The is a malicious application that is classified as a redirect virus which sneaks in the computers without getting the consent of the user. The present itself as a legitimate browser, but in reality this is a completely fake application designed to divert the search queries towards porn websites, and other malicious web pages. Once installed, it immediately modifies the basic browser settings such as home page, and default search provider to without getting your consent. The main goal of the cyber crooks behind developing and distributing this lethal computer infection is to access the confidential financial details of the user, and after collecting such precious information transfer it to the hackers. Besides that, the hackers also use this virus as a tool to generate revenue by diverting traffic to the affiliate sites and promoting affiliate products.

The Manual Removal of

Once it is confirmed that the attacked your system. You need to clean your system through an effective removal method. This malicious application can be removed by using any automatic tool which is easily available. Besides that, the manual removal method is also available which is detailed below:-

Change the Mode of Operation from Normal to Safe Mode

First of all you must boot the computer in the safe mode as you cannot delete these infections by remaining in the normal mode. In this regard, click on the start menu, and select the restart to terminate the normal mode. Press the F8 key to access the boot options while the system is restarted, and select the Safe Mode option before hitting the Enter key.

End the Malicious Processes

The next step of the manual removal process is killing the malicious processes associated with this virus. To access the windows task manager you have to hold the Ctrl+Alt+Delete keys together. Once the task manager is visible on the screen, click on the Processes tab to see the list of running processes, and remove the following associated processes of the


Remove the Associated Data

You have to open the file explorer, and proceed to the system files folder to locate and remove the following suspicious files associated with the with the help of the Delete key:-

  • %Desktopdir%\PasswordAssistant popups.lnk
  • %Programs%\PasswordAssistant popups\PasswordAssistant popups.lnk

Reverse the Modification in the Windows Registry

This complicated process will be completed when you remove the modifications created by this nasty computer worm in the windows registry. Open the start menu, select Run option, and type regedit in the box to access the registry editor. Get rid of the following suspicious entries associated with the before closing the registry editor:-

  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\PasswordAssistant popups\DisplayIcon %AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe,0
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\PasswordAssistant popups
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\PasswordAssistant popups\UninstallString “%AppData%[RANDOM CHARACTERS][RANDOM CHARACTERS].exe” -u
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\[RANDOM CHARACTERS] %AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\PasswordAssistant popups\ShortcutPath “%AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe” -u
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\PasswordAssistant popups\DisplayName PasswordAssistant popups

Restart the PC in the normal mode to check how effectively you have removed the virus manually, and run a system scan through your current antivirus program.

How to Remove

Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>