A Prestonpans customer brought in a laptop last week with a problem that has become one of the most frequent cybersecurity calls we take on the bench: every time he opened Chrome, within two or three clicks the browser would jump off whatever page he was reading and land on a search page he had never heard of. Google at first, then half a second of a redirect chain, then a cheerful but unfamiliar results page serving ads at the top. He had already run three antivirus scans and been told the machine was clean. It was clean of viruses — it was comprehensively hijacked by two Chrome extensions he did not remember installing and a Windows scheduled task that quietly re-added them whenever he removed one.
That is browser-hijacker malware, and it accounts for a surprising share of what we see in Prestonpans, Cockenzie, Musselburgh and across East Lothian. The owner is almost never doing anything obviously risky — the infection usually arrives bundled with a cheerful-looking utility, a video converter, or a “driver updater” downloaded in a hurry, and most antivirus tools leave it alone because the extensions are technically installed with the user’s own consent.
What a Browser Hijack Actually Is
A browser hijacker is a particular kind of unwanted program — the industry calls them PUPs, “potentially unwanted programs” — whose job is to point your searches and your new-tab page somewhere it can serve ads from. Unlike a trojan or ransomware, a hijacker is designed to look as legitimate as it can. It has an installer, an uninstall entry in Windows, a privacy policy, and in most cases it does not steal passwords or touch files. What it does is reroute every search through its own servers so the first page of results you see is one it controls, and skim a share of the ad revenue on the way.
That is why a basic antivirus scan comes back clean. Microsoft Defender and the paid tools all catch obvious trojans, but a browser extension that was installed through Chrome’s own prompt is harder for them to label as a threat. The signatures used for PUPs are deliberately conservative, because flagging a legitimate-looking extension as malware is a lawsuit waiting to happen. The practical result is that your friend’s laptop can be “scanned and clean” and still redirect every search. Treating the symptom means treating the extensions, the scheduled task that reinstalls them, and the browser shortcut on the taskbar that may have been quietly edited to launch Chrome with an alternative start-up URL.
Where Hijacks Hide: Five Places We Check
When we clean one of these at the bench we check five places in this order, because the fix is only permanent if all five come up empty.
- Browser extensions. The obvious one: Chrome, Edge and Firefox each list installed extensions in their menu. A hijacker usually has an innocent-looking name — “Fast Search Pro”, “Easy Converter”, “Weather Toolbar” — and a vague publisher. Removing it stops the redirects until next reboot.
- Default search engine and start page. Even after the extension is gone, a swapped default search in settings keeps the redirects going. Chrome: Settings › Search engine. Edge: Settings › Privacy, search and services. Firefox: Settings › Search. Set each back to a reputable engine you recognise.
- Scheduled tasks. The nastier families install a Windows scheduled task that silently re-adds the extension if it is missing. Open Task Scheduler, look in the Task Scheduler Library for anything you did not create — tasks named “ChromiumUpdate”, “AdobeFlash” (long dead), or random strings. Right-click, Disable, read the trigger before you delete.
- Browser shortcut targets. This one surprises people. A hijacker will sometimes edit the target of the Chrome shortcut on your desktop or taskbar to include an argument such as a forced home-page flag. Right-click the shortcut, Properties, and check that the Target field ends with
chrome.exeand nothing else. - Group policy edits. Enterprise-aggressive hijackers write registry entries under
HKLM\Software\Policies\Google\Chromethat force a particular home page. These are harder to spot and are the single most common reason a hijack “keeps coming back” after what felt like a careful clean. On a home laptop with no company IT, any policy showing up atchrome://policyis almost always from a hijacker.
The One-Second Test: Local or Network?
Before you go through any of that, run the test that saves the most time: is the redirect happening inside the browser, or on the way out of the house?
Open a different browser you have not used recently. If the hijack is on Chrome, try Edge, which ships with Windows. Type a search by hand. If Edge behaves normally, the problem is in the Chrome install and local to that profile. If Edge also redirects, the DNS server on your home router has probably been changed — a nastier infection that overrides whatever DNS your laptop asks for. The fix for that one is to clean the laptop first, then reset the router to factory default and let it pull your ISP’s DNS back fresh, because leaving a router pointed at a hijacker’s DNS will reinfect every device on the network. Our guide to hidden malware on a laptop that got hot covers the “it survived a scan” family in more detail.
Cleaning Chrome, Edge or Firefox the Right Way
Once you know the hijack is browser-local, work through the five hiding places above in order. In Chrome the sequence is: three-dot menu › Extensions › Manage Extensions, and remove anything you do not recognise, including items labelled “Managed by your organization” on a home laptop — that label is a red flag on a personal machine, not a safe sign. Then Settings › Reset settings › “Restore settings to their original defaults”. This nukes the start page, the default search engine, the pinned tabs, and the content settings in one go. It does not delete your passwords or history.
Close Chrome entirely, open Task Scheduler, review the library and disable anything suspicious. Right-click the Chrome shortcut you use most, Properties, and verify the Target. Reboot. Open Chrome. Run a search. If the redirect returns, open Chrome’s hidden policy page by typing chrome://policy into the address bar. Any policy listed there on a home machine is almost certainly from a hijacker. Removing them means editing the registry — safe if you have done it before, not something to attempt blindly, and the point at which we would ask for the laptop in for repair rather than keep digging. Edge is almost identical: edge://extensions, edge://settings/reset, edge://policy. Firefox uses about:addons, about:preferences, and about:policies.
When We See the Same Family Twice
Some hijacker families — the ones built around dropper installers for “PDF converter” or “YouTube to MP3” tools — reinstall themselves even after what felt like a careful clean. The giveaway is a reinfection within a day or two, often after a reboot. On the bench we treat that as a sign that the dropper is still sitting in %AppData% or C:\ProgramData with a scheduled task set to run at user login. Finding and removing it by hand is the honest answer; a fresh Windows install is the certain one.
If the laptop is otherwise in good shape and the dropper looks like a known family, we always try the targeted clean first, because an operating system reinstall is a day of work backing up and restoring your settings. If the laptop is older, slow, and the dropper is a repeat offender, a clean install plus a careful rebuild from a verified backup is faster than a weekly re-clean. We will tell you honestly which route fits your machine before anything is started.
Why Remote Support Can Actually Work for Hijacks
Browser hijackers are one of the few infections where remote support genuinely holds up. The infection is local to the user profile, nothing in the clean requires physical access to the hardware, and a shared-screen session lets us walk the five-place sweep on the actual machine without a trip in. For a customer in Prestonpans, Cockenzie or Longniddry who would rather not drive to Edinburgh, a remote session saves the journey; for anything that reinfects, or that we trace back to a changed router DNS, we would always ask for the machine on the bench so we can verify the clean and check the network.
Signs It Is Something Worse Than a Nuisance
A redirect that only shows up on search results is almost certainly a hijacker, and the five-place sweep is usually enough. A pop-up window that will not close claiming “Microsoft has detected a virus on your PC, call this number” is a tech-support scam page — our walkthrough of tech-support scams in Edinburgh covers that one specifically. A browser that is slow and unresponsive with the fans spinning at full tilt even on a blank new tab is often a cryptominer running alongside the hijacker. A browser whose settings page is missing entries, or whose extension list cannot be opened, is being blocked by a group policy or a user-rights change — bring it in. And a laptop that redirects AND where Windows Security has quietly been disabled is almost always carrying something nastier underneath, and should not keep being used until it is cleaned.
Bringing It In From Prestonpans and East Lothian
If you are in Prestonpans, Cockenzie, Port Seton, Longniddry, Musselburgh, Tranent, Haddington, North Berwick or anywhere along the East Lothian coast and your browser will not stop redirecting, bring the laptop or desktop in and we will walk the full five-place sweep in front of you — extensions, defaults, scheduled tasks, shortcut targets and group policy — plus a check on the router’s DNS to make sure the clean sticks. If it is a Chrome-only redirect caught early, remote support can usually handle it inside half an hour; anything bigger comes in for a bench clean. The Prestonpans virus and malware removal service page has local collection details and typical turnaround, and the broader virus and malware removal service covers how we approach and sequence the cleanup.
Book a diagnostic online or get in touch and we will arrange a convenient time to take a look — usually same day for anything in East Lothian or east Edinburgh.
Last updated: 10 October 2026