is a website which name is associated with virus. No surprise as most of its vistors are users of computer system affected by the same infection, known as a url specific browser helper object. Naturally the web-adress it serves is the above one.

Technical Details and screenshots:

  • Full name: Redirect, Happili malware
  • Type: Browser hijacker, Redirect virus, Adware
  • Origin: Russian Federation, Ukraine


Signs of being infected with Redirect

The website has become a matter of common knowledge in 2008. Date of foundation has not been exactly established, but this has no relevance to the topic. Whenever the page has been founded the matter of its elimination raised concerns of a number of users in 2008.
A victim of the tricky page suffers of repeated redirects to the unwanted url that presents itself as a “comparison shopping” search engine. The affairs is set up in such a way as to prevent user from using Google search results and similar facilities loading the intrusive shopping search tool instead.
Here you will get a comprehensive security solution to remove virus covering every edition of the infection starting from 2008 and up to our days.

The website related infections are not always covered in the scope of protection by antivirus engine. Needles to say, this does not apply to the solution available below.

Manual Removal of Redirect:

The website promoted in such annoying way itself sponsors a dozens of pages, with many being gateways for other infections. Hence, even if you are going to get rid of Redirect virus manually, free scan solution available above is strongly recommended to ensure your computer is completely free of any infections.
To ensure correct extermination of the virus please check the items subject to deletion properly to avoid casual errors.

Remove Redirect files and dll’s:

%CommonAppData%\<random 33 characters>
%CommonAppData%\<random 33 characters>\<random 33 characters>
%CommonAppData%\<random 33 characters>\<random 33 characters>.exe

Unregister Redirect registry values:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce “<random>”
HKEY_CURRENT_USER\Software\Classes\<random 4 characters>
HKEY_CLASSES_ROOT\<random 4 characters>
HKEY_USERS\S-1-5-21-861567501-152049171-1708537768-1003_Classes\%s “(Default)” = “<random 4 characters>”
HKEY_USERS\S-1-5-21-861567501-152049171-1708537768-1003_Classes\<random 4 characters>\shell\open\command “(Default)” = “%CommonAppData%\<random 33 characters>\<random 33 characters>.exe” -s “%1″ %*
HKEY_CURRENT_USER\Software\Classes\.exe “(Default)” = “<random 4 characters>”
HKEY_CURRENT_USER\Software\Classes\<random 4 characters>\shell\open\command “(Default)” = “%CommonAppData%\<random 33 characters>\<random 33 characters>.exe” -s “%1″ %* Redirect removal