How to Remove a Browser Hijacker and Restore Search
Short answer
Remove the extension first, then the installed program, then reset the search engine — in that order, because resetting settings while the extension is present simply undoes itself. On Windows also check Shortcut properties for an added URL after the target path, which is the step most people miss.
On this page
A browser hijacker changes your search engine, homepage or new tab page to one you did not choose, and routes your searches through it to earn advertising money. The symptom is distinctive: you set the search engine back to Google, it works for a session, and by the next day it has changed again.
That recurrence is the whole problem. Something is still installed and it reapplies the setting every time the browser starts. Resetting first and removing second is why most attempts fail, and it is why the order below is not optional.
Find what is reapplying it
Four places. Check all of them before changing a single setting, because fixing settings while the cause is present wastes the effort entirely.
| Location | How to spot it | Platform |
|---|---|---|
| Browser extension | Unfamiliar entry, often a “search” tool | All |
| Installed program | Appeared on the date trouble started | Windows, macOS |
| Browser policy | “Managed by your organisation” in Chrome | Windows, macOS |
| Shortcut target | A URL after the .exe path |
Windows |
The shortcut one is genuinely sneaky and catches people who have done everything else correctly. The hijacker appends a web address to the shortcut’s target, so the browser opens that page every time you launch it from that icon. Nothing is installed, nothing appears in any settings screen, and resetting the browser changes nothing because the browser is innocent.
Remove, in this order
1. Extensions
- Chrome and Edge: the ⋮ menu → Extensions → Manage extensions
- Firefox: the ☰ menu → Add-ons and themes
- Safari: Safari → Settings → Extensions
Remove anything you did not deliberately install, and be sceptical of anything describing itself as a search enhancement, a coupon finder, a download helper, a video downloader or a PDF converter. Those categories are where most of this originates.
If an extension cannot be removed and shows a “managed” or “installed by enterprise policy” label, skip to step 3 first — the policy is holding it in place.
2. Installed programs
Windows: Settings → Apps → Installed apps, sorted by install date. Look at everything installed around the day the problem began, including things that arrived on the same day as software you did want. Uninstall anything unrecognised, plus any PC optimiser, driver updater or toolbar.
macOS: Applications folder in list view, sorted by Date Added. Then check System Settings → General → Login Items & Extensions and switch off anything unaccounted for. The fuller procedure is in checking your Mac for malware.
3. Policies and profiles
Chrome on Windows. If Settings shows “Managed by your organisation” on a
personal computer, a policy is enforcing the search engine. Type
chrome://policy into the address bar to see exactly which policies are set and
where they came from.
Policies live in the registry under
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome and the equivalent under
HKEY_CURRENT_USER. Editing the registry can break Windows if you delete the
wrong key. If you are not comfortable there, the safer route is to run the
Defender offline scan and a Malwarebytes pass, both of which remove the policies
along with the software that set them —
scanning for and removing malware on Windows
walks through it.
macOS. System Settings → Privacy & Security → Profiles. On a personal Mac with no employer or school, any profile present should be removed.
4. Windows shortcuts
For every shortcut you use to open the browser — desktop, taskbar, Start menu:
- Right-click the shortcut → Properties.
- Look at the Target field.
- It should end with
chrome.exe"ormsedge.exe"and nothing after it. - Delete any web address following the closing quotation mark, then click OK.
For a taskbar shortcut, right-click the icon, then right-click the browser name in the menu that appears, and choose Properties from there.
Check every shortcut. People fix the desktop one and keep launching from the taskbar.
Now restore the settings
Only once the above is done.
Reset the search engine and homepage. Chrome: Settings → Search engine, and Settings → On startup. Firefox and Safari have equivalents under Search and General.
Remove the hijacker’s entry from the search engine list, rather than just switching away from it. Chrome: Settings → Search engine → Manage search engines and site search, then delete the entry.
Clear the browsing data for cookies and cached files, which removes tracking identifiers the hijacker left behind. Saved passwords and bookmarks are unaffected unless you tick those boxes.
Reset the browser if anything still looks wrong. Chrome: Settings → Reset settings → Restore settings to their original defaults. This clears extensions, startup pages, pinned tabs and cookies while keeping bookmarks, history and saved passwords.
Check the proxy and DNS settings. Windows: Settings → Network & internet → Proxy. A manual proxy you did not configure means traffic was being routed somewhere, and should be turned off. On macOS the equivalent is under Network → Details → Proxies.
Confirm it is gone
Close the browser entirely, restart the computer, and open the browser again from each shortcut you use. A hijacker that survived something will reassert itself within a session or two.
If it comes back, something was missed. The usual culprits are a second browser
profile, a shortcut you did not check, a scheduled task recreating the software,
or a policy still in place. On Windows, taskschd.msc and a look through Task
Scheduler Library for entries with random names is the next place to look.
Avoiding the next one
Nearly all of these arrive bundled with a free download. The installer offers a recommended option that includes extras, and clicking through quickly accepts them.
- Choose Custom or Advanced in installers, and untick everything pre-selected.
- Download from the vendor’s own site, not from download portals that wrap installers in their own.
- Be wary of free converters and media tools specifically. This category is the single most common carrier. For file conversion, compressing a PDF and the site’s browser-based tools do the job without installing anything at all.
- Read what an extension asks for. Permission to read and change data on all websites is appropriate for an ad blocker and not for a currency converter.
Realistic expectations
Worked through in this order, most hijackers are gone in fifteen minutes and stay gone. The step that most often turns fifteen minutes into an afternoon is the Windows shortcut check, which almost nobody thinks to do.
The honest limit is that if a hijacker keeps returning after you have removed extensions, programs, policies and shortcuts, you are dealing with something with deeper persistence, and continued cleaning is the wrong use of your time. At that point reinstalling Windows is faster and more certain than another evening of removal attempts.