# Hijacked IE Favorites

**URL:** <https://boards.straightdope.com/t/hijacked-ie-favorites/257245>\
**Category:** Factual Questions\
**Created:** [July 28, 2004, 6:17am UTC](https://boards.straightdope.com/t/hijacked-ie-favorites/257245 "2004-07-28T06:17:54Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ephemera](https://avatars.discourse-cdn.com/v4/letter/e/8baadc/32.png) [@Ephemera](https://boards.straightdope.com/u/Ephemera)\
**Post date:** [July 28, 2004, 6:17am UTC](https://boards.straightdope.com/t/hijacked-ie-favorites/257245/1 "2004-07-28T06:17:54Z")

</div>

My IE favorites keep getting hijacked. About a week ago, I first noticed that there were about five adult links in my favorites list when I never put them there. I didn’t think much of it and deleted them and went about my business until I restarted my computer and upon clicking on my favorites, had them show up again.

A little annoyed, I deleted them again only to have the same situation happen again and again. I’ve downloaded both Adaware and Spybot and run them both on my computer to see if they might be able to do anthing but so far, neither has and it’s getting very irksome.

Does anyone have any idea what might be causing this and how I could get rid of the damned things? It would be much appreciated.

---

<div class="post-metadata">

**Author:** ![flight](https://avatars.discourse-cdn.com/v4/letter/f/bbce88/32.png) [@flight](https://boards.straightdope.com/u/flight)\
**Post date:** [July 28, 2004, 7:38am UTC](https://boards.straightdope.com/t/hijacked-ie-favorites/257245/2 "2004-07-28T07:38:16Z")

</div>

What is causing it? Dunno.

How to fix it? Stop using IE. Even Netscape doesn’t get this stuff.

---

<div class="post-metadata">

**Author:** ![Ximenean](https://avatars.discourse-cdn.com/v4/letter/x/aca169/32.png) [@Ximenean](https://boards.straightdope.com/u/Ximenean)\
**Post date:** [July 28, 2004, 10:55am UTC](https://boards.straightdope.com/t/hijacked-ie-favorites/257245/3 "2004-07-28T10:55:05Z")

</div>

There’s possibly something in the Run or Run Once section of the Windows registry that’s creating these shortcuts. If you run **msconfig** , or (my preference) download [Mike Lin’s Startup Control Panel](http://www.mlin.net/StartupCPL.shtml) and run that, you can look in the Run section(s) for the culprit, and remove it. Or you can edit the registry directly with **regedit** , but only if you really know what you’re doing.

If you prefer, post a list of the Run entries here for us resident Windows geeks to have a look at.

If you must use IE, you can avoid this sort of thing by disabling ActiveX scripting. A few sites require ActiveX, though.

---

<div class="post-metadata">

**Author:** ![Ephemera](https://avatars.discourse-cdn.com/v4/letter/e/8baadc/32.png) [@Ephemera](https://boards.straightdope.com/u/Ephemera)\
**Post date:** [July 28, 2004, 11:05am UTC](https://boards.straightdope.com/t/hijacked-ie-favorites/257245/4 "2004-07-28T11:05:03Z")

</div>

I’m not as computer literate as I could be. I know enough to know how to run msconfig but what tab am I supposed to click on afterwards? And are you wanting me to list every program that it shows as running?

---

<div class="post-metadata">

**Author:** ![Ximenean](https://avatars.discourse-cdn.com/v4/letter/x/aca169/32.png) [@Ximenean](https://boards.straightdope.com/u/Ximenean)\
**Post date:** [July 28, 2004, 11:36am UTC](https://boards.straightdope.com/t/hijacked-ie-favorites/257245/5 "2004-07-28T11:36:05Z")

</div>

The Startup tab, the rightmost one. If you are using Windows XP, **msconfig** will tell you where each startup entry is to be found, in the Location column. We’re interested in the ones located in either HKLM\bla bla bla\Run, RunOnce, or HKCU\bla bla bla\Run. Other versions of Windows either don’t have msconfig or don’t show the Location, which is why I prefer Mike Lin’s little program.

Anyway, chances are you will recognise what some of the Run entries are. They may be related to your video card, or your anti-virus software or whatever. One of the ones that you don’t recognise _might_ be the culprit.

---

<div class="post-metadata">

**Author:** ![Ximenean](https://avatars.discourse-cdn.com/v4/letter/x/aca169/32.png) [@Ximenean](https://boards.straightdope.com/u/Ximenean)\
**Post date:** [July 28, 2004, 11:49am UTC](https://boards.straightdope.com/t/hijacked-ie-favorites/257245/6 "2004-07-28T11:49:41Z")

</div>

BTW there’s a pretty comprehensive list of known startup entries [here](http://www.sysinfo.org/startuplist.php), including ones created by spyware. You can search for them by name.

---

<div class="post-metadata">

**Author:** ![Achilles](https://avatars.discourse-cdn.com/v4/letter/a/dc4da7/32.png) [@Achilles](https://boards.straightdope.com/u/Achilles)\
**Post date:** [July 28, 2004, 11:57am UTC](https://boards.straightdope.com/t/hijacked-ie-favorites/257245/7 "2004-07-28T11:57:01Z")

</div>

The cause is likely to be “coolwebsearch” or some such browser hijacker.

They’re a right bitch to get rid of.

Firstly, and I’m fucking sick of telling people, STOP USING IE. It sucks. Use Netscape 7.1 - freely available from [netscape.com](http://netscape.com). If you can / won’t use netscape, use Firefox or Opera. Seriously. These hijackers only affect IE.

This is a very fucking serious problem - check out the story of the guy busted for kiddie pr0n, on account of his broswer being hijacked:

> **[Child porn case highlights browser hijack risks](https://www.theregister.com/2004/05/13/browser_hijacking_risks/)**
>
> Cautionary tales

With a view to getting rid of coolwebsearch, check out this article:

> **[CoolWebSearch is winning Trojan war](https://www.theregister.com/2004/06/29/cws_shredder/)**
>
> Programmer bows out

You’ll need to get CWShredder. Google for it.

And change browser immediately.

---

<div class="post-metadata">

**Author:** ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)\
**Post date:** [July 28, 2004, 12:22pm UTC](https://boards.straightdope.com/t/hijacked-ie-favorites/257245/8 "2004-07-28T12:22:19Z")

</div>

First of all, have you run [Ad-Aware](http://www.lavasoftusa.com/support/download/)? That’s the first thing to do when you get a problem like this. Be sure to update the definitions (click on “Check for Updates Now” when you run it.

Though CoolWebSearch is a problem, this doesn’t sound like a CWS infestation (which hijacks your home page, not your favorites). If Ad-Aware doesn’t fix things, you could try [CWShredder](http://www.majorgeeks.com/download4086.html), though if it’s not CWS, it won’t help (but it won’t hurt, either).

If neither of these works, download and run [Hijackthis](http://www.siena.edu/antivirus/spyware/hijackthis.htm) and post the log at [http://www.spywareinfo.com](http://www.spywareinfo.com) for analysis.

---

<div class="post-metadata">

**Author:** ![Musicat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/musicat/32/20189_2.png) [@Musicat](https://boards.straightdope.com/u/Musicat)\
**Post date:** [July 28, 2004, 12:54pm UTC](https://boards.straightdope.com/t/hijacked-ie-favorites/257245/9 "2004-07-28T12:54:28Z")

</div>

**Aesiron,** did you read the first thread in the GQ Forum? The one at the top? The one that was made a “Sticky” so you couldn’t miss it? The one that is titled [Have a Computer Question ? Read this first."?](http://boards.straightdope.com/sdmb/showthread.php?t=260053)

Think it might be worth reading? First? 🙂

More answers in that thread than you can shake a hijacked stick at.

---

<div class="post-metadata">

**Author:** ![Ephemera](https://avatars.discourse-cdn.com/v4/letter/e/8baadc/32.png) [@Ephemera](https://boards.straightdope.com/u/Ephemera)\
**Post date:** [July 28, 2004, 4:37pm UTC](https://boards.straightdope.com/t/hijacked-ie-favorites/257245/10 "2004-07-28T16:37:42Z")

</div>

No. I didn’t read the sticky. I have a habit of scrolling past the things since I read most of them way back when and never think to look and see if there’re new ones. I’ll look at it now though.

> [@RealityChuck](#):
>
> Though CoolWebSearch is a problem, this doesn’t sound like a CWS infestation (which hijacks your home page, not your favorites). If Ad-Aware doesn’t fix things, you could try CWShredder, though if it’s not CWS, it won’t help (but it won’t hurt, either).

It’s hijacked my homepage too. I have google as the default but every time I restart, it gets reset to about:blank. For a while there, it was directed at some other site but thankfully, it’s stopped that and just gone with what I’ve mentioned. It’s still annoying though.

And coolwebsearch does sound familiar. I think I saw it listed as one of the programs that Spybot flagged but never actually immunizes against. Every time I try to block the programs, the damned thing freezes me out and I have to close it.

Thanks for the replies, everyone. I’ll be sure to check this out when I get home and post further if I have any more questions.

---

<div class="post-metadata">

**Author:** ![Musicat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/musicat/32/20189_2.png) [@Musicat](https://boards.straightdope.com/u/Musicat)\
**Post date:** [July 28, 2004, 5:01pm UTC](https://boards.straightdope.com/t/hijacked-ie-favorites/257245/11 "2004-07-28T17:01:04Z")

</div>

**Aesiron,** the CoolWeb stuff is not detected by AdAware, by their own admission, and Spybot may have a problem with it, too. I have a dialogue going with AdAware over this. So for now, the CWShredder specialized routine is the one to use.

Check for BHO (brower help objects), too. Links in the sticky thread.

---

<div class="post-metadata">

**Author:** ![Algernon](https://avatars.discourse-cdn.com/v4/letter/a/a183cd/32.png) [@Algernon](https://boards.straightdope.com/u/Algernon)\
**Post date:** [July 28, 2004, 6:16pm UTC](https://boards.straightdope.com/t/hijacked-ie-favorites/257245/12 "2004-07-28T18:16:54Z")

</div>

> [@Aesiron](#):
>
> It’s hijacked my homepage too. … it gets reset to about:blank.

Oh man. The about:blank hijacking is about the worst sort to have. I spent a couple weeks before finally getting rid of it. Without the help of the folks at [www.spywareinfo.com](http://forums.spywareinfo.com/), I don’t think I’d have been successful. They are truly helpful – but unfortunately, they’re swamped. It can take days for one of the experts to respond.

I’d suggest going to their forums (link above), and doing a lot of reading. They have numerous tools, techniques, and suggestions that they give to people day after day. You can obtain enough knowledge just by reading to solve your hijacking.

Good luck.
