What to do when adware hijacks your browser's new tab to paid search
Opening Chrome, Edge, or Firefox should bring up your usual new-tab page, but sometimes it loads something else entirely: sponsored links, unfamiliar shopping offers, or a search box that routes every query through an unfamiliar engine. The address bar looks normal, yet the homepage, default search, and new-tab page are no longer yours. This kind of browser tampering, where adware silently replaces the new-tab experience with a paid search portal, has become one of the most common complaints logged with the Australian Cyber Security Centre and ACCC Scamwatch.
For anyone working from a home office in Brisbane or Melbourne, or studying at a university in Perth or Adelaide, a hijacked browser is more than a nuisance. It pushes you toward sponsored listings that may lead to deceptive stores, interferes with ATO myGov logins, and harvests search terms that reveal personal interests. Many users tolerate it for weeks because the symptoms look like a glitch rather than malware. Recognising the pattern early is the fastest route back to a clean browsing experience.
Recognising the patterns of a paid-search hijack
A genuine browser update from Google, Microsoft, or Apple never changes your new-tab layout without asking. When adware takes over, the giveaway is that every fresh tab opens a page branded with an unfamiliar logo, often a "search the web" box sitting on top of a flashy wallpaper and a row of sponsored tiles. The domain in the address bar usually has nothing to do with your usual provider, and searches performed from that box return results loaded with "Ad" markers that ordinary Google or Bing would not surface so prominently.
Other telltale signs include a new toolbar or extension that you do not remember installing, sudden redirects when you type a URL directly, and search suggestions that feel slightly off-key. On Windows machines in particular, programs called "Search Manager," "Web Boost," or "Speed Navigator" frequently appear in the Apps and Features list without your knowledge. On macOS the symptoms are similar, but the rogue extension often hides behind a generic icon and a single-word name like "Search" or "Tab."
How this adware reaches Australian devices
Most paid-search hijackers travel inside the installers of free utilities. PDF readers, video converters, "system optimisers," and even some browser extensions marketed as productivity boosters have been caught bundling this kind of payload. Australian users downloading from international shareware sites, or clicking through pop-up offers while streaming free sports replays, are exposed more often than people who stick to the Mac App Store, Microsoft Store, or well-known Australian software vendors.
A second route is the fake update. A window pops up claiming your Flash Player, Java, or video codec is out of date, and the "update" is actually an installer for adware. This technique circulates heavily on sites offering pirated content, dodgy streaming portals, and some classified ad platforms. Because many Australians rely on NBN connections and mobile tethering rather than always-on ethernet, devices drop in and out of networks more frequently, which can trigger the pop-ups that lead to these bogus downloads.
Quick cleanup steps to try first
Start by opening the extensions page of whichever browser is misbehaving: chrome://extensions in Chrome, about:addons in Firefox, or the equivalent pane in Edge. Remove anything you do not recognise, paying close attention to entries with vague descriptions, no clear publisher, or suspicious "Access your data on all websites" permissions. Once those are gone, visit the browser's search settings and reset the default search engine, homepage, and new-tab URL to Google or Bing, whichever you normally use.
On Windows, open Settings, then Apps, and sort the installed list by install date. Anything that arrived on the same day the hijack began should be uninstalled without hesitation. On a Mac, check the Applications folder and the Login Items under System Settings, removing unfamiliar entries. Clearing the browser's cookies and cached files afterwards prevents the hijacker from simply reasserting itself on the next launch. Users who want a more detailed walkthrough can follow this adware removal walkthrough for step-by-step instructions covering both operating systems.
When the hijack persists after a manual cleanup
Some variants survive a basic uninstall because they have scheduled tasks, registry entries, or helper services that re-create the rogue extension on every reboot. In that case, booting into Safe Mode on Windows or running a clean reinstall of the affected browser is often the next step. A full reset wipes the profile folder, which removes cached policies that lock the new-tab page to the paid-search portal, and forces the browser to behave like a fresh installation.
Running a dedicated anti-malware scan with a reputable tool adds another layer of confidence. Products from established vendors such as Malwarebytes, ESET, or Bitdefender are widely available through Australian retailers and ISPs like Telstra and Optus, and most of them bundle browser-cleanup modules that target exactly this family of threats. Detailed reporting and ongoing protection advice is available through PC Malware Expert, which maintains updated removal playbooks for the most prevalent strains.
Prevention habits and your rights under Australian law
Once the browser is behaving normally again, a few habits will reduce the chance of a repeat infection. Stick to first-party download sources, decline "optional offers" during software installs, and treat any unexpected update prompt with suspicion. Enable click-to-play for plugins and consider running an ad-blocker such as uBlock Origin. Public Wi-Fi at airports, cafes, and libraries in Sydney, Melbourne, and regional centres should always be paired with a reputable VPN, since man-in-the-middle redirects can occasionally push the same paid-search portals onto unsecured sessions.
Australians also have meaningful legal recourse when this kind of software causes harm. The Privacy Act 1988 and the Australian Privacy Principles require any company that collects personal data through deceptive software to handle it transparently, and the Notifiable Data Breaches scheme obliges them to inform affected users when something goes wrong. Complaints about misleading install practices can be lodged with the ACCC, while scams that involve paid-search portals leading to fraudulent stores can be reported through Scamwatch. Combining technical hygiene with these consumer protections gives you both a clean browser and a clear path forward if a hijacker ever returns.
| Approach |
Time required |
Technical skill |
Thoroughness |
Risk of recurrence |
| Manual extension and settings cleanup |
15–30 minutes |
Basic |
Moderate |
Higher if scheduled tasks remain |
| Browser reset or reinstall |
20–40 minutes |
Basic to intermediate |
High for browser-only infections |
Low for browser-only infections |
| Dedicated anti-malware scan |
30–60 minutes |
Basic |
High across the system |
Low when combined with updates |
| Safe Mode boot plus manual removal |
45–90 minutes |
Intermediate |
Very high |
Very low |