Browser Redirect

How to Remove Yoursites123 Virus from Chrome/Firefox/IE (Feb. 2019 Update)

Parasite may reinstall itself multiple times if you don't delete its core files. We recommend downloading SpyHunter to scan for malicious programs installed with it. This may save you hours and cut down your time to about 15 minutes. 

Download SpyHunter Anti-Malware

More information on SpyHunter, steps to uninstallEULAThreat Assessment Criteria, and Privacy Policy.

This page aims to show you how to remove Yoursites123 Virus. Questions like jak usunąć yoursites123 and eliminar yoursites123 have been steadily piling up in our Inbox alongside how to remove Yoursites123 and remove Yoursites123, showing a new global virus threat, affecting different countries.These Yoursites123 virus removal instructions work for Firefox and Chrome as well as every version of Windows.

Yoursites123 has been tagged as a potential computer virus of the Browser Hijacker variety by a number of online security experts.

Remove Yoursites123

Most people are finding Browser Hijacker applications to be more in the annoying category than seen as a potential danger. Yet we find that might be a bit of a misconception. In order to help you we have complied a list of the negative impacts this virus might have on your device as well as a detailed explanation what tricks to expect from Yoursites123 Virus and how to deal with them. That is of course in addition to a detailed instructions jak usunąć yoursites123 and eliminar yoursites123 from your computer. So, let’s start.

Consequences of having Yoursites123 Virus and how to deal with its deceptions

Negative impact it may have on your device:

  • Greatly reduced performance, especially on older systems.
  • Significantly increased execution times for seemingly simple operations like opening your browser, opening a new page or a new tab.
  • Momentary freezes and “lagging”, especially on older systems with slower internet connection.
  • In some extreme cases users might be subjected to their OS crushing or experiencing a serious system error, i.e. the dreaded BSOD.

Here we think would be a good idea to list some of the main tricks associated with this malware and what to avoid when facing them:

  • It is very likely that at some point you will face a pop-up warning you about a virus found on your PC. Consequently a possible “fix” would be suggested in the form of some software. Our advice is to completely disregard any such message, more than likely you will be installing malware instead of an anti-virus software.
  • Other pop-up message in a similar vein might suggest that you download the missing plugins or audio and video codecs required to play some clip. Again you should abstain from downloading any such content from unconfirmed and frankly shady sources.
  • Another deception initiated by the malicious software would be a message informing you about required program updates that you are missing. Most often popular software like Windows Media Player, Adobe products and Java applications are mentioned. We will repeat our advice here – do not download any updates unless that are from an official source.

After all this it is not hard to imagine why people are asking the jak usunąć yoursites123 and eliminar yoursites123 questions.

How did you end up with Yoursites123 on your device?

One of the first questions that pop-up in one’s mind after discovering that there is a computer virus on his device is to look for a way to remove it. Probably the next one is to wonder how did this thing happen at all? There are several ways in which you might have fallen victim to this infection. Probably the oldest trick in the books but still widely used even nowadays is the e-mail attachments way for computer contamination. Our advice – be very careful before opening e-mails from unknown senders even if they seem like reputable sources and be especially careful before opening or downloading any attachments from unfamiliar senders. Most reputable e-mails providers offer some sort of file scanning so it’s advisable you at least do this before opening attachments. We would recommend you additionally scan any file downloaded from an e-mail with an additional anti-malware scanner or anti-virus program.

Another popular way of virus spreading is through contaminated files downloaded from file-sharing websites and torrent sites. There is very little actual control in what is being uploaded and distributed on such sites, so if you end up downloading something be sure to scan it first before opening, especially executable files.

By comparison though the most likely culprit for adware and browser hijackers’ distribution is the software bundles installation method. In short these are normal installers for a most often completely legitimate program, often some kind of freeware, with an easy to miss small addition. Together with the software you actually wanted to install comes additional program that is sometimes harmless but often times might be malicious as in this case. The only way for you to prevent this from happening in the future is to carefully and thoroughly examining what exactly is going to be installed on your computer. The way to achieve that is by always selecting Advanced installation options and deselecting anything that might seem not part of the software that you intended to install in the first place.

Who creates applications like Yoursites123?

It’s a completely logical to assume that at one point or another you have wondered why apps like this are being created. It may seem without much practical value but here’s the thing – software applications like Yoursites123 are being created with one purpose in mind only – for profit.

It is not uncommon for Adware and Browser Hijackers to be actually affiliated in some way with the websites you see being advertised or being redirected to. One of the possible explanations is that any time a user clicks on an Ad they (the creators of these types of malware) get a certain amount of money in exchange, in a way it is a kind of a royalty system. We can only assume that if a user actually spends any money the reward for the creators of the questionable software will be bigger as well.

As a result it is perfectly safe to assume a couple of things:

  1. The ads will be displayed and showcased on the user’s desktop regardless of his or hers preference and permission. The only way to stop them altogether is to completely extirpate the underlying cause.
  2. It is very unlikely that a reputable and above board company or entity will ever use this form of online Advertising. Keep that in mind if you ever find yourself wondering whether you should give away any of your personal information.

How come then this is a way for a company to advertise a web site or product in the first place? It is probably not necessary to look for a reason any further than the overall cost for such an undertaking. By all accounts it turns out this is a way cheaper way of online advertising than other more conventional and reputable types like Google Ads or Facebook business. Let’s say, for argument’s sake that the proprietary owner of such a website decides it is imperative to generate some quick traffic on the cheap for his struggling business. It is not that hard to imagine why he would choose to contact some creators of malware so that the creation of software directing traffic to the desired website can be commissioned. It might be head scratching at first to try and wrap your head around the idea that this could be in any way easier or cheaper way to advertise a product. A fair point, but keep in mind that for all intents and purposes it seems that this type of malicious software is very easy to be created as evidenced by the swarms of new applications that pop-up on a daily basis. Thus the cost is low. Now it is high time we begin with our how to remove instructions!


Name Yoursites123
Type Browser Hijacker
Danger Level High. A very dangerous and annoying software that is not easy to remove.
Symptoms  Various Advertisements, website redirects, hyperlinks appearing while you are browsing.
Distribution Method E-mail attachments, infected files downloaded from torrent or file sharing websites, software bundles.
Detection Tool Malware and Adware are notoriously difficult to track down, since they actively try to deceive you. Use this professional parasite scanner to make sure you find all files related to the infection.Sponsored


How to Remove Yoursites123

If you are a Windows user, continue with the guide below.

If you are a Mac user, please use our How to remove Ads on Mac guide.

If you are an Android user, please use our Android Malware Removal guide.


Some of the steps will likely require you to exit the page. Bookmark it for later reference.

Reboot in Safe Mode (use this guide if you don’t know how to do it).



We get asked this a lot, so we are putting it here: Removing parasite manually may take hours and damage your system in the process. We recommend downloading SpyHunter to see if it can detect parasite files for you.

Press CTRL + SHIFT + ESC at the same time and go to the Processes Tab (the “Details” Tab on Win 8 and 10). Try to determine which processes are dangerous. 


Right click on each of them and select Open File Location. Then scan the files with our free online virus scanner:

Drag and Drop Files Here to Scan
Maximum file size: 128MB.

This scanner is free and will always remain free for our website's users. You can find its full-page version at:

Scan Results

Virus Scanner Result

After you open their folder, end the processes that are infected, then delete their folders. 

Note: If you are sure something is part of the infection – delete it, even if the scanner doesn’t flag it. No anti-virus program can detect all infections. 


Hold together the Start Key and R. Type appwiz.cpl –> OK.


You are now in the Control Panel. Look for suspicious entries. Uninstall it/them.

Type msconfig in the search field and hit enter. A window will pop-up:


Startup —> Uncheck entries that have “Unknown” as Manufacturer or otherwise look suspicious.


Hold the Start Key and R –  copy + paste the following and click OK:

notepad %windir%/system32/Drivers/etc/hosts

A new file will open. If you are hacked, there will be a bunch of other IPs connected to you at the bottom. Look at the image below:

hosts_opt (1)

If there are suspicious IPs below “Localhost” – write to us in the comments.

Open the start menu and search for Network Connections (On Windows 10 you just write it after clicking the Windows button), press enter.

  1. Right-click on the Network Adapter you are using —> Properties —> Internet Protocol Version 4 (ICP/IP), click  Properties.
  2. The DNS line should be set to Obtain DNS server automatically. If it is not, set it yourself.
  3. Click on Advanced —> the DNS tab. Remove everything here (if there is something) —> OK.



  • After you complete this step, the threat will be gone from your browsers. Finish the next step as well or it may reappear on a system reboot.

Right click on the browser’s shortcut —> Properties.

NOTE: We are showing Google Chrome, but you can do this for Firefox and IE (or Edge).


Properties —–> Shortcut. In Target, remove everything after .exe.

ie9-10_512x512  Remove Yoursites123 from Internet Explorer:

Open IE, click  IE GEAR —–> Manage Add-ons.

pic 3

Find the threat —> Disable. Go to IE GEAR —–> Internet Options —> change the URL to whatever you use (if hijacked) —> Apply.

firefox-512 Remove Yoursites123 from Firefox:

Open Firefoxclick  mozilla menu  ——-> Add-ons —-> Extensions.

pic 6

Find the adware/malware —> Remove.
chrome-logo-transparent-backgroundRemove Yoursites123 from Chrome:

Close Chrome. Navigate to:

 C:/Users/!!!!USER NAME!!!!/AppData/Local/Google/Chrome/User Data. There is a Folder called “Default” inside:

Rename the Folder to Backup Default

Rename it to Backup Default. Restart Chrome.


To remove parasite on your own, you may have to meddle with system files and registries. If you were to do this, you need to be extremely careful, because you may damage your system.

If you want to avoid the risk, we recommend downloading SpyHunter
a professional malware removal tool.

More information on SpyHunter, steps to uninstallEULAThreat Assessment Criteria, and Privacy Policy.

Type Regedit in the windows search field and press Enter.

Inside, press CTRL and F together and type the threat’s Name. Right click and delete any entries you find with a similar name. If they don’t show up this way, go manually to these directories and delete/uninstall them:

  • HKEY_CURRENT_USER—-Software—–Random Directory. It could be any one of them – ask us if you can’t discern which ones are malicious.
    HKEY_CURRENT_USER—-Software—Microsoft—-Windows—CurrentVersion—Run– Random
    HKEY_CURRENT_USER—-Software—Microsoft—Internet Explorer—-Main—- Random

If the guide doesn’t help, download the anti-virus program we recommended or try our free online virus scanner. Also, you can always ask us in the comments for help!


  • Re: text document in step 4
    Below my IP I have

    Is this something to be worried about?

    • I am quite positive these are both part of the virus. Copy the addresses to a text file and delete these two lines from your hosts file. If something isn’t right you can just add them in later. But I’m almost completely sure it’s part of the yoursites123 virus.
      Tell me how it went later and if the guide helped you 🙂

  • Hello Sunny,
    Can you tell me what these IPs are? Sometimes IPs in the hosts file can be innocent.
    The DNSAPI.dll message is part of the virus. Ignore it for now and just tell me the IPs. If the message persists after we are finished with the hosts file, we will address the issue. 🙂

  • Hello Marc,
    Try to copy the file somewhere else and edit these 4 IPs out. They are 100% part of the virus. Then replace the old hosts file the edited one.

    • That’s great. I hope this fixes your problem for good and the malware doesn’t come back 🙂 Tell us if anything changes and we’ll try to help you.

  • I’ve done everything here, and everytime i close google chrome and open it again i see the again! What else can i do?

    • If everything else fails, download the scanner from one of our ads. It should help you track the infected files and you can do it from there.
      Also, were there extensions in your version of the virus? There are 1 or two different things you can try if there were extensions.

    • It happened to me too.
      You can do one more thing that doesn’t get removed with all these steps. Go to Settings / On Start up / Open a specific page or set of pages /
      Click on Set pages……delete yoursites123 and set new page

  • The yoursites123 extension doesn’t show up in Chrome, Firefox, or IE. Neither is it on the list of programs in the Control Panel. Yet on startup I’m directed to the yoursites123 page. So basically Step 2 is redundant. I went to the “On Startup” and deleted yoursites and set it to some other page. yoursites came back anyway. I did Step 3. In Step 4, the .txt file doesn’t show any IPs after Localhost. So that’s good. I did the regedit thing too. But it just won’t go away! Please help?

    • Try the following for Chrome:

      Close Chrome. Navigate to:

      C:/Users/!!!!USER NAME!!!!/AppData/Local/Google/Chrome/User Data. There is a Folder called “Default” inside:

      Rename it to Backup Default. Restart Chrome.

      For the rest, you absolutely must have missed some parts of the virus. It’s not your fault, these things can be pretty sneaky… Download the scanner from one of our ads and use it to find the infected files.
      Did any of this help?

  • Hello,

    It is entirely possible that a part of the virus lays somewhere and interferes with your attempts to remove yoursites123. Try again starting from Step 1. If you don’t know what else to do then download the software from the links above and use the scanner to locate the infected files. Let us know how that goes.

  • Hello Ellen,
    Glad to hear you managed to clean up your Chrome browser. As for MS Edge – can you tell me which of steps from our removal guide you managed to complete?

  • Hi,
    I also fell into the trap of this virus.
    Thankfully i found your website and have tried all the steps, just like a text book exercise and it worked. superb. Thank god that you exist. Thanks again from INDIA. m/.

  • Hi Hercules,

    I am assuming you are using WIn 10. Miscrosoft moved the Startup tab to the Task manager. Just look at the tabs, one of them says Startup.

  • You should be fine now, but there’s no guarantee you didn’t miss something that’s still on your PC. If you want to be 100% sure, download the SpyHunter scanner from one of our ads, and check if it finds something.

Leave a Comment