SearchEngines.Net logo — an independent reference on search enginesSearchEngines.NetWho runs which index

Change your default engine

How to remove a search engine hijacker

A hijacked search default is not a setting problem. Something is reapplying it, and until that is gone the dropdown will not hold.

The short answer

If your search engine changes back every time you fix it, the setting is not broken — something installed on the machine is reapplying it, and that something has to go first. Find and remove the mechanism — almost always a browser extension, an administrative policy or a modified program shortcut — then reset the browser, then set the engine you want.

Doing it in that order matters. Resetting the dropdown while the cause is still installed produces the loop that brings most people to a page like this one.

What a browser hijacker actually is

"Hijacker" describes an outcome, not a virus. The software involved is usually ordinary and uses documented browser features exactly as designed — the abuse is in how consent was obtained, not in the technique. Five mechanisms account for nearly all of it, and identifying which one is most of the work.

  • An extension that declares a search provider. Every major browser lets an extension override the default engine, because legitimate engines distribute themselves that way. Once the browser grants it, the settings dropdown is locked to the extension's choice and says so.
  • An administrative policy. Chrome, Edge and Firefox all support enterprise policies that set and lock the default engine so an ordinary user cannot change it. Those policies live in the Windows registry, a macOS configuration profile, or a policy file beside the browser, and nothing stops an installer writing one on a home computer nobody manages.
  • A modified shortcut. On Windows, the desktop or taskbar icon you click is a shortcut with a target command. Appending a URL to that command makes the browser open that page on every launch, with no browser setting involved — which is why a machine can look clean in Settings and still misbehave from one icon.
  • Network-level redirection. A proxy setting, a proxy auto-configuration file, or altered DNS servers can redirect search traffic before it reaches any engine. Rarer, but it survives every browser reset because it is not in the browser.
  • A persistence task. A scheduled task, service or login item that reinstalls the extension after you remove it. This is the reason a fix appears to work until the next restart.

Why anyone bothers: the money

Hijacked search is an advertising-arbitrage business, not vandalism. The redirect chain almost always terminates at a mainstream engine — commonly Microsoft Bing or Yahoo! Search, which itself serves partner-sourced results — because that is where the results and the ads come from. The operator's revenue is the partner fee on traffic handed over, plus whatever the query stream is worth as data. Searches still work, which is the point: a hijack that broke search would be uninstalled immediately.

The practice sits on a spectrum with legitimate distribution rather than apart from it. Some engines ship extensions whose stated function is to change your search provider: Lycos, which has had no crawler of its own since 2001, principally promotes a browser extension that configures Microsoft Bing as the Chrome new-tab search provider (checked August 2026). Ask.com built much of its later traffic on a bundled toolbar and default-search placements, a practice widely reported though thinly documented in primary sources. The difference between distribution and hijacking is consent and reversibility: whether you were asked in terms you understood, and whether you can undo it in the browser's own settings.

Telling a hijack from a change you made

Not every unexpected search engine is malicious. Check these before assuming the worst:

  • The engine changed after you installed something free — a converter, a media downloader, a driver updater, a browser theme — rather than after you opened Settings. This is the single strongest signal.
  • The dropdown is greyed out, or the browser reports that it is managed by an organisation on a computer nobody manages.
  • The search visibly passes through a domain you do not recognise before a mainstream results page appears. Watch the address bar during the redirect.
  • The homepage and new-tab page changed at the same moment. Choosing a search engine never alters either.
  • You cannot name the engine. A search brand with no discoverable operator, no crawler and no privacy policy is a redirect wearing a logo.

Common false alarms worth ruling out: a European Union choice screen offering engines under the Digital Markets Act is a regulatory requirement, not an infection; Microsoft Edge's new-tab box keeping Bing after you changed the address-bar engine is a second setting rather than a hijack; and web results from the Windows taskbar going to Bing is Windows behaving as designed.

Reversing it, in order

Work through these in sequence. Stopping at step four without doing one to three is what causes the loop.

  1. Turn off browser sync first. A signed-in profile can push the hijacked setting back from another device, or push it out to your other devices while you clean this one. Disable sync, clean, then re-enable it.
  2. Remove the extension. Open chrome://extensions, edge://extensions, Add-ons and themes in Firefox, or SafariSettingsExtensions. Remove anything you cannot account for, especially items with permission to read and change data on all sites.
  3. Check for a policy. Open chrome://policy, edge://policy or about:policies. Entries whose names begin DefaultSearchProvider on a personal machine did not come from an employer. On macOS, look for a configuration profile under System SettingsGeneralDevice Management; on iPhone or iPad, under SettingsGeneralVPN & Device Management. Removing the profile removes the policy — safer than editing the Windows registry by hand.
  4. Inspect your shortcuts (Windows). Right-click the browser icon, choose Properties, and read the Target field. It should end with the program name and nothing after it. Delete anything appended after the closing quotation mark, and check desktop, taskbar and Start menu separately — they are different shortcuts.
  5. Uninstall the source. In SettingsAppsInstalled apps on Windows, or the Applications folder on macOS, sort by install date and look at what arrived the day the browser changed.
  6. Check persistence. Windows Task Scheduler, and login items on macOS under System SettingsGeneralLogin Items, are where a reinstaller hides.
  7. Check proxy and DNS. On Windows, network proxy settings; on macOS, the proxies pane of the active network service. Both should normally be off or set by your own network.
  8. Then reset the browser. Chrome and Edge offer a reset that restores the search engine, homepage and startup pages and disables extensions while keeping bookmarks and passwords; Firefox calls its equivalent Refresh Firefox. Delete the unwanted entry from the browser's engine list while you are there, then set the engine you want.

Why it comes back anyway

Three reasons account for nearly every recurrence. Sync restored the value from a device you have not cleaned — phones are the usual culprit. Persistence reinstalled the extension from a scheduled task or login item that the browser reset never touched. Or a policy remains, because a browser reset does not remove administrative policies by design; that is the whole purpose of a policy.

If the setting still reverts after all eight steps, the mechanism is outside the browser: at the operating-system level, on the network, or on another device sharing the profile. A browser still reporting that it is managed after a full reset is clear evidence of a policy in force.

Reducing the odds of a repeat

Nearly all of these arrive as an accepted, if barely-noticed, installation. The practical defences are dull and effective: download software from the developer rather than a download portal, choose the custom or advanced option in installers and read what is pre-ticked, treat any free utility with no obvious business model as being paid for by something, and be sceptical of extensions offering to “enhance” search. Browsers do prompt before an extension takes over search — that prompt is the last checkpoint, and it appears at exactly the moment attention is lowest.

It is also worth periodically opening the browser's search engine list and deleting entries you did not add. Sites register themselves there harmlessly, but an unfamiliar entry is how a returning hijack finds a home.

Then choose a default deliberately

Having removed one, set the default yourself rather than leaving whatever the reset restored. The question worth asking of any engine, including the mainstream one you return to, is whose index it queries and how it makes money. Engines that crawl and rank their own web index are a short list — Google, Microsoft Bing, Brave Search, Mojeek and a handful of others. Everything else is a front end over one of those, which is fine when the operator says so, and is precisely the hijacker's model when it does not. An engine that has to install itself without being asked is telling you what its results are worth.

Frequently asked questions

What is a browser hijacker?

Software that changes browser settings such as the default search engine, homepage or new-tab page without informed consent, and resists being changed back. It is usually not a virus but an ordinary program or extension using documented browser features, installed alongside something else. Its purpose is commercial: routing searches through a chain that earns a partner fee.

Why does my search engine keep changing back after I fix it?

Because the mechanism applying it is still installed. An extension that declares a search provider locks the dropdown, an administrative policy overrides it entirely, and a scheduled task or login item can reinstall a removed extension after a restart. Profile sync can also restore the value from another device you have not cleaned yet.

Will resetting my browser remove a search hijacker?

It removes the symptom, not always the cause. A reset restores the default engine, homepage and startup pages and disables extensions, but it deliberately does not remove administrative policies, modified desktop shortcuts, proxy settings, scheduled tasks or the program that installed them. Clean those first and reset afterwards, or the setting returns.

How do I tell a hijacker from a legitimate search engine change?

Ask whether you initiated it, whether you can name the engine, and whether the change holds. A hijack typically follows installing free software rather than opening Settings, greys out the dropdown, redirects through an unfamiliar domain before reaching a mainstream results page, and changes the homepage at the same time. Genuine engine changes touch nothing but search.

Can a browser extension legally change my default search engine?

Yes. Every major browser supports extensions declaring a search provider, because search engines distribute themselves that way, and the browser prompts for permission first. The difference between distribution and hijacking is whether consent was informed and whether the change can be undone in the browser's own settings without removing anything.

Why do hijacked searches still end up at Bing or Yahoo?

Because the operator has no search engine of its own. The redirect chain terminates at a real index whose partner programme pays for the traffic, and Yahoo itself serves partner-sourced results rather than crawling the web. Searches keep working by design; a redirect that broke search would be removed immediately and earn nothing.

Does a hijacker on my computer affect my phone?

It can, indirectly. If browser sync is enabled on a signed-in profile, a changed default search engine is a synchronised preference and can propagate to other devices on that account. Turning sync off before cleaning, then back on afterwards, prevents a cleaned device from being re-infected with the setting by an uncleaned one.

Is a managed browser notice always a hijacker?

No. Work, school and family-managed devices legitimately show it, and so do some security products. It is a warning sign only on a personal machine that no organisation administers. Opening the browser's policy page shows exactly which policies are active and where they came from, which settles the question without guesswork.

Sources

Top