Removal Guide

Remove Rainbow Prices Ads

Parasite may reinstall itself multiple times if you don't delete its core files. We recommend downloading SpyHunter to scan for malicious programs installed with it. This may save you hours and cut down your time to about 15 minutes. 

Download SpyHunter Anti-Malware

More information on SpyHunter, steps to uninstallEULAThreat Assessment Criteria, and Privacy Policy.

This article is designed to remove Rainbow Prices Ads from Chrome, Firefox and Internet Explorer, and works in all versions of Windows.

Remove Rainbow Prices Ads

Rainbow Prices Ads has infected your computer and you are looking for a way to remove it from your computer? Well you’ve come to the right place. Our step-by-step will help you do this, but before we begin the process we advise you to read the rest of our article carefully. It contains useful overview on this virus and we’ll also be discussing how it got into your computer and what can be done to prevent this in the future.

Rainbow Prices Ads creates advertisements (Ads) every time you start your internet browser or load a page/link/tab in it. Ads can take all shapes and forms – like whole Ad-filled pages, pop-ups, banners and more. They’ll usually advertise stuff that you’ve recently looked up in the internet thanks to Rainbow Prices Ads reading into your private browsing data and search history. This kind of behavior especially is very dangerous, because it’s related to identity theft or at least stolen credit card numbers and online passwords.

Don’t click on the Ads

The chance of getting anything useful out of those Ads is next to nonexistant. If you try to click on them you are only exposing your computer to potential virus installation or at the very least you will be sent to a fraudulent site that will try to trick you into giving it money, which it will of course steal from you.

Viruses /including those Rainbow Prices Ads will try to install on your computer/ usually bypass system protection and infect your computer by using YOU as their trojan horse. Tricking the user into authorizing the virus installation is much easier for virus makers then writing code that targets system vulnerabilities. Over the years many underhanded strategies were developed in order to fool the user and most involved some kind of disguise or misdirection.

Usually when a virus tries to install itself it will be in the form of an .exe file, which carries a different name. It will usually be the name of some popular program or other piece of software. In order to look more enticing it will usually be free of charge. You should never trust free program installations from random sources – and this includes not only Rainbow Prices Ads, but pretty much any Ad out there. If you want to download such free software you should always look it up on Google and get it from the official developer. All other installations could be potentially tainted with a virus.

1: Enter Safe Mode.
2: Remove Rainbow Prices Ads from Chrome, Firefox, Internet Explorer and Safari.
3: Remove the virus from browser shortcuts.
4: Uninstall the virus from your AddRemove Programs.
5: Permanently remove Rainbow Prices Ads from Task Manager’s processes.
6: Delete the virus from Regedit and Msconfig.
7: Optimize your PC after the removal is done.

Remove Rainbow Prices Ads

Before we start you should know that some of this steps might not be necessary for the removal of Rainbow Prices Ads on your computer. The thing is that this virus has been reported to need several different steps in order to be removed and they are not always the same for all people infected. We’ve written everything necessary to remove it from every computer (or so we hope – viruses like this change every day), but this also means some of these step might not be necessary for you, though most are perfectly safe to do anyway.

Carefully review each step – if you don’t see anything like what we are describing, move on with the next one and don’t worry. If you need any assistance, do not hesitate to ask us in the comments.


Our first step here is a reboot in Safe Mode. If you already know how to do it, just skip this and proceed to Step 2. If you do not know how to do it, continue reading:

For Windows 98, XP, Millenium and 7 Users:

Restart your computer. To be sure you don’t miss the time when you need to press it, just spam F8 as soon as the PC starts booting. In the new menu, choose Safe Mode With Networking.

Proceed to Step 2.

For W. 8 and 8.1 Users:

Click the Start button ,then Control Panel —> System and Security —> Administrative Tools —> System Configuration.Administrator permission required


Then check the Safe Boot option and click OK.  Click  Restart in the new pop-up.

Proceed to Step 2.

For Windows 10 Users:

  1. Open the Start menu.
  2. Click the power button icon in the right corner of the new Start menu to show the power options menu.
  3. Press and hold down the SHIFT key on the keyboard and click the Restart option while still holding down the SHIFT key.

Windows 10 will perform the reboot. Next do the following:

Click the Troubleshoot icon, then Advanced options —> Startup Settings. Click Restart.
After the reboot click on Enter Safe Mode With Networking (Fifth Option).


Continue with Step 2.


To remove parasite on your own, you may have to meddle with system files and registries. If you were to do this, you need to be extremely careful, because you may damage your system.

If you want to avoid the risk, we recommend downloading SpyHunter
a professional malware removal tool.

More information on SpyHunter, steps to uninstallEULAThreat Assessment Criteria, and Privacy Policy.

When Rainbow Prices Ads made contact with your computer it immediately infected ALL of your internet browsers. This includes even those that are installed, but you are not actually using actively any more. In order to fully remove Rainbow Prices Ads you’ll have to run Steps 2&3 for every browser you have on your computer. Otherwise the virus might just copy itself back on the next PC reboot.

ie9-10_512x512  For Internet Explorer Users:

Open IE, then click  IE GEAR —–> Manage Add-ons.

pic 3

Find Rainbow Prices Ads . Remove it by pressing Disable.

If your Home Page is different from the usual, click IE GEAR —–> Internet Options>edit the URL box with your preferred search engine, and click Apply.

Go to STEP 3.

firefox-512  For Mozilla Firefox Users:

Open Firefoxclick on mozilla menu (top right) ——-> Add-onsHit Extensions next.

Remove Rainbow Prices Ads From Firefox

Rainbow Prices Ads  should be somewhere around here –  Remove it.

Go to STEP 3.

chrome-logo-transparent-background For Google Chrome Users

 Start Chrome, click chrome menu icon —–>More Tools —–> Extensions. There,  find the virus and  select  chrome-trash-icon(Remove).

Remove Rainbow Prices Ads From Chrome

 Click chrome menu icon again, and proceed to Settings —> Search, the fourth tab, select Manage Search Engines.  Remove anything but the search engines you normally use.

Go to STEP 3.

safari For Safari Users:

Open Safari, and click Safari —–>Preferences —–> Extensions—–>Uninstall the malware.

Go to STEP 3.


Right click on the browser’s shortcut, then click Properties.

NOTE: We are showing Google Chrome, but the method is the same for all browsers.


Once you’ve reached Properties —–> Shortcut (on the band at the top), then in the Target type field, REMOVE EVERYTHING AFTER .exe.

Continue with STEP 4.


(Works for XP, 7,  8,  8.1)

Hold the Windows Key and R together. Write appwiz.cpl in the new field, then click OK.


You are now in the Control Panel. Search around for Rainbow Prices Ads and anything else suspicious-looking. Uninstall it/them. Also, be extremely careful. Viruses often spend one last ditch effort to trick you into installing more of their kind. If you see a screen like this when you click Uninstallchoose NO:


Hold the Windows Key and R againbut this time copy + paste the following and click OK:

notepad %windir%/system32/Drivers/etc/hosts

A .txt file will open – don’t touch anything there. If you are hacked and someone has access to your PC, there will be a bunch of other IPs connected to you at the bottom. This is what a hosts file looks like:

hosts_opt (1)

If there are a bunch of strange IPs connecting to you below “Localhost” you may be hacked, and it’s best to ask us in the comments for directions.

Go to STEP 5.


Open the Task Manager by right clicking on the Taskbar and choosing Start Task Manager.


Once it opens, choose the Processes Tab. Look at all of the processes in front of you and try to determine which ones are a virus. Google them or ask us in the comments and we will provide the best assistance we can.

IMPORTANT! You HAVE to read this!

This is perhaps the most important and difficult step, so we advise that you stay calm and read carefully what follows before attempting to do it. Doing it wrong can damage your PC significantly, especially if you make a big mistake. If you are not feeling comfortable, we advise you to download a professional Rainbow Prices Ads remover that can handle this for you risk-free.

Another good reason why you’d want to do that is because a good anti-malware software can scan your computer for hidden threats you might never see. Things like keyloggers, trojans, rootkits. They are very dangerous as they are impossible detect manually and can steal your credit card numbers, passwords and even your identity.


Right click on each of the virus processes separately and select Open File Location. Also, End the process after you open the folder. Just to make sure we don’t delete any programs you mistakenly took for a virus, copy the folders somewhere, then delete the directories you were sent to.

Move on to STEP 6.


Take a look at the following things:

Type msconfig in the search field and hit enter: you will be transported to a new window. 


Go in the Startup tab and Uncheck anything that has “Unknown” as Manufacturer.

Type Regedit in the windows search field and press Enter.

Once inside, press CTRL and F together and type the virus’s Name. Right click and delete any entries you find with a similar name. If you can’t find them this way, look in these directories, and delete the registries manually:

  • HKEY_CURRENT_USER—-Software—–Random numbers
    HKEY_CURRENT_USER—-Software—Microsoft—-Windows—CurrentVersion—Run– Random
    HKEY_CURRENT_USER—-Software—Microsoft—Internet Explorer—-Main—- Random

Remember to leave us a comment if you run into any trouble!

Did we help you? Please, consider helping us by spreading the word!

STEP 7 – Optimization

We’ve prepared a short and sweet optimization guide, specifically designed for users who just removed a virus. It is completely free, you do not need to download anything, and it’s not very time consuming. If you are interested – How To Remove Guide’s Optimization Tips.


Leave a Comment