Simple steps, and the tools are free to use.

(VIDEO) Remove Sweet-Page virus (Video Removal Guide)

By | March 25, 2014

remove homepageSweet-Page is the homepage hijacker just like NationZoom, Qvo6, do-Search, PortalDoSites and Aartemis, which is installed by browser extensions or addons. This homepage hijacker is bundled with freeware to promote Sweet-Page Search and to make money using advertisements within the search results. Once this Sweet-Page browser hijacker is installed on your computer, the default search engine and homepage for Internet Explorer, Google Chrome or Mozilla Firefox is replaced with Sweet-Page. This Sweet-Page homepage is not malicious process itself and may not be called a virus, but it does change security settings within your favorite browser and is distributed by freeware. Sweet-Page also hijacks the shortcut of your favorite browser and adds a extra argument behind the executable. By doing this hijacking the website always opens when you open the browser, even as you replaced your default homepage with a website of your choice. It’s a very nifty and nasty method of forcing to drive web-traffic to there website.

Please be aware what you install on your computer. The Sweet-Page browser hijacker is most likely installed by the computer user itself because it’s offered during the installation process.

It is advised to always read the Terms and Agreements before installing software on your computer. Do never click too fast through the installation process [Next] button of software as you will agree to software you might not want to install. If the installer offers an Advanced, Custom or Decline button, click it to find out if there is any other malicious softwareoffered and installed during the installation process.

Remove Sweet-Page virus

[vimeo id=”90019556″ mode=”normal”]

Please note that all the software we offer to remove Sweet-Page is free, our instruction is tested and works to remove this threat from your Internet Explorer, Google Chrome or Mozilla Firefox browser. We do not supply any shareware which detects the threat and asks a license in order to remove Sweet-Page.

Follow all steps in correct order to completely and successfuly remove Sweet-Page and it’s shortcut hijack.
This is important: if you have any problem during this removal instruction in order to remove this threat, please stop and ask for assistance using the comments at the end of this instruction.
Step 1 – Remove Sweet-Page homepage using AdwCleaner

Step 2 – Scan your computer using MalwareBytes Anti-Malware free to clean and protect your computer from adware, viruses

This is a comprehensive removal instruction to remove Sweet-Page from your computer. If for some reason the instruction does not deliver the desired results, you can reset your favorite browser Internet Explorer, Google Chrome or Mozilla Firefox to default settings. In first place this is not recommended, as restoring to default settings will remove all your personal settings from your browser. Please use restoring to default settings only if anything else fails.

Remove Sweet-Page homepageRemove Sweet-Page homepage using AdwCleaner

AdwCleaner will scan your computer for malicious Services, Folder, Files, Shortcuts, Registry items and Products. As AdwCleaner tries to delete these malicious content it will also clean the Internet Explorer, Google Chrome and Mozilla Firefox browser. We strongly recommend using AdwCleaner several times a month to keep your computer clean from adware, popups, browser hijackers or toolbars.
Download AdwCleaner (Official link and direct-download)

Select AdwCleaner.exe with right mouse click and Run as Administrator

Remove Sweet-Page homepage - AdwCleaner

If User Account Control asks you to allow AdwCleaner.exe to make changes to your computer, press Yes to continue.

Remove Sweet-Page homepage

Start scanning your computer for any malicious threats by selecting the Scan button, please wait.

Remove Sweet-Page homepage

AdwCleaner will now start scanning your computer. If AdwCleaner is done, it will display a list of malicious items detected, please uncheck the items you do not want to remove that might be detected as malicious.
If you have nothing to uncheck, continue to the removal process and select the Clean button.

Remove Sweet-Page homepage

AdwCleaner will display the following informational alerts and starts rebooting the computer.

All programs will be closed in order to proceed correctly to the removal of the infections. Please save any work in progress and the click [OK]

If you have been brought to use AdwCleaner, it’s probably because your PC contained potentially unwanted programs or adware.
Potentially unwanted programs are often proposed during the installation of software. They may be present form of toolbars that sometimes change the homepage of the browser and slow internet browsing.
To avoid the installation of these programs polluting the computer, it is essential to follow these tips:

– Always download a program from the official link, or a trusted site
– When installing a program, do not click too fast [Next] without paying attention to Terms of Use and third-party programs available.
– If third-party programs are available (toolbars, etc) uncheck them.
– Enable detection of PUP (Potentially Unwanted Program) in your Antivirus.

AdwCleaner must restart the computer to complete the removal process. The report will be opened on the next reboot.

After the reboot a logfile will open. The logfile in Windows XP and Windows 7 will open once the desktop is started. To open the logfile in Windows 8 you need to switch to the Desktop modus by selecting windows key + d on your keyboard.
If you want to check the AdwCleaner log, you can find the report log in your system drive, Adwcleaner folder (for example: C:\adwcleaner)

Result of AdwCleaner – Sweet-Page removal

# AdwCleaner v3.016 – Report created 03/01/2014 at 10:29:12
# Updated 23/12/2013 by Xplode
# Operating System : Windows 8 Pro (64 bits)
# Username :
# Running from : C:\Users\\Desktop\adwcleaner.exe
# Option : Clean

***** [ Services ] *****

Service Deleted : Wpm

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\Conduit
Folder Deleted : C:\ProgramData\Search Protection
Folder Deleted : C:\ProgramData\WPM
Folder Deleted : C:\ProgramData\YoutubeAdblocker
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EZDownloader
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\EZDownloader
Folder Deleted : C:\Program Files (x86)\Mobogenie
Folder Deleted : C:\Program Files (x86)\tuguu sl
Folder Deleted : C:\Program Files (x86)\YoutubeAdblocker
Folder Deleted : C:\Program Files (x86)\NCH_EN
Folder Deleted : C:\Windows\SysWOW64\Searchprotect
Folder Deleted : C:\Users\\AppData\Local\Conduit
Folder Deleted : C:\Users\\AppData\Local\torch
Folder Deleted : C:\Users\\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\\AppData\LocalLow\NCH_EN
Folder Deleted : C:\Users\\AppData\Roaming\Searchprotect
File Deleted : C:\Users\Public\Desktop\EZDownloader.lnk
File Deleted : C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\87pv5a55.default\searchplugins\Conduit.xml
File Deleted : C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\87pv5a55.default\searchplugins\conduit-search.xml
File Deleted : C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\87pv5a55.default\user.js
File Deleted : C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\z5mcwxfd.default-1379072010919\user.js
File Deleted : C:\Windows\System32\Tasks\BackgroundContainer Startup Task

***** [ Shortcuts ] *****

Shortcut Disinfected : C:\Users\Public\Desktop\Google Chrome.lnk
Shortcut Disinfected : C:\Users\Public\Desktop\Mozilla Firefox.lnk
Shortcut Disinfected : C:\Users\\Desktop\Internet Explorer.lnk
Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Shortcut Disinfected : C:\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Shortcut Disinfected : C:\Users\\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
Shortcut Disinfected : C:\Users\\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Shortcut Disinfected : C:\Users\\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
Shortcut Disinfected : C:\Users\\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
Shortcut Disinfected : C:\Users\\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk

***** [ Registry ] *****

Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [BackgroundContainer]
Key Deleted : HKLM\SOFTWARE\Classes\speedupmypc
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Mobogenie.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Search Protection]
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3282495
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{37483B40-C254-4A72-BDA4-22EE90182C1E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{079D463D-06B7-4A05-A737-7D4A09E3A3F5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{37483B40-C254-4A72-BDA4-22EE90182C1E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{37483B40-C254-4A72-BDA4-22EE90182C1E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{37483B40-C254-4A72-BDA4-22EE90182C1E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{079D463D-06B7-4A05-A737-7D4A09E3A3F5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C9B7C1CD-D2E2-4F42-BCCF-335AB7E971D5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7C510E1F-0EE1-4158-80DD-341C968A385A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{37483B40-C254-4A72-BDA4-22EE90182C1E}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{37483B40-C254-4A72-BDA4-22EE90182C1E}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{37483B40-C254-4A72-BDA4-22EE90182C1E}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{37483B40-C254-4A72-BDA4-22EE90182C1E}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\powerpack
Key Deleted : HKCU\Software\tuguu sl
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\BackgroundContainer
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\Software\NCH_EN
Key Deleted : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\supWPM
Key Deleted : HKLM\Software\Uniblue
Key Deleted : HKLM\Software\NCH_EN
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}

***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16384

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]

-\\ Mozilla Firefox v25.0.1 (en-US)

[ File : C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\87pv5a55.default\prefs.js ]

Line Deleted : user_pref(“CT2086743.serviceLayer_services_menu_762ad1e2c7654ebb5a87e30829f1ac53_lastUpdate”, “1388680885078”);
Line Deleted : user_pref(“CT2086743.serviceLayer_services_menu_8981a764e1ec213d5d9d86cc540a880f_lastUpdate”, “1388680885078”);
Line Deleted : user_pref(“CT2086743.serviceLayer_services_menu_aacaa9fbfd9e95e8e51c5f61ea87766a_lastUpdate”, “1388680885079”);
Line Deleted : user_pref(“CT2086743_Firefox.csv”, “[{\”from\”:\”Abs Layer\”,\”action\”:\”loading toolbar\”,\”time\”:1388680869081,\”isWithState\”:\”\”,\”timeFromStart\”:0,\”timeFromPrev\”:0}]”);
Line Deleted : user_pref(“Smartbar.ConduitHomepagesList”, “hxxp://”);
Line Deleted : user_pref(“Smartbar.ConduitSearchEngineList”, “”);
Line Deleted : user_pref(“Smartbar.ConduitSearchUrlList”, “”);
Line Deleted : user_pref(“Smartbar.keywordURLSelectedCTID”, “CT2086743”);
Line Deleted : user_pref(“”, “sweet-page”);
Line Deleted : user_pref(“”, “sweet-page”);
Line Deleted : user_pref(“browser.startup.homepage”, “hxxp://”);
Line Deleted : user_pref(“extensions.crossrider.bic”, “14353d4730eac0e1082cde37c80c229e”);
Line Deleted : user_pref(“plugin.state.npconduitfirefoxplugin”, 2);

[ File : C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\z5mcwxfd.default-1379072010919\prefs.js ]
-\\ Google Chrome v31.0.1650.63

[ File : C:\Users\\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted : homepage
Deleted : search_url
Deleted : keyword
Deleted : urls_to_restore_on_startup


MalwareBytes Anti-Malware free Clean your computer with using MalwareBytes Anti-Malware

Download MalwareBytes Anti-Malware

  • Install MalwareBytes Anti-Malware
  • Perform a Quick Scan
  • when scan is done, right click in the results and select “Check all items
  • Click “Remove Selected” button

Remove malware with MalwareBytes Anti-Malware Free

  • Reboot your computer
  • Enjoy a malware free computer.
Author: Max

Hi, I am Max. I am a computer security researcher. Every day I blog about new adware threats as they are released. I am also active in various online communities to help people with their computer problems. Stay safe!

Leave a Reply

Your email address will not be published.