V9 Redirect Virus

V9 Redirect Virus Description

V9 Redirect Virus Image 1The V9 Redirect Virus is a browser hijacker designed to force computer users to visit the URL v9.com/us repeatedly. This is done in order to generate traffic to this particular website, allowing various forms of monetizing this traffic, such as using affiliate marketing advertising or pay-per-click schemes to profit from infected visitors to this website. The V9 Redirect Virus typically enters a computer because of existing vulnerabilities in your applications or operating system. These can be exploited by specifically crafted scripts contained in attack websites. The V9 Redirect Virus can also spread through malicious email attachments or instant messaging spam. Finally, versions of the V9 Redirect Virus are bundled as toolbars that are included in the installation of popular freeware software from a third party.

The Consequence of a V9 Redirect Virus Infection


Once the V9 Redirect Virus infects a computer, the V9 Redirect Virus will change the infected computer's web browser's home page and default search engine to v9.com. The V9 Redirect Virus will also interfere with your online searches by always directing your search results to that website. Security analysts have also linked the V9 Redirect Virus to the appearance of unwanted pop-up advertisements. These can intrude on your work and interfere with normal online activities. V9 Redirect Virus has the capacity to keep track of your online habits and browser history.

Removing the V9 Redirect Virus is seldom a straightforward process. Even though there may be an uninstaller for this program, your web browser settings probably will need to be changed in order to restore your preferences to their defaults (such as your web browser's homepage and default search engine). Since the V9 Redirect Virus will often infect a computer along with various other forms of malware, the presence of this threat in a computer frequently indicates that other malware is present as well. In the event of a V9 Redirect Virus infection, ESG malware analysts advise PC users to analyze their entire machine with the aid of a fully updated and trustworthy anti-malware solution. To prevent further infections, ESG malware analysts advise using safe browsing practices and never downloading freeware software from sources other than the manufacturer.

Infected with V9 Redirect Virus? Scan Your PC for Free

Download SpyHunter’s Spyware Scanner
to Detect V9 Redirect Virus

Security Doesn't Let You Download SpyHunter or Access the Internet?


Solutions: Your computer may have malware hiding in memory that prevents any program, including SpyHunter, from executing on your computer. Follow to download SpyHunter and gain access to the Internet:
  • Use an alternative browser. Malware may disable your browser. If you're using IE, for example, and having problems downloading SpyHunter, you should open Firefox, Chrome or Safari browser instead.
  • Use a removable media. Download SpyHunter on another clean computer, burn it to a USB flash drive, DVD/CD, or any preferred removable media, then install it on your infected computer and run SpyHunter's malware scanner.
  • Start Windows in Safe Mode. If you can not access your Window's desktop, reboot your computer in 'Safe Mode with Networking' and install SpyHunter in Safe Mode.
  • IE Users: Disable proxy server for Internet Explorer to browse the web with Internet Explorer or update your anti-spyware program. Malware modifies your Windows settings to use a proxy server to prevent you from browsing the web with IE.

If you still can't install SpyHunter? View other possible causes of installation issues.

Technical Information

Infection Statistics


Our MalwareTracker shows malware activity across the world. Explore real-time data of V9 Redirect Virus outbreaks and other threats from global to local level.

File System Details

V9 Redirect Virus creates the following file(s):
# File Name Size MD5 Detection Count
1 %WINDIR%\system32\Newtabs_onmylike.dll 68,488 ec68d5ecd1ea15c81fc88dd6343c9080 689
2 %PROGRAMFILES%\iSafe\iSafeSvc.exe 238,408 0ff2898075716f58332dfd570160115a 561
3 %PROGRAMFILES%\iSafe\iSafeSvc2.exe 69,960 c7590b83285f76abc6636de7abbcf2d2 548
4 %PROGRAMFILES%\iSafe\iSafeTray.exe 403,272 1a2d335d2d6e8c088b79f892d6188cfe 503
5 %AppData%\v9 94
6 %PROGRAMFILES%\Software Plate\gdpclient.exe 235,168 c92ed55a9e5f69b82d87b854da029697 91
7 %PROGRAMFILES%\Software Plate\update.exe 234,656 d8e7fbec59da34ee1c7015bbb99c4035 85
8 %ALLUSERSPROFILE%\MailUpdate\mailUpdate.exe 721,048 bfa913e38b0d4ab800623bca16ac51e4 70
9 %TEMP%\llynew_v9.exe 689,808 2f20dca2ea38d22377a8feafa087a550 52
10 v9hpnt_v2.exe 489,328 acf210196d32fa22e1e7175b667d2c51 40
11 %WINDIR%\system32\Newtabs_22find.dll 66,184 86f6ea136da23a07ac402df2a946f124 2,242
12 %PROGRAMFILES%\newtabs\newtabs.exe 261,032 7331b554fc1ca17dafaf0837ab91aac6 17
13 %PROGRAMFILES(x86)%\Software Plate\RegAssociate.exe 55,424 5b9c994332dcd47cf391748604d359df 3
14 %WINDIR%\system32\Newtabs_v9.dll 60,928 380c6afbfd84a20316c9703933e9c766 1,898
15 %PROGRAMFILES(x86)%\Software Plate\svcgdp.exe 224,416 4fb97fa00f60292e6782180f09792753 1,881

More files

Registry Details

V9 Redirect Virus creates the following registry entry or registry entries:
HKEY..\..\..\..{RegistryKeys}
SOFTWARE\V9Software
SOFTWARE\Wow6432Node\V9Software
SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gjokjdicpfckeiihaniimbbmhadclefc
SOFTWARE\Wow6432Node\V9
SOFTWARE\Microsoft\Tracing\V9 Redirect_RASMANCS
SOFTWARE\Microsoft\Tracing\V9 Redirect_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\V9_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\V9_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\V9Software
SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gbdabnfmdemcjjadpkpjibhhacggangd
Software\Microsoft\Internet Explorer\DOMStorage\v9.com
Software\Microsoft\Internet Explorer\Approved Extensions, value: {F386E548-C533-472E-8C61-C026FB14FEA9}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F386E548-C533-472E-8C61-C026FB14FEA9}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F386E548-C533-472E-8C61-C026FB14FEA9}
SOFTWARE\Wow6432Node\Google\Chrome\Extensions\bpeeepmahhfjiediknjejcmcfmjcjdck
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{F386E548-C533-472E-8C61-C026FB14FEA9}
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{F386E548-C533-472E-8C61-C026FB14FEA9}
Software\Microsoft\Internet Explorer\DOMStorage\www.v9.com
HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}
V9Software
v9 uninstaller
v9 uninstall
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}
CheckRunv9_uninstaller
The following CLSID's were found:
HKEY..\..\{CLSID Path}
{F386E548-C533-472E-8C61-C026FB14FEA9}

Site Disclaimer

Leave a Reply

IMPORTANT! To be able to proceed, you need to solve the following simple math.
Please leave these two fields as-is:
What is 10 + 15 ?