What a browser hijacker does and how to spot it
A browser hijacker is malware that changes how your web browser behaves without your permission. It typically redirects your searches to a different search engine, replaces your homepage, injects ads into pages you visit, or installs unwanted toolbars. Unlike ransomware or spyware that hide completely, hijackers are often visible — you notice your browser acting differently the moment you open it.
The most common signs are: your homepage changed to a site you didn't set, searches redirect through an unfamiliar search engine (often with extra ads), new tabs open to promotional pages, or a toolbar appeared that you didn't install. Some hijackers also slow your browser or cause it to crash. The key difference from other malware is that you can usually see what's happening, which makes documenting it straightforward.
Documenting what you see is the first step toward removing it and reporting it to the right people. This record also helps you explain the problem to technical support or antivirus software if you need help.
Key Takeaways
- Take screenshots of your browser's homepage, search results, and any new toolbars or pop-ups to document exactly what changed.
- Check your browser's settings (homepage, search engine, extensions) and write down what you find before you change anything.
- Note when the hijacking started, what you were doing when you first noticed it, and which browser is affected.
- Report the hijacker to your browser maker (Chrome, Firefox, Safari, Edge) and to antivirus software if you use it.
- Save your documentation in a folder or document so you have it if you need to contact support or file a report later.
Take screenshots of what you see
The first step in documenting a hijacker is to capture what it looks like. Open your browser and take a screenshot of your homepage, your search results page, and any toolbars or pop-ups that appear. On Windows, press the Print Screen key, then open Paint or Word and paste the image. On Mac, press Shift + Command + 3 to save a screenshot to your desktop. On Chromebook, press Ctrl + Show Windows to capture the screen.
Take at least three screenshots: one of your homepage as it appears when you open the browser, one of a search result page (search for something simple like "weather"), and one of any new toolbar or extension that appeared. If pop-ups appear, screenshot those too. Label each screenshot with the date and what it shows — for example, "Homepage_Jan15.png" or "Search_Results_Hijacked.png". This visual record is the clearest way to show what happened.
Check your browser settings and write them down
Open your browser's settings and look at what has changed. In Chrome, click the three-line menu in the top right, then Settings. Check the "On startup" section (what page opens when you start the browser), the "Search engine" section (what search engine is used), and the "Extensions" section (what add-ons are installed). Write down the name of each extension and the URL of your homepage and search engine.
In Firefox, click the menu button (three horizontal lines), then Settings. Check the "Home" section for your homepage, the "Search" section for your search engine, and go to Add-ons to see what extensions are installed. In Safari on Mac, go to Safari menu > Preferences, then check the "General" tab for homepage and search engine. In Edge, click the three-dot menu, then Settings, and check "On startup" and "Privacy, search, and services".
Write all of this down in a document or notepad file. Include the exact URL of your homepage, the name of your search engine, and a list of every extension with its full name. This record shows what the hijacker changed and helps you restore your correct settings later.
Note the timeline and how you got infected
Write down when you first noticed the hijacking. Was it this morning? Last week? The day after you installed something? Did your browser change suddenly, or did it happen gradually? Did you notice any downloads, installation prompts, or suspicious websites you visited around the time it started?
Also note which browser is affected. If you use Chrome, Firefox, and Safari, does the hijacking happen in all three or just one? This detail matters because it tells you whether the malware is system-wide or specific to one browser. Write down what you were doing when you first noticed it — were you downloading a file, visiting a particular website, or just opening the browser normally? This context helps antivirus software and browser makers understand how the hijacker spreads.
Check for unwanted extensions and programs
Go to your browser's extension or add-on page and look for anything you don't recognize. In Chrome, type chrome://extensions in the address bar. In Firefox, type about:addons. Look for extensions with vague names like "Web Helper", "Search Enhancer", "Toolbar", or anything with a generic icon. Write down the exact name of each suspicious extension, who made it, and when it was installed (if that information is shown).
On Windows, also check your installed programs. Go to Settings > Apps > Apps & features and scroll through the list. Look for programs you don't remember installing, especially anything with a generic name or from an unknown company. On Mac, open Applications folder and look for unfamiliar programs. Write down the names and installation dates. These programs often work together with browser hijackers, so documenting them helps you remove the whole infection.
Report the hijacker to your browser maker
Once you have documented everything, report it to the browser company. In Chrome, go to chrome://extensions, find the suspicious extension, click the three dots next to it, and select "Report abuse". This sends your report directly to Google. In Firefox, go to the add-on page, find the extension, click the three dots, and select "Report this add-on". In Safari, there is no built-in report button, but you can report it to Apple at apple.com/feedback. In Edge, right-click the extension and select "Report this extension".
When you report, include your screenshots and the timeline you documented. Describe exactly what the hijacker does — for example, "Every search redirects through searchmyway.com with extra ads" or "My homepage changed to mysearch.net without my permission". The more specific you are, the faster the browser maker can investigate and remove it from their store.
Report to antivirus software and security organizations
If you use antivirus software like Windows Defender, Norton, McAfee, or Malwarebytes, open it and run a full scan. Most antivirus programs have a "Report" or "Submit" option where you can send information about the hijacker. Include your screenshots and the extension names. If you don't use antivirus software, you can report the hijacker to VirusTotal (virustotal.com) by uploading a screenshot or the extension file (if you can download it).
You can also report it to the Internet Crime Complaint Center (IC3) at ic3.gov if the hijacker is stealing your data or redirecting you to phishing sites. The IC3 is run by the FBI and takes reports of online fraud and malware. Include your documentation — the screenshots, timeline, and extension names — so they have a clear record of what happened.
Frequently Asked Questions
Should I remove the hijacker before documenting it?
No. Document first, remove second. Once you delete the extension or program, it becomes harder to prove what it was or report it accurately. Take your screenshots and write down the details while the hijacker is still active, then remove it. You can always reinstall it temporarily if you need more information for a report.
What if I can't find the extension that's causing the hijacking?
Some hijackers hide in your browser's settings rather than as a visible extension. Check your homepage URL and search engine settings — if they point to an unfamiliar site, that's the hijacker. You can also check your browser's "Manage search engines" page (in Chrome and Edge) to see all search engines installed, including hidden ones. Write down any you don't recognize and report them.
Can I report a hijacker if I already removed it?
Yes, but it's harder. If you took screenshots before removing it, include those in your report. Describe what you saw as clearly as you can — the name of the extension, the homepage URL, the search engine it used, and when it appeared. Browser makers and antivirus companies can still investigate based on your description, especially if other people report the same hijacker.
What's the difference between reporting to my browser and reporting to antivirus software?
Browser makers focus on removing malicious extensions from their store and blocking them from being installed. Antivirus companies focus on detecting and removing the malware from your computer. Report to both — they work on different parts of the problem and your report helps both do their job better.
Do I need to report a hijacker if I'm just going to remove it myself?
Reporting helps protect other people. If you report it, the browser maker can remove it from their extension store and warn other users. If you just remove it quietly, the hijacker stays available for others to download. A few minutes to report it can prevent hundreds of people from getting infected.