Wish-you.co ads: what it is and how to remove it

Wish-you.co is the potentially unwanted program that appears on the screen out of nowhere because it gets triggered by the adware-type intruder installed on the machine. The shady service is promoted and mainly used by unsuspected users that believe the usefulness of the holiday greetings generating service.

Facts checked October 6, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

A scan of the PC is a quick way to confirm that nothing installed is behind the wish-you.co redirects.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove Wish-you.co ads yourself 3 steps, about 9 minutes, no software needed.

Start the steps
Wish-you.co: wishyou co virus
Wish-you.co as our 2020 report showed it.

Wish-you.co ads: summary

DistributionThe deceptive page is used as a service for generating greetings, so people send such links to their loved ones. However, a potentially unwanted program that is responsible for these redirects gets installed during the insecure freeware installation process that includes bundles of PUPs
NameWish-you.co
TypeAdware/ redirect virus
DangerThe site redirects to third-party domains and is not responsible for the malicious content that users get exposed to. Unfortunately, adware is related to many questionable advertisers and content creators that aim to get views, pay-per-click revenue from visitors, and traffic. Online advertisements and other shady material involves ad-tracking and triggers privacy issues or even identity theft
Detection namesNo Microsoft detection name is known
DamageNot recorded in the old report
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 7 more facts
SymptomsRedirects to an unknown domain
Evidence4 write-ups by security sites; details still limited
Domainswish-you.co
Ads shown asRedirects through ad pages
BrowsersChrome, Edge and Firefox
First seen6 January 2020
Facts checked6 October 2026

Is Wish-you.co ads dangerous?

From our report of Jan 2020 · not reviewed since

PUPs get to be installed during the insecure installations of desired apps

Programs that focus on traffic reroutes and cause other issues regarding online surfing are silent intruders.

PUP developers rely on bad habits that many internet users have:

These are the main reasons why adware, browser hijackers, and other threats find the way on the system that easily. Clicking on deceptive content, pop-ups, banners, and other questionable material leads to sites where malicious scripts can get triggered.

Also, experts always talk about insecure installations that involve software bundling and directly distribute PUPs. Avoid recommended and quick installation options - choose Advanced or Custom instead and deselect any suspicious apps from the list when you can.

  • using torrent services;
  • skipping through important steps;
  • clicking on commercial content despite the possible danger.

From our report of Jan 2020 · not reviewed since

More from our earlier report on Wish-you.co

  • Wish-you.co removal gives the best results when you use the proper AV tool and scan the machine fully.
  • Such software detects and removes malicious programs or files and makes the PC running smoothly again
  • Note that potentially unwanted programs mainly run in the background, so settings and particular functions may get affected without your permission.
  • Rely on system tools like that may find and fix damaged Windows registry entries or recover the default settings

How Wish-you.co ads got into your browser

From our report of Jan 2020 · not reviewed since

Wish-you.co is the potentially unwanted program that appears on the screen out of nowhere because it gets triggered by the adware-type intruder installed on the machine.

The shady service is promoted and mainly used by unsuspected users that believe the usefulness of the holiday greetings generating service. However, people that receive such messages and get redirected to the shady page can notice suspicious activities instead of enjoying greetings.

First of all, Wish-you.co virus gets a name like this by users online that get affected by the adware-type threat, which is delivered with the help of this redirect program.

When you get exposed to the colorful page and click on anything displayed before you, additional content appears in the form of pop-ups, browser windows, and so on. Then, triggered scripts can pose a threat on your device and anything you click on, lead to malicious pages.

Further analysis of the processes happening due to such Wish-you.co redirects showed that malicious script could get installed on the machine easily. Also, other vulnerabilities may expose you to malware attacks and inject tracking cookies to browsing tool. This simple greeting platform leads to privacy issues and can surely be considered a potentially unwanted program and possibly harmful to the machine.

Wish-you.co is the website used by questionable people that target various credentials with these shady websites and messages, including links to other sites. Such messages appeared during the Christmas and New Years, so people were not paying enough attention to the content they clicked on got exposed to malicious and dangerous material online.

There are tons of such sites that ask for people to enter their names, email addresses, other personal information. However, when people do what Wish-you.co pop-ups ask, programming script that is possibly malicious is executed and searches for additional information that may be valuable for scammers later on.

If malicious people can access the information, social media credentials Wish-you.co links can get directly sent to people without victims' permission. Links back to the malicious site reroutes tons of users and exposes them to potential threats. During the holidays, such greetings are not raising too many questions, so it is more successful for PUP developers and distributors.

People who encountered the redirects to Wish-you.co also state that the form appeared once and only asked for the name of the user. If that happens to you, try to interact with the site as little as possible and don't enter any personal information when asked. You can avoid further damage if you get back to normal browsing as soon as possible.

Even though the site itself has a disclaimer about data tracking issues, you shouldn't trust the service or PUP developers because all the sites that you end up visiting have different policies and terms, so each site can collect different details about you. This is the most dangerous feature of adware-type programs and other cyber intruders.

Since Wish-you.co can be categorized as an adware-type intruder you can encounter other typical symptoms like:

You need to remove Wish-you.co immediately when you noticed at least one of these features and redirects to a questionable page similar to the mentioned URL. There is no other way that could provide such results as automatic AV tools and a full system scan.

Exiting the browser window is not helping since you just avoid malicious content. The potentially unwanted program that runs in the background of your device needs to be terminated fully to end the process of redirecting.

Such free applications can also install other unwanted content like browser extensions, toolbars, utilities, and browsing tools, so make sure to run Wish-you.co removal as soon as possible and avoid further infections, virus damage, and so on. Also, get a PC tool like to tackle possible damage in system settings, folders, and places like the registry.

When such intruder started appearing in the user complaints Wish-you.co got further analyzed by researchers and such investigations revealed that IP addresses associated with this and other sites belong to Cloudflare ID address that is a name known for unwanted and intrusive behavior involving commercial content and online threats.

You need to terminate the shady program that is causing these redirects to Wish-you.co and other suspicious domains. By cleaning the machine and terminating the potentially unwanted programs, you can improve the general performance of your device.

  • web browser redirects;
  • content injected on commonly visited pages;
  • pop-ups, banners, blinking boxes with promotional material;
  • new entries added in Programs folder;
  • in-browser content installed without your permission;
  • the slowness of the internet and the device generally;
  • disabled security programs and functions.
Wish-you.co: wishyou co virus
Wish-you.co in our 2020 report.
Wish-you.co: wishyou co redirects
Wish-you.co in our 2020 report.

Check your browser and PC

  • Address: wish-you.co

How to remove Wish-you.co ads

How to stop the Wish-you.co redirects

Work in this order and test a few links after each step, so you know which one was the cause.

  1. Step 1: Check the browser's extensions

    A browser that keeps landing on wish-you.co by itself usually has an add-on doing it. Open the extension list (chrome://extensions, edge://extensions, or Extensions and themes in the Firefox menu) and remove anything you do not remember installing.

    Coupon, PDF, new tab, search and video downloader add-ons are the usual suspects. Do this in every browser on the Windows 11 or Windows 10 PC.

    Chrome menu with Extensions and Manage extensions highlighted
    Chrome on Windows 11: More > Extensions > Manage extensions.

    Full procedure with screenshots: Remove a browser extension

  2. Step 2: Reset the browser if the redirects continue

    When wish-you.co keeps opening after the extensions are cleaned, reset the browser to its defaults. Chrome: Settings > Reset settings > Restore settings to their original defaults; Edge: Settings > Reset settings; Firefox: Help > More troubleshooting information > Refresh Firefox.

    A reset keeps bookmarks and saved passwords but clears site permissions, the start page and the search engine.

    If every browser still redirects afterwards, the cause is a program in Windows 11 or Windows 10: check Settings > Apps > Installed apps for anything you did not install.

    Chrome Settings page with the Reset settings section open
    Chrome on Windows 11: Settings > Reset settings.

    Full procedure with screenshots: Reset a browser and fix a hijacked search engine

  3. Step 3: Scan the PC if you downloaded anything from the ads

    Most people who only saw the notifications can skip this step. If a notification or the page it opened made you download or run a file, delete the file and run a full scan, then a Microsoft Defender Offline scan.

    In Windows 11 and Windows 10 open Windows Security > Virus & threat protection > Scan options, select Microsoft Defender Antivirus (offline scan) and click Scan now. The PC restarts and the scan takes about 15 minutes, so save your work first.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

Instructions for each browser and system

The detailed steps for every browser and system this guide covers. Open the one you use.

Uninstall from Windows

Get rid of Wish-you.co and related threats by following these steps fully

Uninstall from Windows 10/8:

  1. Type Control Panel into the Windows search box and open the result.
  2. Under Programs, select Uninstall a program.Uninstall from Windows 10/8

Uninstall from Windows 7/XP:

  1. Click on Windows Start > Control Panel (Windows XP users should click on Add/Remove Programs).
  2. In Control Panel, select Programs > Uninstall a program.Uninstall from Windows 7/XP

Remove the unwanted program:

  1. In the Programs and Features window, look for any recently installed suspicious entries, select them, and click Uninstall.
  2. If User Account Control appears, click Yes to confirm, then complete the removal.Uninstall the unwanted program from Windows
Remove from Google Chrome

You need to go through settings on the browser or fully reset Chrome, so all the changes get reversed

Delete malicious extensions from Google Chrome:

  1. Open Google Chrome, click on the Menu (three vertical dots at the top-right corner) and select More tools > Extensions.
  2. In the newly opened window, you will see all the installed extensions. Uninstall all suspicious extensions related to the unwanted program by clicking Remove.Remove extensions from Chrome

Clear cache and web data from Chrome:

  1. Click on Menu and pick Settings.
  2. Under Privacy and security, select Clear browsing data.
  3. Select Browsing history, Cookies and other site data, as well as Cached images and files.
  4. Click Clear data.Clear cache and web data from Chrome

Change your homepage:

  1. Click menu and choose Settings.
  2. Look for a suspicious site in the On startup section.
  3. Click on Open a specific or set of pages and click on three dots to find the Remove option.

Reset Google Chrome:

If the previous methods did not help you, reset Google Chrome to eliminate all the unwanted components:

  1. Click on Menu and select Settings.
  2. In the Settings, scroll down and click Advanced.
  3. Scroll down and locate Reset and clean up section.
  4. Now click Restore settings to their original defaults.
  5. Confirm with Reset settings.Reset Chrome 2
Remove from Microsoft Edge

Delete unwanted extensions from MS Edge:

  1. Select Menu (three horizontal dots at the top-right of the browser window) and pick Extensions.
  2. From the list, pick the extension and click on the Gear icon.
  3. Click Remove.Remove extensions from Edge

Clear cookies and other browser data:

  1. Click on the Menu (three horizontal dots at the top-right of the browser window) and select Settings > Privacy, search, and services..
  2. Under Clear browsing data, pick Choose what to clear.
  3. Select Cookies and other site data and Cached images and files. (apart from passwords, although you might want to include Media licenses as well, if applicable) and click on Clear.Clear Edge browsing data

Restore new tab and homepage settings:

  1. Click the menu icon and choose Settings.
  2. Then find On startup section.
  3. Click Remove next to any suspicious startup page.

Reset MS Edge if the above steps did not work:

  1. Press on Ctrl + Shift + Esc to open Task Manager.
  2. Click on More details arrow at the bottom of the window.
  3. Select Details tab.
  4. Now scroll down and locate every entry with Microsoft Edge name in it. Right-click on each of them and select End Task to stop MS Edge from running.Reset MS Edge
Instructions for Chromium-based Edge

Delete extensions from MS Edge (Chromium):

  1. Open Edge and click select Settings > Extensions.
  2. Delete unwanted extensions by clicking Remove.Remove extensions from Chromium Edge

Clear cache and site data:

  1. Click on Menu and go to Settings.
  2. Select Privacy, search and services.
  3. Under Clear browsing data, pick Choose what to clear.
  4. Under Time range, pick All time.
  5. Select Clear now.Clear browser data from Chroum Edge

Reset Chromium-based MS Edge:

  1. Click on Menu and select Settings.
  2. On the left side, pick Reset settings.
  3. Select Restore settings to their default values.
  4. Confirm with Reset.
  5. This will disable extensions and reset startup pages but will not delete bookmarks, saved passwords, or browsing history.Reset Chromium Edge
Remove from Mozilla Firefox (FF)

Remove any suspicious applications from Firefox when you find them

Remove dangerous extensions:

  1. Open Mozilla Firefox browser and click on the Menu (three horizontal lines at the top-right of the window).
  2. Select Add-ons.
  3. In here, select the unwanted extension and click Remove.Remove extensions from Firefox

Reset the homepage:

  1. Click three horizontal lines at the top right corner to open the menu.
  2. Choose Settings.
  3. Under Home, set your preferred homepage and new tab settings.

Clear cookies and site data:

  1. Click Menu and pick Settings.
  2. Go to Privacy & Security section.
  3. Scroll down to locate Cookies and Site Data.
  4. Click on Clear Data...
  5. Select Cookies and Site Data and Temporary cached files and pages, then click Clear.Clear cookies and site data from Firefox

Reset Mozilla Firefox

If clearing the browser as explained above did not help, reset Mozilla Firefox:

  1. Open Mozilla Firefox browser and click the Menu.
  2. Go to Help and then choose Troubleshooting Information.Reset Firefox 1
  3. Under Give Firefox a tune up section, click on Refresh Firefox...
  4. Once the pop-up shows up, confirm the action by pressing on Refresh Firefox.Reset Firefox 2
Delete from Safari

Remove dangerous extensions:

  1. Open Safari, click Safari in the menu at the top-left of the screen, and select Preferences.
  2. Go to the Extensions tab, look for any suspicious entries, and click Uninstall to remove them.Remove extensions from Safari

Clear history and website data:

  1. Click Safari in the menu and pick Clear History.
  2. Set Clear to all history and confirm with Clear History.Clear history from Safari

Reset Safari:

  1. Click Safari in the menu and select Preferences > Advanced.
  2. Enable Show Develop menu in menu bar.
  3. From the menu bar, click Develop and select Empty Caches.Reset Safari
Delete from macOS

Remove the unwanted application:

  1. From the menu bar, select Go > Applications.
  2. In the Applications folder, look for any suspicious entries, then drag them to Trash (or right-click and pick Move to Trash).Uninstall from Mac

Delete leftover files and folders:

  1. Select Go > Go to Folder.
  2. Enter /Library/Application Support and remove any suspicious folders related to the unwanted program.
  3. Repeat the same check in the /Library/LaunchAgents and /Library/LaunchDaemons folders, deleting any suspicious entries.Delete leftover files from Mac
  4. Finally, empty the Trash to permanently remove the leftovers.
Reset Internet Explorer

Remove dangerous add-ons:

  1. Open Internet Explorer, click on the Gear icon (IE menu) on the top-right corner of the browser
  2. Pick Manage Add-ons.
  3. You will see a Manage Add-ons window. Here, look for suspicious plugins. Click on these entries and select Disable.Remove add-ons from Internet Explorer

Change your homepage if it was altered:

  1. Open IE and click on the Gear icon.
  2. Select Internet Options.
  3. In the General tab, delete the Home page address and replace it by your preferred one (for example, Google.com).
  4. Click Apply and then select OK.Reset IE homepage

Delete temporary files:

  1. Press on the Gear icon and select Internet Options.
  2. Under Browsing history, click Delete...
  3. Select relevant fields and press Delete.Clear temporary files from Internet Explorer

Reset Internet Explorer:

  1. Click on Gear icon > Internet options and select Advanced tab.
  2. Select Reset.
  3. In the new window, check Delete personal settings and select Reset.Reset Internet Explorer

Stream videos without limitations, no matter where you are

There are multiple parties that could find out almost anything about you by checking your online activity.

While this is highly unlikely, advertisers and tech companies are constantly tracking you online. The first step to privacy should be a secure browser that focuses on tracker reduction to a minimum.

Even if you employ a secure browser, you will not be able to access websites that are restricted due to local government laws or other reasons. In other words, you may not be able to stream Disney+ or US-based Netflix in some countries. To bypass these restrictions, you can employ a powerful VPN, which provides dedicated servers for torrenting and streaming, not slowing you down in the process.

Data backups are important - recover your lost files

Ransomware is one of the biggest threats to personal data.

Once it is executed on a machine, it launches a sophisticated encryption algorithm that locks all your files, although it does not destroy them. The most common misconception is that anti-malware software can return files to their previous states. This is not true, however, and data remains locked after the malicious payload is deleted.

While regular data backups are the only secure method to recover your files after a ransomware attack, tools such as can also be effective and restore at least some of your lost data.

From our report of Jan 2020 · not reviewed since

Wish-you.co elimination should be quick if you use needed tools

You need to remember that any website that shows commercial content, causes redirects, pop-ups, and different intrusive symptoms like so-called Wish-you.co virus, cannot be categorized as malware due to lack of damage that PUP makes to the machine. Serious cyber infections lead to crucial changes in system settings or even functions.

It is important to consider all the possible threats, results, and issues regarding the Wish-you.co removal when you try to eliminate the adware, potentially unwanted program, or a browser hijacker. If you try to delete in-browser applications, extensions, and the direct programs that cause all the symptoms, you still end up with PUP infection running in the background.

The best tip for you is to remove Wish-you.co by scanning the machine with an anti-malware program that can find all malicious behavior-based programs and get rid of them completely.

Questions about Wish-you.co ads

Why does my browser keep going to wish-you.co?

Something is sending it there. On one site only, that site's ads are the cause and leaving the site ends it.

On many different sites, the usual causes are an extension you installed with something else, a site you once allowed to send notifications, or an ad-supported program in Windows that changes how the browser behaves. wish-you.co itself is only a stop on the way: it records the visit and forwards you to whatever advertiser pays most.

Check the extensions page, then the list of sites allowed to send notifications, then Installed apps sorted by date. Removing the cause stops the redirects; blocking the domain alone usually does not, because the network moves to a new one.

Should I worry about redirects to wish-you.co?

Worry less about wish-you.co itself and more about what keeps sending you there. A single redirect from a free streaming or download site is normal and harmless once the tab is closed.

Repeated redirects on sites that used to work fine mean something in the browser or in Windows changed, often an extension or program installed alongside other software. It may also collect the pages you visit. Remove the cause with the steps in this guide, and do not act on anything the redirected pages ask:

  • no Allow clicks
  • no downloads
  • no calls

If you already did one of those, the matching section of this guide explains what to do next.

What is Wish-you.co?

Wish-you.co is an ad redirect domain, a kind of adware. It earns money by showing redirects through ad pages, and each view, click or redirect pays whoever runs it. It is not something people usually choose; it arrives through a free download, a fake button or a misleading prompt.

Wish-you.co does not encrypt files or take control of Windows, but its ads are sold to anyone, including scam operators, so they can lead to fake virus warnings and unwanted downloads. The steps in this guide remove it from Windows and from each browser.

Why does wish-you.co keep showing up?

There are two possible reasons. If it appears as desktop notifications, a browser on this PC was given permission to receive them from wish-you.co, usually through a misleading prompt. That permission stays until you remove it in the browser's site settings.

If it appears as tabs or redirects, an ad on a site you visit is opening it, or an extension or program on the PC is. Test a private window: if wish-you.co never appears there, an extension is the likely cause. The plan above covers each case.

Which browsers does Wish-you.co affect?

In the cases we checked, Wish-you.co showed up in Chrome, Edge and Firefox. That does not rule out others on your PC, since adware installers often target every browser they find, and permissions and extensions sync across computers signed in to the same browser account.

Open each browser you have, go to its extensions page and its notification settings, and remove anything you do not recognise. Profiles count separately: Chrome and Edge can each hold several, and each one needs checking on its own.

Are the pop-ups I see really from Wish-you.co?

Compare them with the details in the table above. Wish-you.co produces redirects through ad pages, and the clearest sign of it is redirects to wish-you.co. Other adware looks similar, so check the name of the sending site at the bottom of a notification, the address in the tab that opened, or the newest entries on the extensions page.

If those match, this guide fits. If you see a different name, the same kind of steps apply, but remove the item you actually find rather than guessing.

Can an adware pop-up infect my PC just by appearing?

No. A pop-up, a notification or a new tab is only a web page or a message. It cannot run programs on Windows by itself, provided the browser and Windows are up to date. Infection needs a step from you:

  • running a downloaded file
  • installing an extension
  • giving a stranger remote access

That is why scam pages work so hard to make you click. Close such pages with the tab's X or by closing the browser, not with buttons inside the page, which may start a download.

I let a "support technician" from an ad connect to my PC. What should I do?

Act quickly but calmly. Disconnect the PC from the internet first, so the connection ends. Uninstall the remote access tool they asked you to install and check Installed apps for anything else added during the call.

Run a Microsoft Defender full scan and offline scan. From another device, change your e-mail and banking passwords and sign out of all sessions.

If you paid by card, bank transfer or gift card, contact your bank or the card issuer immediately, and report the scam to the police. Do not answer if they call back.

My scan found nothing, but the ads continue. Why?

Because the source may not be a file a scanner looks for. Browser notifications are a permission stored in the browser, and many adware extensions are not flagged because they come from an official store.

Some ad-supported programs are only reported if you enable detection of potentially unwanted apps. So a clean scan does not mean the job is done. Check each browser's notification permissions and extension list by hand, and turn on Potentially unwanted app blocking in Windows Security before scanning again.

Will Fortect remove Wish-you.co?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For Wish-you.co, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

  1. Privacy: How cookies track you around the web and how to stop them (read October 6, 2026)
  2. Wikipedia: Potentially unwanted program (read October 6, 2026)
  3. Google Chrome Help: Use notifications to get alerts (no longer online) (read October 6, 2026)
  4. FTC: How to recognize, remove and avoid malware (read October 6, 2026)
  5. Microsoft Learn: Microsoft Defender Offline (read October 6, 2026)

More removal guides

Remove Immediate Action Required

Immediate Action Required is a fake notification that might pop-up out of nowhere and prompt users to download useless bogus software Immediate Action Required is a scam that users mightAdwareMedium riskUgnius Kiguolis ·

Remove ReceiverHelper Mac virus

ReceiverHelper virus is a high threat to your personal safety and Mac security ReceiverHelper is a harmful application targeting Mac devices, classified under the Adload malware family. It is notoriousAdwareMedium riskJake Doevan ·

Remove Casalemedia

Casalemedia is a legal advertising service but is sometimes abused by crooks to gain personal income Casalemedia is a legitimate advertising service that provides assistance in monetizing on online contentAdwareMedium riskJake Doevan ·

Remove D1ue3yi0hkdsdl.cloudfront.net ads

D1ue3yi0hkdsdl.cloudfront.net ads is the content related to scam campaigns and fake errors or warnings D1ue3yi0hkdsdl.cloudfront.net is the program that causes notifications and advertisements that may appear unexpectedly, preventing you fromAdwareMedium riskJulie Splinters ·

Questions and experiences: Wish-you.co ads

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,442 members already hereReading, writing, commenting and voting. 0 verified · 167 joined this year