Severity scale:  

Remove virus (Removal Guide) - updated Aug 2017

removal by Ugnius Kiguolis - - | Type: Browser hijacker a search engine that tells you what to search virus virus is a browser hijacker [1] which has mostly been spreading around in Russian-speaking countries [2]. However, unlike most viruses of the sort, after infiltrating the system and altering browser’s settings, this parasite does not add its own URL instead of the home page and a new tab page. Instead, it uses other URLs (e.g., or that automatically redirect people to the needed site.

If such redirects have been interrupting you for a while, you can stop them with the help of removal. For that we recommend using Reimage.

Workno can infiltrate almost every computer because it spreads as an optional component of the freeware. To see such components, you have to be very attentive while downloading freeware, such as download managers, PDF creators, video streaming software and similar programs.

Step-by-step recommendations for avoiding are given later in the post. Besides, you can find a comprehensive removal guide that could be used for getting rid of this hijacker at the end of this article, too. But before we get to that, we'd like to talk about how does this malware operate.

Once the potentially unwanted program (PUP) [3] enters the system, it modifies some of its settings for its own needs. For example, it sets itself to run automatically when the computer starts and adds its registry entries to prevent its removal. When the user starts the system and launches web browser, malicious processes open site.

Questions about virus

The picture of virus seems like a legitimate search engine (illustrated above), but you should be very careful with its results. Some of them may send you to dangerous parts of the web!

From the first sight, it may seem that this search site presents various articles, news, weather forecast and also provides a search engine. We do not recommend browsing the web via this site, as it is believed that it contains untrustworthy links.

Besides, you should not rely on the search engine that it provides, as it was noticed that it triggers redirects to questionable websites sometimes. redirect issue may force you to enter high-risk web pages, and such pages can be filled with malicious content.

Be aware of the fact that dangerous websites can advertise malware programs or urge you to enter personally identifiable information. Bad news is that hazardous web pages are designed to look trustworthy, and inexperienced computer users often fail to understand which site is reliable and which one is not.

It goes without saying that it is better to be safe than sorry. If you believe that you are infected with WorkNo, we highly recommend you to remove from the system as soon as possible. As we have already mentioned, it can be done using an anti-malware software. Just install it and scan your PC for threats.

The different ways you can get infected with this malware

Understanding how hijack works is not a simple task, especially if you are not particularly tech-savvy. However, this does not mean you cannot protect your computer and avoid browser hijacker infiltration. But to do that, you have to remember the main vector of their distribution.

The most popular method used for spreading such unwanted programs is called “bundling”. This technique lets and similar questionable apps travel around with other free programs without getting banned. There are a few things you should remember about this software distribution technique: 

  • Firstly, software bundles may carry PUPs labeled as “recommended downloads”, so you should try to stay away from such misleading “recommendations.”
  • Secondly, you don't have to install these recommended downloads if you don't want to. You may cancel their installation by opting for Advanced or Custom setup modes and deselect every optional component added to your selected piece of software.
  • Finally, you must learn to recognize unsafe websites and try to bypass them. These unsafe domains typically spread PUP-laden software packages, so by avoiding them, you will also be more less likely to download one of them on your PC.

Remove and prevent further unauthorized changes

You should be aware of the fact that third party programs can make arbitrary changes to your computer system without your approval. So if you notice some suspicious activities on your computer, you should scan it with a reliable anti-malware software like Reimage and see what spyware or malware-type software resides in the system.

Speaking of virus, it is a slightly more complicated program compared to other browser hijackers. If you have never tried to delete potentially unwanted programs manually, it might seem like a difficult task to do.

However, do not rush to judge yourself – many computer users do not know how to do it, too, so that is why we have prepared these removal instructions. They are complemented with pictures, and we believe that you will find them useful when trying to find all components of this browser hijacker.

Nevertheless, if you do not want to waste your time trying to understand these instructions and if you would rather like to solve the issue automatically, you can just run the anti-malware application and let it remove for you.

You can remove virus damage automatically with a help of one of these programs: Reimage, SpyHunter 5Combo Cleaner, Malwarebytes. We recommend these applications because they detect potentially unwanted programs and viruses with all their files and registry entries that are related to them.

do it now!
Reimage (remover) Happiness
Reimage (remover) Happiness
Compatible with Microsoft Windows Supported versions Compatible with OS X Supported versions
What to do if failed?
If you failed to remove virus damage using Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to remove virus damage. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.
Alternative Software
Different security software includes different virus database. If you didn’t succeed in finding malware with Reimage, try running alternative scan with SpyHunter 5.
Alternative Software
Different security software includes different virus database. If you didn’t succeed in finding malware with Reimage, try running alternative scan with Combo Cleaner.

To remove virus, follow these steps:

Get rid of from Windows systems

As we have mentioned earlier, virus redirects its victims to,, and similar domains. They have to be uninstalled as well if you want to remove it without giving it a chance to come back. That's why we highly recommend going thru all recently installed programs and uninstalling suspicious entries.

  1. Click Start Control Panel Programs and Features (if you are Windows XP user, click on Add/Remove Programs). Click 'Start -> Control Panel -> Programs and Features' (if you are 'Windows XP' user, click on 'Add/Remove Programs').
  2. If you are Windows 10 / Windows 8 user, then right-click in the lower left corner of the screen. Once Quick Access Menu shows up, select Control Panel and Uninstall a Program. If you are 'Windows 10 / Windows 8' user, then right-click in the lower left corner of the screen. Once 'Quick Access Menu' shows up, select 'Control Panel' and 'Uninstall a Program'.
  3. Uninstall and related programs
    Here, look for or any other recently installed suspicious programs.
  4. Uninstall them and click OK to save these changes. Right click on each of suspicious entries and select 'Uninstall'
  5. Remove from Windows shortcuts
    Right click on the shortcut of Mozilla Firefox and select Properties. Right click on browsers' icon and select 'Properties'
  6. Go to Shortcut tab and look at the Target field. Delete malicious URL that is related to your virus. Select 'Shortcut' tab and delete '' or other suspicious URL

Repeat steps that are given above with all browsers' shortcuts, including Internet Explorer and Google Chrome. Make sure you check all locations of these shortcuts, including Desktop, Start Menu and taskbar.

Eliminate from Mac OS X system

To remove without leaving its leftovers, make sure that you uninstall,, and similar suspicious programs/URLs as well.

  1. If you are using OS X, click Go button at the top left of the screen and select Applications. Cick 'Go' and select 'Applications'
  2. Wait until you see Applications folder and look for or any other suspicious programs on it. Now right click on every of such entries and select Move to Trash. Click on every malicious entry and select 'Move to Trash'

Remove from Internet Explorer (IE)

In order to free your IE browser from the unwanted changes it has undergone while infected with the hijacker, you must reset your browser as indicated in the instruction guide below.

  1. Remove dangerous add-ons
    Open Internet Explorer, click on the Gear icon (IE menu) on the top right corner of the browser and choose Manage Add-ons. Click on menu icon and select 'Manage add-ons'
  2. You will see a Manage Add-ons window. Here, look for and other suspicious plugins. Disable these entries by clicking Disable: Right click on each of malicious entries and select 'Disable'
  3. Change your homepage if it was altered by virus:
    Click on the gear icon (menu) on the top right corner of the browser and select Internet Options. Stay in General tab.
  4. Here, remove malicious URL and enter preferable domain name. Click Apply to save changes. Delete malicious URL, enter your desired domain name and click 'Apply' to save changes
  5. Reset Internet Explorer
    Click on the gear icon (menu) again and select Internet options. Go to Advanced tab.
  6. Here, select Reset.
  7. When in the new window, check Delete personal settings and select Reset again to complete removal. Go to 'Advanced' tab and click on 'Reset' button. Now select 'Delete personal settings' and click on 'Reset' button again

Uninstall virus from Microsoft Edge

As we've mentioned in the article, when hijackers take over browsers, they change their settings. This means that to restore order, you will have to reset Microsoft Edge to its default build. Here is a brief explanation how this can be done

Reset Microsoft Edge settings (Method 1):

  1. Launch Microsoft Edge app and click More (three dots at the top right corner of the screen).
  2. Click Settings to open more options.
  3. Once Settings window shows up, click Choose what to clear button under Clear browsing data option. Go to Settings and select 'Choose what to clear'
  4. Here, select all what you want to remove and click Clear. Select 'Clear' button
  5. Now you should right-click on the Start button (Windows logo). Here, select Task Manager. Open the start menu and select 'Task Manager'
  6. When in Processes tab, search for Microsoft Edge.
  7. Right-click on it and choose Go to details option. If can’t see Go to details option, click More details and repeat previous steps. Right-click 'Microsoft Edge' and select 'Go to details' Select 'More details' if 'Go to details' option fails to show up
  8. When Details tab shows up, find every entry with Microsoft Edge name in it. Right click on each of them and select End Task to end these entries. Find Microsoft Edge entries and select 'End Task'

Resetting Microsoft Edge browser (Method 2):

If Method 1 failed to help you, you need to use an advanced Edge reset method.

  1. Note: you need to backup your data before using this method.
  2. Find this folder on your computer: C:\Users\%username%\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe.
  3. Select every entry which is saved on it and right click with your mouse. Then Delete option. Go to Microsoft Edge folder on your computer, right-click every entry and click 'Delete'
  4. Click the Start button (Windows logo) and type in window power in Search my stuff line.
  5. Right-click the Windows PowerShell entry and choose Run as administrator. Find Windows PowerShell, right-click it and select 'Run as administrator'
  6. Once Administrator: Windows PowerShell window shows up, paste this command line after PS C:\WINDOWS\system32> and press Enter:
    Get-AppXPackage -AllUsers -Name Microsoft.MicrosoftEdge | Foreach {Add-AppxPackage -DisableDevelopmentMode -Register $($_.InstallLocation)\AppXManifest.xml -Verbose}
    Copy and paste a required command and press 'Enter'

Once these steps are finished, should be removed from your Microsoft Edge browser.

Erase from Mozilla Firefox (FF)

Mozilla Firefox, just like any other browser targeted by a browser hijacker, undergoes certain changes. To reverse these alternations, you will have to follow the directions below

  1. Remove dangerous extensions
    Open Mozilla Firefox, click on the menu icon (top right corner) and select Add-ons Extensions. Click on menu icon and select 'Add-ons'
  2. Here, select and other questionable plugins. Click Remove to delete these entries. Select 'Extensions' and look for malicious entries. Click 'Remove' to get rid of each of them
  3. Change your homepage if it was altered by virus:
    Click on the menu (top right corner), choose Options General.
  4. Here, delete malicious URL and enter preferable website or click Restore to default.
  5. Click OK to save these changes. When in 'General' tab, delete malicious URL from 'Home Page' section or click on 'Restore to Default' button. Click 'OK' to save changes
  6. Reset Mozilla Firefox
    Click on the Firefox menu on the top left and click on the question mark. Here, choose Troubleshooting Information. Click on menu icon and then on '?'. Select 'Troubleshooting Information'
  7. Now you will see Reset Firefox to its default state message with Reset Firefox button. Click this button for several times and complete removal. Click on 'Reset Firefox' button for a couple of times

Delete from Google Chrome

Google Chrome reset works like this:

  1. Delete malicious plugins
    Open Google Chrome, click on the menu icon (top right corner) and select Tools Extensions. Click on menu icon. Select 'Tools' and 'Extensions'
  2. Here, select and other malicious plugins and select trash icon to delete these entries. Look for malicious entries and delete each of them by clicking on the Trash bin icon
  3. Change your homepage and default search engine if it was altered by your virus
    Click on menu icon and choose Settings.
  4. Here, look for the Open a specific page or set of pages under On startup option and click on Set pages. After clicking on menu and 'Settings', select 'Set pages'
  5. Now you should see another window. Here, delete malicious search sites and enter the one that you want to use as your homepage. Click 'X' to remove malicious URLs
  6. Click on menu icon again and choose Settings Manage Search engines under the Search section. When in 'Settings', select 'Manage search engines...'
  7. When in Search Engines..., remove malicious search sites. You should leave only Google or your preferred domain name. Click 'X' to remove malicious URLs
  8. Reset Google Chrome
    Click on menu icon on the top right of your Google Chrome and select Settings.
  9. Scroll down to the end of the page and click on Reset browser settings. When in 'Settings', scroll down to 'Reset browser settings' button and click on it
  10. Click Reset to confirm this action and complete removal. Click on 'Reset' button to complete your removal

Get rid of from Safari

  1. Remove dangerous extensions
    Open Safari web browser and click on Safari in menu at the top left of the screen. Once you do this, select Preferences. Click on 'Safari' and select 'Preferences'
  2. Here, select Extensions and look for or other suspicious entries. Click on the Uninstall button to get rid each of them. Go to 'Extensions' and uninstall malicious add-ons
  3. Change your homepage if it was altered by virus:
    Open your Safari web browser and click on Safari in menu section. Here, select Preferences as it was displayed previously and select General.
  4. Here, look at the Homepage field. If it was altered by, remove unwanted link and enter the one that you want to use for your searches. Remember to include the "http://" before typing in the address of the page. When in 'General', delete malicious URL and enter your desired domain name
  5. Reset Safari
    Open Safari browser and click on Safari in menu section at the top left of the screen. Here, select Reset Safari.... Click on 'Safari' and select 'Reset Safari...'
  6. Now you will see a detailed dialog window filled with reset options. All of those options are usually checked, but you can specify which of them you want to reset. Click the Reset button to complete removal process. Select all options and click on 'Reset' button

About the author

Ugnius Kiguolis
Ugnius Kiguolis - The mastermind

If this free removal guide helped you and you are satisfied with our service, please consider making a donation to keep this service alive. Even a smallest amount will be appreciated.

Contact Ugnius Kiguolis
About the company Esolutions


Removal guides in other languages

  1. drake says:
    June 13th, 2016 at 10:18 am

    These ad-based search engines really annoys me!

  2. Resnya says:
    June 13th, 2016 at 10:19 am

    I hope the developer of this search engine cannot sleep at night. This software ruins browsing experience for ppl, who can create such trashy programs?

  3. Cindy says:
    June 13th, 2016 at 10:20 am

    thank you for helping me uninstall it. I swear, I honestly didnt know what is a browser hijacker and what does it do. Now I know everything, plus, I learned how to remove it!

  4. jamiiie99 says:
    June 13th, 2016 at 10:21 am

    good and easy to follow instructions, exactly what i was looking for.

Your opinion regarding virus