Infpub.dat (Bad Rabbit Ransomware) File Removal

This article can help you to remove Infpub.dat Virus. The step by step removal works for every version of Microsoft Windows.

Check out today’s article to learn all you need to know about Infpub.dat. This Trojan horse is associated with the infamous Bad Rabbit Ransomware. In other words, you’re stuck with one immensely harmful and problematic parasite. Trojans are capable of causing some serious damage so don’t waste time. As soon as you encounter the parasite’s presence on board, take measures. The virus must be immediately uninstalled. Infpub.dat has a rich variety of tricks in store for you. For starters, it messes with your system registry. Some of your system files get modified and others get straight out damaged by the Trojan. And this is just the beginning of a long, long list of malicious traits. This infection causes your machine to crash and freeze on a daily basis. In addition, The Blue Screen of Death becomes a regular view. Infpub.dat slows the overall PC speed significantly so using your device is no longer fun. It is no longer safe either. Remember, you are dealing with a sneaky cyber parasite. Hackers’ devious creation might alter some of your preferred browser settings. In this case, the Trojan injects your once reliable browsers with sponsored ads. We’re talking coupons, discounts, product deals and offers, price comparisons, best prices, etc. Consider your browsing activities effectively destroyed because such ads are obsessive. They cover all websites you visit and attempt to trick you into clicking them. However, clicking any commercial that is generated by an infection would be a wrong move. If you’re unlucky enough, you will get redirected to some harmful page filled with malware. Hence, you could compromise your safety further. The Trojan might add some highly questionable extensions or plugins. Bear in mind the advertisements this pest displays are potentially corrupted so be careful what you click. Unless you’re willing to test out the limits of your luck, avoid the commercials. Infpub.dat jeopardizes your privacy by sending your personal data to hackers. It goes without saying crooks could cause you serious issues. For example, they might sell your details to third parties with unclear intentions. As a result, your data may end up in the wrong hands.

Remove Infpub.dat

How did I get infected with?

This infection travels the Web via bogus software updates. In the future, stay away from suspicious-looking updates as well as program bundles. Always keep an eye out for potential intruders to save yourself the hassle that is removing malware. Another popular technique involves spam messages and emails. When you receive some email-attachment that you find unreliable, better delete it. Preventing virus infiltration is much less time-consuming than having to uninstall malware. All it takes to infect your machine is one single wrong move online. On the other hand, removing a virus could take you some long hours. Do yourself a favor and be cautious. Many viruses get spread online via freeware/shareware bundles and malicious torrents. We’d recommend that you avoid unverified websites as those are usually dangerous. Last but not least, Trojans use exploit kits and fake pop-ups to get distributed on the Internet. The only way to make sure your device remains infection-free is by paying attention.

Why is this dangerous?

Infpub.dat serves as a back door to more infections. For instance, it could help some extremely dangerous ransomware get installed. The virus also wreaks havoc in silence and modifies your default PC settings. It might inject your browsers with sponsored, bogus and harmful pop-ups as well. What’s even more worrisome is the fact hackers steal your private details. They successfully spy on your browsing history, IP addresses, passwords and usernames. Infpub.dat may not stop there, though. This nuisance could monitor some of your personally identifiable details too. Yes, that includes your bank account data and online credentials. Hackers have plenty of monetizing platforms to choose from. Therefore, they will find a way to gain effortless profit out of your sensitive details. The sooner you remove Infpub.dat, the better. This program takes up a lot of CPU memory and causes a complete mess on your device. To delete it manually, please follow our detailed removal guide down below.

Manual Infpub.dat Removal Instructions

The Infpub.dat infection is specifically designed to make money to its creators one way or another. The specialists from various antivirus companies like Bitdefender, Kaspersky, Norton, Avast, ESET, etc. advise that there is no harmless virus.

If you perform exactly the steps below you should be able to remove the Infpub.dat infection. Please, follow the procedures in the exact order. Please, consider to print this guide or have another computer at your disposal. You will NOT need any USB sticks or CDs.

STEP 1: Track down Infpub.dat related processes in the computer memory

STEP 2: Locate Infpub.dat startup location

STEP 3: Delete Infpub.dat traces from Chrome, Firefox and Internet Explorer

STEP 4: Undo the damage done by the virus

STEP 1: Track down Infpub.dat related processes in the computer memory

  • Open your Task Manager by pressing CTRL+SHIFT+ESC keys simultaneously
  • Carefully review all processes and stop the suspicious ones.


  • Write down the file location for later reference.

Step 2: Locate Infpub.dat startup location

Reveal Hidden Files

  • Open any folder
  • Click on “Organize” button
  • Choose “Folder and Search Options”
  • Select the “View” tab
  • Select “Show hidden files and folders” option
  • Uncheck “Hide protected operating system files”
  • Click “Apply” and “OK” button

Clean Infpub.dat virus from the windows registry

  • Once the operating system loads press simultaneously the Windows Logo Button and the R key.


  • A dialog box should open. Type “Regedit”


Depending on your OS (x86 or x64) navigate to:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] or
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] or

  • and delete the display Name: [RANDOM]

delete backgroundcontainer

  • Then open your explorer and navigate to: %appdata% folder and delete the malicious executable.

Clean your HOSTS file to avoid unwanted browser redirection

Navigate to %windir%/system32/Drivers/etc/host

If you are hacked, there will be foreign IPs addresses connected to you at the bottom. Take a look below:


Step 4: Undo the possible damage done by Infpub.dat

This particular Virus may alter your DNS settings.

Attention! this can break your internet connection. Before you change your DNS settings to use Google Public DNS for Infpub.dat, be sure to write down the current server addresses on a piece of paper.

To fix the damage done by the virus you need to do the following.

  • Click the Windows Start button to open the Start Menu, type control panel in the search box and select Control Panel in the results displayed above.
  • go to Network and Internet
  • then Network and Sharing Center
  • then Change Adapter Settings
  • Right-click on your active internet connection and click properties. Under the Networking tab, find Internet Protocol Version 4 (TCP/IPv4). Left click on it and then click on properties. Both options should be automatic! By default it should be set to “Obtain an IP address automatically” and the second one to “Obtain DNS server address automatically!” If they are not just change them, however if you are part of a domain network you should contact your Domain Administrator to set these settings, otherwise the internet connection will break!!!


  • Check your scheduled tasks to make sure the virus will not download itself again.

How to Permanently Remove Infpub.dat Virus (automatic) Removal Guide

Please, have in mind that once you are infected with a single virus, it compromises your whole system or network and let all doors wide open for many other infections. To make sure manual removal is successful, we recommend to use a free scanner of any professional antimalware program to identify possible virus leftovers or temporary files.

Leave a Comment