A ‘browser hijack’ usually occurs when criminals alter a genuine website so that the behaviour of a web browser used by a website visitor is changed without the user’s consent. Criminals typically manipulate the browser to display unwanted adverts and warnings of ‘PC Infections’, redirect search queries to rogue websites, or even collect sensitive information such as login credentials.
Here are common signs of a browser hijack:
• The browser ‘freezes’ and displays a dire warning that the PC is infected with a terrible virus, and to call the displayed telephone number immediately
• Homepage or search engine change: Your browser’s homepage or default search engine gets changed without your permission.
• Excessive pop-up ads: You encounter frequent pop-up ads, even on sites that don’t normally have them.
• Unwanted toolbars: New toolbars appear in your browser that you didn’t install.
• Redirects: Clicking on links takes you to unfamiliar or questionable websites.
• Slow browser performance: The browser might become sluggish, often due to the hijacker’s scripts or excessive ads.
Although hijacking most commonly occurs after visiting a website that has been compromised, it can also happen through malicious software installations or browser extensions that users unknowingly install, which are often bundled with other software. It’s important to avoid clicking suspicious links, only download software from trusted sources, and maintain good security software.
To avoid browser hijacking, it’s essential to adopt safe browsing habits and implement security measures. Here are key steps to help protect your browser:
• Install Trusted Security Software Use reputable antivirus and anti-malware software to detect and remove threats before they infect your system.
• Enable real-time protection and regularly update the software to stay protected against the latest threats.
• Be Cautious with Downloads Only download software, apps, or browser extensions from trusted and official sources, such as the developer’s website or reputable app stores.
• Avoid ‘pirated’ software or installations from ‘sharing’ websites – these often bundle malware with semi-legitimate programs.
• Be wary when downloading free software for the same reason – some freeware installers include unwanted programs or browser extensions.
• Avoid Suspicious Links and Emails Don’t click on suspicious links in emails, pop-ups, or websites. Phishing emails often trick users into downloading malicious software. Verify the sender and the link source before clicking.
• Use a Pop-up Blocker Enable a pop-up blocker in your browser to reduce the risk of accidentally clicking on malicious pop-up ads.
• Review Browser Extensions and Add-ons Regularly review and clean up your browser extensions. Remove any that you don’t recognize or no longer need.
Only install extensions from trusted developers.
• Carefully Read Installation Prompts When installing new software, opt for the custom or advanced installation option. This allows you to uncheck additional bundled software, which is often the source of unwanted browser modifications.
Be on the lookout for any pre-checked boxes that offer to change your homepage or search engine.
• Keep Your Browser and System Updated Regularly update your web browser and operating system to benefit from the latest security patches and vulnerability fixes.
Use browsers that have built-in protections, such as Google Chrome or Mozilla Firefox, which block unsafe downloads and alert users to suspicious sites.
• Enable Two-Factor Authentication (2FA) Protect your accounts with 2FA, which requires a second step (like a code sent to your phone) before logging in. This adds an extra layer of security in case a hijacker attempts to access your accounts.
• Backup Your Data Regularly back up your files to an external hard drive or a cloud service. In the event of a severe malware infection, this will allow you to restore your data without major loss.
By adopting these habits and keeping your browser and software secure, you can significantly reduce the risk of a browser hijack.
If your browser has already been hijacked, here are steps to rectify the issue and remove the hijacker:
1. Identify and Remove Malicious Software
Run an Antivirus/Antimalware Scan: Use a reputable antivirus or antimalware tool to scan your computer for any malicious software. Tools like Malwarebytes, Avast, or Bitdefender can help detect and remove malware, including browser hijackers.
Run a Full Scan: Make sure to perform a full system scan, as hijackers may be hiding in various places on your device.
2. Uninstall Suspicious Programs
Windows:
Go to Control Panel > Programs > Uninstall a Program.
Look for suspicious or recently installed programs you don’t recognize or didn’t install.
Select and uninstall them.
3. Remove Unwanted Browser Extensions
Google Chrome:
Click the three dots in the upper right corner and go to More Tools > Extensions.
Look for suspicious or unwanted extensions.
Click Remove next to the ones you don’t recognize or trust.
Firefox:
Click the menu button (three lines) and select Add-ons and Themes.
Select Extensions and review the installed add-ons.
Remove any suspicious add-ons by clicking Remove.
Microsoft Edge:
Click the three dots in the upper right corner and go to Extensions.
Look for unfamiliar extensions and click Remove.
4. Reset Your Browser Settings
This will restore your browser to its default settings, removing any changes made by the hijacker (like changed homepage or search engine).
Google Chrome:
Click the three dots in the upper right corner, select Settings.
Scroll to the bottom and click Reset settings under Reset and clean up.
Confirm the reset.
Firefox:
Open the menu (three lines), then go to Help > More Troubleshooting Information.
Click Refresh Firefox.
Microsoft Edge:
Click the three dots in the upper right corner, go to Settings > Reset Settings.
Select Restore settings to their default values.
5. Check and Reset Your Default Search Engine
Google Chrome: Go to Settings > Search engine and set your preferred search engine.
Firefox: Go to Preferences > Search and select your preferred search engine.
Microsoft Edge: Go to Settings > Privacy, Search, and Services, scroll to Address Bar and Search to change the default search engine.
6. Clear Browser Cache and Cookies
This helps remove any leftover traces of the hijacker.
Google Chrome: Go to Settings > Privacy and security > Clear browsing data.
Firefox: Go to Settings > Privacy & Security > Clear Data.
Microsoft Edge: Go to Settings > Privacy, search, and services > Clear browsing data.
7. Block Suspicious Pop-Ups and Redirects
Google Chrome: Go to Settings > Privacy and security > Site Settings, and under Pop-ups and redirects, make sure it’s set to Blocked.
Firefox: Go to Preferences > Privacy & Security, under Permissions, ensure Block pop-up windows is checked.
Microsoft Edge: Go to Settings > Cookies and site permissions, scroll to Pop-ups and redirects, and block them.
8. Check and Remove Unwanted Shortcuts
Sometimes browser hijackers alter desktop shortcuts to redirect you to malicious websites. Check for suspicious shortcuts or alterations.
Right-click on your browser’s desktop shortcut and select Properties.
In the Target field, ensure it only points to the browser’s executable file
(e.g., “C:\Program Files x86\Google\Chrome\Application\chrome.exe”).
Remove any additional URLs or text after the executable path.
9. Reset Network Settings
If the hijacker made deeper changes, resetting network settings may be required.
Windows:
Go to Settings > Network & Internet > Status.
Scroll down and click Network reset.
10. Restore Browsers’ Normal Function By following these steps, you should be able to remove a browser hijack and restore your browser’s normal function.
If the issue persists, consider contacting a professional IT support service for help in removing the hijacker. They can help eliminate deeply embedded malware that might be causing persistent issues.
Our Managed IT Service is designed specifically to meet the needs of small businesses in the North West, allowing them to focus on what they do best.
So, if you run a small business in the North West and need help to remove malware from a hijack attack, require information about anti-phishing software, a security audit, cyber security training, or other help then please get in touch.