Browser Keeps Redirecting? A Prestonpans Repair Guide

A bench walkthrough of what a browser hijack actually is, the five places it hides on a PC, and how a Prestonpans or East Lothian customer can tell a nuisance redirect from something nastier underneath.

10 October 2026 8 min read Cybersecurity Alex M.
Browser keeps redirecting? A Prestonpans repair guide from PC Repair Services

A Prestonpans customer brought in a laptop last week with a problem that has become one of the most frequent cybersecurity calls we take on the bench: every time he opened Chrome, within two or three clicks the browser would jump off whatever page he was reading and land on a search page he had never heard of. Google at first, then half a second of a redirect chain, then a cheerful but unfamiliar results page serving ads at the top. He had already run three antivirus scans and been told the machine was clean. It was clean of viruses — it was comprehensively hijacked by two Chrome extensions he did not remember installing and a Windows scheduled task that quietly re-added them whenever he removed one.

That is browser-hijacker malware, and it accounts for a surprising share of what we see in Prestonpans, Cockenzie, Musselburgh and across East Lothian. The owner is almost never doing anything obviously risky — the infection usually arrives bundled with a cheerful-looking utility, a video converter, or a “driver updater” downloaded in a hurry, and most antivirus tools leave it alone because the extensions are technically installed with the user’s own consent.

What a Browser Hijack Actually Is

A browser hijacker is a particular kind of unwanted program — the industry calls them PUPs, “potentially unwanted programs” — whose job is to point your searches and your new-tab page somewhere it can serve ads from. Unlike a trojan or ransomware, a hijacker is designed to look as legitimate as it can. It has an installer, an uninstall entry in Windows, a privacy policy, and in most cases it does not steal passwords or touch files. What it does is reroute every search through its own servers so the first page of results you see is one it controls, and skim a share of the ad revenue on the way.

That is why a basic antivirus scan comes back clean. Microsoft Defender and the paid tools all catch obvious trojans, but a browser extension that was installed through Chrome’s own prompt is harder for them to label as a threat. The signatures used for PUPs are deliberately conservative, because flagging a legitimate-looking extension as malware is a lawsuit waiting to happen. The practical result is that your friend’s laptop can be “scanned and clean” and still redirect every search. Treating the symptom means treating the extensions, the scheduled task that reinstalls them, and the browser shortcut on the taskbar that may have been quietly edited to launch Chrome with an alternative start-up URL.

Where Hijacks Hide: Five Places We Check

When we clean one of these at the bench we check five places in this order, because the fix is only permanent if all five come up empty.

  • Browser extensions. The obvious one: Chrome, Edge and Firefox each list installed extensions in their menu. A hijacker usually has an innocent-looking name — “Fast Search Pro”, “Easy Converter”, “Weather Toolbar” — and a vague publisher. Removing it stops the redirects until next reboot.
  • Default search engine and start page. Even after the extension is gone, a swapped default search in settings keeps the redirects going. Chrome: Settings › Search engine. Edge: Settings › Privacy, search and services. Firefox: Settings › Search. Set each back to a reputable engine you recognise.
  • Scheduled tasks. The nastier families install a Windows scheduled task that silently re-adds the extension if it is missing. Open Task Scheduler, look in the Task Scheduler Library for anything you did not create — tasks named “ChromiumUpdate”, “AdobeFlash” (long dead), or random strings. Right-click, Disable, read the trigger before you delete.
  • Browser shortcut targets. This one surprises people. A hijacker will sometimes edit the target of the Chrome shortcut on your desktop or taskbar to include an argument such as a forced home-page flag. Right-click the shortcut, Properties, and check that the Target field ends with chrome.exe and nothing else.
  • Group policy edits. Enterprise-aggressive hijackers write registry entries under HKLM\Software\Policies\Google\Chrome that force a particular home page. These are harder to spot and are the single most common reason a hijack “keeps coming back” after what felt like a careful clean. On a home laptop with no company IT, any policy showing up at chrome://policy is almost always from a hijacker.

The One-Second Test: Local or Network?

Before you go through any of that, run the test that saves the most time: is the redirect happening inside the browser, or on the way out of the house?

Open a different browser you have not used recently. If the hijack is on Chrome, try Edge, which ships with Windows. Type a search by hand. If Edge behaves normally, the problem is in the Chrome install and local to that profile. If Edge also redirects, the DNS server on your home router has probably been changed — a nastier infection that overrides whatever DNS your laptop asks for. The fix for that one is to clean the laptop first, then reset the router to factory default and let it pull your ISP’s DNS back fresh, because leaving a router pointed at a hijacker’s DNS will reinfect every device on the network. Our guide to hidden malware on a laptop that got hot covers the “it survived a scan” family in more detail.

Cleaning Chrome, Edge or Firefox the Right Way

Once you know the hijack is browser-local, work through the five hiding places above in order. In Chrome the sequence is: three-dot menu › Extensions › Manage Extensions, and remove anything you do not recognise, including items labelled “Managed by your organization” on a home laptop — that label is a red flag on a personal machine, not a safe sign. Then Settings › Reset settings › “Restore settings to their original defaults”. This nukes the start page, the default search engine, the pinned tabs, and the content settings in one go. It does not delete your passwords or history.

Close Chrome entirely, open Task Scheduler, review the library and disable anything suspicious. Right-click the Chrome shortcut you use most, Properties, and verify the Target. Reboot. Open Chrome. Run a search. If the redirect returns, open Chrome’s hidden policy page by typing chrome://policy into the address bar. Any policy listed there on a home machine is almost certainly from a hijacker. Removing them means editing the registry — safe if you have done it before, not something to attempt blindly, and the point at which we would ask for the laptop in for repair rather than keep digging. Edge is almost identical: edge://extensions, edge://settings/reset, edge://policy. Firefox uses about:addons, about:preferences, and about:policies.

When We See the Same Family Twice

Some hijacker families — the ones built around dropper installers for “PDF converter” or “YouTube to MP3” tools — reinstall themselves even after what felt like a careful clean. The giveaway is a reinfection within a day or two, often after a reboot. On the bench we treat that as a sign that the dropper is still sitting in %AppData% or C:\ProgramData with a scheduled task set to run at user login. Finding and removing it by hand is the honest answer; a fresh Windows install is the certain one.

If the laptop is otherwise in good shape and the dropper looks like a known family, we always try the targeted clean first, because an operating system reinstall is a day of work backing up and restoring your settings. If the laptop is older, slow, and the dropper is a repeat offender, a clean install plus a careful rebuild from a verified backup is faster than a weekly re-clean. We will tell you honestly which route fits your machine before anything is started.

Why Remote Support Can Actually Work for Hijacks

Browser hijackers are one of the few infections where remote support genuinely holds up. The infection is local to the user profile, nothing in the clean requires physical access to the hardware, and a shared-screen session lets us walk the five-place sweep on the actual machine without a trip in. For a customer in Prestonpans, Cockenzie or Longniddry who would rather not drive to Edinburgh, a remote session saves the journey; for anything that reinfects, or that we trace back to a changed router DNS, we would always ask for the machine on the bench so we can verify the clean and check the network.

Signs It Is Something Worse Than a Nuisance

A redirect that only shows up on search results is almost certainly a hijacker, and the five-place sweep is usually enough. A pop-up window that will not close claiming “Microsoft has detected a virus on your PC, call this number” is a tech-support scam page — our walkthrough of tech-support scams in Edinburgh covers that one specifically. A browser that is slow and unresponsive with the fans spinning at full tilt even on a blank new tab is often a cryptominer running alongside the hijacker. A browser whose settings page is missing entries, or whose extension list cannot be opened, is being blocked by a group policy or a user-rights change — bring it in. And a laptop that redirects AND where Windows Security has quietly been disabled is almost always carrying something nastier underneath, and should not keep being used until it is cleaned.

Bringing It In From Prestonpans and East Lothian

If you are in Prestonpans, Cockenzie, Port Seton, Longniddry, Musselburgh, Tranent, Haddington, North Berwick or anywhere along the East Lothian coast and your browser will not stop redirecting, bring the laptop or desktop in and we will walk the full five-place sweep in front of you — extensions, defaults, scheduled tasks, shortcut targets and group policy — plus a check on the router’s DNS to make sure the clean sticks. If it is a Chrome-only redirect caught early, remote support can usually handle it inside half an hour; anything bigger comes in for a bench clean. The Prestonpans virus and malware removal service page has local collection details and typical turnaround, and the broader virus and malware removal service covers how we approach and sequence the cleanup.

Book a diagnostic online or get in touch and we will arrange a convenient time to take a look — usually same day for anything in East Lothian or east Edinburgh.

Last updated: 10 October 2026

Frequently Asked Questions

What Prestonpans and East Lothian customers ask us when a browser will not stop redirecting.

Because most antivirus tools deliberately avoid flagging potentially unwanted programs — the family that browser hijackers belong to — as outright malware. The extension was installed through Chrome’s own prompt, so technically it was consented to, and the scanner leaves it alone to avoid wrongly removing a legitimate add-on. The fix is a manual sweep of extensions, default search, scheduled tasks, shortcut targets and the chrome://policy page, not another antivirus scan.

Almost always because a Windows scheduled task, or a dropper file sitting in your AppData folder, is re-adding the extension at login or on a reboot. Open Task Scheduler, look through the library for anything you did not create, and disable it before you remove the extension. If you cannot find the trigger, bring the machine in — the dropper usually has a predictable hiding place but it is faster to find on the bench than to describe over the phone.

Not always, but on a home laptop with no company IT, it is a strong signal. Chrome shows that line whenever a policy has been written into the registry under the Chrome policy keys. A legitimate reason exists only on managed work machines. On a personal laptop, open chrome://policy and treat every policy listed there as a hijacker artefact until proven otherwise.

Only if the redirect also happens in a second browser on the same network, or on a second device entirely. That points at a changed DNS setting on the router rather than something living on your laptop. In that case, cleaning the laptop first and resetting the router to factory default (then letting it pull your ISP’s DNS back) does the job. If a different browser or device is unaffected, the router is innocent and the problem is browser-local.

Most Chrome-only redirects we can clear in a remote session: a shared-screen tool lets us walk the extensions, scheduled tasks, shortcut targets and policy page together, and verify the clean before we end the session. If the hijack keeps coming back, or if a second device on the home network is affected (which points at a router DNS change), we would ask you to bring it in so we can check the router and run a longer scan on the bench.

Browser Still Redirecting in Prestonpans?

Bring the laptop or desktop in and we will walk the full five-place sweep — extensions, defaults, scheduled tasks, shortcut targets and group policy — plus a check on the router’s DNS so the clean actually sticks.