Browser hijacking is when a virus changes your browser settings without permission. That might not sound serious, but browser hijackers are a major security, privacy, and usability concern. If you’re a cybersecurity novice looking to learn how to remove a browser hijacker, you’re in the right place. I’ll explain the risks involved, how to tell if your device is infected, and how to protect yourself from browser hijacking.

What is a browser hijacker, and what can they do?

Browser hijackers are a type of malware designed to take full control of your web browser. They’re able to change all sorts of settings, edit webpages, and even view cookies stored by the sites you visit. In other words, there’s very little they can’t do. Thankfully, browser hijackers aren’t usually very discreet; here’s are some common signs you may be infected: 

  • Your homepage changes unexpectedly. This is usually to funnel you towards other malware or artificially inflate the advertising revenue of a specific website.
  • Your browser keeps redirecting you to different websites. A classic indicator of browser hijacking. The goal is to make you accidentally click something on a scammy website that will further compromise your device. Can also be combined with phishing attacks to steal personal information.
  • A new toolbar appears in your browser. Often filled with buttons that link to malicious sites. Almost always slows down your computer and may even log details of your browsing activity. Also, they take up a lot of screen space, increasing the chance you click on something harmful.
  • You are bombarded with popups. Hijackers can accept push notifications from shady sites, resulting in a constant stream of scam attempts. Alternatively, they might just continuously redirect you to pages filled with ads for fake virus-removal services. Clicking these will put you directly in contact with a scammer who will try to steal as much of your money and personal information as possible.
  • You’re forced to use a specific search engine. Normally, the results will be low-quality and full of promoted content or ads. Scammers don’t have to build a good search engine since they know nobody is using it by choice. They profit whenever a victim searches for anything, including help swapping back to their original search engine.

Can browser hijackers steal my passwords?

Graphic showing ways browser hijackers can profit from victims

Stealing passwords isn’t the main objective of browser hijackers (they’d rather profit from you in other ways), but it’s possible. A malicious browser extension could steal passwords by monitoring what you enter into login fields. Alternatively, attackers could steal a saved authentication token, which would let them breach your account without logging in. SpyCloud’s Identity Exposure Report reveals 8.6 billion cookies were stolen last year, so this is not a rare occurrence.

How to remove browser hijackers and prevent future infections

The good news is that it’s reasonably easy to get rid of most browser hijackers. Because the signs of infection are so obvious, malicious toolbars and extensions try to appear legitimate and can often be removed like any other app.

Make no mistake, though: the goal is feeding you slop you didn’t ask for. Conduit, a company that created custom toolbars widely classified as malware, admits as much in a press release, proudly stating, “This isn’t about search; it is about brand.”

How to get rid of a browser hijacker

  1. If excessive pop-ups are preventing you from using your PC, restart it while holding Shift. Then, select Safe Mode with Networking (Windows) or Safe Mode (MacOS).
    Browser Hijacking - Windows - Safe Mode 5
  2. Begin by checking your list of installed programs. To do this, just press the Windows key+X, then click Installed apps. If you’re on MacOS, open the Finder and press Command+Shift+A instead.
  3. Search for apps you don’t recognize, then Google their names to see if others have reported them as malicious. If so, delete them. Make sure to check all drives. Filtering by date ensures that recently installed apps (the most likely culprits) appear at the top of the list.

    Screenshot showing the filters on Windows' installed apps page
    You’re unlikely to have a browser hijacker for long without noticing, so I’d recommend scrutinizing any apps you’ve installed recently.
  4. It’s time to check your browser extensions. Just open the menu and look for an option labeled Extensions or something similar. We’re looking for anything unfamiliar or, failing that, any extensions you installed recently.

    Screenshot showing Chrome's extensions page
    Nothing unusual here. However, if you did find a suspicious-looking extension, all you have to do is hit the Remove button.
  5. Run a malware scan using reputable antivirus software. Most should be able to remove potentially unwanted programs like browser hijackers without much trouble.
  6. Restore your browser to default settings. This will undo any changes the hijacker made, clear any data they stored, and change your search engine back. What’s more, if you’re logged in, you shouldn’t lose your bookmarks, addons, or history.

    Screenshot showing Chrome's browser reset option
    You can reset Chrome, Opera, and Edge by opening the menu and clicking Reset settings. Firefox users should visit “about:support” and click Refresh Firefox.
  7. Finally, change the passwords of any accounts you used while the browser hijacker was installed. This stops any stolen login credentials from being used against you.

How to defend yourself against browser hijacking

Browser hijackers can be installed in various ways so staying safe requires a multi-faceted approach. They’re commonly bundled with other software, requiring you to opt out using a “Custom installation” menu. However, it’s easier to avoid bundled installers entirely. Get apps directly from official sources and avoid third-party hosts whenever possible.

Alternatively, you may have gotten infected by opening a malicious email attachment or clicking a fake download button. Pirated software often comes packed with malware too, which is just another reason to give it a wide berth. I’d suggest reading our newcomer-friendly guide to cybersecurity so you can identify danger signs and be better protected moving forward.

Clearing your cookies and cache regularly is a good idea too. This ensures that even if your browser is hijacked, attackers will have a harder time stealing authentication tokens.

Finally, an up-to-date operating system, browser, and antivirus may have flagged the threat before anything nefarious happened. That’s why software updates are so important, and why you shouldn’t put them off indefinitely. Spend a few minutes updating – it’s worth it.

Conclusion

Nobody wants to spend their time dealing with malware. Luckily, most browser hijackers are pretty easy to spot and can be removed in a matter of minutes. You can protect yourself by being careful about what you click online, only downloading apps from official websites, and ensuring you install security updates as soon as possible.