ePlans.aim.com is a browser hijacker that redirects your homepage and new tab pages to unwanted advertising portals, often routing through suspicious domain chains before landing you on search results filled with sponsored links. This hijacker typically arrives bundled with free software installers and modifies browser settings across Chrome, Firefox, Edge, and other browsers without clear user consent. While not as destructive as ransomware or banking trojans, ePlans.aim.com degrades your browsing experience, tracks your search queries, and can expose you to further malware through the ad networks it promotes.
The hijacker earns revenue for its operators through pay-per-click advertising and affiliate commissions from the search traffic it redirects. Users often discover the infection when their browser suddenly opens to unfamiliar search pages or when legitimate search queries get rerouted through multiple redirects before reaching results pages. The persistence mechanisms make it more stubborn than a simple homepage change — it reinstalls itself if you don't remove all components.
Threat Profile
| Attribute | Details |
|---|---|
| Family | Browser hijacker / Potentially Unwanted Program (PUP) |
| Aliases | ePlans redirect, aim.com hijacker, ePlansaim.com redirect virus |
| Platform | Windows 7/8/10/11; affects Chrome, Firefox, Edge, Internet Explorer |
| Discovered | Active variants observed since 2018 (family evolves continuously) |
| Distribution | Software bundling, fake update prompts, malvertising chains, torrent packages |
| Persistence | Browser extensions, scheduled tasks, registry modifications, startup entries |
| Capabilities | Homepage/new tab hijacking, search redirection, tracking cookie deployment, settings lockdown |
| Data Collection | Search queries, browsing history, IP address, system info, potentially form data |
| Network Behavior | Redirects through multiple domains before final destination; communicates with ad networks |
| Payload Delivery | May download additional PUPs or adware as secondary infections |
| Removal Difficulty | Moderate — requires browser cleanup, extension removal, registry edits, and policy resets |
| Reinfection Risk | High if the original bundled installer remains on the system or in downloads folder |
How It Spreads
ePlans.aim.com rarely travels alone. The primary distribution method is software bundling, where the hijacker component gets packaged with legitimate-looking freeware installers. Users download what they think is a PDF converter, video codec, or system utility from a third-party download site, and the installer includes multiple "optional offers" that are pre-checked or buried in custom installation screens. If you click through the wizard quickly using the "Express" or "Recommended" installation option, you consent to installing the hijacker without realizing what you've agreed to.
The second common vector is fake update notifications that appear while browsing sketchy websites — particularly streaming sites, torrent portals, or adult content pages. These pop-ups claim your Flash Player, Java, or browser needs an urgent update. The download delivers the hijacker instead of the promised software. Some variants also spread through malicious browser extensions advertised as productivity tools, coupon finders, or weather widgets that request excessive permissions during installation.
Once on your system, ePlans.aim.com can facilitate additional infections by redirecting you to landing pages that push other PUPs. Here are the primary infection pathways:
- Bundled installers from download portals like Softonic, download.com mirrors, or torrent packages containing cracked software
- Fake update prompts masquerading as Adobe Flash, Java, or browser update notifications
- Malicious browser extensions installed from third-party stores or direct download links sent via spam
- Email attachments containing dropper scripts in macro-enabled documents (less common for this specific hijacker)
- Infected websites that exploit browser vulnerabilities or use social engineering to trigger downloads
- Peer-to-peer networks where executable files are disguised as media files or game cracks
What It Does On Your Machine
When ePlans.aim.com establishes itself, the first thing you'll notice is that your browser no longer opens to your chosen homepage. Instead, it loads a search portal — sometimes directly at a domain involving "eplans" or "aim.com" variations, sometimes through a redirect chain that bounces through multiple domains before landing on a search page filled with sponsored results. New tabs open to the same hijacked page instead of your blank page or speed dial. Search queries typed into the address bar get intercepted and rerouted through the hijacker's servers before returning results that prioritize advertiser links over relevant content.
Behind the scenes, the hijacker modifies browser configuration files and preferences to lock in these changes. In Chrome, it may alter the Preferences and Secure Preferences JSON files in your user profile directory. Firefox users find modified prefs.js and user.js files. The hijacker often installs a browser extension or helper object that re-applies these settings if you try to change them manually through the browser interface. When you attempt to reset your homepage, it either reverts immediately or changes back after the next restart.
The tracking component runs continuously while you browse. The hijacker plants cookies and may inject JavaScript into web pages to monitor your activity. It logs which sites you visit, what you search for, how long you spend on pages, and sometimes what you click. This data gets transmitted to remote servers where it builds an advertising profile. You'll start seeing targeted ads that seem to know too much about your recent browsing — that's the tracking component at work. Some variants also modify search results in real-time, injecting additional sponsored links at the top of results pages or replacing legitimate ads with substitute ads that generate revenue for the hijacker operators.
The persistence mechanisms ensure the hijacker survives browser resets and even some removal attempts. Common artifacts you might find include:
Manual Removal — Step by Step
Disconnect and Document
Disconnect your computer from the internet to prevent the hijacker from downloading additional components or updating its configuration. Take a quick screenshot of your current browser homepage and note any unfamiliar extensions you see in your browser's extension list — you'll verify these are gone later.
Boot Into Safe Mode with Networking
Restart your computer and press F8 repeatedly during boot (or Shift+Restart from Windows settings on newer systems). Select "Safe Mode with Networking" from the menu. This prevents the hijacker's startup items from loading and makes it easier to delete locked files while still allowing you to download removal tools if needed.
Uninstall Suspicious Programs
Open Control Panel → Programs and Features (or Settings → Apps on Windows 10/11). Sort by install date and look for anything installed around the time the hijacking started. Remove programs with names containing "ePlans," "aim," "Helper," "Updater," or any software you don't recognize. Watch out for fake uninstallers that try to install more junk — decline any "special offers" during uninstallation.
Remove Browser Extensions
Open each browser you use and navigate to the extensions/add-ons manager. In Chrome, go to chrome://extensions. In Firefox, use about:addons. In Edge, use edge://extensions. Remove any extensions you didn't install yourself or that have suspicious permissions. Even if an extension looks legitimate, remove anything installed around the time the problem started — you can reinstall genuine ones later from official sources.
Delete the Program Folders
Navigate to C:\Program Files, C:\Program Files (x86), %LOCALAPPDATA%, and %APPDATA%. Look for folders named "ePlans," "ePlansHelper," "ePlansAim," or similar variations. Delete these entire folders. If Windows says files are in use, note the folder location and return after Step 6. Also check your Downloads folder and delete any installers that brought this in originally.
Clean Registry and Scheduled Tasks
Press Windows+R, type "taskschd.msc" and delete any scheduled tasks with "ePlans" or suspicious random names. Then press Windows+R, type "regedit" and navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. Delete any entries referencing ePlans paths. Also check HKLM\SOFTWARE\Policies\Google and HKLM\SOFTWARE\Policies\Mozilla for policy entries that lock your homepage — delete the entire Policies key if it only contains hijacker settings.
Reset Browser Settings
In each browser, navigate to settings and perform a full reset. Chrome: Settings → Advanced → Reset and clean up → Restore settings to defaults. Firefox: Help → More troubleshooting information → Refresh Firefox. Edge: Settings → Reset settings → Restore settings to defaults. This clears the hijacked homepage, search engine, and startup pages while preserving your bookmarks and passwords.
Scan with Reputable Anti-Malware
Reconnect to the internet and download Malwarebytes Free from malwarebytes.com (verify the URL carefully). Run a full scan to catch any remaining components. The free version works fine for one-time cleanup. Let it quarantine everything it finds, then restart when prompted. Consider running a second scan with HitmanPro or AdwCleaner for thoroughness — these tools often catch what each other miss.
Change Passwords from a Clean Device
If the hijacker was present for more than a few days, assume it may have logged your keystrokes or form data. From a different device (your phone or a known-clean computer), change passwords for important accounts — email, banking, shopping sites. Enable two-factor authentication wherever possible to protect accounts even if passwords were compromised.
Reboot and Verify
Restart your computer normally (not in safe mode). Open each browser and verify your homepage is what you set, new tabs open correctly, and searches go through your chosen search engine. Check Task Manager (Ctrl+Shift+Esc) for any suspicious processes still running. Monitor for a few days — if the hijacker returns, you likely missed a persistence mechanism or the original installer is still present.
Prevention
- Download software only from official sources. Avoid third-party download sites like Softonic, download.com, or any site that wraps the real installer in their own downloader. Go directly to the developer's website or use Microsoft Store for Windows applications.
- Always choose "Custom" installation. When installing free software, never click "Express" or "Recommended" install. Select "Custom" or "Advanced" and read each screen carefully. Uncheck any boxes offering toolbars, browser changes, or additional software you didn't specifically seek out.
- Keep your browser and OS updated. Enable automatic updates for Windows and your browsers. Security patches close vulnerabilities that hijackers exploit. The inconvenience of occasional restarts is minor compared to cleaning up an infection.
- Use a reputable ad blocker. Extensions like uBlock Origin block malicious ads and fake update prompts that lead to infections. This stops many hijacker distribution methods before they reach you. Just install ad blockers from official browser stores, not third-party sites.
- Ignore "update required" pop-ups on websites. Legitimate software updates come through the application itself or Windows Update, not browser pop-ups on random websites. If you think you actually need an update, close the pop-up and go directly to the vendor's official site to download it.
- Review installed extensions quarterly. Make it a habit to audit your browser extensions every few months. Remove anything you don't actively use. Check the permissions for extensions you keep — if a weather widget wants permission to "read and change all your data on all websites," that's a red flag.
- Run periodic scans with Malwarebytes. Even with careful browsing, occasional scans catch things that slip through. The free version works fine for scheduled manual scans. Run one monthly to catch PUPs before they become entrenched.
- Create a standard user account for daily use. Run Windows with a standard (non-administrator) user account for everyday browsing and work. Many installers require admin credentials, which gives you a moment to question whether you really want to install something. Save the admin account for deliberate software installations.
Bring It In
If you've worked through these steps and the hijacker keeps coming back, or if you're just not comfortable editing the registry and hunting through program folders, bring the computer to our shop in Roswell. We see browser hijackers every week, and we have the tools and experience to clean them out completely — including the ones that hide in places the manual steps above might miss. We'll also check for secondary infections that often travel with hijackers, make sure your system is fully patched, and help you understand what happened so it doesn't happen again.
Call us at (770) 695-6000 or stop by at 1835 Mack Dobbs Road NW, Roswell, GA 30075. We're open Monday through Friday and can usually get your machine cleaned and back to you within 24 hours. No appointment needed for drop-offs — just bring it in and we'll take a look. If it's a simple hijacker removal, we'll quote you a flat rate up front, no surprises when you pick it up.