Click on screenshot to zoom
Danger level 8
Type: Browser Hijackers
Common infection symptoms:
  • Hijacks homepage
  • Changes default search engine

Finding in your Internet Explorer browser as your new home page can indicate that your computer has been infected with a browser hijacker. This hijacker seems to mainly target Chinese computer users, which is supported by the statistics showing 99.4% visitors from that region. This search page seems to be a travel-related website with lots of articles, videos, accommodation, cuisine, and more. If this page loads when you launch your Internet Explorer browser, it is possible that you have installed some free software lately. Reports show that this hijacker mostly travels bundled with other malicious software installers. This simply means that right now you may have multiple threats on board. If you do not act ASAP, you may infect your computer with more malware programs and that could cripple your whole operating system, not to mention the possibility that cyber criminals might also gain access to your computer and your stored files. We recommend that you delete even if it may not be the most dangerous infection on your PC. However, you will also need to run a full-system malware scan in order to make sure that you know what you are up against. Leaving any malware infection on your computer can make it vulnerable. If you want to find out more about this browser hijacker and how you can protect yourself from similar attacks, please read on.

We have found that this search page is hosted in China ( IP). This site has absolutely no use for you unless you speak and read Chinese. But even in that case, we advise you not to engage with the content of this page as it may contain potentially unreliable third-party advertisements and content as well. Using its search tool might also redirect you to harmful pages. It is also possible that this hijacker can collect information about you and your browsing habits in order to use it to target you with customized ads and links. Cyber criminals might also have ways to exploit this browser hijacker to their advantage.

Once this hijacker enters your system, it modifies a number of registry keys to support its operations. For example, it overwrites the HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes key to contain instead of the default or preferred search engine. This way, whenever you search online you will end up on this search page. Apart from this, your home page will also be set by this browser hijacker to make sure your exposure to this site. Since you cannot be sure of the reliability of any related content, we advise you to remove as soon as possible.

We have found that this browser hijacker mainly spreads in bundles. This means that there is no official or promotional website that would distribute it as an application. This is very typical for browser hijackers that they travel in bundles. This way they have a high chance that they will be installed. The reason behind it is that inexperienced computer users tend to overlook certain steps while installing software packages. The most important thing to know about bundles is that most of the time you are offered an opportunity to deselect the components you do not wish to install. Usually you are presented with a few checkboxes to untick if you do not want the related tool or change to take place. Sometimes these are only revealed if you choose that custom installation option. It is also possible that you will only know what you are about to install if you read the license agreement carefully.

One way to avoid your computer being infected with malicious programs is not to land on suspicious websites, including pornographic, torrent, and freeware pages. The biggest problem is cause by unfamiliar sites because you have no idea where you can safely click without infecting your computer. It is possible that you want to download a free program and there are at least 3 download buttons and links on the page, but only one will be functioning while the other two will be well-disguised third-party ads. These ads may drop a malicious bundle onto your machine or take you to other malicious websites. In any case, landing on unfamiliar file-sharing sites is never a good idea. Mostly because some of them can run a malicious code through a banner, for example, that can also drop malware infections onto your hard drive. In this case you do not even need to click anywhere as simply loading the page can trigger this.

It is also possible that your computer had already been penetrated by malware, such as adware applications, and you clicked on an advertisement displayed by this infection and that is how you download a malicious bundle containing this browser hijacker. All in all, we think that you should remove if you want to have order on your PC.

Unfortunately, this hijacker has no uninstaller; therefore, it cannot be easily uninstalled via Control Panel. Instead, you need to restore the home page URL setting in Internet Explorer; however, this leaves a little mess behind. If you want to get rid of this infection entirely, after removing either through your browser settings or manually through the Windows Registry, you need to clean up several CLSIDs in the registry. Please use our guide below as a reference and follow each step carefully. Remember that working with the Windows Registry has its own risks. Only go for the manual method if you are confident enough and consider yourself an experienced computer user. Otherwise, we recommend you an automated solution. The web is full of security tools, so it is important that you find yourself a reliable and powerful one. We can recommend SpyHunter since this antimalware program has proved to be trustworthy for us. Protect your PC with the tool of your choice to be safe every time you switch on your computer.

How to remove from your browser

Internet Explorer

  1. Press Alt+T and open Internet options.
  2. Click the General tab.
  3. Press Use default or enter a home page URL of your choice.
  4. Click OK.

Remove manually

  1. Tap Win+Q and enter regedit. Hit the Enter key.
  2. Find HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes and overwrite the value data of “” with a search engine you prefer.
  3. Find HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page and overwrite the value data of “” with a home page URL you prefer.

Clean up the Windows Registry

  1. If the editor is not open, tap Win+Q and enter regedit. Hit the Enter key.
  2. Check the CLSIDs in the following registry keys. If the CLSID has a value data of “,” delete the key:
    [HKLM|HKCU]\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    [HKLM|HKCU]\SOFTWARE\Microsoft\Internet Explorer\Extensions
    [HKLM|HKCU]\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars
    [HKLM|HKCU]\SOFTWARE\Microsoft\Code Store Database\Distribution Units
    [HKLM|HKCU]\SOFTWARE\Microsoft\Internet Explorer\Toolbar
    [HKLM|HKCU]\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser
    [HKLM|HKCU]\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ShellBrowser
    [HKLM|HKCU]\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks
    [HKLM|HKCU]\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping
    [HKLM|HKCU]\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
  3. Reboot your system.
Download Spyware Removal Tool to Remove*
  • Quick & tested solution for removal.
  • 100% Free Scan for Windows

Post comment — WE NEED YOUR OPINION!

Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.