Apusx: what it is and how to remove it
Apusx is a browser hijacker that is capable of altering browser's settings installed on any Windows computer. This potentially unwanted program (PUP) might infiltrate computer's unnoticed, alter browser's settings, change its startup page and display aggressive or questionable ads.
Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
Not sure what changed your search to bedynet.ru? An automatic scan checks extensions, programs and browser settings in one pass.
Do it yourself · free Remove Apusx yourself 5 steps, about 15 minutes, no software needed.
Start the steps
Apusx: summary
| Detection names | No Microsoft detection name is known |
|---|---|
| Distribution | Not recorded in the old report |
| Damage | Not recorded in the old report |
| Name | Apusx |
| Type | Search hijacker extension |
| Symptoms | A changed search engine |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 5 more facts
| Evidence | 4 write-ups by security sites; details still limited |
|---|---|
| Search page | bedynet.ru |
| Browsers | Chrome, Edge and Firefox |
| First seen | 24 January 2018 |
| Facts checked | 7 October 2026 |
Is Apusx dangerous? What it collects
From our report of Jan 2018 · not reviewed since
Apusx browser hijacker might cause unwanted changes on web browsers
Apusx is a browser hijacker that is capable of altering browser's settings installed on any Windows computer.
This potentially unwanted program (PUP) might infiltrate computer's unnoticed, alter browser's settings, change its startup page and display aggressive or questionable ads.
When Apusx virus gets into the system (usually with the help of free program installers), it alters browser's settings, including Google Chrome, Mozilla Firefox, Internet Explorer or other browsers that are supported by Windows OS.
Typically, the hijacker sets Apusx.com as browser's startup page. Researchers detected two versions of this website. One of them displays Windows Server webpage which provides Internet Information Services. Clicking on "Welcome" icon redirects to Microsoft IIS website.
The second version of the apusx.com is a suspicious search engine which is called a "Dreamer" and promoted as a "new way to explore the world." However, security specialists do not recommend trusting and using this Google-based search engine because it might trick you into visiting potentially dangerous websites.
Apusx.com virus might trigger unwanted redirects when you click on a specific link on the results page. Instead of redirecting you to the needed site, you might end up on a commercial third-party site. However, specialists from the bedynet.ru report about highly suspicious Apusx redirect tendencies when users are rerouted to phishing sites where they can lose personal information or money.
Additionally, the appearance of the browser hijacker might increase the risk of infiltration of other malware. Apusx might also display ads that might contain misleading or malicious content. Thus, it's highly recommended staying away from them and taking necessary measures for the hijacker's removal.
To sum up, Apusx might cause these problems on the affected computer:
In order to remove Apusx and change your homepage, you should perform a full system scan with a professional and updated anti-malware software. Tools like can easily locate all hijacker-related entries and wipe out this cyber threat within a couple of minutes.
However, if you can also opt for the manual Apusx removal. However, we want to warn that many users encountered difficulties with this method due to hijackers complexity. Though, we cannot stop you from trying to do it. Thus, we have provided detailed guidelines at the end of the article in order to help you.
- alteration of homepage or default search engine;
- installation of unknown browser add-ons or extensions without asking user's permissions;
- modification of Windows registry and browser's settings in order to prevent users from reverting all the changes;
- diminished browsing experienced due to the delivery of ads and redirects;
- the general sluggishness of the computer due to the above-mentioned activities or data tracking.


How Apusx got into your browser
From our report of Jan 2018 · not reviewed since
This potentially unwanted application spreads with the help of many programs that are available to download for free on various websites or P2P networks.
The majority of users make the major mistake when installing freeware, so they are potential targets of the Apusx hijack or installation of other unwanted apps.
The problem is that users employ "Recommended" or "Quick" installation settings that do not disclose about third-party applications that might be included in the software packages. However, using "Custom" or "Advanced" settings help to avoid this mistake.
When using "Advanced" installer, you have to unmark all pre-selected applications that are offered to download along with the primary program. It doesn't matter they promise to improve your browsing life or to optimize your PC, most of the time it's not true.
Check your browser and PC
- Address:
bedynet.ru
How to remove Apusx
How to remove Apusx and get your search engine back
Remove the extension first.
The search settings only stay fixed once nothing on the PC can change them again.
Step 1: Remove extensions you did not add
In Chrome open
chrome://extensions, in Edgeedge://extensions, and in Firefox the menu > Extensions and themes.Remove every extension you do not remember adding, especially search, new tab, coupon, PDF, weather or video downloader add-ons. Check every browser and every profile, because each keeps its own list.
If an extension has no Remove button or comes back, a browser policy holds it (see "Managed by your organization" in the procedure below). The pages are the same on Windows 11 and Windows 10.

Chrome on Windows 11: More > Extensions > Manage extensions. Full procedure with screenshots: Remove a browser extension
Step 2: Put the search engine back and delete bedynet.ru
In Chrome open Settings > Search engine > Manage search engines and site search, make an engine you trust the default, and delete
bedynet.rufrom the list.In Edge type
search engineinto the search box at the top of Settings and open Manage search engines; in Firefox use Settings > Search. Then check the homepage and the new tab page in the same settings, because hijackers change all three.If bedynet.ru is back after a restart, an extension, a program or a policy still sets it, so finish the other steps and check again. The settings are the same on Windows 11 and Windows 10.

Chrome on Windows 11: check Search engine and On startup. Full procedure with screenshots: Reset a browser and fix a hijacked search engine
Step 3: Uninstall programs you did not mean to install
Apusx rarely comes alone: it is usually installed by, or together with, a free program. In Windows 11 open Settings > Apps > Installed apps, in Windows 10 Settings > Apps > Apps & features, and sort by install date.
Uninstall every entry from the day the trouble began that you did not install on purpose, for example a download manager, a converter or a browser you never chose.
Keep drivers and entries from Microsoft, Intel, AMD, NVIDIA or your PC's maker unless you are sure.
Full procedure with screenshots: Uninstall a program or app in Windows On uGetFix
Step 4: Reset the browser
A reset removes what the steps above could miss:
- changed start pages
- site permissions
- hidden settings
In Chrome open Settings > Reset settings > Restore settings to their original defaults; in Edge Settings > Reset settings; in Firefox Help > More troubleshooting information > Refresh Firefox.
Tip: Bookmarks and saved passwords stay, while extensions are turned off and the search engine and start page return to the defaults.
Reset every browser on the PC, including Edge, which Windows 11 and Windows 10 always have.

Chrome on Windows 11: Settings > Reset settings. Full procedure with screenshots: Reset a browser and fix a hijacked search engine
Step 5: Scan the PC, then run the offline scan
A scan finds the parts of Apusx that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.
Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.
It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Instructions for each browser and system
The detailed steps for every browser and system this guide covers. Open the one you use.
Uninstall from Windows
To get rid of Apusx manually, follow these steps attentively and set your web browsers to the default state:
Uninstall from Windows 10/8:
- Type Control Panel into the Windows search box and open the result.
- Under Programs, select Uninstall a program.

Uninstall from Windows 7/XP:
- Click on Windows Start > Control Panel (Windows XP users should click on Add/Remove Programs).
- In Control Panel, select Programs > Uninstall a program.

Remove the unwanted program:
- In the Programs and Features window, look for any recently installed suspicious entries, select them, and click Uninstall.
- If User Account Control appears, click Yes to confirm, then complete the removal.

Remove from Google Chrome
Follow these steps to recover Google Chrome after the virus attack:
Delete malicious extensions from Google Chrome:
- Open Google Chrome, click on the Menu (three vertical dots at the top-right corner) and select More tools > Extensions.
- In the newly opened window, you will see all the installed extensions. Uninstall all suspicious extensions related to the unwanted program by clicking Remove.

Clear cache and web data from Chrome:
- Click on Menu and pick Settings.
- Under Privacy and security, select Clear browsing data.
- Select Browsing history, Cookies and other site data, as well as Cached images and files.
- Click Clear data.

Change your homepage:
- Click menu and choose Settings.
- Look for a suspicious site in the On startup section.
- Click on Open a specific or set of pages and click on three dots to find the Remove option.
Reset Google Chrome:
If the previous methods did not help you, reset Google Chrome to eliminate all the unwanted components:
- Click on Menu and select Settings.
- In the Settings, scroll down and click Advanced.
- Scroll down and locate Reset and clean up section.
- Now click Restore settings to their original defaults.
- Confirm with Reset settings.

Remove from Microsoft Edge
Delete unwanted extensions from MS Edge:
- Select Menu (three horizontal dots at the top-right of the browser window) and pick Extensions.
- From the list, pick the extension and click on the Gear icon.
- Click Remove.

Clear cookies and other browser data:
- Click on the Menu (three horizontal dots at the top-right of the browser window) and select Settings > Privacy, search, and services..
- Under Clear browsing data, pick Choose what to clear.
- Select Cookies and other site data and Cached images and files. (apart from passwords, although you might want to include Media licenses as well, if applicable) and click on Clear.

Restore new tab and homepage settings:
- Click the menu icon and choose Settings.
- Then find On startup section.
- Click Remove next to any suspicious startup page.
Reset MS Edge if the above steps did not work:
- Press on Ctrl + Shift + Esc to open Task Manager.
- Click on More details arrow at the bottom of the window.
- Select Details tab.
- Now scroll down and locate every entry with Microsoft Edge name in it. Right-click on each of them and select End Task to stop MS Edge from running.

Delete extensions from MS Edge (Chromium):
- Open Edge and click select Settings > Extensions.
- Delete unwanted extensions by clicking Remove.

Clear cache and site data:
- Click on Menu and go to Settings.
- Select Privacy, search and services.
- Under Clear browsing data, pick Choose what to clear.
- Under Time range, pick All time.
- Select Clear now.

Reset Chromium-based MS Edge:
- Click on Menu and select Settings.
- On the left side, pick Reset settings.
- Select Restore settings to their default values.
- Confirm with Reset.
- This will disable extensions and reset startup pages but will not delete bookmarks, saved passwords, or browsing history.

Remove from Mozilla Firefox (FF)
Uninstall suspicious Firefox extensions and reset its settings to remove Apusx.com from the startup page:
Remove dangerous extensions:
- Open Mozilla Firefox browser and click on the Menu (three horizontal lines at the top-right of the window).
- Select Add-ons.
- In here, select the unwanted extension and click Remove.

Reset the homepage:
- Click three horizontal lines at the top right corner to open the menu.
- Choose Settings.
- Under Home, set your preferred homepage and new tab settings.
Clear cookies and site data:
- Click Menu and pick Settings.
- Go to Privacy & Security section.
- Scroll down to locate Cookies and Site Data.
- Click on Clear Data...
- Select Cookies and Site Data and Temporary cached files and pages, then click Clear.

Reset Mozilla Firefox
If clearing the browser as explained above did not help, reset Mozilla Firefox:
- Open Mozilla Firefox browser and click the Menu.
- Go to Help and then choose Troubleshooting Information.

- Under Give Firefox a tune up section, click on Refresh Firefox...
- Once the pop-up shows up, confirm the action by pressing on Refresh Firefox.

Delete from Safari
Remove dangerous extensions:
- Open Safari, click Safari in the menu at the top-left of the screen, and select Preferences.
- Go to the Extensions tab, look for any suspicious entries, and click Uninstall to remove them.

Clear history and website data:
- Click Safari in the menu and pick Clear History.
- Set Clear to all history and confirm with Clear History.

Reset Safari:
- Click Safari in the menu and select Preferences > Advanced.
- Enable Show Develop menu in menu bar.
- From the menu bar, click Develop and select Empty Caches.

Delete from macOS
Remove the unwanted application:
- From the menu bar, select Go > Applications.
- In the Applications folder, look for any suspicious entries, then drag them to Trash (or right-click and pick Move to Trash).

Delete leftover files and folders:
- Select Go > Go to Folder.
- Enter /Library/Application Support and remove any suspicious folders related to the unwanted program.
- Repeat the same check in the /Library/LaunchAgents and /Library/LaunchDaemons folders, deleting any suspicious entries.

- Finally, empty the Trash to permanently remove the leftovers.
Reset Internet Explorer
After the hijack, follow these steps to fix Internet Explorer:
Remove dangerous add-ons:
- Open Internet Explorer, click on the Gear icon (IE menu) on the top-right corner of the browser
- Pick Manage Add-ons.
- You will see a Manage Add-ons window. Here, look for suspicious plugins. Click on these entries and select Disable.

Change your homepage if it was altered:
- Open IE and click on the Gear icon.
- Select Internet Options.
- In the General tab, delete the Home page address and replace it by your preferred one (for example, Google.com).
- Click Apply and then select OK.

Delete temporary files:
- Press on the Gear icon and select Internet Options.
- Under Browsing history, click Delete...
- Select relevant fields and press Delete.

Reset Internet Explorer:
- Click on Gear icon > Internet options and select Advanced tab.
- Select Reset.
- In the new window, check Delete personal settings and select Reset.

Access your website securely from any location
When you work on the domain, site, blog, or different project that requires constant management, content creation, or coding, you may need to connect to the server and content management service more often. The best solution for creating a tighter network could be a dedicated/fixed IP address.
If you make your IP address static and set to your device, you can connect to the CMS from any location and do not create any additional issues for the server or network manager that needs to monitor connections and activities. VPN software providers like can help you with such settings and offer the option to control the online reputation and manage projects easily from any part of the world.
Recover files after data-affecting malware attacks
While much of the data can be accidentally deleted due to various reasons, malware is one of the main culprits that can cause loss of pictures, documents, videos, and other important files.
More serious malware infections lead to significant data loss when your documents, system files, and images get encrypted. In particular, ransomware is is a type of malware that focuses on such functions, so your files become useless without an ability to access them.
Even though there is little to no possibility to recover after file-locking threats, some applications have features for data recovery in the system. In some cases, can also help to recover at least some portion of your data after data-locking virus infection or general cyber infection.
From our report of Jan 2018 · not reviewed since
Remove Apusx.com and get back access to your web browser
In the first part of the article, we have mentioned two possible Apusx removal methods.
One of them is automatic which requires just scanning the device with reputable anti-malware software.
Another way to remove Apusx.com allows looking for hijacker-related components manually. We have provided detailed instructions that will help you to succeed with the removal. However, if you fail and hijacker comes back, please switch to the automatic elimination.
Questions about Apusx
Why does my search engine keep changing to bedynet.ru?
Because something keeps setting it. An extension can change the search engine every time the browser starts, and an ad-supported program in Windows can do it for every browser and re-add the extension after you remove it. Some hijackers also add a policy that locks the setting.
Changing the search engine back only works once the source is gone. Remove extensions you do not recognise, uninstall programs installed around the time bedynet.ru first appeared, and then set the search engine again. If it still returns, check the browser for the Managed by your organization message and follow the policy steps in this guide.
Did bedynet.ru come with a program I installed?
Most likely, yes. Search hijackers such as bedynet.ru usually arrive with free software, where an extra offer is pre-ticked in the installer, or as an extension that promises something useful, such as file conversion, maps, recipes or streaming.
Look at Settings, Apps, Installed apps sorted by install date: whatever was installed just before the search engine changed is the main suspect. Uninstall it, then remove any extension you do not recognise. In future, choose the custom or advanced option in installers and untick extra offers, and install extensions only from the official store pages of publishers you know.
What is bedynet.ru?
It is the search page used by the browser hijacker Apusx. It has no search index of its own: it forwards your queries to another search engine and adds ads and tracking along the way.
People rarely choose it on purpose; it becomes the default search engine, home page or new tab after an extension, program or policy changes the browser settings. The page itself is not malware, but it should not be in your browser if you did not set it. The steps above remove the source and restore your settings.
Is bedynet.ru dangerous?
It is not designed to infect the PC, but it is not neutral either. It logs searches, adds sponsored results that are hard to tell apart from real ones, and its ad partners are not checked as strictly as those of major search engines.
Some hijacker pages have shown ads for fake updates, tech support scams and unwanted software. The main harm is to privacy. Remove Apusx, and if you entered personal data on sites reached through its results, check those sites carefully.
Do I have to fix every browser?
Yes, every one where the search engine or start page changed. In the cases we checked, Apusx affected Chrome, Edge and Firefox.
Each browser stores its own search settings and extensions, so fixing one does not fix the others, and Windows-level changes such as shortcuts can affect each browser differently. Work through them one at a time:
- remove the extension
- check the policies
- restore the search engine
- start page
If you sync a browser, stay signed in so the fix spreads to your other computers.
Did bedynet.ru record my searches?
Almost certainly. Logging is the point of a hijacker search page: each query, with your IP address, browser details and the result you clicked, is valuable to advertisers.
The operators of bedynet.ru can store and share that data under their own privacy policy, which you never agreed to knowingly. There is no way to delete it from their side. What you can do is stop the flow:
- remove Apusx
- clear cookies and site data for bedynet.ru
- treat sensitive searches made in the meantime as known to a third party
Why can't I change my search engine back?
Because something keeps setting it. If an extension controls the search engine, Chrome and Edge show a note that an extension is controlling this setting, and your change is reverted. If a policy controls it, the field is greyed out and the browser shows Managed by your organization.
Remove the extension first, then the policies, and only then change the search engine; the change will stay. If it still reverts, look for a program in Installed apps or a scheduled task that reinstalls the extension.
What do I lose if I reset Chrome or Edge?
Less than you might think. A reset turns off all extensions, which you can turn back on one by one, restores the default search engine, home page, new tab and pinned tabs, and clears cookies, so you are signed out of most sites.
Bookmarks, history, saved passwords and autofill data stay. Firefox's equivalent, Refresh Firefox, keeps the same essentials but removes add-ons completely. Before you reset, make sure you know your main passwords or have them saved, since you will need to sign in again.
Can I just block bedynet.ru?
You can, but it treats the symptom. Blocking the domain in a firewall or the hosts file makes searches fail instead of redirecting, while the extension or program that set it keeps running and collecting data.
Hijacker operators also switch to new domains in updates, so a block may stop working within weeks. Remove the source instead, then set your own search engine. If you want extra protection afterwards, turn on Potentially unwanted app blocking in Windows Security, which stops many hijacker installers before they run.
Will Fortect remove Apusx?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For Apusx, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- FTC: How to recognize, remove and avoid malware (read October 7, 2026)
- Microsoft Learn: Microsoft Defender Offline (read October 7, 2026)
- Microsoft Learn: How Microsoft names malware (read October 7, 2026)