Common causes
- A free app, video converter, or PDF tool whose installer bundled a search-changing extension or potentially unwanted program you didn't notice.
- A browser extension that seemed useful, such as a coupon, weather, or new-tab add-on, but was built to redirect your searches for ad revenue.
- A previously trustworthy extension that was sold to a new owner and updated with ad-injection or search-redirect code.
- Browser policies added to the Windows registry that force a search engine, homepage, or extension and show 'Managed by your organization'.
- Modified desktop or taskbar shortcuts that open a specific website every time you start the browser.
- Browser sync restoring a hijacking extension from another device signed in to the same browser account.
- A changed Windows proxy setting that routes your web traffic through a server you didn't choose.
- Allowing notifications from a spammy website, which then pushes fake alerts and ads even when the site isn't open.
Advertisement
Step-by-step fixes
Step 1
Uninstall unfamiliar programs from Windows
Many hijackers reapply their browser changes from a companion program, so start in Windows rather than the browser. In Windows 11, open Settings > Apps > Installed apps, sort by Date installed, and look at anything added around the time your search engine changed (Windows 10: Settings > Apps > Apps & features). Uninstall search tools, 'safe search' helpers, download managers, PDF or media converters, and anything with a name you don't recognize. If an uninstaller opens a web page or asks whether you want to keep its settings, close the page and decline. Restart the PC afterward, because some programs finish removing themselves during a reboot. Success is an apps list with nothing you didn't knowingly install.
Step 2
Remove suspicious browser extensions
Open your browser's extensions page: chrome://extensions in Chrome, edge://extensions in Edge, or about:addons in Firefox. Remove, rather than just disable, anything you don't recognize or no longer use, especially new-tab, search, coupon, PDF, and 'security' add-ons. Be suspicious of extensions with little information or broad permissions, such as reading and changing your data on all websites, that they don't obviously need. If an extension can't be removed and says it's installed or managed by your administrator, a policy is forcing it; the last step in this guide deals with that. If you use browser sync, remove the extension on every signed-in device, or sync may reinstall it. Success is a short list of extensions you chose yourself.
Step 3
Fix your search engine, homepage, and startup pages
In Chrome, go to Settings > Search engine and choose Google, Bing, or another engine you trust, then open Manage search engines and site search and delete entries you don't recognize. Under Settings > On startup, remove unknown pages. In Edge, type 'search' into the Settings search box, open Address bar and search, and pick your search engine, then check the Start, home, and new tabs settings. In Firefox, choose your default engine in Settings > Search and set your homepage and new windows in Settings > Home. Yahoo itself is a legitimate search engine; the problem is when searches pass through an unknown site before landing there. Success is an address-bar search going straight to the engine you chose.
Advertisement
Step 4
Check browser shortcuts for an added web address
Some hijackers edit the shortcut you click so the browser always opens their page. Right-click the browser's desktop shortcut and select Properties (in Windows 11, you may need to select Show more options first). On the Shortcut tab, look at the Target field. It should end with the browser's program file, such as chrome.exe or msedge.exe inside quotation marks, sometimes followed by a legitimate switch like --profile-directory. If a web address appears after it, delete that part and select OK. Taskbar pins can hide the same change, and the simplest fix is to unpin the browser icon and pin it again from the Start menu. Check Start menu shortcuts too. Success is the browser opening to your own startup page from every shortcut.
Step 5
Reset Chrome, Edge, or Firefox to default settings
A reset clears changes that are hard to find by hand. In Chrome, go to Settings > Reset settings > Restore settings to their original defaults and confirm. This resets your startup page, new tab page, search engine, and pinned tabs, disables extensions, and clears temporary data such as cookies, but keeps bookmarks, history, and saved passwords. In Edge, go to Settings > Reset settings > Restore settings to their default values > Reset. In Firefox, open about:support and select Refresh Firefox, which removes add-ons and customizations while keeping bookmarks, history, passwords, and cookies. After the reset, re-enable only the extensions you trust. Success is a browser that stays on your chosen search engine after you close and reopen it.
Step 6
Block notification spam and check proxy settings
Pop-up ads in the corner of your screen are often website notifications rather than malware. In Chrome, go to Settings > Privacy and security > Site settings > Notifications and remove sites you don't trust. In Edge, type 'notifications' into the Settings search box and review the allowed sites. In Firefox, go to Settings > Privacy & Security, scroll to Permissions, and select Settings next to Notifications. Next, make sure nothing is rerouting your traffic. In Windows 11, open Settings > Network & internet > Proxy (Windows 10: Settings > Network & Internet > Proxy). Unless you or your workplace set up a proxy, Use a proxy server and Use setup script should be off, and Automatically detect settings on. Success is no more desktop pop-ups and no unexpected proxy.
Step 7
Run Malwarebytes AdwCleaner and a full malware scan
AdwCleaner is a free Malwarebytes tool built for adware, unwanted programs, and hijackers. Download it only from the official Malwarebytes website, run it, and select Scan now. Review the results, leave items checked unless you recognize a program you want to keep, and select Quarantine. Save your work first, because it closes open programs and may ask to restart. If the hijack survives, AdwCleaner's settings include optional basic repair actions, such as resetting browser policies. Afterward, run a full scan with Microsoft Defender (Windows Security > Virus & threat protection > Scan options > Full scan) or Malwarebytes to catch anything more serious that arrived in the same bundle. Success is AdwCleaner and a full scan both coming back clean when you run them again.
Step 8
Remove leftover 'Managed by your organization' policies
Warning: editing the registry incorrectly can cause problems, so back it up with File > Export in Registry Editor first, and don't do this on a work or school PC, where policies are legitimate. If Chrome or Edge still says 'Managed by your organization', open chrome://policy or edge://policy and note entries such as ExtensionInstallForcelist, DefaultSearchProviderSearchURL, or HomepageLocation that point to sites or extensions you don't recognize. Press Windows key + R, type regedit, and check HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome and HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge, plus the same paths under HKEY_CURRENT_USER. Delete the values the hijacker added. For Firefox, check about:policies and remove a policies.json file you didn't create from C:\Program Files\Mozilla Firefox\distribution. Restart the browser. Success is the message disappearing.
How to prevent it
- During software installs, choose Custom or Advanced setup and uncheck bundled toolbars, search tools, and extra offers.
- Install extensions only from the Chrome Web Store, Microsoft Edge Add-ons, or Firefox Add-ons, and keep your list short.
- Review your extensions every few months and remove ones you no longer use, since ownership and behavior can change after updates.
- Decline website notification requests unless you genuinely want alerts from that site.
- Keep Potentially unwanted app blocking on in Windows Security > App & browser control > Reputation-based protection settings.
Tools that can help
You can remove most hijackers for free with the Windows and browser settings above. AdwCleaner is worth running when the change keeps coming back, and a full malware scanner makes sense if the hijacker arrived bundled with other unwanted software.
Best for adware and hijackers
Malwarebytes AdwCleaner
A free Malwarebytes tool that finds and quarantines adware, potentially unwanted programs, and browser hijackers that change your homepage or search engine. It runs alongside your existing antivirus.
Get AdwCleanerBest for cleanup
Malwarebytes
The free Malwarebytes scanner is a strong second opinion for malware, adware, and unwanted programs, while Premium adds real-time, ransomware, and web protection that can run alongside Microsoft Defender.
Visit MalwarebytesBest free one-time scan
ESET Online Scanner
ESET's free one-time scanner downloads its current detection engine, scans and cleans the PC, and works without relying on Microsoft Defender or conflicting with your existing antivirus.
Get ESET Online ScannerTechyLeakz may earn a commission if you buy through these links, at no extra cost to you. Affiliate disclosure
What to do next if this fails
- Move to the next fix instead of repeating the same step multiple times.
- Check the related guides in this cluster before attempting a full reset.
- If startup, update, and corruption symptoms overlap, widen the diagnosis instead of treating one error in isolation.
Advertisement
FAQ
Why does my search engine keep changing to Yahoo?
Yahoo Search is legitimate, but many hijackers route your searches through their own site and then pass them to Yahoo, earning money from the ads you see. If searches briefly show an unfamiliar web address before landing on Yahoo, or the setting changes back after you fix it, a program, extension, or browser policy is forcing it. Remove the source using the steps above rather than just changing the setting again.
Why does Chrome say it's managed by my organization?
Chrome shows this whenever any policy is set on the PC. On a work or school computer that's normal. On a personal PC, it often means a hijacker has added policies to force an extension, homepage, or search engine, although some legitimate security and password tools set policies too. Visit chrome://policy to see exactly which policies are active and what they contain before deciding what to remove.
Is a browser hijacker dangerous?
Most hijackers are adware rather than malware that steals files, but they aren't harmless. They can track your searches and browsing, show scam ads, push fake download buttons, and send you to phishing pages. Some arrive alongside more serious malware in the same software bundle. That's why it's worth removing the hijacker completely and running a full malware scan afterward, not just changing your search engine back.
Will reinstalling my browser get rid of a hijacker?
Often not. Browser policies stored in the Windows registry survive a reinstall, browser sync can restore a bad extension from your account, and the program that installed the hijacker may simply reapply it. Reinstalling only helps after you've removed the source program, cleared the policies, and removed the extension from every synced device. A browser reset usually achieves the same result with less effort.
Can a browser hijacker steal my passwords?
An extension with permission to read and change data on all websites can, in principle, see what you type into web pages, including sign-in forms. Most hijackers focus on ads and search revenue, but you can't be sure what a malicious extension collected. After removing one, change passwords for important accounts, starting with email, turn on two-factor authentication, and review recent sign-in activity.
How do I stop a browser hijacker from coming back?
Remove all three parts: the Windows program, the browser extension, and any policies. Then remove the extension from every device signed in to the same browser account so sync doesn't bring it back. Going forward, choose Custom or Advanced installation for free software, decline bundled offers, install extensions only from official stores, and keep Windows Security's Potentially unwanted app blocking turned on.