Browser Hijacking Removal: A Step-by-Step Fix Guide for Chrome, Firefox, and Edge

Key Takeaways
If your browser has suddenly started sending you to websites you never asked for, swapped out your homepage, or replaced your search engine with something you've never heard of, you're not imagining things. You've likely been hit by a browser hijacker.
Browser hijacking is one of the most disruptive forms of malware regular users encounter. And the worst part? Simply changing your settings back rarely works. Hijackers are engineered to come right back.
This guide walks you through exactly what browser hijacking is, how to spot it, and how to completely remove it from Google Chrome, Mozilla Firefox, and Microsoft Edge, step by step.
What is browser hijacking?
Browser hijacking is a type of cyberattack in which malicious software, called a browser hijacker, modifies your browser's settings without your knowledge or consent. According to Malwarebytes, hijackers typically target your homepage, default search engine, and new tab page. The more sophisticated ones go much further: injecting ads, logging keystrokes, installing rogue extensions, and even locking your settings using Windows Group Policies so you can't change them back.
The goal is almost always money. Attackers generate revenue by forcing your browser to visit specific ad-heavy websites, routing your searches through monetized redirect chains, or harvesting your personal data for sale.
Warning signs: is your browser hijacked?
Recognizing a browser hijacker early is the first step. Watch for these telltale symptoms, flagged by Airlock Digital and Kaspersky:
- Your homepage or new tab page changed to an unfamiliar site
- Your default search engine was replaced and keeps reverting when you try to fix it
- Unexpected redirects where you search for something and get routed through strange domains before landing on results
- New extensions or toolbars appeared that you didn't install
- Excessive pop-ups and ads, even on sites that normally don't show them
- Slow browser performance or frequent crashes
- Chrome or Edge shows "Managed by your organization" on a personal PC, a major red flag that malware has enforced policies on your browser
- Browser shortcuts were modified to open a specific URL when launched
If you're seeing several of these at once, it's time to act.
How do browser hijackers get in?
Most hijackers don't break in. They're let in, often through:
- Bundled software ("freeware traps"): Hijackers are packaged as "optional offers" inside installers for free utilities, PDF converters, download managers, or video players. Most people click through the installation without reading the checkboxes.
- Malicious browser extensions: A seemingly innocent extension, like a coupon finder or a file converter, contains hidden hijacking code.
- Phishing links and deceptive ads: Clicking on a misleading pop-up that looks like a software update prompt can trigger a silent download.
- Drive-by downloads: Simply visiting a compromised website can initiate an automatic download in the background.
- Malicious email attachments: A hijacker can be bundled inside files sent via phishing emails.
Before you start: do these things first
Before diving into browser-specific fixes, take these preparatory steps:
- Close all open browsers. Running browsers can allow the hijacker to keep writing settings and undo your changes in real time.
- Note any recently installed programs. Sort your installed apps by install date. Malware is usually one of the most recently added programs.
- Do NOT install any "cleaner" tools suggested by pop-ups. Hijackers routinely push fake cleanup tools that are actually more malware.
- If you use browser sync, be prepared to remove unwanted extensions again after signing in. Sync can restore them.
- Back up your bookmarks if you plan to reset or reinstall your browser.
Step 1: uninstall the malicious program from Windows
Many browser hijackers install a companion program on Windows that continuously re-applies browser changes. Removing it is your first priority.
On Windows 11:
- Press Windows + I to open Settings
- Click Apps then Installed Apps
- Click Sort by: Install date to surface recent additions
- Look for programs you don't recognize, such as generic names, "search" tools, download managers, or browser "helpers"
- Click the three-dot menu next to the suspicious program, then Uninstall
- Read each uninstall prompt carefully. Some use deceptive wording to trick you into keeping components.
On Windows 10:
- Press Windows + I, then Apps, then Apps & Features
- Sort by install date, identify suspicious entries, and uninstall
Pro tip: If you see entries like "Search Manager," "Browser Assistant," "Default Tab," or any tool whose name includes words like "search," "tab," or "toolbar" that you don't remember installing, uninstall it.
Step 2: remove browser hijacking from Google Chrome
2a. Remove suspicious extensions
- Open Chrome and go to chrome://extensions.
- Review every extension listed and remove anything you don't recognize or didn't intentionally install.
- Click Remove on suspicious extensions.
2b. Reset Chrome's search engine and homepage
- Open chrome://settings
- Under Search engine, click Manage search engines
- Delete any unfamiliar search engines and set your preferred engine as default
- Under On startup, make sure it's set to your preferred behavior, not a third-party site
2c. Check for forced policies ("Managed by your organization")
If Chrome displays "Managed by your organization" on a personal PC, a malicious Group Policy is in effect.
- Visit chrome://policy. If you see unfamiliar policies listed, they need to be removed from the Windows Registry.
- Press Windows + R, type regedit, and press Enter
- Navigate to: `HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome`
- If this folder exists and you didn't create it, right-click and Delete
- Also check: `HKEY_CURRENT_USER\SOFTWARE\Policies\Google\Chrome`
2d. Reset Chrome to default settings
- Go to chrome://settings/reset
- Click Restore settings to their original defaults
- Click Reset settings to confirm
This will clear your startup page, new tab page, pinned tabs, and disable extensions, but it will NOT delete bookmarks, history, or saved passwords.
Step 3: remove browser hijacking from Mozilla Firefox
3a. Remove suspicious add-ons
- Click the hamburger menu then Add-ons and Themes, then Extensions
- Remove any extensions you don't recognize or trust
3b. Reset your search engine and homepage
- Go to Settings
- Under Home, set your preferred homepage and new tab page
- Under Search, choose your preferred search engine and remove unfamiliar ones
3c. Refresh Firefox
Firefox's Refresh feature resets settings and removes add-ons while preserving your bookmarks, passwords, and open tabs.
- Click the hamburger menu, then Help, then More troubleshooting information
- Click Refresh Firefox
- Confirm in the dialog box
Firefox will create a desktop folder called Old Firefox Data with your previous profile info, in case you need to retrieve anything.
Step 4: remove browser hijacking from Microsoft Edge
4a. Remove suspicious extensions
- Open Edge and go to edge://extensions
- Review and remove any extensions you don't recognize
4b. Reset your homepage and search engine
- Go to edge://settings/startHomeNTP and set your preferred startup behavior
- Go to edge://settings/search and change the default search engine back to your preferred choice
4c. Check for forced policies in Edge
If Edge shows "Managed by your organization" on a personal device, malware has installed policies.
- Visit edge://policy to see active policies
- Press Windows + R, type regedit, press Enter
- Navigate to: `HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge`
- If this key exists and you didn't set it, right-click and Delete
- Also check: `HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Edge`
4d. Reset Microsoft Edge to default settings
- Go to edge://settings/reset
- Click Restore settings to their default values
- Confirm by clicking Reset
Step 5: scan with anti-malware tools
After manually cleaning your browsers, run a dedicated scan to catch anything you may have missed. Security experts at MalwareTips recommend this multi-tool approach:
- Malwarebytes Free excels at detecting PUPs (potentially unwanted programs) and browser hijackers that traditional antivirus misses. Run a full scan and quarantine everything flagged.
- AdwCleaner (by Malwarebytes) is specifically built to remove adware, unwanted toolbars, and malicious browser policies. It can remove forced Group Policy entries automatically.
- ESET Online Scanner is a free, browser-based scanner from a trusted security vendor that can catch what other tools miss. No installation required.
Run these tools in sequence, not simultaneously, for best results. Always download them from the official vendor website, not a search result ad.
Step 6: check and clean your browser shortcuts
This is a frequently overlooked step. Hijackers sometimes modify your browser's desktop or taskbar shortcut to force it to open a specific URL every time you launch it.
- Right-click your Chrome, Firefox, or Edge desktop shortcut
- Select Properties
- Look at the Target field. It should end with the browser executable only:
- Chrome: `...chrome.exe"`
- Firefox: `...firefox.exe"`
- Edge: `...msedge.exe"`
- If there's a URL or extra text appended after the `.exe"`, delete the extra text and click Apply
Step 7: prevent browser hijackers from coming back
Removal is only half the battle. Here's how to stay protected going forward:
- Download software only from official websites, never from third-party download aggregators
- Always choose "Custom" or "Advanced" installation so you can uncheck bundled software
- Review browser extensions regularly and delete anything you no longer use or don't remember installing
- Keep your browser and OS updated. Patches close the vulnerabilities hijackers exploit.
- Be skeptical of pop-ups that tell you to "update" your browser or video player. These are among the most common hijacker delivery vectors.
- Enable Safe Browsing in Chrome and Edge's SmartScreen to block known malicious sites
When to consider a full browser reinstall
If you've followed every step above and the hijacker keeps coming back, it may be time to fully uninstall and reinstall the affected browser.
For Chrome:
- Uninstall Chrome via Settings, then Apps
- Manually delete leftover folders at `C:\Program Files\Google\Chrome` and `C:\Users\[YourName]\AppData\Local\Google\Chrome`
- Reinstall from google.com/chrome
- Do not sign in immediately. First verify the hijacker is gone, then restore your profile.
The same approach applies to Firefox and Edge: uninstall, clear leftover data, and do a clean reinstall.
Stay protected before the next hijacker tries its luck
Manually cleaning a hijacked browser works, but it's reactive. By the time you're running through registry keys, the damage has already started.
Guardio works differently. It runs quietly on your browser and your phone, blocking hijacker installs, malicious extensions, and forced redirects before they take hold, so you never have to work through a seven-step removal guide again.
Get a free security scan with Guardio today and stay protected from browser hijacking.
Conclusion
Browser hijackers are built to be persistent. A quick settings change won't cut it. A complete fix requires working through the problem systematically: removing the underlying program, cleaning each browser, purging malicious registry entries and policies, running dedicated anti-malware scanners, and patching the shortcuts hijackers like to quietly modify.
With the steps in this guide, you can fully reclaim your browser and take the preventive measures that make a repeat infection far less likely.
FAQs
Will resetting my browser delete my passwords and bookmarks?
Browser resets generally preserve bookmarks and saved passwords but will remove extensions, custom settings, and cached data. Always export your bookmarks before resetting, just in case.
My browser says "Managed by your organization." What does that mean?
This message means Group Policies are controlling your browser's settings. On a personal PC, this is almost always the work of malware. Use AdwCleaner or manually delete the relevant registry keys as described in Steps 2c and 4c of this guide.
I ran a virus scan and it found nothing. Can I still have a hijacker?
Yes. Many hijackers are classified as PUPs (Potentially Unwanted Programs) rather than traditional malware, so standard antivirus may not flag them. Use a dedicated tool like Malwarebytes Free or AdwCleaner, which are specifically built to catch PUPs.
My search engine keeps reverting even after I change it. Why?
This is the hallmark of a persistent hijacker. It may have installed a background Windows program, a scheduled task, or a Group Policy that overrides your manual changes. Follow all the steps in this guide, not just the browser reset.
Is browser hijacking dangerous, or just annoying?
Both. Beyond the frustration of unwanted redirects and ads, some hijackers contain keyloggers that record your passwords and banking details. Others redirect you to phishing sites built to steal your credentials. Treat any browser hijacker as a genuine security threat, not just an inconvenience.
Can browser hijackers affect Mac or mobile browsers?
Yes, though the removal steps differ. On Mac, focus on removing suspicious apps from Applications, reviewing Safari and Chrome extensions, and running a Mac-compatible malware scanner. On mobile, try clearing browser data and removing suspicious apps.
What is the fastest way to remove a browser hijacker?
The fastest effective approach is to run AdwCleaner, which handles malicious Group Policies and adware in one pass, followed by a Malwarebytes Free scan. Then reset your browser to default settings and check your shortcuts. Skipping steps is how hijackers come back.
How do I know if a browser extension is malicious?
Warning signs include: it requests more permissions than it needs for its stated purpose, your browser is redirecting searches, you're seeing unusual ads, or it was installed without your action. Guardio monitors extensions automatically and alerts you to suspicious behavior.
How-To & Safety TipsSpring Cleaning for Your Computer: Inside and Out





