By GoldSparrow in Browser Hijackers

Threat Scorecard

Ranking: 2,060
Threat Level: 50 % (Medium)
Infected Computers: 18,177
First Seen: September 18, 2013
Last Seen: February 25, 2024
OS(es) Affected: Windows Image is a low quality search engine. Its main page mimics the appearance of Google's iconic layout, with an image of a locomotive in place of Google's logo. Despite the fact that looks like a harmless search engine, ESG security analysts strongly advise computer users against this risky online content. Many computer users have complained that they are being redirected to constantly against their will or that their homepage and other default websites have been changed to If this is the case, it indicates that your computer has become infected with a PUP (Potentially Unwanted Program) that should be removed immediately in order to restore your computer to normal and stop these unwanted symptoms.

How Works

Low quality search engines that are coupled with browser hijackers are amid the most used types of online scams today. Basically, websites like are designed to deliver advertisements and search results that are actually poorly-disguised advertisements promoting potentially threatening online content. Inexperienced computer users may not find anything wrong with the website, believing that it is normal for this website to appear as their homepage or default search engine. Inexperienced computer users are also the most likely to install the types of PUPs commonly associated with, which often take the path for Web browser toolbars or extensions.

What You Should Expect When Infected by

There are several reasons why ESG security researchers strongly advise computer users to take action if their computer is compromised by a PUP associated with The following symptoms are associated with these types of infections:

  • PUPs associated with may change your homepage and default search engine to without your permission.
  • Browser redirects to the website, often occur after carrying out a search on a search engine or clicking on an unrelated link.
  • redirects are often coupled with pop-up windows containing advertisements that may expose your computer to other PUPs or threats.

SpyHunter Detects & Remove

File System Details may create the following file(s):
# File Name MD5 Detections
1. npffividiplg.dll 63b0af5d8fed833d39981c54c988c749 77
2. ividi.crx 6748de5fc375ca8b8bae846cff85d9ac 62
3. iVIDIPlugin.exe 73a54e58b3578a9d28ba7d2a156421a7 30
4. ividi.exe 63efb51ad6c737baf36d605b8a67a37c 1

Registry Details may create the following registry entry or registry entries:
Software\iVIDI Plugin
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F964AFD9-C4F0-4367-B5B8-E14DDBD524A8}
Software\Unitech LLC\ividi
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F964AFD9-C4F0-4367-B5B8-E14DDBD524A8}
SOFTWARE\Wow6432Node\Unitech LLC\ividi

Directories may create the following directory or directories:

%AppData%\Microsoft\Windows\Start Menu\Programs\iVIDI
%ProgramFiles%\ plugin
%ProgramFiles(x86)%\ plugin

URLs may call the following URLs:



Most Viewed