registry

If the program is removed, go to the registry editor (regedit), call the search tool (Ctrl + F), enter the name of the removed application and press the enter key or the "Find next" button. Get rid of all found entries (keys and partitions) by moving from one to another by re-invoking the search by pressing the above buttons. When the system says there are no more matches, close the editor.

Now open File Explorer and navigate to the location of the files that was defined earlier. Delete all files, subdirectories and root directories (if possible, of course).

In addition, for the most complete cleaning of the browser from ads and viruses, take a look at the startup section, where you will need to uncheck suspicious objects and services that start with the operating system. In the OS of the seventh version and below, this section is located in the configuration (msconfig), and in the eighth and tenth modifications it is placed directly inTask Manager (taskmgr).

How to clean the browser from viruses and ads?

At the next step, start the browser used to work on the Internet and go to the section for viewing installed add-ons (extensions). If you find something suspicious, either disable the plugin or completely remove it. Now, in the settings of the start page, set the default one to empty, and also change the search engine (if it was changed by a virus), then close the browser.

Checking browser shortcuts

Finally, it should be borne in mind that an advertising virus in a Yandex browser or in any other browser, when it infects a browser, can independently generate special links that lead to an advertising or potentially dangerous resource directly when the main browser is launched. programs.

If a shortcut has been created for the browser on the Desktop, use the RMB menu to go to the properties item and look at the object type field.

Checking the browser shortcut
Checking the browser shortcut

After the name of the browser startup executable file with the EXE extension, there should be nothing else! For the Opera browser, the start file is called Launcher.exe. If there is something else in the field, delete all postscripts, save the changes, and only after that close all active programs and perform a complete restart of the computer system.

Note: if you have several different browsers installed, including the built-in IE or Edge applications in Windows, similar operations are performedfor each of them.

What should I do if the virus files are not removed?

If, for some reason, certain actions, most often associated with the inability to remove virus applet files from the disk, cannot be performed, try to first get rid of registry keys before uninstalling programs, and only then use normal deletion in the programs section and components, followed by cleaning files on the hard drive.

If this doesn't help, use the Unlocker utility. After installation, its main command will appear in the Explorer RMB menu. On the selected file via RMB, call the utility, and from the action menu, select object deletion. If that still fails, open the tree of processes that are currently using the file, kill them all, and try again.

Bootable antivirus Kaspersky Rescue Disk
Bootable antivirus Kaspersky Rescue Disk

If nothing helps at all, download the Kaspersky Recue Disk antivirus image from the official resource, create a bootable media based on it, start from it instead of booting the OS, check all the checkboxes, set the options to the deepest possible scan and wait completion of the processes of search and neutralization of threats. It is believed that this particular software product is the most powerful and most effective of all known, since it allows you to track even those viruses that are firmly established in RAM.

Using uninstallers

Finally, a few words should be said separately about how to remove virus ads in a browser usinguninstaller applications like iObit Uninstaller. First of all, find the dubious applet in the sorted list of applications, then click the delete button and do not forget to check the box for automatic search and removal of residual files.

Removing browser panels in iObit Uninstaller
Removing browser panels in iObit Uninstaller

After the process is complete, go to the extensions and browser panels section and follow the same steps with plugins. After that, check the browser shortcut again, make adjustments if necessary, and restart your computer. The advantage of such tools is that they ignore the restrictions on deleting files and folders, and also delete absolutely all entries in the registry on their own, which saves you from having to perform such complex actions manually. But you will have to clean the labels of all available browsers yourself.

Popular topic

Editor's choice

  • The Psijic Order from The Elder Scrolls - who are they?
    The Psijic Order from The Elder Scrolls - who are they?

    The Psijics are the name of a mysterious and ancient Order from the Elder Scrolls game universe. Its members practice magic and are notorious for being at odds with the Thalmor. Even more interesting information about the Psijic Order can be found in today's guide

  • Three easy ways to turn off notifications in Viber
    Three easy ways to turn off notifications in Viber

    "Viber" today is one of the most popular and widespread instant messengers. Sometimes a situation arises that the sound of constantly incoming messages bothers or distracts a person from important matters. How to turn off notifications in Viber? The article presents three of the simplest and easiest ways to do this, and they will help you set the silent mode on both Android and iOS

  • How to advertise on Instagram yourself?
    How to advertise on Instagram yourself?

    One of the most effective methods of website promotion and business development at the moment is advertising on social networks. Social networks, where people actively communicate, are more willing to pay attention to useful posts, join groups, like posts and make reposts, are an almost inexhaustible source of traffic. A properly built advertising campaign will allow you to get new customers, keep the attention of existing ones and again win over those who were dissatisfied with the service

  • Google - what is it?
    Google - what is it?

    The article talks about the multidisciplinary corporation Google. Its services and the company's work as a device manufacturer are considered

  • How to remove a user from important friends on VKontakte: all ways
    How to remove a user from important friends on VKontakte: all ways

    Important friends of "VKontakte" are determined automatically. When friends, family, and a loved one appear first on the list, this is convenient. But relationships can change for various reasons, and the need to constantly see a person’s page may disappear. In this article, we will tell you how to remove from important VKontakte friends those users whom you do not want to see at the top of the list