Browser hijacking happens when unwanted software, a malicious extension, or a changed system setting takes control of some part of your web browser. You may notice that searches go through an unfamiliar site, your home page changes, new tabs open by themselves, or advertisements appear on pages that normally look clean.
Not every browser problem is a hijack. A poorly configured extension, a bundled installation option, a changed DNS setting, or a compromised online account can create similar symptoms. The safest approach is to identify what changed, remove suspicious components in a controlled order, and stop before making changes that could affect saved passwords, business access, or important data.
Common signs of browser hijacking
A hijacked browser may show one symptom or several. Watch for changes that occur repeatedly rather than a single unusual advertisement or a temporary website outage.
- Your default search engine or home page changes without your approval.
- Searches are redirected through unfamiliar domains before reaching a results page.
- New tabs, pop-ups, or notification prompts appear frequently.
- Unknown extensions or add-ons appear in the browser.
- Browser settings are locked, keep changing back, or cannot be edited normally.
- Pages load slowly, crash, or display advertisements in unusual places.
- You see security warnings that pressure you to call a number, install software, or pay immediately.
These signs do not prove that the entire computer is infected. The cause might be limited to one browser profile. However, repeated redirects across browsers, suspicious programs in Windows, or changes affecting every device on the same network deserve a broader investigation.
Before removing anything, protect your accounts and data
Do not enter passwords, payment details, or business credentials into a page that appeared through an unexpected redirect. A hijacked browser can display a convincing copy of a familiar sign-in page.
If you entered a password after the symptoms began, use a different trusted device to change it. Start with your email account, because access to email can be used to reset other accounts. Turn on multifactor authentication where available and review recent sign-ins. Do not reuse the affected password elsewhere.
Also make sure you know whether browser synchronization is enabled. Removing an unwanted extension or setting from one device may be undone if the same change is synchronized from another device. On a work computer, check with the person responsible for IT before removing company-managed extensions or security software.
Step 1: Close suspicious pages without interacting with them
If a page says your computer is infected, your account is expiring, or you must call a number, do not call, click its buttons, or install its recommended tool. Close the browser window. If it will not close normally, use the operating system’s standard way to end the browser process, then reopen it without restoring the suspicious tabs.
A browser notification is not the same as a system infection. Some websites obtain permission to send notifications and then use that permission for misleading alerts. You can remove notification permission later from the browser’s site settings.
Step 2: Check extensions and add-ons
Extensions are a common source of browser changes. Open the browser’s extensions or add-ons page and review every installed item. Remove anything you do not recognize, no longer need, or did not intentionally install. Be cautious with extensions that claim to provide search tools, coupons, video downloads, PDF features, or security protection without a clear reason for being installed.
Do not remove a known business, accessibility, password-management, or security extension merely because it has a technical name. If the browser says an extension is installed by an administrator, it may be controlled by Windows policy or an organization’s management system. Removing it may not be appropriate or possible.
After removing a suspicious extension, close and reopen the browser. Test with a few trusted sites. If the extension returns, another device may be synchronizing it, or a program on the computer may be reinstalling it.
Step 3: Restore browser settings carefully
Check the settings for the start-up page, home button, new-tab behavior, default search engine, and search shortcuts. Replace unfamiliar entries with settings you recognize. Browsers also provide a reset or restore-settings option. This normally disables extensions and returns many settings to their defaults, but it may not remove a Windows program or repair a modified network setting.
Before resetting, review what the browser says will happen. Depending on the browser and account, a reset may affect pinned pages, start-up preferences, permissions, or other customizations. It should not normally delete locally saved bookmarks, history, or passwords, but you should not rely on that without reading the browser’s warning and confirming that important information is backed up or available through a trusted account.
If unwanted settings return immediately after the reset, stop repeating the reset. That pattern suggests the browser is not the only part of the problem.
Step 4: Remove suspicious programs from the computer
In Windows, review installed apps and programs by name and installation date. Look for software installed around the time the browser behavior began, especially programs you do not remember approving. Search the publisher and program name from a trusted device if you are uncertain, but do not assume that an unfamiliar name is automatically malicious.
Uninstall only software you can identify with reasonable confidence. Some unwanted programs use names that resemble legitimate Windows components, and deleting files manually can damage the operating system. If an uninstaller asks you to keep a browser extension or change search settings, decline those optional changes.
Run a full scan with a reputable, up-to-date security tool already trusted on the computer. Windows Security can perform a full scan, and its offline scan option can be useful when persistent software interferes with normal Windows operation. Do not install several competing antivirus products at once. If the scan identifies a threat, record the detection name and follow the product’s recommended quarantine or removal process.
Step 5: Check for network-level or system-level changes
If the same redirects occur in multiple browsers, the cause may be outside the browser. Possible sources include a changed DNS server, a modified hosts file, unwanted proxy settings, router configuration changes, or malware that continues to alter settings.
Check the computer’s proxy settings and confirm that a proxy is not enabled unless your workplace, school, or security software requires it. Do not edit the Windows hosts file or registry casually. An incorrect change can prevent legitimate websites from loading or interfere with business applications.
Test the affected computer on a different trusted network, such as a phone hotspot, only if doing so is safe and permitted by your organization. If the problem disappears on the alternate network, inspect the router and DNS configuration rather than repeatedly resetting the browser. Change the router’s administrator password from a trusted device, update its firmware when appropriate, and verify that its DNS settings were not replaced. Contact the internet provider or network administrator if you are unsure which settings are legitimate.
Step 6: Review browser and account security
After cleaning up the browser, review saved passwords, autofill information, extensions, connected devices, and recent account activity. If an unfamiliar extension had access to browsing data, assume that information viewed or entered while it was active may have been exposed. Change important passwords from a clean device and sign out other sessions where the service provides that option.
For a small business, document the affected computer, user account, approximate start time, suspicious domains, and any credentials entered. This information can help determine whether the issue is limited to one workstation or requires a wider response.
When to stop troubleshooting and get help
Stop and seek qualified assistance if security software cannot run, settings are controlled by unknown policies, the browser keeps reinstalling unwanted components, redirects continue in every browser, or you suspect account theft. Also stop before using registry cleaners, “PC repair” utilities from pop-ups, unofficial removal tools, or instructions that ask you to disable security protections.
A technician may need to examine scheduled tasks, installed services, browser policies, DNS and proxy settings, the router, and security logs. If malware is suspected, preserve useful evidence before wiping or reinstalling the computer. If the computer contains regulated business information, financial records, or sensitive personal data, follow the organization’s incident-response process first.
How to reduce the chance of another hijack
- Keep Windows or macOS, browsers, extensions, and security tools updated.
- Install software only from the developer’s official source or a trusted app store.
- Read installation screens and decline optional search tools, extensions, and bundled utilities.
- Use a standard user account for everyday work when practical.
- Review browser extensions periodically and remove those you no longer need.
- Do not trust urgent pop-ups that demand payment, remote access, or a phone call.
- Use unique passwords and multifactor authentication for email and important accounts.
- Keep reliable backups of important files, separate from the computer being cleaned.
Browser hijacking can be a minor settings problem, but it can also be an early sign of unwanted software or compromised credentials. Start with extensions and browser settings, protect accounts before entering more information, and broaden the investigation when symptoms cross browsers or devices. If the cause is unclear or the behavior persists, a careful diagnostic review is safer than repeatedly installing cleanup tools or making unverified system changes.
When to call a professional
If the problem continues, the data is important, or the repair requires work beyond your comfort level, AME Computers can provide professional diagnosis and repair or call 402-505-6600.
Free repair guidance
Get New Computer Repair Guides by Email
Practical PC and Mac help from AME Computers. Confirm your email once and unsubscribe anytime.

