What is Yapages.ru?

Yapages.ru might be not only an extremely irritating application but also a potentially dangerous one. Our researchers consider it to be a browser hijacker because as soon as it settles in, the threat may modify default browser’s settings so it could load Yapages.ru or redirect the user to other unreliable web pages automatically. To make matters worse, it appears to be that the search engine might show you suspicious advertisements from the third party or inject these ads in its displayed results. We have to warn you that if you happen to click such ads, you might be redirected to web pages, which could be malicious. Provided, you do not want to endanger the system, and you wish to restore the browser’s settings back to the way they were before this hijacker showed up, we encourage you to have a look at the instructions placed at the end of this page and remove the application.test

Where does Yapages.ru come from?

Our researchers at Anti-spyware-101.com believe the search engine could travel with bundled installation files of other unreliable programs. Usually, users get such installers from file-sharing web pages that distribute freeware. Therefore, to avoid threats like Yapages.ru in the future, we would advise you to keep away from such websites as much as possible. You could replace them with legitimate web pages of reputable software publishers. Additionally, we would suggest using a reliable antimalware software. With a legitimate security tool, users could perform regular checkups on their systems and also scan suspicious installers or other data downloaded from the Internet. If you encounter various threats from time to time, it is worth to consider such an option.

How does Yapages.ru work?

To force your browser to load Yapages.ru each time you open it, the application should modify its Target Line. You can check this data if you right-click the browser’s shortcut, choose properties, and select the Shortcut tab. The Target Line should contain a link to the browser’s launcher, e.g. “C:\Program Files\Internet Explorer\iexplore.exe.” After the hijacker modifies it, the original link should be replaced with a path similar to this one: %Homedrive%: \Users\{user name}\AppData\Roaming\Browsers\exe.xoferif.bat. As you can see, the path points to a particular file placed in a directory called Browsers. This folder and the data inside it should belong to the browser hijacker. While testing these files, our specialists noticed that some of them, like the one we just mentioned (exe.xoferif.bat), contain obfuscated commands, which tell the browser to load Yapages.ru.

If you want to browse safely, it might be best to replace this search engine with a more reliable one, e.g., google.com, yahoo.com, and so on. We advise against its usage because the application might inject the results it displays with unreliable advertising content from its third-party partners. Since we do not know from where these ads may originate from, there is a possibility they could come from web pages distributing other similar threats like adware, potentially unwanted programs, or even more dangerous applications, such a Trojans, viruses, etc.

How to remove Yapages.ru?

Firstly, users should get rid of the browser hijacker’s created folder together with all data that might be in it. Then you could manually restore all affected browser icons by replacing their Target Line, although it might be faster to erase the hijacked icons and create new ones. If you require any help with these tasks, we encourage you to check the instructions placed below as they will explain the removal process more accurately. Still, deleting Yapages.ru manually might be not an easy task, so in case it appears to be too difficult, we advise using a reliable antimalware tool instead. With it you could clean the whole system in just a couple of minutes; not to mention, it could help you guard the system against future threats too.

Erase Yapages.ru

  1. Press Win+E.
  2. Copy and paste this directory %APPDATA% into the Explorer.
  3. Press Enter and locate a folder named as Browsers.
  4. Right-click it and select Delete.
  5. Search the listed paths and find the hijacked browser’s shortcuts:
    %ALLUSERSPROFILE%\Start Menu\Programs
    %APPDATA%\Microsoft\Windows\Start Menu\Programs
    %USERPROFILE%\Microsoft\Windows\Start Menu\Programs
    %ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs
    %ALLUSERSPROFILE%\Application Data\Microsoft\Windows\Start Menu\Programs
  6. Right-click them and press Delete.
  7. Choose directories where you want to place new browser shortcuts.
  8. Click the right mouse button and press New.
  9. Select Shortcut and click browse.
  10. Find the directory where the browser’s launcher is placed.
  11. Choose Next then select Finish.
  12. Empty your Recycle Bin.
100% FREE spyware scan and
tested removal of Yapages.ru*

Leave a Comment

Enter the numbers in the box to the right *