Removing Adware and Browser Hijackers Step by Step
Adware and browser hijackers are among the most common unwanted programs found on business and home computers. They may not always behave like traditional viruses, but they can still make a device difficult to use, expose users to dangerous websites, collect browsing information and create opportunities for more serious infections.
A browser hijacker may change your homepage, replace your preferred search engine, install unwanted extensions or redirect you to unfamiliar websites. Adware typically fills webpages with intrusive adverts, pop-ups and misleading notifications.
The good news is that many infections can be removed without wiping the computer. The key is to work methodically and avoid clicking anything generated by the unwanted software.
Common Signs of Adware or a Browser Hijacker
You may have adware or a hijacker installed if you notice:
- Your homepage or search engine has changed unexpectedly.
- Searches are being redirected through unfamiliar websites.
- New tabs open by themselves.
- Pop-up advertisements appear even when you are not browsing.
- Websites contain far more adverts than usual.
- Unfamiliar browser extensions have appeared.
- Your browser displays fake security warnings.
- Notifications claim your computer is infected.
- The browser has become unusually slow or unstable.
- Programs you do not recognise appear in the installed applications list.
- Your preferred browser settings return to the unwanted values after you change them.
A single unusual advert does not necessarily mean the computer is infected. However, repeated redirects, persistent setting changes or unwanted extensions should be investigated.
Before You Start: Do Not Interact With the Pop-Ups
Avoid clicking buttons inside suspicious adverts or warning messages, including buttons labelled:
- Scan now
- Remove virus
- Allow
- Update browser
- Download cleaner
- Call support
- Renew protection
Even a close button inside a malicious advert may trigger another webpage or download.
Instead, close the browser normally. If it refuses to close, use Task Manager on Windows or Force Quit on a Mac.
On Windows, press Ctrl + Shift + Esc, select the browser and choose End task.
On macOS, press Option + Command + Escape, select the browser and choose Force Quit.
Step 1: Disconnect From the Internet if the Behaviour Is Severe
If the browser is continuously opening pages, downloading files or displaying aggressive warnings, temporarily disconnect the computer from the internet.
You can turn off Wi-Fi or unplug the network cable.
This does not remove the infection, but it can stop additional adverts, redirects or downloads while you investigate.
You will need to reconnect later to update security software and run online scans.
Step 2: Remove Suspicious Browser Extensions
Unwanted extensions are one of the most common causes of browser redirects and altered search results.
Google Chrome
Open Chrome and go to:
Menu > Extensions > Manage Extensions
Review every installed extension. Remove anything you do not recognise, no longer use or did not intentionally install.
Be especially cautious of extensions claiming to be:
- Search assistants
- Shopping helpers
- Coupon finders
- PDF converters
- Video downloaders
- Weather tools
- New-tab customisers
- Browser security scanners
Microsoft Edge
Go to:
Menu > Extensions > Manage Extensions
Disable suspicious extensions first. If the browser immediately improves, remove the extension completely.
Mozilla Firefox
Go to:
Menu > Add-ons and Themes > Extensions
Remove unfamiliar or unnecessary add-ons.
Safari
Open:
Safari > Settings > Extensions
Uninstall any extension you do not recognise.
An extension can have a harmless-sounding name while still modifying searches or injecting adverts. If you are unsure whether an extension is necessary, disable it temporarily and test the browser.
Step 3: Check the Homepage, Startup Page and Search Engine
Browser hijackers often change several settings at once. Correcting only the homepage may not solve the problem.
Check the following settings:
- Default search engine
- Homepage
- New-tab page
- Pages opened when the browser starts
- Site notification permissions
- Default browser
Remove any unfamiliar search providers or startup addresses.
A hijacker may use a website that looks similar to a legitimate search engine. Check the full address carefully rather than relying only on the logo or page design.
Step 4: Remove Unwanted Notification Permissions
Many alarming pop-ups are not generated by installed malware. They are browser notifications from a website that was previously given permission to send alerts.
These notifications may appear in the corner of the desktop and claim that:
- Your antivirus has expired.
- Several viruses have been detected.
- Your computer is at immediate risk.
- You have won a prize.
- A payment has failed.
- You must call technical support.
Do not click the notification.
Open the browser’s privacy or site settings and locate Notifications. Remove or block websites you do not recognise.
In Chrome and Edge, this is usually found under:
Settings > Privacy and Security > Site Settings > Notifications
Also remove any suspicious sites listed under the section that allows notifications.
Step 5: Uninstall Suspicious Applications
Browser hijackers are sometimes installed alongside another program. Removing the extension alone may therefore be temporary.
On Windows 11
Go to:
Settings > Apps > Installed apps
Sort the list by installation date and look for programs installed around the time the problems began.
Potential warning signs include:
- Applications with vague names
- Multiple programs installed on the same day
- Software published by an unfamiliar company
- Browser assistants or search tools
- Programs you do not remember installing
- Fake optimisation or cleaning utilities
Select the unwanted program and choose Uninstall.
Do not remove Microsoft components, device drivers or business applications simply because you do not recognise their names. Search for the program’s exact name or ask an IT professional before removing anything uncertain.
On macOS
Open the Applications folder and look for unfamiliar programs.
Move unwanted applications to the Bin, but be aware that some adware leaves additional files or background components behind. Check System Settings > General > Login Items for unfamiliar applications that start automatically.
Step 6: Check Startup Programs and Background Processes
Some unwanted programs automatically reinstall browser settings every time the computer starts.
Windows
Open Task Manager and select Startup apps.
Disable unfamiliar entries, especially those connected to recently installed software.
You can also review running processes, but avoid ending system processes unless you know what they are.
macOS
Go to:
System Settings > General > Login Items
Remove applications you do not recognise from both the login and background activity sections.
Restart the computer after making changes and check whether the browser settings remain correct.
Step 7: Run a Full Security Scan
Open the computer’s trusted security software and install the latest security updates before scanning.
On Windows, you can use Windows Security:
- Open Windows Security.
- Select Virus & threat protection.
- Choose Scan options.
- Run a Full scan.
- Quarantine or remove anything detected.
For persistent problems, an offline scan may help because it checks the computer before the normal Windows environment fully loads.
On a business device, use the security software approved by your organisation. Installing multiple antivirus products can create conflicts and may reduce protection rather than improve it.
Avoid downloading a cleaner recommended by the suspicious pop-up itself.
Step 8: Clear Browser Data
After removing unwanted software, clear cached files, cookies and temporary website data.
This can remove stored scripts, redirect information and persistent login data associated with suspicious sites.
In most browsers, open the browsing data settings and clear:
- Cached images and files
- Cookies and site data
- Hosted application data, where available
Clearing cookies may sign you out of websites, so make sure you know any passwords you need before continuing.
You should also review saved passwords if you suspect the browser has been compromised.
Step 9: Reset the Browser
If the problem continues, reset the affected browser to its default settings.
A reset generally disables extensions, restores startup settings and removes unwanted customisation. Bookmarks and saved passwords are usually retained, although you should verify what the browser will remove before confirming.
Look for an option such as:
- Reset settings
- Restore settings to their original defaults
- Refresh Firefox
- Clear history and website data
Safari does not offer one universal reset button, so its extensions, history, website data, homepage and notification settings may need to be cleaned separately.
Step 10: Check the Browser Shortcut
On Windows, some hijackers alter the browser shortcut so that it opens a suspicious website every time it launches.
Right-click the browser shortcut, select Properties and inspect the Target field.
It should end with the browser’s executable file, such as:
chrome.exe
or:
msedge.exe
There should not be a website address or additional command appended after the executable path.
Only change the shortcut if you are confident it has been modified.
Step 11: Check Proxy and DNS Settings
More persistent hijackers may alter network settings so that web traffic is redirected even after the browser has been cleaned.
On Windows, search Settings for Proxy and check that no unfamiliar manual proxy server has been configured.
You should also inspect the computer’s DNS settings. Most devices are configured to obtain DNS information automatically from the router or organisation’s network.
Unexpected proxy or DNS entries should be treated cautiously, particularly on company computers. Legitimate business security products, VPNs and filtering systems may intentionally use these settings.
Consult your IT provider before changing network settings on a managed device.
Step 12: Update the Browser and Operating System
Install available updates for:
- Windows or macOS
- Your web browser
- Security software
- Frequently used applications
Updates can close security weaknesses and replace damaged or outdated browser components.
After installing updates, restart the computer rather than simply closing and reopening the browser.
Step 13: Review Online Accounts
If the browser hijacker appeared after you installed unknown software, entered a password into a suspicious page or allowed remote access, take additional precautions.
Using a known-clean device, change passwords for important accounts, starting with:
- Microsoft or Apple account
- Online banking
- Cloud storage
- Business systems
- Social media
Use unique passwords and enable multifactor authentication wherever possible.
Review recent sign-ins and active sessions. Sign out devices or locations you do not recognise.
Email should be prioritised because access to an email account can often be used to reset passwords for other services.
What if the Hijacker Keeps Coming Back?
If the browser returns to the same unwanted homepage or search engine after every restart, something is probably reinstalling the settings.
Possible causes include:
- A remaining unwanted application
- A scheduled task
- A login item
- A managed browser policy
- A synchronised malicious extension
- A compromised browser profile
- A modified proxy or DNS configuration
- Malware that was missed by the initial scan
Temporarily disable browser synchronisation and check whether the unwanted extension returns. If a suspicious extension has synchronised to your browser account, removing it from one computer may not be enough.
On business devices, browser settings may also be controlled by legitimate company policies. Do not attempt to remove management settings without speaking to your IT administrator.
Should You Reinstall the Browser?
Reinstalling the browser can help when its files or user profile have been damaged, but it should not be the first step.
If the unwanted program remains installed elsewhere on the computer, it may simply hijack the newly installed browser again.
Remove suspicious software, scan the device and check network settings before reinstalling.
For stubborn cases, create a fresh browser profile rather than importing every setting and extension from the old one.
When Is a Full Computer Reset Necessary?
Most adware infections do not require a complete Windows or macOS reinstall.
However, a clean installation may be the safest option if:
- Security tools detect a more serious infection.
- Administrative accounts have been compromised.
- The attacker was given remote access.
- Security software has been disabled.
- The infection returns after thorough cleaning.
- Business or confidential information may have been exposed.
- You cannot confirm that the computer is trustworthy.
Important data should be backed up before reinstalling, but avoid copying unknown applications, browser profiles or suspicious files into the clean system.
How Adware and Browser Hijackers Get Installed
These unwanted programs commonly arrive through:
- Free software bundles
- Fake browser updates
- Misleading download buttons
- Cracked or pirated software
- Fake antivirus warnings
- Browser notification prompts
- Malicious adverts
- Untrusted browser extensions
- Remote-access scams
- Installation screens that hide additional offers
The installation may appear legitimate because the unwanted component is buried within a lengthy setup process or enabled by default.
Always choose the custom or advanced installation option when installing unfamiliar software. Read each screen carefully and decline additional browser tools, search providers or optimisation utilities.
How Businesses Can Reduce the Risk
Businesses should not rely entirely on individual users spotting every suspicious prompt.
Useful controls include:
- Removing unnecessary local administrator rights
- Restricting unapproved browser extensions
- Using web and DNS filtering
- Deploying managed endpoint protection
- Keeping applications automatically updated
- Blocking known malicious websites
- Monitoring unusual browser activity
- Providing regular cybersecurity awareness training
- Maintaining tested backups
- Using multifactor authentication
- Standardising approved browsers and applications
Centralised management can prevent an unwanted extension or application from spreading across multiple devices.
Do Not Call the Number in a Browser Warning
A legitimate security warning will not normally instruct you to call an unknown support number displayed inside a webpage.
These messages are frequently connected to technical support scams. The caller may ask you to install remote-access software, reveal passwords or pay for unnecessary services.
Close the page and contact your existing IT provider using a telephone number you already trust.
Final Checklist
After cleaning the computer, confirm that:
- Unwanted extensions have been removed.
- The correct homepage and search engine remain selected.
- Suspicious notification permissions have been revoked.
- Unknown programs have been uninstalled.
- Startup entries have been reviewed.
- A full security scan has completed.
- The browser has been updated or reset.
- Proxy and DNS settings are correct.
- Important passwords have been changed where necessary.
- Multifactor authentication is enabled.
- The problem does not return after restarting.
Need Help Removing Adware or a Browser Hijacker?
Persistent browser redirects can indicate more than a simple unwanted extension. Hamilton Group can inspect the affected device, remove suspicious software, secure your browser and check whether passwords or business information may have been exposed.
For professional IT support, call Hamilton Group on 0330 043 0069 or visit hgmssp.com to book a meeting with one of our experts.