{"id":27861,"date":"2024-10-24T21:24:41","date_gmt":"2024-10-24T21:24:41","guid":{"rendered":"https:\/\/gridinsoft.com\/blogs\/?p=27861"},"modified":"2024-10-28T14:49:16","modified_gmt":"2024-10-28T14:49:16","slug":"zoomfind-extension-virus","status":"publish","type":"post","link":"https:\/\/gridinsoft.com\/blogs\/zoomfind-extension-virus\/","title":{"rendered":"Removal Guide For The ZoomFind Chrome Extension"},"content":{"rendered":"<p>ZoomFind is a Chrome extension that may unexpectedly appear among the others, causing the browser to redirect your search queries. It belongs to the class of browser hijackers and poses a less obvious danger to anyone who keeps using the system. Removing this unwanted extension is not an easy task, so in this post, I will explain its origins and show how to remove it for good.<\/p>\n<h2>Overview<\/h2>\n<p>ZoomFind is a specific type of malware that aims at taking over the web browser, changing its behavior to the liking of malware masters. In this particular case, all search queries are getting redirected to malicious search engines \u2013 Finditfasts.com and <a href=\"https:\/\/gridinsoft.com\/online-virus-scanner\/url\/potterfun-com\">Potterfun.com<\/a>.<\/p>\n<figure id=\"attachment_27862\" aria-describedby=\"caption-attachment-27862\" style=\"width: 1024px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/10\/ZoomFind-1024x402.jpg\" alt=\"ZoomFind Chrome Extension\" width=\"1024\" height=\"402\" class=\"size-large wp-image-27862\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/10\/ZoomFind-1024x402.jpg 1024w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/10\/ZoomFind-300x118.jpg 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/10\/ZoomFind-768x301.jpg 768w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/10\/ZoomFind-1536x603.jpg 1536w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/10\/ZoomFind-2048x803.jpg 2048w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/10\/ZoomFind-860x337.jpg 860w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption id=\"caption-attachment-27862\" class=\"wp-caption-text\">ZoomFind Chrome Extension<\/figcaption><\/figure>\n<p>To complicate counteractions from the user, this extension exploits a remote management feature of Google Chrome and Chromium browser known as <a href=\"https:\/\/gridinsoft.com\/blogs\/managed-by-your-organization-remove\/\">\u201cManaged by your organization\u201d<\/a>. This line appears in settings once ZoomFind is installed, rendering any attempts to change settings or remove the extension fruitless.<\/p>\n<p>Over the last couple of months, search hijacker-type rogue extensions have become prevalent. ZoomFind hijacker falls into this category by all the parameters. They route user searches to a different search engine, the one controlled by fraudulent actors. This can end up with quite worrying consequences, especially when the user pays no attention to where they click.<\/p>\n<h2>How does it work?<\/h2>\n<p>Like a <a href=\"https:\/\/gridinsoft.com\/blogs\/removal-guide-primelookup-chrome-extension\/\">PrimeLookup<\/a> or <a href=\"https:\/\/gridinsoft.com\/blogs\/swiftseek-extension-virus-removal\/\">SwiftSeek Extension<\/a>, a ZoomFind falls into the category of <a href=\"https:\/\/gridinsoft.com\/browser-hijacker\">search hijacker<\/a> plugin. <strong>Key elements of its activity are about intercepting all the search queries<\/strong> made by the user and routing them through malicious search systems. With this specific plugin, Potterfun.com is the final destination, though this may change in other similar rogue extensions. In the process of redirection, however, an intermediary website shows up, where additional query parameters are added. This is what leads to the main danger of the attack scheme.<\/p>\n<figure id=\"attachment_27864\" aria-describedby=\"caption-attachment-27864\" style=\"width: 1024px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/10\/potterfun-zoomsearch-1024x707.jpg\" alt=\"Potterfun.com search hijacker\" width=\"1024\" height=\"707\" class=\"size-large wp-image-27864\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/10\/potterfun-zoomsearch-1024x707.jpg 1024w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/10\/potterfun-zoomsearch-300x207.jpg 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/10\/potterfun-zoomsearch-768x530.jpg 768w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/10\/potterfun-zoomsearch-860x594.jpg 860w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/10\/potterfun-zoomsearch.jpg 1418w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption id=\"caption-attachment-27864\" class=\"wp-caption-text\">The result of ZoomFind extension activity &#8211; redirections to Potterfun.com<\/figcaption><\/figure>\n<p>When the user types their search query, instead of Google (or the search engine of their choice) they see the results of Potterfun.com, additionally infused with search ads. And this is the major point of concern: these ads contain a lot of phishing pages and scams. Not like Google or Bing contain 100% safe promotions, but in these cases, dangerous results are meant to be here. Following them (which may easily happen for users who don\u2019t understand what is happening) will certainly lead to credentials leak, money loss, or even malware injection.<\/p>\n<h3>Spreading Ways<\/h3>\n<p>In the majority of cases, users get infected with ZoomFind through fraudulent software sharing\/downloading websites. They can offer unwanted extensions under the guise of a desired program, a game mod, or sometimes even a film. Unsuspecting folks click the downloaded file and in fact, install the malicious extension.<\/p>\n<figure id=\"attachment_27868\" aria-describedby=\"caption-attachment-27868\" style=\"width: 790px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/10\/ZoomFind-Download.jpg\" alt=\"ZoomFind downloading page\" width=\"790\" height=\"696\" class=\"size-full wp-image-27868\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/10\/ZoomFind-Download.jpg 790w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/10\/ZoomFind-Download-300x264.jpg 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/10\/ZoomFind-Download-768x677.jpg 768w\" sizes=\"auto, (max-width: 790px) 100vw, 790px\" \/><figcaption id=\"caption-attachment-27868\" class=\"wp-caption-text\">One of the pages where users can accidentally download ZoomFind extension from<\/figcaption><\/figure>\n<p>Sometimes users may see not a file sharing site, but a fake bot protection page, that requires one to confirm they\u2019re a human by installing the \u201csecurity browser plugin\u201d. The outcome may be different, as quite a lot of other viruses use the same scheme. We have a special article regarding these fake human verification \u2013 consider checking that out.<\/p>\n<p>Despite generally aiming at fraudulent spreading ways, it was available from the Chrome Web Store for a short period of time. It is likely done to legitimize the extension: users won\u2019t see the warning in the Extension tab, and will find it through search in the Web Store. Nonetheless, it is not even remotely safe, as I\u2019ve proven above.<\/p>\n<h2>How to Remove ZoomFind?<\/h2>\n<p>There are two options for removing ZoomFind, an automated approach and a manual one. I recommend sticking to automated, as it will eliminate the malicious extension and all other unwanted elements. Still, you can try undoing the extension manually, even though it is time consuming and requires certain amount of PC skill.<\/p>\n<h3>Using Anti-Malware<\/h3>\n<p>To get rid of the ZoomFind extension automatically, run a Full scan with GridinSoft Anti-Malware. This will take about 15 minutes, and will remove the malware even from the most remote parts of the system.<\/p>\n<img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/antimalware-main.webp\" alt=\"GridinSoft Anti-Malware main screen\" width=\"886\" height=\"689\" class=\"aligncenter size-full wp-image-22665\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/antimalware-main.webp 886w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/antimalware-main-300x233.webp 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/antimalware-main-768x597.webp 768w\" sizes=\"auto, (max-width: 886px) 100vw, 886px\" \/>\n<p>Download and install Anti-Malware by clicking the button below. After the installation, run a Full scan: this will check all the volumes present in the system, including hidden folders and system files. Scanning will take around 15 minutes.<\/p>\n<div style=\"text-align:center\"><a href=\"\/download\/antimalware\" class=\"btn border-black\" rel=\"nofollow\">Download Anti-Malware<\/a><\/div>\n<p>After the scan, you will see the list of detected malicious and unwanted elements. It is possible to adjust the actions that the antimalware program does to each element: click \"Advanced mode\" and see the options in the drop-down menus. You can also see extended information about each detection - malware type, effects and potential source of infection.<\/p>\n<img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/antimalware-result.webp\" alt=\"Scan results screen\" width=\"886\" height=\"689\" class=\"aligncenter size-full wp-image-22666\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/antimalware-result.webp 886w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/antimalware-result-300x233.webp 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/antimalware-result-768x597.webp 768w\" sizes=\"auto, (max-width: 886px) 100vw, 886px\" \/>\n<p>Click \"Clean Now\" to start the removal process. Important: removal process may take several minutes when there are a lot of detections. Do not interrupt this process, and you will get your system as clean as new.<\/p>\n<img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/antimalware-clean.webp\" alt=\"Removal finished\" width=\"886\" height=\"689\" class=\"aligncenter size-full wp-image-22667\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/antimalware-clean.webp 886w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/antimalware-clean-300x233.webp 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/antimalware-clean-768x597.webp 768w\" sizes=\"auto, (max-width: 886px) 100vw, 886px\" \/>\n<h3>Manual Removal Steps<\/h3>\n<p>To delete ZoomFind manually, you will need to undo the changes it has made to the system. This involves going through the system registry, and also Group Policies list. Please, follow these steps thoroughly, so nothing will restrict you from deleting the pesky extension.<\/p>\n<h4>Step 1. Group Policies Removal<\/h4>\n<p>First step in dealing with Managed by your organization is to remove policies that the malware changes to enable this state. This method does not require having access to Group Policies Editor, which is unavailable for non-Pro editions of Windows. All you have to do is find and remove all the folders listed below. <strong>Note: their deletion will require administrator privileges.<\/strong><\/p>\n<p><code style=\"font-size: 14px\">Windows\\System32\\GroupPolicy<br \/>\nWindows\\System32\\GroupPolicyUsers<br \/>\nProgramFiles(x86)\\Google\\Policies<br \/>\nProgramFiles\\Google\\Policies<\/code><\/p>\n<h4>Step 2. Removing Registry Keys<\/h4>\n<p>Next step is going through the registry keys that may contain malicious configurations. <strong>Press the Win+R combination, and type &#8220;regedit&#8221;<\/strong> in the search window. This will get you to the Registry Editor; there, find and delete the keys you see below.<\/p>\n<p><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/04\/run-regedit.png\" alt=\"Run Regedit\" width=\"350\" height=\"337\" class=\"aligncenter size-full wp-image-21019\" title=\"\"><\/p>\n<p><code style=\"font-size: 14px\">HKEY_LOCAL_MACHINE\\Software\\Policies\\Google\\Chrome<br \/>\nHKEY_LOCAL_MACHINE\\Software\\Policies\\Google\\Update<br \/>\nHKEY_LOCAL_MACHINE\\Software\\Policies\\Chromium<br \/>\nHKEY_LOCAL_MACHINE\\Software\\Google\\Chrome<br \/>\nHKEY_LOCAL_MACHINE\\Software\\WOW6432Node\\Google\\Enrollment<br \/>\nHKEY_CURRENT_USER\\Software\\Policies\\Google\\Chrome<br \/>\nHKEY_CURRENT_USER\\Software\\Policies\\Chromium<br \/>\nHKEY_CURRENT_USER\\Software\\Google\\Chrome<br \/>\n\"HKEY_LOCAL_MACHINE\\Software\\WOW6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\" \/v \"CloudManagementEnrollmentToken\"<\/code><\/p>\n<p>Not all keys may be present, as it depends on installed software, browser configurations, malware that did the changes and other things. Nonetheless, you should delete all the keys you can find.<\/p>\n<p>Once done, reboot your computer to apply the changes. Then, you should be able to <a href=\"https:\/\/support.google.com\/chrome\/answer\/114662?hl=en&#038;co=GENIE.Platform%3DDesktop\" rel=\"nofollow noopener\" target=\"_blank\">edit any of the Chrome settings<\/a> and remove any browser extensions that may have previously been blocked from editing.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>ZoomFind is a Chrome extension that may unexpectedly appear among the others, causing the browser to redirect your search queries. It belongs to the class of browser hijackers and poses a less obvious danger to anyone who keeps using the system. Removing this unwanted extension is not an easy task, so in this post, I [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":27867,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","_sitemap_exclude":false,"_sitemap_priority":"","_sitemap_frequency":"","footnotes":""},"categories":[17,4],"tags":[646,619,35],"class_list":{"0":"post-27861","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-labs","8":"category-tips-tricks","9":"tag-browser-hijacker","10":"tag-cybersecurity","11":"tag-virus-in-browser"},"featured_image_src":"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/10\/ZoomFind-Chrome-Extension.jpg","author_info":{"display_name":"Stephanie Adlam","author_link":"https:\/\/gridinsoft.com\/blogs\/author\/adlam\/"},"_links":{"self":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/27861","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/comments?post=27861"}],"version-history":[{"count":6,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/27861\/revisions"}],"predecessor-version":[{"id":27980,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/27861\/revisions\/27980"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/media\/27867"}],"wp:attachment":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/media?parent=27861"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/categories?post=27861"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/tags?post=27861"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}