If your browser now opens to an unfamiliar search page, redirects every search through an odd-looking site, or a new toolbar has appeared that you never installed, you're dealing with a browser hijacker β€” a form of adware that changes browser settings, often bundled with free software downloads. This guide shows you how to remove it properly rather than just resetting the homepage, which alone rarely fixes the underlying cause.

How to Recognise a Browser Hijack

  • Your homepage or new tab page has changed to an unfamiliar search engine
  • Searches from the address bar get redirected through a third-party site before reaching real results
  • A new toolbar, "search assistant," or extension appears that you don't remember installing
  • Excessive pop-up ads appear even on sites that don't normally show them
  • Your default search engine keeps reverting to the hijacked one even after you manually change it back

Safety warning: Do not enter any passwords, card details, or personal information into your browser while a hijacker is active. Some hijackers include tracking or credential-harvesting components, and redirected "search results" pages are sometimes designed to mimic login pages for popular sites.

Step 1: Check Installed Programs for the Culprit

Browser hijackers are almost always installed alongside free software β€” a "bundled" toolbar or search tool you unknowingly agreed to during a rushed installation.

  1. Open Settings > Apps > Installed apps on Windows.
  2. Sort by Install date and look for anything installed around the time the problem started.
  3. Look for unfamiliar names, especially anything containing words like "Search," "Toolbar," "Assistant," "Optimizer," or "Helper."
  4. Uninstall anything suspicious by selecting it and choosing Uninstall.
  5. Restart your PC after uninstalling, even if not prompted.

Step 2: Remove Malicious Browser Extensions

Google Chrome / Microsoft Edge

  1. Open the browser and go to Settings > Extensions (or type chrome://extensions / edge://extensions directly into the address bar).
  2. Review every listed extension. Remove anything you don't specifically recognise and remember installing β€” click Remove next to it.
  3. Pay particular attention to extensions with vague names, no publisher information, or very few reviews if you check the Chrome/Edge Web Store listing.

Mozilla Firefox

  1. Go to Settings > Extensions & Themes (or type about:addons into the address bar).
  2. Check both Extensions and Appearance tabs for unfamiliar entries.
  3. Remove anything suspicious.

Step 3: Reset Your Search Engine and Homepage

After removing the culprit extension or program, the settings themselves often need to be manually reset since the hijacker doesn't clean up after itself.

Chrome

  1. Go to Settings > Search engine and set your preferred default (Google, Bing, DuckDuckGo) from the dropdown.
  2. Go to Settings > On startup and set your preferred homepage, removing any unfamiliar URLs listed.
  3. Go to Settings > Reset settings > Restore settings to their original defaults for a thorough clean slate if problems persist.

Edge

  1. Go to Settings > Privacy, search, and services > Address bar and search and set your preferred search engine.
  2. Go to Settings > Start, home, and new tabs and correct the homepage and new tab settings.
  3. Use Settings > Reset settings > Restore settings to their default values if needed.

Firefox

  1. Go to Settings > Search and choose your default search engine, removing any unfamiliar ones from the list via Remove.
  2. Go to Settings > Home and set Homepage and new windows back to your preference.
  3. If problems persist, use about:support and click Refresh Firefox for a clean reset that keeps bookmarks and passwords but removes hijacked configuration.

Step 4: Check Shortcut Targets (A Commonly Missed Step)

A particularly persistent form of hijack modifies your browser's desktop or taskbar shortcut to append the hijacker's URL as a launch parameter, so it reopens the unwanted page every time you click the icon β€” even after resetting all in-browser settings.

  1. Right-click your browser shortcut (desktop, taskbar, or Start menu) and choose Properties.
  2. Look at the Target field. It should end simply in ...\chrome.exe" (or edge.exe/firefox.exe) with no additional text after the closing quotation mark.
  3. If you see a URL appended after the executable path (e.g. chrome.exe" http://hijacked-site.example), delete everything after the closing quotation mark and click OK.
  4. Repeat for every shortcut to that browser you have β€” desktop, taskbar pin, and Start menu tile can each be modified independently.

Pro tip: This shortcut-hijacking trick is why resetting browser settings sometimes "doesn't work" β€” the browser opens correctly from its settings, but the icon you actually click is still forcing the hijacked page. Always check shortcut targets if a reset alone doesn't resolve things.

Step 5: Run a Full Malware Scan

  1. Open Windows Security > Virus & threat protection and run a Quick scan followed by a Full scan.
  2. Download and run Malwarebytes (from the official malwarebytes.com site) for a second-opinion scan β€” its free version is specifically strong at catching adware and potentially unwanted programs (PUPs) that hijackers rely on, which traditional antivirus sometimes classifies as "low risk" and leaves in place.
  3. Quarantine and remove anything detected, then restart.

Step 6: Check for Modified DNS or Proxy Settings

Some more advanced hijackers modify your network settings rather than (or in addition to) the browser itself, redirecting traffic at a lower level.

  1. On Windows, go to Settings > Network & Internet > Proxy and confirm "Use a proxy server" is switched off unless you deliberately configured one.
  2. Check your DNS settings under your network adapter's properties β€” if a hijacker has set a custom DNS server you didn't configure, switch it back to automatic or to a trusted public DNS like 1.1.1.1.
  3. If you're comfortable doing so, check your router's DNS settings too (in its admin page) β€” some hijackers modify router-level DNS to affect every device on the network, not just one browser.

Step 7: Prevent It Happening Again

  • When installing free software, always choose Custom or Advanced installation rather than "Express" or "Recommended" β€” this reveals and lets you decline bundled toolbars and search tools.
  • Read each installation screen rather than clicking "Next" repeatedly.
  • Download software only from the official developer site or a trusted source like the Microsoft Store, not from third-party "download portal" sites that repackage installers with bundled extras.
  • Keep your browser and Windows updated, and periodically review your installed extensions list even when nothing seems wrong.

A browser hijack is rarely dangerous on its own compared to a trojan or ransomware, but treat it as a warning sign that something got installed without your full awareness β€” take the extra ten minutes to check the surrounding installed programs and shortcuts rather than just resetting the homepage and hoping it stays fixed.


Was this guide helpful? Explore more Malware Removal guides, or browse all Security & Performance articles.