(formerly How to remove ( is a russian browser-hijacker. It is positioned as a search engine but in fact it redirects all search queries to As a rule this intrusive website appears in all installed browsers: Chrome, Firefox, Opera, Internet Explorer, etc. It has a lot of domains-redirectors. They all redirect to:


Below you will find the step by step guide and a video guide about how to get rid of in the browser.

Attention! The guide is divided into two parts: automatic removal and manual removal. Unfortunately the automatic method is not 100% successful on practice because the developers of the hijacker are constantly modifying their malware. So, if you can not remove the pop-up using the automatic method, please try to remove it manually.

How to remove automatically

1. Scan system with HijackThis

Download the TrendMicro HihackThis tool.

Run it and press Scan.

Inspect the list thoroughly. Select the items that contain unknown URLs or domain names and press Fix checked:


2. Scan with AdwCleaner

Download and launch the AdwCleaner utility.

Press Scan and wait.

Then press Clean:


3. Scan with HitmanPro

Download HitmanPro.

Scan the system and remove all found malicious programs:


How to remove manually

1. Find out the site that redirects you to

The best way to do it is to turn off the internet. So you can:

  • unplug the ethernet cable from the network adapter;


  • disconnect from the wireless network;


  • disable the network connection;


After you turned off the Internet restart your computer:


On system startup the browser will launch and you will be able to see which site tries to load initially (before


Save the name of the site to notepad or elsewhere! Now let us start removing from Windows.

2. Delete harmful task

There is a task that ads the to the registry. Launch the Task scheduler and look through all tasks. Delete all the task executing unknown files:


This is also can be done with CCleaner:


3. Inspect the startup

In Windows XP and 7 you can run msconfig:


Go to Startup tab and uncheck the items that contain harmful elements:


In Windows 8 and 10 we recommend to use CCleaner. Go to Tools – Startup – Windows. If you see a suspicious string containing the malware URL select it and press Delete:


4. Clear some folders in user profile

  • Open the folder:

Delete folders with strange names like:

  • Empty the folder:


5. Remove from the registry

Press Win+R
Type regedit
Press Enter:


  • Search by the phrases

Click on Computer.
Click on Edit in the menu.
Select Find.
Type utm_source or utm_content
Press Find Next:

and delete all found items:


  • Search for the name of site-redirector (that you have found out in step 1)


and delete all detected items.

  • Search for
cmd /c start


and delete all found items as well.

6. Remove ( from Mozilla Firefox

  • Go to:
  • Open the file

or something like that with .js extension

  • Delete the string containing something like:
user_pref(«browser.startup.homepage», «»);
user_pref(«», 1);
  • Save the js-file.

Video Guide: how to remove and

List of domains redirecting to

1 thought on “ (formerly How to remove”

  1. I did all of this but i had some problems.

    On regedit, I didn’t found any of those malicious files it was just complete blank, and i’m still getting
    the .ru popup ads, how do i fix this, I just got a new pc and i really want to remove this .ru file, any tips on how to removing it?


Leave a Comment