Click on screenshot to zoom
Danger level 6
Type: Browser Hijackers
Common infection symptoms:
  • Hijacks homepage is a useless and potentially harmful addition to your browsers that may appear as your home page after you get infected with a browser hijacker. As a matter of fact, this hijacker is quite well-known to us since it belongs to an ever growing family of similar and identical threats, including and This browser hijacker offers you a parcel tracking tool as well as a few easy-access buttons on a fake toolbar leading to popular websites. We do not advise you to use this search engine page at all because any content coming through this infection may put your virtual security at risk. We suggest that you remove as soon as you can in order to protect your system from further malware infections and the possibility of your landing on malicious pages and cause more serious harm to your files and your privacy. Please read our article if you want to know more about this infection and how you can clean your system of this threat.

This browser hijacker uses the same method to spread over the net as all its predecessors in the family. It is mostly distributed in freeware bundles along with other malicious software installers. This is why you may find several other threats, such as adware programs, browser hijackers, Trojans, fake alerts, and potentially unwanted programs, after you find this hijacker on your system. You may not even realize for some time that it is there in your browsers because it may just look like any other search engine that may have appeared in your browsers as your home page in the past. A lot of users do not even consider questionable search engine pages as a real threat. In general, these infections may not cause too many problems unless you use them. Although, they can still spy on you in the background and gather information about your online activities and compile a profile on you that could be shared with third parties.

You can easily expand your browsers with such a potentially unreliable search engine if you click on an unsafe third-party advertisement. Such an ad can also be disguised so that you would not recognize it as a commercial. Therefore, it is possible that you see a fake download or next-page button, or a fake system notification that urges you to download a Flash update (or any other kind of update for that matter). It is possible for you to encounter such ads when you visit suspicious file-sharing and gaming websites. As you may have noticed, these pages are filled with annoying third-party ads. If you land on an unfamiliar website, chances are you will click on malicious content, such as fake buttons. This can end badly for you if you are not cautious enough, as you can drop a bundle of malware threats onto your machine. This is why we emphasize the need for scanning your system with a reliable malware scanner right after you delete from your browsers.

This malware infection poses as a useful tool that provides you with a parcel tracking button along with a few other buttons leading to popular websites, such as Facebook, YouTube, and Gmail, on a fake toolbar, which is a characteristic of all the hijackers in this family. There is also a local weather-related button; however, this may take you to a widget page where you will find a couple of potentially harmful third-party ads. This is why we do not recommend that you engage with any content provided by this search engine. It is possible that it can inject its own third parties’ ads that may not all be reliable at all. Another extra feature in this case is the package tracking input field below the main search box. After entering your tracking number, you may be able to track your parcel by clicking on the “Track My Package” button.

Another big issue with this browser hijacker is that it may modify the search results. This is indeed a serious problem since it means that you could be exposed to unreliable third-party ads and sponsored links that may lead you to malicious websites even if you end up on a reputable Yahoo search results page. One click on the wrong content could directly drop infections onto your system or open malicious pages in new tabs or new windows. Cyber criminals are looking forward to your visit so that they can scam you. In such an online scam you may reveal your banking and personal details without even realizing what has just happened until it is too late. This is the main reason why we advise you to delete from your computer.

We have found that this browser hijacker may only alter your home page settings in your affected browsers, including Mozilla Firefox, Google Chrome, and Internet Explorer. You can use the settings of your browsers to restore the home page, but you can also use our manual removal guide if you want to know more about such an infection and how it affects your computer. Do not forget about the possibility that there could be other malicious programs on board that may endanger the normal operations of your PC. We recommend that you use a reliable malware remover, such as SpyHunter that can automatically identify all existing malware infections and clean them from your system or prevent them from entering your PC in the first place.

Remove from browsers

Google Chrome

  1. Tap Win+E.
  2. Locate your “%LocalAppData%\Google\Chrome\User Data\Default” folder.
  3. Delete Preferences, Secure Preferences, and Web Data files.

Mozilla Firefox

  1. Tap Win+E.
  2. Find the “%AppData%\Mozilla\Firefox\Profiles\{Unique Mozilla user ID}” folder.
  3. Edit the prefs.js file.
  4. Find user_pref("browser.startup.homepage", "") and replace the malicious URL with a home page URL of your choice.

Internet Explorer

  1. Tap Win+Q and enter regedit. Hit the Enter key.
  2. Replace value data “” in these registry keys:
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main\Start Page (64-bit)
    HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page
    HKCU\Software\Microsoft\Internet Explorer\Main\Start Page
  3. Locate “HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}” registry key and change the following value data:
    FaviconURL (“”)
    FaviconURLFallback (“”)
    TopResultURL (“”)
    URL (“”)
  4. Exit the registry editor.
Download Spyware Removal Tool to Remove*
  • Quick & tested solution for removal.
  • 100% Free Scan for Windows

Post comment — WE NEED YOUR OPINION!

Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.