Cleaning a browser hijacker that changes your browser language
A growing number of people in Sydney, Melbourne, and other Australian cities are reporting that their Chrome or Edge browser suddenly displays everything in Russian, Chinese, or Arabic after a single careless click. The change often comes bundled with a new default search engine, unfamiliar homepage, and toolbars that nobody installed. These are classic signs of a browser hijacker, a category of malware that rewrites browser preferences to push ads, harvest data, or steer users toward shady sites. Travellers returning to Brisbane from overseas trips frequently encounter the problem because public computers in hotels and airport lounges are common infection points.
The good news is that cleaning a browser hijacker that changes browser language settings does not require reinstalling the operating system. A methodical approach that combines manual cleanup, reputable antivirus scanning, and a few prevention habits is enough in most cases. The walkthrough below covers Windows 10 and Windows 11, plus macOS Ventura and Sonoma, and works for the four browsers Australians rely on most: Chrome, Edge, Firefox, and Safari.
Recognising the signs of a language-switching hijacker
The first clue is usually visual. Menus, error messages, and Google results suddenly appear in a language the user never selected. Some hijackers target Australian English speakers specifically by forcing locale codes such as "ru-RU" or "zh-CN" to disrupt web searches and force redirect chains through foreign ad networks.
Other indicators include a new default search engine, unfamiliar toolbar buttons, and homepage changes that survive a normal browser restart. If clicking the browser shortcut on the desktop triggers an unexpected URL or opens a second tab pointing to a coupon site, that is another red flag. Users on Telstra or Optus home networks sometimes also notice DNS-level redirects that point genuine addresses toward dodgy pages, although this usually points to a deeper infection than a simple hijacker.
First response steps before deep cleaning
Before touching any settings, disconnect from the internet. This stops the hijacker from phoning home, downloading more payloads, or updating its registry entries. Open Task Manager (Ctrl+Shift+Esc on Windows) or Activity Monitor on Mac and end any process that looks unfamiliar, especially ones running from temporary folders or AppData.
Next, gather the cleanup targets. The comparison below shows where each browser keeps its preferences on Windows and Mac, which is useful when checking for leftover files after the visible cleanup is done.
| Browser |
Reset path in menu |
Profile folder on Windows |
Profile folder on macOS |
| Chrome |
Settings → Reset → Restore settings |
%LOCALAPPDATA%\Google\Chrome\User Data |
~/Library/Application Support/Google/Chrome |
| Edge |
Settings → Reset → Restore settings |
%LOCALAPPDATA%\Microsoft\Edge\User Data |
~/Library/Application Support/Microsoft Edge |
| Firefox |
Help → More Troubleshooting → Refresh |
%APPDATA%\Mozilla\Firefox\Profiles |
~/Library/Application Support/Firefox/Profiles |
| Safari |
Develop → Empty Caches, then reset |
n/a (iCloud sync instead) |
~/Library/Safari |
If the infection appears more advanced, such as random pop-ups persisting after a browser reset, follow the broader workflow on the PC Malware Expert homepage for layered malware removal guidance.
Removing suspicious extensions and add-ons
Extensions are the easiest way for a hijacker to maintain persistence, and they are often the only payload required to flip browser language settings. In Chrome, navigate to chrome://extensions, switch on Developer mode, and read every entry carefully. Anything installed around the time the language changed is a prime suspect, particularly tools with names such as "Save Translator," "Coupon Finder AU," or generic alphanumeric strings.
Edge users follow the same path at edge://extensions, and Firefox users go to about:addons. On Safari, open Safari → Settings → Extensions and disable anything you did not install yourself. Public Wi-Fi at cafes in Surry Hills, Fitzroy, or Fremantle is a common vector, so disable extensions immediately if the problem appeared after browsing from a shared hotspot.
Resetting browser settings and clearing shortcuts
After pruning extensions, use the built-in reset feature for the affected browser. In Chrome and Edge, choose "Restore settings to their original defaults." This rolls back the homepage, default search engine, and pinned tabs. In Safari, clear history, website data, and caches from the Privacy tab, then quit and reopen the browser.
Browser shortcuts deserve special attention because some hijackers edit the target line of the desktop shortcut to relaunch the browser with a malicious URL parameter. Right-click the shortcut, choose Properties on Windows or Get Info on Mac, and confirm the target ends with chrome.exe" or the equivalent browser executable, with no extra arguments. If you find something like chrome.exe https://some-sketchy-site.com, delete the shortcut and create a fresh one from the Start menu or Applications folder.
Running a full malware scan
Manual cleanup handles the visible symptoms, but a dedicated scanner catches hidden components. Run a full system scan with a reputable tool such as Malwarebytes, ESET Online Scanner, or Bitdefender. Make sure definitions are fully updated before scanning, because hijackers that modify locale settings often bundle with trojans that quietly download extra payloads.
For systems that show signs of more aggressive infections, such as email-borne worms spreading through Outlook or Mac Mail, work through a dedicated worm removal walkthrough to cover the file-replication and registry keys that generic tools may miss. The worm cleanup guide covers those scenarios in detail.
Preventing future hijacker infections
A clean system stays clean with a few steady habits. Keep your browser and operating system updated, because most hijackers exploit known vulnerabilities that patches already address. Avoid installing free PDF converters, video downloaders, and "system optimiser" tools, which are the most common carriers of language-flipping hijackers in Australia. When downloading software, prefer the publisher's official site over third-party download portals.
Consider switching to a reputable DNS service such as Cloudflare 1.1.1.1 or Quad9, which block known malicious domains at the resolver level. For Australian businesses and remote workers, the Australian Cyber Security Centre publishes updated alerts on active campaigns, including browser hijacker waves that target .au domains. Run a quick browser extension audit once a month; a five-minute review beats a multi-hour cleanup every time.