Ads by KeepNow is an adware program that infiltrates Windows computers and injects unwanted advertisements into web browsers. This potentially unwanted program (PUP) installs itself as a browser extension or system-level component and begins displaying pop-ups, banners, in-text ads, and sponsored content across nearly every website you visit. While not a virus in the traditional sense, KeepNow significantly degrades your browsing experience, tracks your online activity, and creates security vulnerabilities that more dangerous malware can exploit.

Ads by KeepNow — cybersecurity illustration
Photo by Ann H on Pexels

Users typically discover they have KeepNow when their browser suddenly becomes cluttered with ads labeled "Ads by KeepNow," "Brought to you by KeepNow," or "Powered by KeepNow." These ads appear even on websites that normally have no advertising, and clicking them—even accidentally—often redirects you to questionable websites promoting fake software updates, bogus tech support, or potentially malicious downloads.

Think you're infected right now? Disconnect from the internet if you're seeing suspicious pop-ups or redirects. Don't click on any ads or warnings claiming your system is infected. Call Computer Repair Roswell at (770) 856-1242 or bring your machine to our shop at 1750 Woodstock Rd. We can remove adware infections same-day and verify no additional threats are present.

Threat Profile

Threat Name Ads by KeepNow (KeepNow adware)
Classification Adware / Potentially Unwanted Program (PUP)
Family Adware bundler family, similar to SaverAddon, BrowseFox, and Adpeak variants
Affected Platforms Windows 7, 8, 8.1, 10, 11 (all editions); Chrome, Firefox, Edge, Internet Explorer
Risk Level Medium (privacy invasion, system slowdown, gateway to higher threats)
Distribution Method Software bundling, fake updates, deceptive installers, malvertising
Persistence Mechanisms Browser extensions, scheduled tasks, registry Run keys, system services (varies by variant)
Primary Capabilities Ad injection, click fraud, browsing data collection, browser redirection, affiliate revenue generation
Data at Risk Browsing history, search queries, clicked links, IP address, system information, potentially form data
Network Behavior Connects to ad-serving domains, downloads additional components, reports tracking data to remote servers
Common Artifacts Browser extensions with random names, folders in %LOCALAPPDATA% or %PROGRAMFILES%, registry modifications
Removal Difficulty Moderate (reinstalls itself if components are missed, may require Safe Mode removal)

How It Spreads

KeepNow rarely arrives alone. The primary distribution method is software bundling, where the adware is packaged with legitimate free software that users intentionally download. When you install a free PDF converter, video codec, download manager, or system optimizer from a third-party download site, KeepNow may be included in the installation wizard as a "recommended" or "sponsored" component. The installation screens are deliberately designed to make it difficult to decline these extras—using confusing language, pre-checked boxes, or "Express" installation options that don't show you what's really being installed.

Another common vector is fake software updates. You might encounter a pop-up claiming your Flash Player, Java, or video codec is out of date and needs updating. These fake update notifications appear on compromised websites or are served through malicious advertising networks. When you click "Update Now," you're actually downloading an installer that includes KeepNow along with other unwanted programs.

KeepNow spreads through these methods:

  • Bundled freeware and shareware — attached to popular free downloads from sites like Softonic, Download.com, or torrent sources
  • Fake update notifications — misleading pop-ups claiming you need to update Flash, Java, media players, or browser components
  • Malicious advertisements — ads on legitimate websites that redirect to installer pages when clicked (malvertising)
  • Deceptive download buttons — fake "Download" buttons on file-sharing sites that install adware instead of the file you wanted
  • Email attachments and links — less common, but some variants spread through spam campaigns with misleading subject lines
  • Cracked software installers — pirated programs or key generators that include adware as part of the crack

What It Does On Your Machine

Once installed, KeepNow integrates itself into your system at multiple levels. It typically adds extensions to all browsers on your computer—Chrome, Firefox, Edge, and Internet Explorer. These extensions have permission to "read and change all your data on the websites you visit," which allows them to inject advertisements into any webpage. The ads appear as pop-ups, banner ads at the top or bottom of pages, in-text ads (where random words become clickable links), comparison shopping boxes, and video ads that auto-play.

The advertisements themselves are the visible symptom, but KeepNow's background activities are more concerning. The adware tracks your browsing behavior: what sites you visit, what you search for, what links you click, how long you spend on each page. This data is packaged and sent to remote advertising servers, where it's used to build a profile of your interests for targeted advertising. Some variants also collect system information like your IP address, operating system version, browser type, installed software, and geographic location.

Beyond the privacy invasion, KeepNow degrades system performance. Your browser loads more slowly because it has to fetch and display the injected ads. Pages become cluttered and harder to read. Your CPU usage increases as the adware processes scripts in the background. Your network bandwidth is consumed uploading tracking data and downloading ad content. Users commonly report their computers "running slower" after infection, with browsers taking several extra seconds to load each page.

The security risk is equally serious. KeepNow ads frequently promote questionable content: fake system optimizers that are themselves malware, tech support scams claiming your computer is infected, surveys that steal personal information, and websites that attempt to download trojans or ransomware. Even if you don't intentionally click the ads, some variants use aggressive tactics like pop-unders (ads that open behind your browser), forced redirects, and auto-download attempts. Each ad you're exposed to is another opportunity for a more serious infection.

Typical KeepNow Filesystem and Registry Artifacts
C:\Program Files (x86)\KeepNow\ C:\Users\[username]\AppData\Local\KeepNow\ C:\Users\[username]\AppData\Roaming\KeepNow\ C:\Users\[username]\AppData\Local\Temp\nsi[random].tmp\ Browser Extension Folders: C:\Users\[username]\AppData\Local\Google\Chrome\User Data\Default\Extensions\[random-id]\ C:\Users\[username]\AppData\Roaming\Mozilla\Firefox\Profiles\[profile]\extensions\{random-guid} Registry Persistence: HKCU\Software\Microsoft\Windows\CurrentVersion\Run // Autostart entries HKLM\Software\Microsoft\Windows\CurrentVersion\Run HKCU\Software\KeepNow // Configuration data HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CLSID} // Browser helper object Scheduled Tasks: schtasks /query /fo LIST /v | findstr KeepNow Task: KeepNowUpdate // Runs updater at login or hourly

Manual Removal — Step by Step

01

Disconnect from the Internet

Unplug your Ethernet cable or disable Wi-Fi. This prevents KeepNow from downloading additional components or reporting back to its command servers during the removal process. Some adware variants will attempt to reinstall themselves by pulling fresh files from the internet if they detect components are being deleted.

02

Restart Windows in Safe Mode with Networking

Reboot your computer and press F8 repeatedly during startup (or hold Shift while clicking Restart on Windows 10/11). Select "Safe Mode with Networking" from the boot options menu. Safe Mode loads only essential drivers and services, which prevents KeepNow's startup items from launching and makes it much easier to remove without interference.

03

Uninstall KeepNow Through Programs and Features

Open Control Panel → Programs and Features (or Settings → Apps on Windows 10/11). Look for "KeepNow," "Keep Now," or any entries you don't recognize that were installed around the time the ads started appearing. Sort by install date to find recent additions. Uninstall anything suspicious. Also look for bundled programs with names like "SaveNow," "DealKeeper," "Shopping Helper," or randomly generated names—adware often installs multiple components.

04

Remove Browser Extensions

Open each browser and go to its extensions page (Chrome: chrome://extensions, Firefox: about:addons, Edge: edge://extensions). Remove any extensions you don't recognize or didn't intentionally install, especially those with generic names, no icon, or random strings of characters. KeepNow extensions might be named "KeepNow," "Shopping Assistant," "Deal Finder," or have completely random names. Don't just disable them—click Remove to delete them completely.

05

Delete KeepNow Folders Manually

Open File Explorer and navigate to C:\Program Files (x86)\, C:\Users\[YourUsername]\AppData\Local\, and C:\Users\[YourUsername]\AppData\Roaming\. Look for folders named "KeepNow" or similar variations. Delete these folders completely. To see the AppData folder, you'll need to enable "Show hidden files" in File Explorer's View options. If Windows says a file is in use, note the filename and return to this step after Step 6.

06

Clean Registry Entries and Scheduled Tasks

Press Windows+R, type "regedit", and hit Enter. Navigate to HKEY_CURRENT_USER\Software\ and HKEY_LOCAL_MACHINE\Software\ and delete any keys named "KeepNow." Also check HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run for any autostart entries related to KeepNow. Next, open Task Scheduler (search for it in the Start menu), and look through the task list for anything named "KeepNowUpdate" or similar—delete these tasks. Be careful in the registry; only delete entries you're certain are related to the infection.

07

Scan with Malwarebytes or Similar

Download Malwarebytes Free (from malwarebytes.com) and run a full system scan. Malwarebytes is specifically designed to catch adware and PUPs that traditional antivirus misses. Let it quarantine everything it finds. If you can't download Malwarebytes because KeepNow is blocking certain websites, use a different computer to download the installer to a USB drive, then transfer it to the infected machine.

08

Reset Browser Settings

Even after removing the extensions, KeepNow may have changed your homepage, default search engine, or new tab page. In Chrome, go to Settings → Reset settings → Restore settings to their original defaults. In Firefox, type about:support in the address bar and click "Refresh Firefox." In Edge, go to Settings → Reset settings → Restore settings to their default values. This will remove any lingering configuration changes the adware made.

09

Change Passwords for Sensitive Accounts

While KeepNow primarily tracks browsing behavior, you don't know for certain whether it captured any login credentials or form data. From a clean device or after completing all other removal steps, change passwords for your email, banking, social media, and other important accounts. Enable two-factor authentication where available for an extra layer of security.

10

Reboot and Verify Removal

Restart your computer normally (not in Safe Mode). Reconnect to the internet and open your browser. Visit a few different websites and watch for any "Ads by KeepNow" labels or suspicious pop-ups. Check Task Manager (Ctrl+Shift+Esc) to see if any processes with random names are consuming resources. If ads are still appearing, the infection may have additional components that require professional removal.

Prevention

  1. Download software only from official sources. Get programs directly from the developer's website rather than third-party download sites. Avoid Softonic, Download.com, and similar aggregators that bundle adware with installers.
  2. Always choose Custom or Advanced installation. Never click "Express Install" or "Recommended Settings" when installing software. The Custom option shows you exactly what's being installed and lets you uncheck bundled adware before it reaches your system.
  3. Keep your actual software updated. Real updates come through the software itself or Windows Update—never through pop-ups on websites. Ignore any browser message claiming you need to update Flash, Java, or video codecs. Flash is deprecated anyway; legitimate sites have moved to HTML5.
  4. Use an ad blocker with malware protection. Browser extensions like uBlock Origin block most malicious ads before they can load. This prevents exposure to the malvertising that often distributes adware installers.
  5. Enable Windows Defender or use reputable antivirus. Keep real-time protection enabled. Windows Defender does a reasonable job catching known adware if its definitions are current. Supplement with periodic Malwarebytes scans.
  6. Be skeptical of "free" versions of paid software. Cracked software, key generators, and pirated programs are common adware vectors. If something expensive is offered free through unofficial channels, it likely comes with unwanted extras.
  7. Read what you're agreeing to. If an installer asks for permission to change your homepage, install a browser extension, or add a search tool, decline. These requests are red flags for bundled adware.
  8. Educate other users of your computer. If family members or employees use your system, make sure they understand the risks of casual clicking and Express installations. One uninformed user can infect a shared machine.
Our 90-Day Warranty
When Computer Repair Roswell removes adware from your system, we guarantee our work for 90 days. If KeepNow or related adware returns within that period, bring your computer back and we'll remove it again at no additional charge. We also verify that no additional malware hitchhiked in with the adware—many infections don't arrive alone.

Bring It In

Manual removal can be time-consuming and frustrating, especially if KeepNow has deeply embedded itself or if you're dealing with multiple adware infections at once. If you've followed these steps and still see ads, or if you simply want professional assurance that your system is completely clean, Computer Repair Roswell is here to help. We remove adware infections same-day in most cases, and we check for rootkits, trojans, and other threats that might be hiding alongside the obvious adware symptoms.

Call us at (770) 856-1242 or visit our shop at 1750 Woodstock Rd, Roswell, GA 30075. We're open Monday through Saturday, and we offer free diagnostics—you'll know what you're dealing with and what it'll cost to fix before you commit to anything. Don't let adware slow your computer and invade your privacy. Bring it in and we'll get you back to clean, fast browsing.