Experiencing a hijacked Chrome browser can be incredibly frustrating. If your Chrome homepage has unexpectedly changed, or if you’re bombarded with unwanted ads and pop-ups, you may be dealing with Chrome malware or browser hijacking. This guide will help you identify signs of a hijacked browser and provide comprehensive solutions for removing malware across different platforms.
Quick Fixes to Try First
- Check for unknown extensions immediately: chrome://extensions
- Reset Chrome settings: chrome://settings/reset
- Run Windows Defender or macOS XProtect scan
- Update Chrome to the latest version
Identifying Signs of Browser Hijacking
- Homepage changed without permission
- Default search engine modified to Yahoo, Bing, or an unknown search engine
- New toolbars or extensions appeared
- Unexpected pop-up ads or redirects
- Browser running slowly
- New tabs opening to ad sites automatically
- Cannot change homepage or search back to normal
- Unknown bookmarks or favorites added
- Browser settings being reset repeatedly
- Fake security warnings or tech support scams
Solutions for Windows
Remove Suspicious Extensions
- Visit chrome://extensions
- Review all extensions carefully
- Remove any you don’t recognize or didn’t install
- Look for extensions with generic names like “Search Helper” or “Browser Protector”
- Disable developer mode if enabled unexpectedly
Use Chrome Cleanup Tool
- Go to chrome://settings/cleanup
- Click “Find” under “Find and remove harmful software”
- Let the scan complete (may take several minutes)
- Remove anything found
- Restart Chrome
Reset Chrome Settings
- Go to chrome://settings/reset
- Click “Restore settings to their original defaults”
- Confirm reset
- This removes extensions, clears cookies, and resets homepage/search
Remove Suspicious Programs
- Open Control Panel > Programs > Uninstall a program
- Sort by “Installed On” date
- Remove recently installed unknown programs
- Look for malware names like Search Conduit, MyWebSearch, Babylon, Ask Toolbar, Delta Search, Sweet Page
- Also check Settings > Apps > Installed apps
Run Malwarebytes (Free)
- Download from malwarebytes.com
- Run a full system scan
- Quarantine and remove threats
- Restart computer
Run Windows Defender Full Scan
- Go to Windows Security > Virus & threat protection
- Choose Scan options > Full scan
- Run the scan (may take 1+ hour)
Check Windows Startup Programs
- Open Task Manager > Startup tab
- Disable suspicious entries
- Look for unknown publishers
Check Hosts File
- Navigate to
C:\Windows\System32\drivers\etc - Open “hosts” file with Notepad (as admin)
- Remove any suspicious redirects
- The file should only have localhost entries and comments
Check Browser Shortcuts
- Right-click Chrome shortcut > Properties
- Check “Target” field
- It should only be the path to chrome.exe
- Remove any URLs or extra parameters after .exe
Clear DNS Cache
- Open Command Prompt as admin
- Run:
ipconfig /flushdns - Restart browser
Solutions for macOS
Remove Suspicious Extensions
- Visit chrome://extensions
- Remove unknown extensions
Reset Chrome on Mac
- Visit chrome://settings/reset
- Restore defaults
Check Applications Folder
- Open Finder > Applications
- Look for unknown apps
- Drag suspicious apps to Trash
- Empty Trash
Remove Login Items
- Go to System Preferences > Users & Groups > Login Items
- Remove suspicious startup items
Check Launch Agents
- Open Finder, press Cmd+Shift+G
- Navigate to
~/Library/LaunchAgents - Also check
/Library/LaunchAgentsand/Library/LaunchDaemons - Remove files from unknown sources
Run Malwarebytes for Mac
- Free version available
- Scans for Mac-specific adware
- Removes browser hijackers
Use CleanMyMac or Similar
- Use malware removal feature
- Finds hidden malware components
Solutions for Linux
Remove Extensions
- Visit chrome://extensions same as other platforms
Reset Chrome
- Delete
~/.config/google-chromefolder - Reinstall Chrome if needed
Check for Malware
- Install ClamAV:
sudo apt install clamav - Update database:
sudo freshclam - Run scan:
clamscan -r /home
Manual Cleanup – All Platforms
Fix Homepage
- Visit chrome://settings
- Under “On startup”, select your preferred option
- Set a specific page if needed
Fix Search Engine
- Visit chrome://settings/searchEngines
- Remove unknown search engines
- Set Google (or preferred) as default
- Look for: search.yahoo.com, bing.com (if unwanted), or unknown search domains
Clear All Browsing Data
- Press Ctrl+Shift+Delete (Cmd+Shift+Delete on Mac)
- Select “All time”
- Check all boxes including cookies, cache, site data
- Clear data
Disable Notifications
- Visit chrome://settings/content/notifications
- Block all or remove suspicious sites
- Fake notification permission often used by hijackers
Checking for Chrome Policies (Enterprise Hijacking)
Check for Managed Settings
- Go to chrome://policy
- If policies are listed, the browser may be managed
- “Managed by your organization” should not appear on a personal computer
Remove Chrome Policies (Windows)
- Open Registry Editor (regedit)
- Navigate to:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome - Also check:
HKEY_CURRENT_USER\SOFTWARE\Policies\Google\Chrome - Delete suspicious keys
- Also check:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Update
Remove Policies (Mac)
- Open Terminal
- Run:
defaults read com.google.Chrome - Delete policy files in
/Library/Managed Preferences
Solutions for Mobile Devices
Android
- Go to Settings > Apps > Chrome > Clear Data
- Check Settings > Apps for suspicious apps
- Remove unknown apps
- Factory reset if the infection is severe
iOS
- Delete Chrome and reinstall
- iOS sandbox prevents most malware
- Check for unknown device profiles: Settings > General > Profiles
Prevention Tips
- Only install extensions from Chrome Web Store
- Read extension reviews and permissions before installing
- Don’t click “Allow” on random notification requests
- Avoid downloading software from unknown sites
- Keep Chrome and OS updated
- Use reputable antivirus software
- Don’t click suspicious email links
- Be cautious of “free” software bundles
- Read installation screens carefully (uncheck bundled software)
- Enable Chrome Safe Browsing: Settings > Privacy > Security > Enhanced protection
When to Completely Reinstall Chrome
If malware persists after all steps:
- Export bookmarks and passwords to Google account (sync)
- Uninstall Chrome completely
- Delete all Chrome folders:
- Windows:
%LOCALAPPDATA%\Google\Chrome - Mac:
~/Library/Application Support/Google/Chrome - Restart computer
- Download fresh Chrome from google.com/chrome only
- Reinstall
- Sign in to restore data
- Only install trusted extensions
By following these steps, you can effectively remove Chrome hijacking and malware, restoring your browser to its original, secure state. Stay cautious in the future to prevent similar issues.