TechTalk & Personal Computing Guide

How to fix a hijacked homepage

meghavi thumbnail
Posted: 19 years ago
Question: When I startup my computer my homepage switches to a site that I don't want. No matter what I do I can't make this problem go away. What can I do?

Answer: Uh oh, your browser has been hijacked. Some Internet company out there has put a little program on your computer that switches your homepage everytime you either restart your browser or your computer. Not nice.

The good news is there are ways to fix the problem.

First here's the normal way of changing your browser's homepage. At the top of Internet Explorer, click Tools then Internet Options then change the Home page address and click ok. In Netscape 7, click Edit then Preferences and then change the homepage address in the box that appears.

If you've been hijacked this won't work for long, because the rogue programming on your computer will soon change it back. So how did this happen?

Well from a prgrammming perspective here's what's happened:

The most common scheme used by homepage hijackers is to put a reference to their site in your Startup folder or Registry Run key, so that it runs every time the computer is started and changes your settings. If you try to change any of these back, the programming they put on your computer changes everything so you end up with their site in your browser.

The only way to fix this is to find the hijacking software and remove it.

"But I didn't download anything to allow this happen!" you might say. Well, if you don't regularly update your browser or use Windows Update to install security fixes, then you did. Several of these hijackers exploit an Internet Explorer/Outlook Express bug that let's them secretly install a program (called an ActiveX control) on your system just by viewing their Web page. Hijackers exploiting this bug will insert one or several .hta files on your hard drive which run when you start up Windows.

The easiest way to fix a problem like this is to scan your computer for what's called spyware - programs like this that have been secretly installed by surreptitious downloads or programs you downloaded. Spy Ware Killer is a good choice to get rid of this stuff automaticallly. Click here for more info about this great and useful software. Also consider the really great Pest Patrol which also finds spyware cookies and has a keylogger scanner.

To fix this nastiness manually, search your computer for *.hta files. Click Start and Search or Find and then Files or Folders and type in *.hta. If you find them rename them so that they can't be found. For example, change file.hta to file.hta1 or move the files to another folder on your computer. Then switch your homepage back to one you like. If your computer doesn't do weird things after this permanently delete them. If it does, you might want to put them back one by one until you find the offender and then delete it.

Also, don't forget to grab the Microsoft patch which fixes the browser hole that allows the hijacker to work this little piece of dark magic.

To get the fix, run Windows Update found on your START menu or click here and select one of the suggested download links toward the bottom of the page.

Some hijackers, like Gohip, install an executable program (ending in .exe, something like hijack.exe) on your your computer. Since .EXE programs can't be automatically downloaded in the secure browsers (with all the latest security fixes installed), you usually get this by downloading a program from the web.

Hijackers sometimes mark these program as "browser updates" or "browser enhancements" or some other trickery. The hijacker typically offers you all kinds of incentives (freebies, special deals and stuff like that) to install the evil program.

To remove Gohip, use this program: http://www.pchell.com/support/gohip.shtml. Or to remove other spyware, so its called, got to this page: http://www.pchell.com/support/spyware.shtml.

Finally, there's another hijacking method. Some sites will find a way to put a shortcut in the Windows Startup folder or Registry Run key that starts the Registry Editor (regedit), then tells it to add the contents of a hidden file (e.g. C:\windows\temp\abcdefg.tmp) that contains the necessary information to set the hijacker's homepage to the Registry on every startup.

For more info and useful Articles  on computers go to http://www.cyberwalker.net/  There is stuff like How to Add Memory FAQ for Personal Computers, and way more articles.

 

Edited by meghavi - 19 years ago

Created

Last reply

Replies

2

Views

2235

Users

3

Frequent Posters

HUMM thumbnail
Anniversary 19 Thumbnail Group Promotion 4 Thumbnail + 3
Posted: 19 years ago
thanks meghavi, actually my friend had similar problems, but ur article shall definately happy!.. thanksπŸ‘πŸ‘πŸ‘
nandiinii thumbnail
Posted: 19 years ago
thanks 4 the wonderful info!!!!!!!!!!😊