Remove Google Chrome, Explorer, Mozilla Firefox

These are Netz-Trends‘ experiences when downloading two well-known duplicate file finders, one of them starting with ‘tot…’, the other one with ‘all…’. In this article, we explain how to remove currently causing a lot of trouble is currently annoying a lot of users but whether you can talk about a virus or malware or a potentially unwanted programme is currently not clear. However, it’s fact that gets installed automatically as a browser plugin when downloading free software into the browsers Google Chrome, Mozilla Firefox or Internet Explorer (BHO).

First things first: is considered to be a browser hijacker which basically ‘kidnaps’ browsers everybody uses to access the internet. It is currently not clear whether the alleged ‘search engine’ attaches itself automatically to free or maybe even fee-based downloadable software or whether the affected programmes actively promote’s download. Some bloggers describe the following: Once has been installed it will automatically open every time you open the browser. itself is not malicious. In fact, there are countless other programmes that use a similar method and also change settings on the user’s computer or in programmes. However, what a lot of users reporting to Netz-Trends find malicious regarding is that the programme sneaks into the download of other software and adds Windows shortcuts to the desktop and to the Start Menu – and, as previously mentioned, changes settings in internet browsers (please use our comment feature to leave your comment and recommend us in Facebook or google+).

According to our experiences, this programme seems to exploit a security loophole in Google Chrome, for example. Even if we changed the home page of our browser in the settings and deleted, the website would be back as our home page with the next start of Google Chrome.

Contrary to other search engines, the alleged search engine cannot be deleted normally in Google Chrome – the X is missing.

We had similar experiences with Internet Explorer. It was only in Mozilla Firefox that we managed to delete the annoying quite easily through changing the browser’s home page. If you enter a search term into the alleged search engine you get automatically redirected to

However, we find it hard to understand that Yahoo would voluntarily cooperate with software like this. It is much more likely that earns some money through users clicking on one of the displayed advertisements. In these advertisements, mixes noticeably respectable and well-known brands (Google, YouTube, Facebook, ebay) and little known or unknown brands – probably with the aim that the user will click on little known or unknown brands (see picture at the top of the article).

The following brands were shown during the Netz-Trends tests (see picture): Facebook, Google, YouTube, Prime Slots, ebay, Casino Club, FlirtFair, eDates, Anno Online, Big Farm, Empire, War Thunder, Merkur Spiele!, S.K.I.L.L., Battlefield Heroes.
We assume that finances itself through advertisement and sponsored links in its search results but also through the displayed website ads.

It is also safe to assume that the search terms entered by the users (or customers) from each search request are collected by’s partners are most likely cooperating with the website in order to artificially increase a website’s ranking in the search results – you could name this Black Hat SEO.

Technically speaking, is not a virus but a PUP (PARC Universal Packet Protocol) or a potentially unwanted programme. However, it does show quite a few malicious features, for example its rootkit abilities. Through these abilities, can dig deeply into the operating system – amongst others through browser hijacking.

The programme can only be deleted if the user is experienced. Netz-Trends tested if uninstalling the browser Google Chrome would do the job. However, even after a complete deinstallation and a subsequent re-installation of Google Chrome, was back as a search engine that could not be uninstalled in Google Chrome. At the end of the day, though, this is a security loophole, so Google Chrome’s mistake, which the programmers of are exploiting.

It seems that changes the loading time of Internet Explorer, for example, or activates a blocking feature in Firefox which will block rivaling software. This is made possible through a feature that inhibits certain changes in Mozilla’s settings and therefore bypasses the browser’s content security policy.

Mozilla Icon.

Up until now, we have had the experience that can also not be uninstalled through ‘Uninstall a program’ since there is no programme with the name ‘’ The browser hijacker can also not be deleted or uninstalled by uninstalling or deleting the programme through which the user caught What are left are laborious manual counter measures.

As a general rule: when installing free or fee-based software, you should always make sure that additional programmes are not installed. Software installation packages often have an optional installation of additional programmes – like which is actually a browser hijacker.

Additional software can be displayed quite obviously as an additional installation option. Through piggy-back installation, it can also be installed secretly as the desired programme is being installed. The tests by Netz-Trends seem to confirm that the latter is what happened in the case of during the installation of programmes that can find and eliminate duplicate files on the computer, was installed piggy-back.

As a general rule, you should always use ‘custom installation’ – even if (as software providers like to point out) a custom installation is not recommended. However, if you are custom installing a programme you have a higher chance of being able to actively deselect or delete unwanted additional programmes.

As a general rule: anything on the internet, that neither you nor your friends don’t know, should be accessed with caution or ignored from the start and not be installed. It goes without saying that you should not install software that you don’t trust. In case of doubt, rely on your gut instincts.

Please note: Even antivirus software like Antivir did not protect against during the test. We have observed that the Antivir software which costs about 20 Euros did not prevent the installation of even though Antivir checked the duplicate file software before the installation.

Removal Guide for

There are several possibilities how to delete the browser hijacker from your Internet Explorer, Mozilla Firefox or Google Chrome. Make sure you follow the steps in the correct order.

Step 1: Install one of the following programmes for the removal of unwanted software: either adwcleaner_3.016, junkware Removal Tool (download via Internet Explorer or Mozilla Firefox), Malwarebytes Anti-Malware or HitmanPro.

Recommended Anti Malware Programmes

According to our experience up to now, the programme can in some cases only be removed using various anti-junkware programmes. You might have to make a few attempts. It is very important that you share your experiences with our readers and that you leave comments at the end of this test. After you ran any of these programmes, it is very important that the computer is shut down and rebooted completely. Only then you can judge whether has been successfully removed.


At first, please try to remove using adwcleaner_3.016 (tool will automatically download, click on the button at the bottom left or right). As with all anti-virus or malware programmes, please close all open programmes and internet browsers before you start the programme. Then double-click on the icon of AdwCleaner. The process will then start.

Junkware Removal Tool

As an alternative, you can also try one of the programmes listed above or maybe even the ‘Junkware Removal Tool’ – however, our users don’t seem to have been successful using this tool. Attention: the programme Junkware Removal Tool automatically starts downloading. You only need to confirm, usually bottom left or right, that you would like to install it. As soon as you have downloaded Junkware Removal Tool, double-click on the JRT.exe icon. Confirm the Windows prompt that you would like to execute Junkware Removal Tool.

Junkware Removel Tool: Please do not ignore what’s written in white but read very carefully what to do.

Junkware Removal Tool will now start. During the prompt you need to press any key to start the scan for This can take up to ten minutes so please be patient. The duration of the scan depends on how fast your system is.

Once Junkware Removal Tool has finished the scan it will create a protocol with all the malicious files and registry keys that have been removed from your computer. If is still present on your computer please try one of the other programmes – for example AdwCleaner, Malwarebytes Anti-Malware or HitmanPro.

Remove from the browser icon

If the programme is nesting in the browser icon of Mozilla Firefox, Google Chrome or Internet Explorer on the desktop for example, right-click the relevant browser icon. A menu will open. Click on the menu item “Properties” and a pop up window will open.

You can also try to remove by right-clicking on the affected browser icon on your desktop.
It is possible that the locations in the line "Target" or "Start in" do not contain the following links: "C:Program Files (x86)Mozilla Firefoxfirefox.exe" (in "Target") or “C:Program Files (x86)Mozilla Firefox” (in “Start in”). Instead, these lines will display a link such as the following:

If this is the case, simply delete the link and paste the links described above into the respective lines. Click “OK” at the bottom of the pop up window. This will solve the problem of having hijack the icon. (Please note: this will only work if you have installed Firefox on drive C.)

Other recommendations on how to deal with is registered in the US at, LLC (registrar). If you would like to let off some steam you can send the complaint at the end of the text to the following two complaints centres: and The same text should be sent to the official US American registry office:

Complaint regarding


"The website seems to be a virus or an unwanted program. I was not aware of its download. Now that website opens whenever I start Google Chrome or Internet Explorer, even Mozilla Firefox. I was able to delete it in Mozilla Firefox, but was unable to delete it in Google Chrome or Internet Explorer. seems to exploit a security loophole in those browsers and is now permanently set to be the home page of those browsers. I ask you kindly to take actions against As far as I know is installed piggy-back as a plugin through some free software tools."