Eridanus is a new adware which basically looks and acts the same as LaSuperba. It displays plenty of intrusive advertisements labelled as “optimized by Eridanus“, “brought by Eridanus“, “powered by Eridanus” or simply as “Ads by Eridanus“.
Eridanus adware creates 2 folders with random names in the C:\Windows\System32. Into these 2 folders Eridanus adware adds a special file with .dat extension and random name as well. These two folders also contain sort of a hosts file, which contains the following redirections:
In order that Eridanus adware starts its malicious job, the infection patches the file C:\Windows\System32\dnsapi.dll instead of \drivers\etc\hosts and adds the file it created:
Ads by Eridanus adware are definitely not worth clicking. Users may be brought to all kinds of dangerous places in the web. Eventually, their computer may be brutally infected with other cyber threats and computer viruses.
In addition, the system contaminated with Eridanus infection may be permanently working out of order, extremely slow. The adware is known to cause a lot of stability issues due to high CPU usage and consumption of many system resources. We recommend that you follow the detailed guide below to remove Ads by Eridanus from your PC for good.
Anti-malware tool necessary to eliminate Ads optimized by Eridanus automatically.
Detailed automatic removal instructions:
- Download GridinSoft Anti-Malware via the download button (above).
- Install the application and scan your computer with it.
- At the end of scan click “Apply” to remove all infections related to this adware:
- Important! It is also very important that you reset your browsers using GridinSoft Anti-Malware after you delete this particular adware. Shut down all your available browsers right now.
- In GridinSoft Anti-Malware click on “Tools” tab and select “Reset browser settings“:
- Select which particular browsers you would like to be reset and choose the reset options:
- Finally, Click on “Reset” button.
- You will receive the confirmation windows about browser settings reset successfully.
- Click on “Run” and execute cmd.exe on behalf of Administrator.
- Execute these 2 commands in cmd.exe on behalf of Administrator – sfc /scanfile=C:\Windows\system32\dnsapi.dll and
- Reboot your system now.
Video explaining how to reset your browser using GridinSoft Anti-Malware:
Manual (free) instructions to get rid of Ads brought by Eridanus.
Step 1. Uninstalling Eridanus adware from the Control Panel of your computer.
- Make sure that all your browsers infected with Ads powered by Eridanus are shut down (closed).
- In Windows XP, Vista and 7 click on “Start” and go to the “Control Panel“.
- To access the Control Panel in Windows 8 or 8.1, move the PC mouse next to the left-bottom hot corner of your Windows 8 or 8.1 screen, then right-click on it.
- In Windows XP click on “Add or remove programs“.
- In Windows Vista, 7, 8 and 8.1 click on “Uninstall a program“.
- Uninstall Eridanus adware program from your system. To do it, in Windows XP click “Remove” button related to it. In Windows Vista, 7, 8 and 8.1 right-click on Eridanus program with the computer mouse and click on “Uninstall / Change“.
Step 2. Removing the adware from the list of add-ons and extensions of your browser.
In addition to removal of any suspicious adware programs from the Control Panel of your PC as explained above, you also need to remove this adware from the add-ons or extensions of your browser. Please follow this guide for managing browser add-ons and extensions for more detailed information. Remove any items related to this particular adware and other unwanted applications installed on your PC.
Instructions to prevent your system from being contaminated with adware again:
GridinSoft Anti-Malware renders an excellent tool to prevent malicious applications from being started in your computer ahead of time. By default, this feature is disabled after you install GridinSoft Anti-Malware. To enable the Real-Time Protection mode click on the “Protect” button and hit “Start” as demonstrated below:
As soon as this feature is enabled, your PC will be protected against all possible malware targeting your computer and attempting to launch and install itself. You may click on the “Confirm” button to continue blocking this infected file from being started, or you may ignore this warning and launch this file.