Lifestion.info Pop-up “Virus” Removal (Chrome/Firefox/IE) June 2018 Update

Keep in mind, SpyHunter’s malware & virus scanner is free. To remove the infection, you'll need to purchase its full version. More information about SpyHunter and steps to uninstall.


How irritating is this problem? (2 votes, average: 5.00)
Loading...

This page aims to help you remove Lifestion.info Pop-up “Virus”. Our removal instructions work for Chrome, Firefox and Internet Explorer, as well as every version of Windows.

Usually, the browser redirects, also known as browser hijackers, are not damaging r dangerous. A standard version of this irritating category is Lifestion.info “Virus”. It may be integrated into all of the browsers you have installed on your PC – Chrome, Explorer, Opera, and others. The possible unwanted effects that might come from this hijacker are unpleasant redirects to different web locations, changes of the appearance of your browsers regarding the default search engines and homepages that are set as well as various intensive ad generation.

What else could characterize the browser hijackers like Lifestion.info “Virus”?

As we already mentioned, hijackers aren’t really all that threatening. Landing such a software on your PC might be unpleasant and frustrating but in terms of actual damage, there will likely be none. Typically, the most unpleasant part of having a hijacker/page redirect on your PC is the intrusiveness that would come from.. The true mischievous infections that are brought by Trojan and Ransomware could result in many nasty things like file encryption, tracking some of your credentials or banking details, spying on you in some way, blackmailing warnings and even – identity thefts!

On the flip side, the hijackers we have stumbled across so far may only bring a lot of irritation because of their ability to send a user to pages they have not ever planned to visit. Possible effects of Lifestion.info are not only the changes of the usual browser homepage and/or search engine, but also the production of a vast number of adverts.

How may browser hijackers be distributed?

Hijackers could generally come to your systems via different methods. One such method is what is called file bundles. Bundles like these are programs which are put and distributed together. Since typically, such bundles are free, users are likely to install them on their PC without thinking about it too much. It is typical for such software bundles to also contain a piece of ad-broadcasting software like a version of adware, or of a hijacker. Such bundles can be downloaded from a lot of different sites that are all over the Internet so you have to be really careful with the web locations that you visit.

What we recommend for the removal of Lifestion.info:

We hope that our Guide and the article is going to be what you have been looking for in order to solve the problems you have related to Lifestion.info.

Lifestion.info Pop-up “Virus” Removal

If you have a Windows virus, continue with the guide below.

If you have a Mac virus, please use our How to remove Ads on Mac guide.

If you have an Android virus, please use our Android Malware Removal guide.

If you have an iPhone virus, please use our iPhone Virus Removal guide


Step1

Some of the steps will likely require you to exit the page. Bookmark it for later reference.

Reboot in Safe Mode (use this guide if you don’t know how to do it).

Step2

WARNING! READ CAREFULLY BEFORE PROCEEDING!

We get asked this a lot, so we are putting it here: Removing parasite manually may take hours and damage your system in the process. If you want a fast safe solution, we recommend SpyHunter. 

>> Click to Download Spyhunter. If you don't want this software, continue with the guide below.

Keep in mind, SpyHunter’s malware & virus scanner is free. To remove the infection, you'll need to purchase its full version. More information about SpyHunter and steps to uninstall.

Press CTRL + SHIFT + ESC at the same time and go to the Processes Tab (the “Details” Tab on Win 8 and 10). Try to determine which processes are dangerous. 

malware-start-taskbar

Right click on each of them and select Open File Location. Then scan the files with our free online virus scanner:

Drag and Drop Files Here to Scan
Maximum file size: 128MB.

This scanner is free and will always remain free for our website's users. You can find its full-page version at: https://howtoremove.guide/online-virus-scanner/




Scan Results


Virus Scanner Result
ClamAV
AVG AV
Maldet

After you open their folder, end the processes that are infected, then delete their folders. 

Note: If you are sure something is part of the infection – delete it, even if the scanner doesn’t flag it. No anti-virus program can detect all infections. 

Step3

Hold together the Start Key and R. Type appwiz.cpl –> OK.

appwiz

You are now in the Control Panel. Look for suspicious entries. Uninstall it/them.

Type msconfig in the search field and hit enter. A window will pop-up:

msconfig_opt

Startup —> Uncheck entries that have “Unknown” as Manufacturer or otherwise look suspicious.

Step4

Hold the Start Key and R –  copy + paste the following and click OK:

notepad %windir%/system32/Drivers/etc/hosts

A new file will open. If you are hacked, there will be a bunch of other IPs connected to you at the bottom. Look at the image below:

hosts_opt (1)

If there are suspicious IPs below “Localhost” – write to us in the comments.

Open the start menu and search for Network Connections (On Windows 10 you just write it after clicking the Windows button), press enter.

  1. Right-click on the Network Adapter you are using —> Properties —> Internet Protocol Version 4 (ICP/IP), click  Properties.
  2. The DNS line should be set to Obtain DNS server automatically. If it is not, set it yourself.
  3. Click on Advanced —> the DNS tab. Remove everything here (if there is something) —> OK.

DNS

Step5

  • After you complete this step, the threat will be gone from your browsers. Finish the next step as well or it may reappear on a system reboot.

Right click on the browser’s shortcut —> Properties.

NOTE: We are showing Google Chrome, but you can do this for Firefox and IE (or Edge).

browser-hijacker-taskbar-properties

Properties —–> Shortcut. In Target, remove everything after .exe.

ie9-10_512x512  Remove Lifestion.info from Internet Explorer:

Open IE, click  IE GEAR —–> Manage Add-ons.

pic 3

Find the threat —> Disable. Go to IE GEAR —–> Internet Options —> change the URL to whatever you use (if hijacked) —> Apply.

firefox-512 Remove Lifestion.info from Firefox:

Open Firefoxclick  mozilla menu  ——-> Add-ons —-> Extensions.

pic 6

Find the adware/malware —> Remove.
chrome-logo-transparent-backgroundRemove Lifestion.info from Chrome:

Close Chrome. Navigate to:

 C:/Users/!!!!USER NAME!!!!/AppData/Local/Google/Chrome/User Data. There is a Folder called “Default” inside:

Rename the Folder to Backup Default

Rename it to Backup Default. Restart Chrome.

Step6

WARNING!
To remove parasite, you may have to meddle with system files and registries. Making a mistake and deleting the wrong thing may damage your system.
Avoid this by using SpyHunter - a professional Parasite removal tool.

Keep in mind, SpyHunter’s malware & virus scanner is free. To remove the infection, you'll need to purchase its full version. More information about SpyHunter and steps to uninstall.

Type Regedit in the windows search field and press Enter.

Inside, press CTRL and F together and type the threat’s Name. Right click and delete any entries you find with a similar name. If they don’t show up this way, go manually to these directories and delete/uninstall them:

  • HKEY_CURRENT_USER—-Software—–Random Directory. It could be any one of them – ask us if you can’t discern which ones are malicious.
    HKEY_CURRENT_USER—-Software—Microsoft—-Windows—CurrentVersion—Run– Random
    HKEY_CURRENT_USER—-Software—Microsoft—Internet Explorer—-Main—- Random

If the guide doesn’t help, download the anti-virus program we recommended or try our free online virus scanner. Also, you can always ask us in the comments for help!

Does that mean that downloading a bundle equals catching a hijacker like Lifestion.info?

Most of the time, safe installation of the main program from a bundle so that you don’t get the potentially added hijacker is possible. You could download a bundle and maybe even try different products from it without getting the hijacker. As a whole, you must just install the bundle in an appropriate way.

The best way for installing every type of software involves making sure to customize the installation process. With this we mean that you have to access the installation customization settings and from there choose what to leave out of the installation before you initiate it. Those settings would usually be labeled as advanced or customized. Always make sure to go for these options if you don’t want to accidentally land some unpleasant and unwanted piece of software.

Why are such programs created?

Advertising products, software or services are not a new idea at all. At first, the advertisements used to be broadcast on the television and on the radio. These days advertising online is growing more and more rapidly because more and more people have access to the Internet. Signing contracts for cooperation between advertisers and software developers is rather common. The first ones agree to promote a product as effectively as they can while the second party is pays for the advertising service.  In the end, advertisers are paid generally on the basis of the whole number of the loaded or clicked on advertisements. Actually, that kind of business activity does not break any rules – such advertising is typically legitimate.

SUMMARY:

Name Lifestion.info
Type Browser Hijacker
Danger Level Medium (nowhere near threats like Ransomware, but still a security risk)
Symptoms  Nothing really harmful , just the too intensive generation of ads and request redirections.
Distribution Method Via bundles and all sorts of spam, as well as shareware and torrents.
Detection Tool We generally recommend SpyHunter or a similar anti-malware program that is updated daily.