goJumboGPT

Security Malware and cleanup: when a device starts misbehaving

Pop ups, redirects and adware: fixing a hijacked browser

Why your browser suddenly opens ads, where the change really lives (extensions, search settings, notifications), and how to remove it without installing another cleaner.

8 min read How we write

The short answer

  • A hijacked browser is almost always a settings problem rather than an infection, and the fix is removing a permission, an extension or a search setting by hand.
  • Desktop alerts that arrive with the browser closed come from a web push permission you approved once, and revoking it stops them immediately.
  • An extension allowed to read and change all sites can insert ads into pages that never carried any, which is why disabling extensions is the fastest test.
  • A setting that keeps snapping back is being forced by a policy on Windows or a configuration profile on a Mac, and the policy has to go before the setting will stick.
  • Cleaner and optimizer software is part of the problem rather than the cure, so stick to the built in scanner plus at most one on demand second opinion.
  • If every device on your wifi shows the same junk, check the router before you touch the computers.

If ads appear where they never used to, your searches land on a site you did not choose, or alerts pop up with the browser closed, the cause is almost always a setting inside your browser rather than an infection inside your computer. Four changes cover most cases: a notification permission you clicked Allow on, an extension injecting scripts into pages, a hijacked default search engine, and a modified shortcut. All four are reversible by hand in about fifteen minutes, and none of them needs a cleaner tool.

Diagnose by symptom before you touch anything

Guessing means uninstalling things that were never broken while the real cause stays put. Each symptom points at one place, and the place tells you the fix.

What you seeWhere the change livesWhat removes it
Alerts in the corner of the screen, even with the browser closedA web push permission granted to a siteRevoke that site notification permission
New tabs or ads open when you click anything on a normal pageAn extension injecting script into every pageDisable extensions, re-enable one at a time
Searches go somewhere you never pickedDefault search setting, sometimes locked by a policyReset search, then remove the policy or profile
A promo page opens every time the browser startsStartup pages, or an address added to the shortcutFix startup pages, check the shortcut target
Ads inside apps or on the desktopA program installed at system levelUninstall it, then run one on demand scan
Every device on the wifi shows the same junkThe router, usually its DNS settingFactory reset the router and update its firmware

One test separates the two worlds. Open a browser you almost never use, with no extensions in it, and visit a few ordinary sites. If it behaves, the problem sits in your main browser profile. If not, skip to the system checks below.

Notifications: the alert that arrives with the browser closed

This is the most common complaint and the least serious. Web push lets a site send desktop alerts once you allow it, and junk sites collect that permission with a prompt engineered to look like something else: click Allow to prove you are not a robot, click Allow to start the download. The site can then post alerts styled to look like system warnings about viruses or a prize. Nothing was installed. One permission was granted.

Those alerts usually lead to a page with a support number on it, and the rest of that script is in how a fake virus warning becomes a fake refund.

  1. Open the notification list: chrome://settings/content/notifications, edge://settings/content/notifications, Privacy and Security in Firefox settings, or Websites then Notifications in Safari settings.
  2. Delete every site in the allowed list. A site you genuinely want alerts from will ask again.
  3. Set the top level option to the stricter choice, described as quieter messaging or as not letting sites ask. That kills the prompts rather than relying on you refusing them.
  4. Clear leftovers under Settings, System, Notifications on Windows, or System Settings then Notifications on a Mac. If alerts survive with the browser fully quit, the source is not web push.

Extensions: the most common source of injected ads

An extension allowed to read and change data on all sites can rewrite any page you open: adding ads the site never sold, swapping affiliate codes into shopping links, or redirecting a click. It explains ads on sites that normally carry none. The extension need not be new, since plenty were honest for years before being sold to someone else, a failure mode covered in why one extension permission is effectively total access.

  1. Open the list: chrome://extensions, edge://extensions, about:addons, or the Extensions tab of Safari settings.
  2. Turn every one of them off. Not remove, off. Then browse normally for a few minutes.
  3. If the ads stop, switch them back on one at a time until the ads return. The last one you enabled is the culprit, and it should be removed rather than disabled.
  4. Turn on Developer mode at the top of the Chrome or Edge page, which reveals extensions added by another program rather than from the store.
  5. An extension labelled as installed by enterprise policy, with no remove button, was added through the policy system, which is the next section.

Search engine, homepage and the locked settings trick

Hijackers go after search because search traffic pays. The crude version changes your default engine and startup page. The stubborn version installs a policy so the setting snaps back, and says so with a banner reading managed by your organization on a computer that belongs to none.

  1. Reset the basics. In Chrome and Edge, open Settings then Search engine, set the default yourself, and delete the unwanted entry from the list of other engines. Check On startup and New tab in the same place. Firefox keeps both under Home and Search.
  2. On Windows, right click the browser shortcut, choose Properties, and check the Target box. It should end with the program name and nothing else, so delete any web address after it. The pinned taskbar icon is a separate shortcut file, so check that too.
  3. If the setting reverts, open chrome://policy or edge://policy to see what is being forced. On Windows the policy comes from a program you can uninstall. On a Mac it arrives as a configuration profile, removed under System Settings, General, Device Management.
  4. Then reset the browser: restore settings to their original defaults in Chrome and Edge, or Refresh Firefox on about:support. Both keep bookmarks and passwords while clearing extensions, permissions and search settings.
  5. Sign out of browser sync before the reset and back in afterwards, or a hijacked profile will push the same extensions back onto this device and your others.

When the problem is outside the browser

If every browser is affected, something is running on the machine. Work through the places that survive a restart, because anything that returns after a reboot is being launched by something.

On Windows, open Settings, then Apps, then Installed apps, and sort by install date. Programs that arrived the day the trouble started are the prime suspects, and most are bundled extras from a free download rather than anything hidden. Then check Startup apps in Task Manager, look in Task Scheduler for tasks that launch a browser with an address attached, and turn off any manual proxy under Network and internet.

On a Mac, open System Settings, then General, then Login Items and Extensions, and remove unknown entries, then check the Applications folder and the configuration profiles above. Mac trouble of this kind is nearly always a bundled installer or an extension rather than a deep infection, so resist the urge to dig through system folders.

If phones and tablets on the same wifi show junk too, the router is the problem: its DNS settings point at someone else's servers, which redirects lookups for ordinary addresses, as explained in how DNS decides where a web address takes you. Factory reset it, set a new admin password, turn off remote management, and apply the firmware update, one of the cases in which updates to install now.

Only then is it worth scanning. Run a full scan with the built in security software, and on Windows add the offline scan option, which restarts the machine and checks the disk before Windows loads so nothing can hide. One second opinion scan from an established vendor is reasonable, run once and uninstalled. Which families of malicious software this applies to is set out in the plain English guide to malware families.

Why cleaner and optimizer software makes it worse

Search for help with pop ups and you will be offered cleaners, optimizers, registry fixers and driver updaters. Treat that whole category as part of the problem. The business model is a free scan reporting an alarming number of issues, most of them harmless leftovers such as cached thumbnails and old log entries, followed by a payment to fix them. Registry cleaning does nothing measurable for speed on a modern system, several of these products bundle the toolbars you are trying to remove, and some install a process that nags forever.

There is a second reason to stay away. A tool that shouts about thousands of problems trains you to trust scary counts on a screen, the reflex fake warning pages depend on. The honest list is short: the security software that shipped with your system, plus at most one on demand scanner from a well known vendor.

What to do next

Work the order: notification permissions, extensions, search and startup settings, the shortcut target, a browser reset, then system checks and one scan. Most people finish at step two. If the behavior survives a full reset and a clean scan, stop patching and rebuild: uninstall the browser, delete the leftover profile folder, install a fresh copy. For a machine misbehaving beyond the browser, follow the step by step cleanup for an infected computer.

Two habits stop a repeat. Choose the custom option whenever you install anything and untick the extras, and leave notifications on the strict setting permanently. Then, if a fake page collected a login while your browser was hijacked, change that password from a device that was never affected and review what your browser has been storing using the checklist for browser saved passwords.

Common questions

How do I stop pop ups that show up when Chrome is closed?

Those are web push notifications from a site you allowed at some point, not pop ups from a program. Open the notifications page in your browser settings, delete every site in the allowed list, and set the top option so sites cannot ask at all. If alerts continue with the browser fully quit, turn off notifications for the browser in Windows Settings or macOS System Settings, then look for an installed program.

Is adware a virus, and can it steal my passwords?

Most adware is not a virus in the self spreading sense, and much of it is a legally distributed program bundled with a free download. It can still be serious, because anything able to rewrite the pages you view can also capture what you type into them. Treat ad injection inside your browser as a credential risk, not just an annoyance.

My search engine keeps changing back to something else, what now?

A setting that reverts is being enforced rather than simply changed. Look for a banner saying your browser is managed by an organization, then open the policy page in the browser to see what is being applied. On Windows the source is usually an installed program you can uninstall, and on a Mac it is a configuration profile you remove under Device Management in System Settings.

Do I need to pay for a cleanup tool to remove this?

No. Every step that works here is free and built in: browser permissions, the extension list, search settings, the startup item list, and the scanner already included with Windows or the protections in macOS. Paid cleaners and optimizers frequently bundle the same kind of junk they claim to remove, and their issue counts are largely theatre.

Should I just reinstall my browser?

Reinstalling helps only if you delete the old profile folder too, because a plain reinstall leaves extensions, permissions and search settings exactly as they were. Try the built in reset option first, since it keeps bookmarks and passwords. If the reset does not hold, a clean profile is faster than hunting any further.