How To Remove YahooSoso “Virus” from Chrome/Firefox

Keep in mind, SpyHunter’s malware detection tool is free. To remove the infection, you'll need to purchase its full version. More information about SpyHunter and steps to uninstall.

This page aims to help you remove YahooSoso. These YahooSoso removal instructions work for Chrome, Firefox and Internet Explorer, as well as every version of Windows.

Nature of Browser Hijackers. Characteristics of YahooSoso.

If you are reading this article, you may have come across a new “friend” while surfing the Internet. Most probably this new mate is now showering you in a constant stream of pop-ups, advertisement banners, or it is redirecting you to magical websites promoting super products that will solve all the issues of your system or your car, or your work and even of your life. This new buddy is referred to as YahooSoso. It is not really a virus. In the real sense of the word, it is an Browser Hijackers application that may be nasty and irritating, as well as possessive. We will now explain its characteristics and give you some advice on how to never meet it anymore.

YahooSoso "Virus"

YahooSoso Chrome Removal

Browser Hijackers – characteristics

A Browser Hijacker is any software product, in which advertisements are displayed while the product is being executed. The creators of such programs include additional code that enables the distribution of a great number of diverse ads. They may be encountered as pop-up windows, or via a bar that appears on the user’s computer screen. Sometimes even via text hyperlinks or in integrated search results. Browser Hijackers may track browsing information about the user’s personal preferences, searches and interests. It may also gather data anonymously and sell it to 3rd parties.

However, Browser Hijackers is not a virus or a malware – it doesn’t copy and collect any banking, private or account data. It is just a way of making profit – the programmers embed the code for delivering advertisements in order to make money to sustain their companies, to fund further programming practices or just to find and alternative funding source.

People may come across Browser Hijackers in many ways but the most common are:

  • When a person downloads free software from the WEB – this type of free or very cheap programs come in bundles with “bonuses”- integrated Browser Hijackers scripts, that may annoy you, slow down your computer’s performance or track down your personal browsing preferences in order to irritate you even more.;
  • When a person is tempted by a promising message and clicks on something on an infected webpage. In this way, Browser Hijackers programs may integrate themselves in any browser (Firefox/Chrome/Explorer/Opera… etc.) :

Generally, Browser Hijackers programs are relatively harmless and mostly irritating. However, their ads may promote a malware program or redirect you to a dangerous or deceptive website. is a very good example of a Browser Hijackers program. It has been created for delivering numerous different advertisements based on the user’s personal browsing preferences and searches. Maybe the program’s approach will seem relatively aggressive to you as YahooSoso will keep promoting pages and products until your patience runs out and you make a decision to get rid of it completely. If you detect this software and make an effort to uninstall it, you need to remove every single bit of it. Yet it is important to make a certain distinction. When people refer to YahooSoso as a “Virus” , they are not correct in their assessment. YahooSoso is not really a computer virus, but we understand we people might be confused about the distinction between a Browser Hijacker and a full blown virus.

If you have a reliable anti-malware tool, installed on your computer, it is likely that it will detect an Browser Hijackers application and will give you the option to remove it from your system. You may also be able to manually delete it. However, this is not recommended for people with little or no experience in similar matters. It will be best if you follow the instructions below in order to ensure your system’s future security.

In order to avoid getting “close” to Browser Hijacker programs in the future, always remember to choose carefully what you install on your computer. Also, you should really think about purchasing a good anti-malware product that will automatically block the possibly infected pages and software products. What’s essential is that you should really be cautious when it comes to the installation process of any program – always select the Manual/Customized option of the installation tool. Never let any software make any undesired changes to your system, create additional toolbars or install “extra” programs that may become a problem after that. Last but not least, your Firewall and OS must be completely functional and frequently updated over time. All this information will help you prevent your system from getting any annoying issues with and other Browser Hijackers in the future.


Name YahooSoso
Type Browser Hijacker
Danger Level Medium
Symptoms Unwanted Ads appear, Browser redirects. Browser changes. Slower computer performance than usual.  
Distribution Method File sharing websites (such as torrents), infected free or cheap software bundles.
Detection Tool YahooSoso may be difficult to track down. Use SpyHunter – a professional parasite scanner – to make sure you find all files related to the infection.

Keep in mind, SpyHunter’s malware detection tool is free. To remove the infection, you’ll need to purchase the full version.
More information about SpyHunter and steps to uninstall.


How To Remove YahooSoso from Chrome/Firefox

Readers are interested in:



Reboot in Safe Mode (use this guide if you don’t know how to do it).

This was the first preparation.


To remove parasite, you may have to meddle with system files and registries. Making a mistake and deleting the wrong thing may damage your system.
Avoid this by using SpyHunter - a professional Parasite removal tool.

Keep in mind, SpyHunter’s malware detection tool is free. To remove the infection, you'll need to purchase its full version. More information about SpyHunter and steps to uninstall.

Reveal All Hidden Files and Folders.

  • Do not skip this – YahooSoso may have hidden some of its files.

Hold together the Start Key and R. Type appwiz.cpl –> OK.


You are now in the Control Panel. Look for suspicious entries. Uninstall it/them.

Type msconfig in the search field and hit enter. A window will pop-up:


Startup —> Uncheck entries that have “Unknown” as Manufacturer.


Hold the Start Key and R copy + paste the following and click OK:

notepad %windir%/system32/Drivers/etc/hosts

A new file will open. If you are hacked, there will be a bunch of other IPs connected to you at the bottom. Look at the image below:

hosts_opt (1)

If there are suspicious IPs below “Localhost” – write to us in the comments.


Right click on the browser’s shortcut —> Properties.

NOTE: We are showing Google Chrome, but you can do this for Firefox and IE (or Edge).


Properties —–> Shortcut. In Target, remove everything after .exe.

ie9-10_512x512 Remove YahooSoso from Internet Explorer:

Open IE, click IE GEAR —–> Manage Add-ons.

pic 3

Find the threat —> Disable. Go to IE GEAR —–> Internet Options —> change the URL to whatever you use (if hijacked) —> Apply.

firefox-512 Remove YahooSoso from Firefox:

Open Firefox, click mozilla menu ——-> Add-ons —-> Extensions.

pic 6

Find the Browser Hijackers/malware —> Remove.
chrome-logo-transparent-backgroundRemove YahooSoso from Chrome:

Close Chrome. Navigate to:

C:/Users/!!!!USER NAME!!!!/AppData/Local/Google/Chrome/User Data. There is a Folder called “Default” inside:

Rename the Folder to Backup Default

Rename it to Backup Default. Restart Chrome.

  • At this point the threat is gone from Chrome, but complete the entire guide or it may reappear on a system reboot.


Press CTRL + SHIFT + ESC simultaneously. Go to the Processes Tab. Try to determine which ones are dangerous. Google them or ask us in the comments.


This is the most important and difficult part. If you delete the wrong file, it may damage your system irreversibly. If you can not do this,
>> Download SpyHunter - a professional parasite scanner and remover.

Keep in mind, SpyHunter’s malware detection tool is free. To remove the infection, you'll need to purchase its full version. More information about SpyHunter and steps to uninstall.

Right click on each of the problematic processes separately and select Open File Location. End the process after you open the folder, then delete the directories you were sent to.



Type Regedit in the windows search field and press Enter.

Inside, press CTRL and F together and type the threat’s Name. Right click and delete any entries you find with a similar name. If they don’t show this way, go manually to these directories and delete/uninstall them:

  • HKEY_CURRENT_USER—-Software—–Random Directory. It could be any one of them – ask us if you can’t discern which ones are malicious.
    HKEY_CURRENT_USER—-Software—Microsoft—-Windows—CurrentVersion—Run– Random
    HKEY_CURRENT_USER—-Software—Microsoft—Internet Explorer—-Main—- Random

Remember to leave us a comment if you run into any trouble!

  • HowToRemove.Guide Team

    Hi tj, remove all lines that are connected to suspicious chinese websites. Let me know if you need more help.

  • HowToRemove.Guide Team

    Hi Nadeem, these sites are associated with the Ads for sure. Delete all from the hosts sile, then save the changes.

  • HowToRemove.Guide Team

    Hi tj, you’ve essentially created a new file by saving it in a different place. The new file is a dud and won’t do anything.

    To properly safe the file If you experience any problems with permission rights when you try to save the file do the following:

    Search for Notepad in Windows search -> right click on the executable and select Run as Administrator.
    From inside Notepad click on the File-> Open menu and navigate to the hosts file

    You should now be able to save the file properly.

  • HowToRemove.Guide Team

    Yes, all but mcafee need to be deleted.