InfoAboutTomorrow.com is a browser hijacker that forcibly redirects users to unwanted websites, manipulates search results, and reconfigures browser settings without permission. This potentially unwanted program (PUP) typically arrives bundled with free software downloads and immediately takes control of your default homepage, new tab page, and search engine preferences. While not technically a virus in the traditional sense, InfoAboutTomorrow.com exhibits aggressive behavior that can expose users to malicious advertising, phishing attempts, and further malware infections through the deceptive sites it promotes.
Once installed, this hijacker proves frustratingly persistent, resisting standard removal attempts by reinstalling itself through hidden helper files and modified browser shortcuts. Users frequently report being unable to change their settings back, with InfoAboutTomorrow.com reappearing immediately after each attempted fix. The program generates revenue for its operators by forcing traffic to sponsored search engines and advertising networks, degrading your browsing experience while potentially harvesting your search queries and browsing habits for profit.
Threat Profile
| Attribute | Details |
|---|---|
| Threat Type | Browser Hijacker, Potentially Unwanted Program (PUP) |
| Family | Search redirect/homepage hijacker family |
| Aliases | InfoAboutTomorrow redirect, InfoAboutTomorrow.com hijacker, PUP.Optional.InfoAboutTomorrow |
| Affected Platforms | Windows 7/8/10/11; affects Chrome, Firefox, Edge, Internet Explorer |
| Distribution Method | Software bundling, fake update prompts, deceptive download buttons on freeware sites |
| Persistence Mechanism | Modified browser shortcuts, browser extension/add-on installation, scheduled tasks, registry modifications |
| Primary Capabilities | Homepage/search engine replacement, traffic redirection, ad injection, browsing data collection |
| Typical Artifacts | Browser extensions with randomized names, modified shortcut targets, registry keys under HKCU\Software\[random GUID] |
| Network Behavior | Constant connections to ad networks and redirect chains; queries to infoabouttomorrow.com and affiliated search portals |
| Data at Risk | Search queries, browsing history, frequently visited sites, potentially form data on hijacked pages |
| Removal Difficulty | Moderate — resists simple uninstallation through self-protection and hidden components |
| Reinfection Risk | High if bundled software sources are not avoided |
How It Spreads
InfoAboutTomorrow.com spreads primarily through software bundling, a deceptive practice where free or pirated applications include additional unwanted programs in their installers. When users rush through installation dialogs using the "Express" or "Recommended" settings, they unknowingly authorize the installation of the hijacker alongside the desired program. The bundling is often disguised through pre-checked boxes buried in lengthy terms-of-service agreements or presented in confusing language designed to trick users into consent.
Freeware download sites represent the most common infection vector. These sites frequently wrap legitimate software in custom installers packed with PUPs like InfoAboutTomorrow.com, generating revenue through pay-per-install schemes. Users searching for popular free tools—video converters, PDF readers, download managers, system optimizers—encounter download buttons designed to mislead, with the actual software download link hidden among multiple fake download buttons that instead deliver bundled installers.
Additional distribution methods include:
- Fake browser update notifications appearing on compromised or low-quality websites, claiming your browser is out of date and offering a malicious "update" file
- Malicious advertising (malvertising) on legitimate sites, where clicking specific ads triggers automatic downloads of bundled installers
- Email attachments disguised as documents that actually contain installer executables with misleading double-extensions
- Torrent downloads and crack/keygen tools for pirated software, which frequently include browser hijackers and worse malware
- Fake video codec installers presented on streaming sites claiming you need special software to view video content
- Social engineering through search results where attackers optimize fake download pages to appear in Google searches for popular free software
What It Does On Your Machine
Once executed, InfoAboutTomorrow.com immediately targets your browser configuration files and Windows settings to establish control over your web browsing. The hijacker modifies your browser's homepage, default search engine, and new tab page to redirect through infoabouttomorrow.com or associated domains. Every search query you enter gets routed through the hijacker's servers before being forwarded to a legitimate search engine—allowing the operators to log your searches, inject additional advertisements into results, and potentially redirect you to sponsored pages instead of your intended destination.
The program installs persistence mechanisms that survive standard removal attempts. It creates copies of itself in hidden system folders, modifies Windows registry keys to launch on startup, and alters your browser shortcut files to include command-line parameters that force the hijacked homepage. Even after you manually reset your browser settings, these persistence mechanisms reapply the hijacker's configuration within seconds or upon the next restart. Many variants install a browser extension or add-on that enforces the settings from within the browser itself, making removal impossible through Windows control panel alone.
InfoAboutTomorrow.com also monitors your browsing activity to collect marketable data. The hijacker tracks which websites you visit, what you search for, how long you spend on pages, and which links you click. This information gets transmitted to remote servers where it's used to build advertising profiles or sold to third-party data brokers. While the hijacker isn't typically classified as spyware in the strictest sense, the privacy violation is substantial—you have no control over who receives this information or how it's used.
The redirect chains employed by this hijacker can expose you to genuinely dangerous content. The intermediate pages you're bounced through before reaching your search results or intended website may contain drive-by download exploits, phishing forms designed to steal credentials, or fake security warnings pushing additional malware. The hijacker's operators have no quality control over their advertising partners, meaning you might encounter anything from annoying pop-ups to serious threats like ransomware installers presented as "required security updates."
Manual Removal — Step by Step
Disconnect and Document
Disconnect from the internet to prevent the hijacker from downloading additional components or updating its configuration. Take screenshots of your current browser settings (homepage, search engine, extensions) and note any programs you installed around the time the redirects began. This documentation helps identify all related components.
Boot to Safe Mode with Networking
Restart Windows in Safe Mode to prevent the hijacker's startup items from launching. On Windows 10/11, hold Shift while clicking Restart, then navigate to Troubleshoot → Advanced Options → Startup Settings → Restart, and select Safe Mode with Networking (option 5). This limits the hijacker's ability to protect itself during removal.
Uninstall Suspicious Programs
Open Settings → Apps → Apps & features (or Control Panel → Programs → Uninstall a program on older Windows). Sort by install date and remove any unfamiliar programs installed around the time redirects started. Look for generic names, publisher names that don't match the program name, or anything with "Search," "Helper," "Updater," or similar vague terms. Uninstall anything suspicious, even if you're not certain it's related.
Remove Browser Extensions
Open each affected browser and thoroughly clean extensions. In Chrome/Edge, go to the menu → Extensions → Manage Extensions and remove anything unfamiliar or that you didn't deliberately install. In Firefox, go to menu → Add-ons and themes → Extensions. The hijacker extension often has a generic name and lacks a proper icon. Remove it even if the browser warns that it's "managed by your organization"—that message is fake enforcement by the hijacker.
Delete Hijacker Folders and Files
Open File Explorer and navigate to %LOCALAPPDATA% and %APPDATA% (paste these into the address bar). Look for folders with random GUID names (like {A7B3C894-...}) or folders containing "Info," "Search," or "Tomorrow." Delete any suspicious folders. Check your Desktop and Startup folder (shell:startup) for unexpected shortcuts. Also check C:\Program Files and C:\Program Files (x86) for any folders matching suspicious program names you uninstalled.
Clean Registry Persistence Keys
Press Win+R, type regedit, and hit Enter. Navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and look for entries pointing to random executables or containing "InfoAboutTomorrow" or similar terms—delete those entries. Also check HKEY_CURRENT_USER\Software for any keys named InfoAboutTomorrow or suspicious GUIDs and delete them. Be careful only to delete items you're confident are related; modifying the wrong registry keys can cause system problems.
Remove Scheduled Tasks
Open Task Scheduler (search for it in the Start menu). Expand Task Scheduler Library and look through the tasks, especially under Microsoft\Windows subfolders, for anything with unfamiliar names or descriptions. Check the Actions tab of suspicious tasks—if they point to executables in %APPDATA% or %LOCALAPPDATA% with random names, delete the task. The hijacker often creates tasks that run hourly to re-establish settings.
Fix Browser Shortcuts
Right-click your browser shortcuts (on Desktop, Taskbar, and in Start menu), select Properties, and examine the Target field. It should end with the browser executable path (like chrome.exe or firefox.exe) with nothing after it. If you see --homepage or --new-tab-url parameters followed by URLs, delete everything after the .exe" including the space. Click OK to save. Do this for every browser shortcut you use.
Reset Browser Settings
Open each browser and perform a settings reset. In Chrome/Edge, go to Settings → Reset settings → Restore settings to their original defaults. In Firefox, go to Help → More troubleshooting information → Refresh Firefox. This removes remaining hijacker configurations while preserving your bookmarks and passwords. After reset, manually reconfigure your preferred homepage and search engine.
Scan with Anti-Malware Software
Reconnect to the internet and download Malwarebytes Free (from malwarebytes.com directly, not a download site). Run a full Threat Scan to catch any components you may have missed. Also run Windows Defender's offline scan (Settings → Update & Security → Windows Security → Virus & threat protection → Scan options → Microsoft Defender Offline scan). These tools catch hijacker remnants that manual removal often misses.
Verify and Monitor
Restart your computer normally (not in Safe Mode) and test your browsers. Verify that your homepage and search engine remain as you set them after several restarts and browsing sessions. If redirects return, the hijacker has a component you missed—repeat the removal process more carefully or bring the machine in for professional cleaning. Monitor your browser behavior for the next few days to ensure the problem doesn't resurface.
Prevention
- Download software only from official sources. Get programs directly from the developer's website, not from download portals, freeware sites, or search result ads. When in doubt, type the official domain directly into your browser rather than clicking search results.
- Always choose Custom/Advanced installation. Never use Express or Recommended install options. The Custom path shows you exactly what's being installed and lets you deselect bundled software. Read every screen carefully and uncheck any boxes offering additional programs, toolbars, or homepage changes.
- Keep Windows and browsers updated. Enable automatic updates for Windows, Chrome, Firefox, and Edge. Updates patch vulnerabilities that malware exploits and improve built-in protection against hijackers and PUPs.
- Use browser security extensions sparingly but wisely. Install uBlock Origin (not uBlock or other variants) to block malicious advertising. Consider adding Windows Defender Browser Protection extension. Avoid installing many extensions—each one is a potential security risk.
- Enable Windows Defender real-time protection. Don't disable it to run questionable software. The real-time protection catches many PUPs during installation. Also enable Windows SmartScreen filter, which blocks known malicious downloads.
- Be skeptical of urgent warnings and update prompts. Legitimate software updates happen through the program itself or Windows Update, not through pop-ups on websites. Any site telling you that your browser, Flash, video codec, or Windows needs immediate updating is lying.
- Review installed programs monthly. Check your programs list regularly and remove anything you don't recognize or no longer use. Hijackers sometimes install silently through vulnerabilities in other programs, and catching them early prevents deeper infection.
- Create a standard user account for daily use. Don't use an administrator account for regular browsing and email. PUPs have harder time installing persistence mechanisms when you're running as a standard user, as they can't easily modify system-wide settings or protected registry keys.
Bring It In
Browser hijackers like InfoAboutTomorrow.com rarely travel alone. If your system got infected with this PUP, there's a good chance other unwanted programs came with it—toolbars, adware, fake system optimizers, or worse. While the removal steps above handle typical InfoAboutTomorrow.com infections, persistent or complicated cases benefit from professional attention. Our technicians have removed thousands of hijackers and know the tricks these programs use to survive amateur removal attempts. We'll clean your machine thoroughly, verify that all malware components are gone, and optimize your browser performance while we're at it.
Computer Repair Roswell is located at 1279 Hembree Road in Roswell, just a few minutes from downtown. We offer same-day service for malware removal—most hijacker cleanups take one to two hours, and you're welcome to wait while we work. Call us at (770) 674-6996 or stop by during business hours. We'll get your browser back under your control and make sure the infection doesn't return. No appointment necessary for drop-offs, though calling ahead helps us prepare for your arrival.