If your browser's homepage has mysteriously changed, you're being bombarded with pop-up adverts, or searches are being redirected through unfamiliar sites, you're very likely dealing with adware or a browser hijacker. These are among the most common forms of unwanted software, usually bundled in with free downloads, and while rarely as dangerous as a full virus, they're intrusive, privacy-invasive, and can be surprisingly stubborn to remove. This guide shows you exactly how to identify and eliminate them for good.

What's the difference between adware and a browser hijacker?

Adware is software that displays unwanted advertisements β€” pop-ups, banners, or injected ads on web pages that shouldn't have them. It often runs quietly in the background, generating revenue for whoever created it every time you see or click an ad.

Browser hijackers go a step further, actively changing your browser's settings without permission: your homepage, default search engine, or new tab page gets redirected to an unfamiliar site, often one filled with ads or fake search results, and search queries may be routed through additional tracking servers before reaching a genuine search engine.

Both are typically installed as "bundled" extras when installing free software, especially from third-party download sites, or by clicking through installers too quickly without unticking optional add-ons.

Signs of adware or a browser hijacker

  • Your browser's homepage or default search engine has changed without you doing it
  • Pop-up adverts appear on websites that normally don't have them, or even with no browser open at all
  • New toolbars or extensions you don't remember installing
  • Searches redirect through an unfamiliar intermediate website before reaching results
  • Your browser feels noticeably slower, or new tabs open automatically
  • A "System Alert" or "Your PC is infected" pop-up urging you to call a number or download software β€” this is almost always a scam, not a genuine warning

Warning: Never call a phone number or download software from a pop-up claiming your PC is infected, no matter how convincing or official it looks. These are scareware scams designed to trick you into paying for fake support or installing further malware. Genuine Windows security alerts never appear as a random browser pop-up.

Step 1: Close the browser and check running processes

If pop-ups are appearing persistently, open Task Manager (Ctrl+Shift+Esc) and check for unfamiliar processes using significant CPU or memory, particularly anything with a vague or randomly generated name. End any suspicious tasks before continuing, though be cautious not to end essential Windows processes you don't recognise β€” search the exact process name online from another device if unsure.

Step 2: Uninstall unfamiliar programs

Adware is very often installed as a standalone program alongside whatever you actually intended to download.

  1. Go to Settings > Apps > Installed apps.
  2. Sort by Install date, and look closely at anything installed around the time your symptoms started.
  3. Look for generic-sounding names like "Search Protect," "Browser Assistant," "PC Optimizer," "Driver Updater," or anything you don't specifically recall installing.
  4. Select each suspicious entry and click Uninstall, following any prompts.

Step 3: Remove malicious or unwanted browser extensions

Even after uninstalling the parent program, its browser extension often lingers and needs removing separately.

Chrome

  1. Click the three-dot menu > Extensions > Manage Extensions.
  2. Review every extension listed. Remove anything you didn't deliberately install by clicking Remove.

Microsoft Edge

  1. Click the three-dot menu > Extensions > Manage extensions.
  2. Remove any unfamiliar entries the same way.

Firefox

  1. Click the menu button > Add-ons and themes > Extensions.
  2. Remove anything suspicious via the three-dot menu next to each extension.

Pro tip: If an extension refuses to uninstall, or the removal button is greyed out, it may have been installed by group policy or an enterprise management profile β€” a sign of a more serious hijack. In this case, proceed to the full scan and reset steps below rather than fighting with the extension manager.

Step 4: Reset your browser's homepage, search engine, and new tab page

Even after removing the offending extension or program, hijacked settings often don't revert automatically.

Chrome

  1. Go to Settings > You and Google > Sync and Google services, or directly to Settings > Search engine, and confirm your default search engine is set correctly.
  2. Go to Settings > On startup and check the homepage/startup pages listed β€” remove any unfamiliar URLs.
  3. For a thorough clean-up, go to Settings > Reset settings > Restore settings to their original defaults.

Microsoft Edge

  1. Go to Settings > Start, home, and new tabs and check for unfamiliar URLs.
  2. Go to Settings > Privacy, search, and services > Address bar and search, and confirm the search engine.
  3. Use Settings > Reset settings > Restore settings to their default values for a full reset.

Firefox

  1. Go to Settings > Home and check the homepage setting.
  2. Go to Settings > Search and confirm the default search engine.
  3. For a full reset, go to Help > More troubleshooting information > Refresh Firefox.

Step 5: Run a full scan with Windows Defender and Malwarebytes

Adware and hijackers can leave behind hidden files, scheduled tasks, or registry entries that keep reinstalling themselves even after you remove the obvious program and extension.

  1. Open Windows Security > Virus & threat protection > Scan options > Full scan, and let it complete.
  2. Download and run Malwarebytes free edition from the official malwarebytes.com site β€” it's particularly effective against adware and potentially unwanted programs (PUPs), which mainstream antivirus tools sometimes deprioritise.
  3. Quarantine or remove everything both tools flag.

See our companion guide on how to scan for and remove viruses for a more detailed walkthrough of the scanning process itself.

Step 6: Check for scheduled tasks and startup entries

Some persistent adware reinstalls itself using a scheduled Windows task that redownloads it periodically.

  1. Open Task Scheduler (search for it in the Start menu).
  2. Look through the Task Scheduler Library for unfamiliar tasks, particularly ones with random-looking names or ones set to run daily.
  3. Right-click and Disable or Delete anything suspicious, checking the task's Actions tab first to see what program it actually runs.
  4. Also check Task Manager > Startup apps for anything unfamiliar set to launch automatically, and disable it there.

Step 7: Check your DNS and proxy settings

Some hijackers redirect your traffic at a network level rather than (or in addition to) the browser level.

  1. Go to Settings > Network & Internet > Proxy and ensure Use a proxy server is switched off, unless you deliberately configured one.
  2. If it's on and you didn't set it, switch it off immediately.
  3. Check your DNS settings haven't been changed β€” see our dedicated article on DNS errors for the full process of checking and resetting these.

Step 8: Clear your browser data

After removing the underlying cause, clear cookies and cached data to remove any lingering tracking or redirect scripts:

  • Chrome/Edge: Settings > Privacy and security > Clear browsing data > choose "All time" and tick Cookies and cached files.
  • Firefox: Settings > Privacy & Security > Cookies and Site Data > Clear Data.

Preventing reinfection

  • When installing free software, always choose Custom or Advanced install options rather than Express/Quick, so you can see and untick any bundled extras.
  • Download software only from official developer websites, not third-party "download portal" sites that repackage installers with adware bundled in.
  • Read each screen of an installer carefully rather than clicking Next repeatedly.
  • Consider using an ad blocker browser extension from a reputable, well-reviewed source to reduce exposure to malicious ads that trigger drive-by installs.

Closing thoughts

Adware and browser hijackers are more of a persistent nuisance than a serious security threat, but they can be surprisingly tenacious, often requiring you to clean up the program, the browser extension, the browser settings, and any scheduled tasks all at once for the fix to stick. Working through each layer methodically, as outlined above, ensures nothing is left behind to silently reinstall itself. Going forward, taking the extra 30 seconds to choose a custom install and read installer screens carefully is by far the best prevention.


Was this guide helpful? Explore more Malware Removal guides, or browse all Security & Performance articles.