Browser Redirect

Remove Bodlift “Virus” (Chrome/FF/IE)


How irritating is this problem? (7 votes, average: 5.00)
Loading...

This page aims to help you remove Bodlift “Virus”. Our removal instructions work for Chrome, Firefox and Internet Explorer, as well as every version of Windows.

If you click on the “Allow” button, then you will start seeing unwanted pop-up ads from Bodlift.com on your desktop even when your browser is closed.

To trick you into subscribing to its mailing list and to receive notifications, the Bodlift.com site will display the following message

Bodlift.com wants to Show notifications

 Allow Block

One of the main elements of the computer system that a lot of malware programs tend to target in order to infiltrate the users’ machines are the Internet browsers. Since the browser is the main connection between the computer and the online world, a lot of hackers make sure to exploit that and use any browser vulnerabilities that they may find in order to sneak their malicious programs inside more and more computers. This is why it is essential to keep your browser clean and secure. And when it comes to making sure that your browser isn’t a potential target for malware, one of the key aspects here is to ensure that your search engine is legitimate, that your homepage isn’t potentially unsafe and that there aren’t any elements in your Chrome, Safari, Firefox or another browser, that may page-redirect you to shady addresses and spam your screen with questionable advertisements. Unfortunately, such software elements are quite common and the collective term used to describe them is browser hijackers. Normally, those are browser add-on-like components for the browser that are have the goal of promoting something – it may be a certain site or some custom search engine that shows distorted search results that are in favor of different advertised sites. To achieve its goal, the hijacker may introduce various changes in your browser and prevent you from overriding them. This, in turn, may make your browser more susceptible to attacks – if your search engine is of low-quality and shows you questionable results in its attempts to advertise different sites or if your homepage is from some ad-oriented site with obscure contents, then it is definitely better to make sure that those changes go away.

One recently reported hijacker is the one that changes the starting page of the user to Bodlift or replaces their search engine to one with the Bodlift logo. Many are the users who have complained about it and we are here to tell you that it may not be all that difficult to deal with this unpleasant annoyance provided that you follow the instructions we have prepared for you. Again, even if the changes in the browser or the occasional ad disruption are not that irritating to you and you can put up with them, having a hijacker in your browser may make the browser, and by extension your whole system, less safe and more likely to get attacked by real malware threats – ones the likes of Trojans, Rootkits and Ransomware. And, since you surely don’t want to get your files locked by some nasty Ransomware cryptovirus or your system damaged by a Trojan, we advise you to take a very careful look at the steps from our Bodlift removal guide and complete them all in order to get rid of the pesky hijacker. If, for some reason, the Bodlift hijacker is still bothering you after you’ve completed the guide, you may try the removal tool linked in this page as it can automatically uninstall the invasive app and rid you of its annoyance.

SUMMARY:

Name Bodlift
Type Browser Hijacker
Danger Level Medium (nowhere near threats like Ransomware, but still a security risk)
Symptoms Hijackers are mostly known for changing the browser’s settings without the permission of the user.
Distribution Method The methods that the hijacker creators use to distribute such apps are mainly related to spam messages and file bundling.
IP Address 213.227.150.132
Detection Tool

Remove Bodlift “Virus”

If you have a Windows virus, continue with the guide below.

If you have a Mac virus, please use our How to remove Ads on Mac guide.

If you have an Android virus, please use our Android Malware Removal guide.

If you have an iPhone virus, please use our iPhone Virus Removal guide


Step1

Some of the steps will likely require you to exit the page. Bookmark it for later reference.

Reboot in Safe Mode (use this guide if you don’t know how to do it).

Step2

WARNING! READ CAREFULLY BEFORE PROCEEDING!

Press CTRL + SHIFT + ESC at the same time and go to the Processes Tab (the “Details” Tab on Win 8 and 10). Try to determine which processes are dangerous. 

malware-start-taskbar

Right click on each of them and select Open File Location. Then scan the files with our free online virus scanner:

Drag and Drop Files Here to Scan
Maximum file size: 128MB.

This scanner is free and will always remain free for our website's users. You can find its full-page version at: https://howtoremove.guide/online-virus-scanner/




Scan Results


Virus Scanner Result
ClamAV
AVG AV
Maldet


After you open their folder, end the processes that are infected, then delete their folders. 

Note: If you are sure something is part of the infection – delete it, even if the scanner doesn’t flag it. No anti-virus program can detect all infections. 

Step3

Hold together the Start Key and R. Type appwiz.cpl –> OK.

appwiz

You are now in the Control Panel. Look for suspicious entries. Uninstall it/them.

Type msconfig in the search field and hit enter. A window will pop-up:

msconfig_opt

Startup —> Uncheck entries that have “Unknown” as Manufacturer or otherwise look suspicious.

Step4

Hold the Start Key and R –  copy + paste the following and click OK:

notepad %windir%/system32/Drivers/etc/hosts

A new file will open. If you are hacked, there will be a bunch of other IPs connected to you at the bottom. Look at the image below:

hosts_opt (1)

If there are suspicious IPs below “Localhost” – write to us in the comments.

Open the start menu and search for Network Connections (On Windows 10 you just write it after clicking the Windows button), press enter.

  1. Right-click on the Network Adapter you are using —> Properties —> Internet Protocol Version 4 (ICP/IP), click  Properties.
  2. The DNS line should be set to Obtain DNS server automatically. If it is not, set it yourself.
  3. Click on Advanced —> the DNS tab. Remove everything here (if there is something) —> OK.

DNS

Step5

  • After you complete this step, the threat will be gone from your browsers. Finish the next step as well or it may reappear on a system reboot.

Right click on the browser’s shortcut —> Properties.

NOTE: We are showing Google Chrome, but you can do this for Firefox and IE (or Edge).

browser-hijacker-taskbar-properties

Properties —–> Shortcut. In Target, remove everything after .exe.

ie9-10_512x512  Remove Bodlift from Internet Explorer:

Open IE, click  IE GEAR —–> Manage Add-ons.

pic 3

Find the threat —> Disable. Go to IE GEAR —–> Internet Options —> change the URL to whatever you use (if hijacked) —> Apply.

firefox-512 Remove Bodlift from Firefox:

Open Firefoxclick  mozilla menu  ——-> Add-ons —-> Extensions.

pic 6

Find the adware/malware —> Remove.
chrome-logo-transparent-backgroundRemove Bodlift from Chrome:

Close Chrome. Navigate to:

 C:/Users/!!!!USER NAME!!!!/AppData/Local/Google/Chrome/User Data. There is a Folder called “Default” inside:

Rename the Folder to Backup Default

Rename it to Backup Default. Restart Chrome.

Step6

Type Regedit in the windows search field and press Enter.

Inside, press CTRL and F together and type the threat’s Name. Right click and delete any entries you find with a similar name. If they don’t show up this way, go manually to these directories and delete/uninstall them:

  • HKEY_CURRENT_USER—-Software—–Random Directory. It could be any one of them – ask us if you can’t discern which ones are malicious.
    HKEY_CURRENT_USER—-Software—Microsoft—-Windows—CurrentVersion—Run– Random
    HKEY_CURRENT_USER—-Software—Microsoft—Internet Explorer—-Main—- Random

If the guide doesn’t help, download the anti-virus program we recommended or try our free online virus scanner. Also, you can always ask us in the comments for help!


Leave a Comment