Skip to main content
FixMyTech

How to Remove a Browser Hijacker and Restore Search

By

Published

8 min read

Share

Short answer

Remove the extension first, then the installed program, then reset the search engine — in that order, because resetting settings while the extension is present simply undoes itself. On Windows also check Shortcut properties for an added URL after the target path, which is the step most people miss.

On this page

A browser hijacker changes your search engine, homepage or new tab page to one you did not choose, and routes your searches through it to earn advertising money. The symptom is distinctive: you set the search engine back to Google, it works for a session, and by the next day it has changed again.

That recurrence is the whole problem. Something is still installed and it reapplies the setting every time the browser starts. Resetting first and removing second is why most attempts fail, and it is why the order below is not optional.

Find what is reapplying it

Four places. Check all of them before changing a single setting, because fixing settings while the cause is present wastes the effort entirely.

Location How to spot it Platform
Browser extension Unfamiliar entry, often a “search” tool All
Installed program Appeared on the date trouble started Windows, macOS
Browser policy “Managed by your organisation” in Chrome Windows, macOS
Shortcut target A URL after the .exe path Windows

The shortcut one is genuinely sneaky and catches people who have done everything else correctly. The hijacker appends a web address to the shortcut’s target, so the browser opens that page every time you launch it from that icon. Nothing is installed, nothing appears in any settings screen, and resetting the browser changes nothing because the browser is innocent.

Remove, in this order

1. Extensions

  • Chrome and Edge: the ⋮ menu → Extensions → Manage extensions
  • Firefox: the ☰ menu → Add-ons and themes
  • Safari: Safari → Settings → Extensions

Remove anything you did not deliberately install, and be sceptical of anything describing itself as a search enhancement, a coupon finder, a download helper, a video downloader or a PDF converter. Those categories are where most of this originates.

If an extension cannot be removed and shows a “managed” or “installed by enterprise policy” label, skip to step 3 first — the policy is holding it in place.

2. Installed programs

Windows: Settings → Apps → Installed apps, sorted by install date. Look at everything installed around the day the problem began, including things that arrived on the same day as software you did want. Uninstall anything unrecognised, plus any PC optimiser, driver updater or toolbar.

macOS: Applications folder in list view, sorted by Date Added. Then check System Settings → General → Login Items & Extensions and switch off anything unaccounted for. The fuller procedure is in checking your Mac for malware.

3. Policies and profiles

Chrome on Windows. If Settings shows “Managed by your organisation” on a personal computer, a policy is enforcing the search engine. Type chrome://policy into the address bar to see exactly which policies are set and where they came from.

Policies live in the registry under HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome and the equivalent under HKEY_CURRENT_USER. Editing the registry can break Windows if you delete the wrong key. If you are not comfortable there, the safer route is to run the Defender offline scan and a Malwarebytes pass, both of which remove the policies along with the software that set them — scanning for and removing malware on Windows walks through it.

macOS. System Settings → Privacy & Security → Profiles. On a personal Mac with no employer or school, any profile present should be removed.

4. Windows shortcuts

For every shortcut you use to open the browser — desktop, taskbar, Start menu:

  1. Right-click the shortcut → Properties.
  2. Look at the Target field.
  3. It should end with chrome.exe" or msedge.exe" and nothing after it.
  4. Delete any web address following the closing quotation mark, then click OK.

For a taskbar shortcut, right-click the icon, then right-click the browser name in the menu that appears, and choose Properties from there.

Check every shortcut. People fix the desktop one and keep launching from the taskbar.

Now restore the settings

Only once the above is done.

Reset the search engine and homepage. Chrome: Settings → Search engine, and Settings → On startup. Firefox and Safari have equivalents under Search and General.

Remove the hijacker’s entry from the search engine list, rather than just switching away from it. Chrome: Settings → Search engine → Manage search engines and site search, then delete the entry.

Clear the browsing data for cookies and cached files, which removes tracking identifiers the hijacker left behind. Saved passwords and bookmarks are unaffected unless you tick those boxes.

Reset the browser if anything still looks wrong. Chrome: Settings → Reset settings → Restore settings to their original defaults. This clears extensions, startup pages, pinned tabs and cookies while keeping bookmarks, history and saved passwords.

Check the proxy and DNS settings. Windows: Settings → Network & internet → Proxy. A manual proxy you did not configure means traffic was being routed somewhere, and should be turned off. On macOS the equivalent is under Network → Details → Proxies.

Confirm it is gone

Close the browser entirely, restart the computer, and open the browser again from each shortcut you use. A hijacker that survived something will reassert itself within a session or two.

If it comes back, something was missed. The usual culprits are a second browser profile, a shortcut you did not check, a scheduled task recreating the software, or a policy still in place. On Windows, taskschd.msc and a look through Task Scheduler Library for entries with random names is the next place to look.

Avoiding the next one

Nearly all of these arrive bundled with a free download. The installer offers a recommended option that includes extras, and clicking through quickly accepts them.

  • Choose Custom or Advanced in installers, and untick everything pre-selected.
  • Download from the vendor’s own site, not from download portals that wrap installers in their own.
  • Be wary of free converters and media tools specifically. This category is the single most common carrier. For file conversion, compressing a PDF and the site’s browser-based tools do the job without installing anything at all.
  • Read what an extension asks for. Permission to read and change data on all websites is appropriate for an ad blocker and not for a currency converter.

Realistic expectations

Worked through in this order, most hijackers are gone in fifteen minutes and stay gone. The step that most often turns fifteen minutes into an afternoon is the Windows shortcut check, which almost nobody thinks to do.

The honest limit is that if a hijacker keeps returning after you have removed extensions, programs, policies and shortcuts, you are dealing with something with deeper persistence, and continued cleaning is the wrong use of your time. At that point reinstalling Windows is faster and more certain than another evening of removal attempts.

Frequently asked questions

Why does my search engine change back after I reset it?
Because the thing that changed it is still installed and reapplies the setting. An extension, a Windows program, a policy entry or a modified shortcut will all do this, which is why removal has to come before resetting.
What does "Managed by your organisation" mean in Chrome?
That an administrative policy is controlling Chrome settings. On a work laptop that is expected. On a personal computer it usually means software installed a policy to lock in a search engine, and the policy must be removed before settings will stick.
Is a browser hijacker a virus?
Not in the self-replicating sense. It is unwanted software, usually installed alongside something else you agreed to, whose purpose is routing your searches through a page that earns advertising revenue.
How did it get installed without me noticing?
Almost always bundled with a free download, pre-ticked in an installer's custom options. Free converters, media players, driver updaters and PDF tools are the usual carriers, and clicking through an installer quickly is how it happens.
Will resetting the browser lose my bookmarks?
A browser reset clears extensions, pinned tabs, cookies and startup pages but keeps bookmarks, history and saved passwords. Signing in to sites again afterwards is expected.

All Security guides