Aliases: TR/Midhos (Avira) Trojan.Win32.Midhos (Kaspersky) Win32/Medfos (ESET) Medfos (McAfee) Trojan/Win32.Midhos (AhnLab) Trojan.Win32.Medfos (Ikarus)
Microsoft security software detects and removes this family of threats.
These threats install malicious Internet browser extensions and redirect your search results. This means that if you search using Google, Bing, or Yahoo, for example, the site returns normal search results. However, if you click on any of the results, instead of going to the correct website, you might be redirected to a different website.
These threats can also be used for click-fraud.
Variants of Win32/Medfos can be installed by other malware, including variants of the Trojan:Win32/Necurs family.
Use the following free Microsoft software to detect and remove this threat:
You should also run a full scan. A full scan might find other, hidden malware.
You may need to remove add-ons from your browser:
If you’re using Windows XP, see our Windows XP end of support page.