Description of redirect and consequences of its residing on your PC’s redirect virus is selective in attracting users to its facilities. For IPs resident to certain countries of the Third World the website is not available, or they are presented with bizarre image like squinting cats on the background of the moon accompanied with the caption running “I have been expecting you”.
IPs located in all other countries make a target audience for the virus, which in that case loads full-featured version of the website. The infection tends to load its sponsored url instead of Google thus interfering with user's searches.

Technical Details and screenshots:

  • Full name: Gimmeanswers redirection malware,, Gimme answers,
  • Type: Browser hijacker, Redirect virus, Adware
  • Origin: Russian Federation, Ukraine

Signs of being infected with Gimmeanswers redirection malware pretends to do a job of Google. Visitors of this website are brought to this url as they are trying to get answers from common search engines. The reason why they see the unexpected substitution is the virus.
In the other words, is clearly and unambiguously detectable by redirects of Google and other websites leading to the same-name page.

Gimmeanswers redirection malware automatical removal:

The redirect virus deals with various aspects of computer system. In the long run, it corrupts it badly so that lingering when infected with the virus is not a good tactic to follow.

Manual Removal of Gimmeanswers redirection malware:

Remove virus manually to browse the web without annoying redirects. Please note the guide is updated as soon as new data is available on the virus modifications. To ensure complete computer cleanup, please refer to the section above.

Remove Gimmeanswers redirection malware files and dll’s:

%CommonAppData%\<random 33 characters>
%CommonAppData%\<random 33 characters>\<random 33 characters>
%CommonAppData%\<random 33 characters>\<random 33 characters>.exe

Unregister Gimmeanswers redirection malware registry values:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce “<random>”
HKEY_CURRENT_USER\Software\Classes\<random 4 characters>
HKEY_CLASSES_ROOT\<random 4 characters>
HKEY_USERS\S-1-5-21-861567501-152049171-1708537768-1003_Classes\%s “(Default)” = “<random 4 characters>”
HKEY_USERS\S-1-5-21-861567501-152049171-1708537768-1003_Classes\<random 4 characters>\shell\open\command “(Default)” = “%CommonAppData%\<random 33 characters>\<random 33 characters>.exe” -s “%1″ %*
HKEY_CURRENT_USER\Software\Classes\.exe “(Default)” = “<random 4 characters>”
HKEY_CURRENT_USER\Software\Classes\<random 4 characters>\shell\open\command “(Default)” = “%CommonAppData%\<random 33 characters>\<random 33 characters>.exe” -s “%1″ %*