How to stop spyware from tracking searches and causing redirects
Unexpected redirects can be a sign that spyware, adware, or a browser hijacker has altered your computer. Instead of reaching Google, Bing, or a familiar shopping site, you may be sent to fake search pages, gambling promotions, tech-support scams, or cloned banking websites. Search terms may also be collected to build a profile of your browsing habits.
This behaviour is more serious than an irritating pop-up. Malicious extensions and background processes can monitor visited pages, inject adverts, change your default search provider, or steal information entered into websites. A compromised browser may also expose passwords and session cookies, especially when the threat includes keylogging or form grabbing.
Australian users should treat suspicious redirects carefully because fake parcel notices, banking alerts, and government-themed scams often imitate local services. Whether the computer is used in a Sydney flat, a Melbourne office, or a regional home relying on an NBN connection, the first priority is to stop interacting with suspicious pages and contain the device.
Recognise the warning signs
A browser hijacker commonly changes the home page, new-tab screen, search engine, or results page without clear permission. You may notice several redirects before reaching a legitimate result, unfamiliar toolbars, a flood of adverts, or warnings claiming that the computer is infected. Search results can contain extra sponsored links designed to send traffic to unsafe domains.
Other symptoms appear outside the browser. The computer may run slowly, use unusual network bandwidth, display unknown notifications, or open programs at startup. A new extension, application, scheduled task, or login item may have appeared after installing free software, a cracked program, or a seemingly harmless browser add-on.
Do not enter passwords, card details, Medicare information, or myGov credentials into a page reached through an unexpected redirect. Close the tab using the browser’s window controls rather than clicking buttons inside the page. If the tab resists closing, disconnect from the internet temporarily and end the browser process through Task Manager on Windows or Force Quit on macOS.
Contain the infected device
Disconnect Wi-Fi or unplug Ethernet if redirects continue, particularly when the computer contains business files or saved passwords. This limits communication with a command-and-control server and prevents the spyware from downloading additional components. A phone or separate, trusted computer can be used to contact a bank, email provider, or workplace administrator.
From a clean device, change the passwords for email, banking, cloud storage, social media, and shopping accounts. Start with the email account because it can be used to reset other credentials. Use unique passwords and enable multifactor authentication. If banking details may have been exposed, contact the bank through its official Australian website or the number printed on a card, rather than a number shown in a pop-up.
Review browser synchronisation as well. A malicious extension or altered setting can spread through a Google, Microsoft, or Apple account to other computers. Remove unfamiliar extensions from the account and sign out active sessions where available. Australian businesses should preserve relevant logs and notify their IT team before wiping a device, while individuals can report scam activity to Scamwatch.
Remove spyware and restore the browser
Begin with installed applications and browser extensions. Uninstall software you do not recognise, especially items added around the time the redirects began. Check startup entries, scheduled tasks, proxy settings, and DNS settings for unexplained changes. On macOS, inspect Login Items, Profiles, Applications, and browser extensions; on Windows, review installed apps, startup programs, and Task Scheduler.
Run a reputable, updated security scanner and allow it to quarantine detected spyware, potentially unwanted programs, and browser hijackers. A second-opinion scan can identify remnants missed by the first tool. If the threat blocks security software or immediately returns, restart Windows in Safe Mode with Networking and scan there. Avoid downloading several unknown “cleaner” programs, since fake removal utilities are themselves common malware.
Mac users dealing with injected adverts or unwanted extensions can follow this Mac adware guide for a more detailed cleanup process. After removing the infection, reset the affected browser’s homepage, search provider, permissions, and notification settings. Only restore bookmarks after checking that they do not contain suspicious extensions or saved redirect links.
Check for stolen information
Spyware that observes search activity may also monitor forms, clipboard content, screenshots, or keystrokes. If a Mac shows signs of keylogging, use this keystroke spyware guide to examine common persistence locations and account risks. Windows users should similarly inspect unknown accessibility tools, remote-control software, and security exclusions.
Look for password-reset emails, unfamiliar sign-ins, new browser sessions, changed forwarding rules, and purchases you do not recognise. Check cloud storage sharing and email filters because attackers may silently forward messages or maintain access after a password change. Revoke unknown app permissions and generate new recovery codes for multifactor authentication.
If personal information was exposed, document dates, affected accounts, screenshots, and transactions. Australian consumers can contact ReportCyber for cybercrime guidance, while suspected scams can be reported to Scamwatch. Organisations covered by the Privacy Act 1988 may also need to assess whether a data breach triggers notification obligations under the Notifiable Data Breaches scheme.
Prevent future search hijacking
Keep Windows, macOS, browsers, extensions, and security tools updated. Install programs from official publishers or reputable Australian retailers, and choose custom installation options when available. Decline bundled browser extensions, “search helpers,” and optional utilities. A download that promises a free movie codec, coupon tool, or urgent driver update deserves particular caution.
Use a standard user account for everyday work, maintain offline or versioned backups, and enable browser protection against dangerous sites. Do not allow every website to send notifications or access location, camera, microphone, and clipboard data. Practical security advice and additional malware-related guidance are available in these security tips.
| Sign or situation |
Likely risk |
Appropriate response |
| Search results change or redirect |
Browser hijacker or adware |
Disconnect if persistent, remove extensions, reset settings, run a scan |
| Unknown login or password-reset email |
Stolen credentials or session cookies |
Change passwords from a clean device, revoke sessions, enable MFA |
| Key presses or form data seem exposed |
Spyware or keylogger |
Stop sensitive activity, scan deeply, review accounts and financial records |
| Pop-up demands payment for removal |
Scareware or technical-support scam |
Do not call or pay; close the page and use trusted security software |
| Infection returns after removal |
Persistence mechanism or synchronised extension |
Check startup items, profiles, scheduled tasks, and browser sync; consider professional IT assistance |
After cleanup, monitor accounts and browser behaviour for several days. Persistent redirects, repeated reinfection, or signs of unauthorised access may justify backing up essential documents and performing a trusted operating-system reset. Any backup should be scanned before it is restored, and saved passwords should be treated as exposed until replaced.