A browser hijacker is the digital equivalent of someone quietly changing the locks on your front door and handing a copy of the key to a stranger. Your browser still opens, but the homepage, search engine, and sometimes every new tab now route through a page you never chose. On Windows 11 the fix is very doable — but only if you clean the browser, the shortcuts, and the persistence points, because a hijacker that survives one of those three will simply grow back.
Before You Change Anything
Don't panic-uninstall everything. Removing the wrong program can break your browser profile or delete saved passwords. Identify first, remove second.
Write down what you see before you fix it. Note the hijacked homepage URL, the search engine name, and any unfamiliar program names. This is your evidence trail.
Back up bookmarks and passwords (browser sync or an export file) before you reset anything.
Disconnect from untrusted networks if the hijack appeared right after installing "free" software or a browser add-on.
Don't pay for a "removal tool" you found in a pop-up. The pop-up is often the hijacker's own sales pitch.
Keep one clean browser available (Edge or Chrome with no extensions) so you can search for help if you break your main one.
If this is a work PC, tell IT before you change settings. Group Policy may be enforcing the "hijack," and you'd be fighting your own admin.
Having this problem on your own PC?
Describe what's happening and get a real AI diagnosis in seconds — no account needed.
Confirm You Have This Problem
A hijacker is not the same as a slow PC or a bad Wi-Fi connection. You have a hijacker if two or more of these are true:
Your homepage or startup page changed and won't stay changed after you reset it.
New tabs open to a search or "portal" page you never set.
Your default search engine switched to something unfamiliar (often a lookalike of Google or Bing).
Search results are redirected through an odd domain before landing on the real site.
Your browser has extensions or toolbars you don't remember installing.
Desktop, taskbar, or Start menu shortcuts for Chrome/Edge launch a different site or a strange URL.
You get pop-ups or "your PC is infected" warnings even when the browser is closed.
If only one item is true and it's a homepage you can fix once and it stays fixed, you probably just have a settings change, not a persistent hijacker.
Possible Causes
| Evidence Observed | Likely Cause | Next Check |
|---|---|---|
| Homepage/search resets itself after you fix it | Scheduled task or service re-applying settings | Task Scheduler and Services for unknown entries |
| Shortcut opens a weird URL | Shortcut target edited to append a site address | Right-click shortcut → Properties → Target |
| Toolbar or unknown extension in browser | Bundled adware installed with free software | Browser extension list + Installed apps |
| Redirects only in one browser | Extension or profile-level hijack | Test in a second browser/profile |
| Redirects in every browser | System-level proxy, DNS, or hosts file change | Windows proxy settings, DNS, hosts file |
| Pop-ups appear with browser closed | Adware program running in background | Startup apps and Task Manager |
Step-by-Step Diagnostic (Lowest Risk First)
Work top to bottom. Stop as soon as the symptom disappears — you don't need to do steps that aren't relevant.
1. Test in a clean browser profile. Open Edge or Chrome in a fresh profile (or use InPrivate/Incognito). If the hijack vanishes there, the problem lives in your main profile's extensions or settings, not the whole system. This one test saves you an hour of guessing.
2. Check your browser extensions. In Chrome go to chrome://extensions, in Edge edge://extensions. Remove anything you don't recognize or don't actively use. Look for "search protectors," coupon tools, PDF converters, and VPN add-ons you never installed. Disable first, then remove if the symptom clears.
3. Inspect your shortcuts. Right-click your desktop and taskbar browser shortcuts → Properties → Target. A clean Chrome target looks like "C:\Program Files\Google\Chrome\Application\chrome.exe". If there's a URL tacked on after the closing quote, that's your hijack. Delete the extra text, or delete the shortcut and recreate it from the Start menu.
> Still unsure what's causing the issue? Run a free AI diagnosis at DiagnoseMyPc.com — no download required, 5 free analyses per month.
4. Reset homepage, search, and startup pages. In Chrome: Settings → On startup, and Settings → Search engine. In Edge: Settings → Start, home, and new tabs, and Settings → Privacy, search, and services. Set them to what you actually want. If they revert within minutes, a persistence mechanism is re-applying them — continue below.
5. Check installed programs. Settings → Apps → Installed apps. Sort by install date and look at what arrived around the time the problem started. Uninstall anything unfamiliar, especially "search," "toolbar," "driver updater," or "PC cleaner" utilities. Use the program's own uninstaller, then reboot.
6. Check startup apps and Task Manager. Open Task Manager (Ctrl+Shift+Esc) → Startup apps, and the Details tab. Look for unfamiliar processes with random names or ones pointing to AppData\Local\Temp. Disable startup entries you don't recognize before deleting anything.
7. Check Task Scheduler and Services. Press Win+R, type taskschd.msc, and review the Task Scheduler Library for tasks that run a browser or script at logon. Then run services.msc and look for unknown services set to Automatic. This is where the "it keeps coming back" hijackers hide.
8. Check the system proxy and DNS. Settings → Network & Internet → Proxy. If "Use a proxy server" is on and you didn't set it, turn it off. Then check your DNS: Settings → Network & Internet → your adapter → DNS server assignment. Set it to Automatic or a known resolver.
9. Check the hosts file. Open Notepad as Administrator, then open C:\Windows\System32\drivers\etc\hosts. Legitimate entries are usually commented out with #. Any active line mapping a search engine or homepage domain to 127.0.0.1 or an unknown IP is a hijack — remove it and save.
10. Scan with Windows Defender. Run a Full scan, not a quick scan: Windows Security → Virus & threat protection → Scan options → Full scan. Then open Protection history and review what was quarantined.
11. Scan with Malwarebytes Free. The free version is a legitimate, well-known second opinion that catches adware Defender sometimes ignores. Run a full scan, quarantine what it finds, and reboot. You do not need the paid version for this.
12. Reset the browser as a last resort. If the profile is still dirty, Chrome and Edge both offer Reset settings to their original defaults. This disables extensions and clears startup/search settings but keeps bookmarks and passwords. Do this only after the steps above, since it's the most disruptive.
How to Know It's Fixed
Your homepage, new tab, and search engine stay exactly where you set them after a reboot.
Shortcuts launch the browser normally with no appended URL.
No unfamiliar extensions, startup entries, scheduled tasks, or services remain.
A full Defender scan and a Malwarebytes scan both come back clean.
You can search in every installed browser without redirects.
Give it 24–48 hours of normal use before you call it done. Hijackers that rely on a scheduled task often wait for a reboot to reapply.
When to Stop and Get Help
Stop and get professional help if:
The hijack returns after a full clean, which can indicate a rootkit or a compromised Windows account.
You see redirects on a work laptop that IT manages — this may be policy, not malware.
Your browser or Windows won't launch after removal, or you can't reach Windows Security.
You're seeing signs of identity theft (unexpected password-reset emails, logins you didn't make). Change passwords from a different, known-clean device first.
In 25+ years of IT support and 9 years running a corporate help desk, the pattern I see most is this: people fix the homepage, reboot, and the hijack returns because they never touched the shortcut or the scheduled task. Clean all three layers — browser, shortcuts, persistence — and it stays gone.
Dealing with this one-time? The $4.99 Fix Pass gives you 7 days of full Pro access — no subscription needed.
Found this helpful?
Share it with someone who could use it.
DiagnoseMyPC Team
Expert PC diagnostics and troubleshooting guides to help you keep your Windows system running smoothly.
Get the free Windows Troubleshooting Checklist
Subscribe and instantly download our 50-point Windows troubleshooting checklist — plus practical fixes, performance tips, and security alerts from the DiagnoseMyPC team.
No spam. Unsubscribe anytime.
Frequently Asked Questions
How do I know if my PC has malware?
Common signs include sudden slowdowns, pop-ups, unfamiliar programs, high network or CPU usage when idle, and browser changes you didn't make. An AI diagnosis can flag suspicious activity in your system data — run a free scan at diagnosemypc.com to check.
Is Windows Defender enough to protect my PC?
For most home users, Windows Defender plus safe browsing habits and regular updates is solid protection. The bigger risks are outdated software, weak passwords, and clicking malicious links — good habits matter more than any single tool.
What should I do first if I think I've been hacked?
Disconnect from the internet, change important passwords from a different device, run a full security scan, and check for unfamiliar programs or startup entries. A diagnosis helps confirm what changed on your system so you know exactly what to clean up.
Does this tool make changes to my PC without asking?
No. The analyzer only reads the diagnostic data you choose to share and shows you any recommended fixes first. You stay in complete control of what actually runs on your computer.



