Browser hijacked? How to spot it and clean it up

Changed homepage, unfamiliar search engine, redirects you did not ask for. How browser hijackers get in, how to remove one, and how to keep it out.

ETA System Doctor7 min read
Five numbered removal steps, ending with a browser reset as step five rather than step one

A hijacked browser is rarely subtle. Your homepage changes, searches go through a provider you have never heard of, and new tabs open on pages you did not ask for. The good news is that most hijackers are adware rather than malware, and removing them is methodical rather than difficult.

Signs worth taking seriously

  • Your homepage or new-tab page changed and changes back when you fix it
  • Searches are routed through a provider you did not choose
  • Extensions you do not remember installing appear in the extensions list
  • New tabs or pop-ups open on their own, often on ad-heavy pages
  • Pages you trust suddenly carry ads that were never there before

How they get in

Almost always through something you installed on purpose. Free software installers frequently bundle extra offers, pre-ticked, on a screen most people click past. Choosing the custom or advanced option during installation and unticking the extras prevents the large majority of these.

The second common route is a browser extension that was harmless when installed and changed hands later. An extension with permission to read and change data on every site can begin injecting ads after an update, with no further action from you.

Removing one

  1. Check your extensions first. In Chrome, open chrome://extensions. Remove anything you do not recognise or no longer use, paying particular attention to anything that can read data on all sites.
  2. Reset your search engine and homepage in Settings. If they revert, an extension or a program is still enforcing them — go back to step one.
  3. Check installed programs. Open Settings, then Apps, sort by install date, and look at what arrived around the time the trouble started.
  4. Check browser shortcut targets. Right-click the shortcut, open Properties, and make sure the Target field ends at chrome.exe with no URL appended after it — a URL there is a classic hijack.
  5. Run a scan. Windows Defender handles most of it; a dedicated adware scan catches things classed as unwanted rather than malicious.

Reset your browser as a last step rather than a first one. It clears the symptoms, but if the cause is still installed, everything returns within a day and you have lost your settings for nothing.

The hosts file, if nothing else worked

A more stubborn class of hijack edits the Windows hosts file to redirect specific domains, which survives a browser reset entirely. The file lives at C:\Windows\System32\drivers\etc\hosts and can be opened in Notepad running as administrator. Entries you did not add — particularly ones naming search engines or security vendors — are worth removing.

Staying clean afterwards

  • Choose custom installation for free software and read the offer screens
  • Review your extensions every few months and remove what you no longer use
  • Be sceptical of extensions asking to read and change data on all sites
  • Download software from the developer's own site rather than a download portal

ETA System Doctor includes a Shortcut Fixer for the appended-URL case, an Extension Manager for reviewing what is installed, and a Hosts File Integrity Guard that watches for entries appearing outside your own settings.

Give your PC the ETA System Doctor cleanup

Clear browser clutter, free up disk space, and speed up Windows — no bloatware, no cloud upload, everything runs locally.