Skip to content
  • Active
  • Severity: Medium
  • Browser Hijackers
  • Windows, Mac
  • Verified · Apr 2021

How to remove Google WebHP virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Olivia Morelli · Ransomware analyst

WebHP – a term used to describe a suspicious Chrome redirect activity

WebHP virus is a term that many users adapted after they saw a suspicious behavior when using their Google Chrome web browser. According to users, each time when they load their homepage or search for something online, they are instead redirected[1] to google.com/webhp. In most cases, the activity is only prevalent when searching through the omnibar.

This activity is difficult for many users to explain, as they seek to find the root causes of such redirects. While the term “WebHP virus” sounds dangerous, in reality, it is not likely to be a virus. First of all, suspicious homepage and new tab address changes can be related to a browser hijacker – a type of a potentially unwanted program that modifies web browser settings to insert ads into users' searchers.

This is especially true if any attempt to search online using the assigned engine results in the list filled with advertisements, redirects, banners, and in-text links the lead to suspicious material online with the purpose of rerouting to sponsored pages. Experts report that computer users that experience continuous redirects to http://google.com/webhp should also check their computers for the Conduit virus. These are the computer intruders that focus on forcing users to visit low-quality websites, possible advertising platforms, so the revenue can get easily made from all the page visits and clicks on pop-ups ads. 

However, this activity also might be related to internal Google processes, namely ones related to how the company handles search results and implements security certificates, known as SSL. Therefore, users might also encounter similar behavior with https //www.google.com/ gws_rd=ssl redirect.

Google also uses different scripts that are based on users' location. Therefore, some users might also encounter https //www.google.es/ gws_rd=ssl if they are coming from Spain, for example.

Name Google WebHP virus
Type Browser hijacker
Issues The program replaces the homepage, search engine, new tab preferences, so the content can be controlled and users exposed to shady advertising pages
Distribution Freeware installations lead to such infiltrations of questionable programs because users tend to choose recommended or quick options instead of Advanced or Custom ones
Elimination Google WebHP virus elimination is possible with anti-malware tools and similar programs that can check the machine for any suspicious applications and files. All traces of the potentially unwanted program get deleted this way
Repair There are parts of the system that can get damaged by this program directly. It ads files or removes them, affects processes and system functions, so run FortectIntego to find such altered parts and fix possible damage automatically

HTTP redirects are usually considered suspicious, as they might indicate an infection of a browser hijacker or another potentially unwanted program. These apps are typically installed unintentionally by users due to a well-known, deceptive distribution technique known as software bundling. Alternatively, they might also be tricked by misleading advertisements, or fake update prompts. However, some might also install PUPs on their systems when believing that it could be a good addition to web browsing activities.

The so-called Chrome WebHP virus infiltrates the computer system silently and adds a hazardous browser extension[2] to an affected web browser. It can also change the browser’s homepage to google.com/webhp or google.co.uk/webhp.

Google WebHP can also display misleading ads pushing users into installing fake updates and useless programs. Promotional ads can have direct download scripts and lead to other related intruder installations like Searchou. This redirect issue occurs on Firefox, Chrome, Safari browsers, and can lead to serious problems with performance, speed, security, or privacy issues. 

These websites look exactly like the real Google search engine. Unfortunately, due to its resemblance to the real Google search, it can deceive the computer user and trick him/her into using it, thinking that it is a safe search engine.

Unfortunately, the fake search engine that is provided by this virus is dangerous to use because it can trigger redirects to various third-party websites, which can be malicious or provide misleading content. Please, do not use this search engine if you see the webhp appended to the URL.

The hijacker can compromise your search settings despite the country you live in, so for example, French PC users might start experiencing redirects to google.fr/webhp.[3] In this case, make sure you initiate Google WebHP redirect removal. For that, you can either uninstall all suspicious third-party software and reset your web browsers or scan your computer with FortectIntego for the further function repair.

Google WEBHP

Reportedly, this hijacker slithers into the computer system along with the infamous Conduit Toolbar, so make sure you remove it as well. Beware that sometimes the hijacker doesn't even change the homepage address in the browser, causing additional problems while trying to eliminate it. In this case, check Chrome's Omnibox which should deliver you altered search results each time you attempt to search via URL box.

If you cannot remember installing Conduit or similar third-party software, you need to remove it together with other suspicious files from your computer. This should fix the issue with the Google WebHP virus. The best way to do so would be running a scan with anti-malware tools like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes.

Potentially unwanted programs might appear on your system without permission

The most of redirect viruses manage to enter computer systems in a rather subtle way. They typically pretend to be safe-to-use programs and even present themselves as “recommended” software. However, they do not reveal themselves in a direct way. They spread along with other free applications and get installed in one software bundle. 

As you have understood, the browser hijacker is distributed in software packs, so in order to avoid installing it, you need to decompose such software packs. When you launch the installer of software you have just downloaded, do not rush!

Please read absolutely all information the installer provides, including Terms of Use/Privacy Policy documents. After that, proceed to the next step. Once you reach installation “settings,” choose either Advanced or Custom option (NOT Default/Standard ones!). Then simply deselect all suspicious-looking components.

Google WebHP removal instructions

To remove Google WebHP, you need to carefully review the list of programs that were recently installed on your computer, and also all browser extensions that were added without your knowledge. You have to delete all programs and extensions that you cannot remember installing.

WebHP virus can be related to potentially unwanted programs and you should not ignore its existence because it can pose a threat to your computer. The sooner you run the anti-malware program the better because you can clear threats properly from the machine and avoid further damage.

Please follow the Google Webhp removal instructions provided under this article and you will easily banish the malware from your computer. No matter what, we strongly recommend you to scan your computer with our recommended computer security software to see if there are no other dangerous programs silently diminishing your computer’s performance or posing a threat to it.

It is also important to note that you will most likely be unable to remove the so-called https //www.google.com/ gws_rd=ssl virus from your system, as it is not related to malicious activity but used by Google itself.

Uninstall from Windows

Uninstall from Windows 10/8:

  1. Type Control Panel into the Windows search box and open the result.
  2. Under Programs, select Uninstall a program.Uninstall from Windows 10/8

Uninstall from Windows 7/XP:

  1. Click on Windows Start > Control Panel (Windows XP users should click on Add/Remove Programs).
  2. In Control Panel, select Programs > Uninstall a program.Uninstall from Windows 7/XP

Remove the unwanted program:

  1. In the Programs and Features window, look for any recently installed suspicious entries, select them, and click Uninstall.
  2. If User Account Control appears, click Yes to confirm, then complete the removal.Uninstall the unwanted program from Windows

Delete from macOS

Remove the unwanted application:

  1. From the menu bar, select Go > Applications.
  2. In the Applications folder, look for any suspicious entries, then drag them to Trash (or right-click and pick Move to Trash).Uninstall from Mac

Delete leftover files and folders:

  1. Select Go > Go to Folder.
  2. Enter /Library/Application Support and remove any suspicious folders related to the unwanted program.
  3. Repeat the same check in the /Library/LaunchAgents and /Library/LaunchDaemons folders, deleting any suspicious entries.Delete leftover files from Mac
  4. Finally, empty the Trash to permanently remove the leftovers.

Reset Internet Explorer

Remove dangerous add-ons:

  1. Open Internet Explorer, click on the Gear icon (IE menu) on the top-right corner of the browser
  2. Pick Manage Add-ons.
  3. You will see a Manage Add-ons window. Here, look for suspicious plugins. Click on these entries and select Disable.Remove add-ons from Internet Explorer

Change your homepage if it was altered:

  1. Open IE and click on the Gear icon.
  2. Select Internet Options.
  3. In the General tab, delete the Home page address and replace it by your preferred one (for example, Google.com).
  4. Click Apply and then select OK.Reset IE homepage

Delete temporary files:

  1. Press on the Gear icon and select Internet Options.
  2. Under Browsing history, click Delete...
  3. Select relevant fields and press Delete.Clear temporary files from Internet Explorer

Reset Internet Explorer:

  1. Click on Gear icon > Internet options and select Advanced tab.
  2. Select Reset.
  3. In the new window, check Delete personal settings and select Reset.Reset Internet Explorer

Remove from Microsoft Edge

Delete unwanted extensions from MS Edge:

  1. Select Menu (three horizontal dots at the top-right of the browser window) and pick Extensions.
  2. From the list, pick the extension and click on the Gear icon.
  3. Click Remove.Remove extensions from Edge

Clear cookies and other browser data:

  1. Click on the Menu (three horizontal dots at the top-right of the browser window) and select Settings > Privacy, search, and services..
  2. Under Clear browsing data, pick Choose what to clear.
  3. Select Cookies and other site data and Cached images and files. (apart from passwords, although you might want to include Media licenses as well, if applicable) and click on Clear.Clear Edge browsing data

Restore new tab and homepage settings:

  1. Click the menu icon and choose Settings.
  2. Then find On startup section.
  3. Click Remove next to any suspicious startup page.

Reset MS Edge if the above steps did not work:

  1. Press on Ctrl + Shift + Esc to open Task Manager.
  2. Click on More details arrow at the bottom of the window.
  3. Select Details tab.
  4. Now scroll down and locate every entry with Microsoft Edge name in it. Right-click on each of them and select End Task to stop MS Edge from running.Reset MS Edge

Instructions for Chromium-based Edge

Delete extensions from MS Edge (Chromium):

  1. Open Edge and click select Settings > Extensions.
  2. Delete unwanted extensions by clicking Remove.Remove extensions from Chromium Edge

Clear cache and site data:

  1. Click on Menu and go to Settings.
  2. Select Privacy, search and services.
  3. Under Clear browsing data, pick Choose what to clear.
  4. Under Time range, pick All time.
  5. Select Clear now.Clear browser data from Chroum Edge

Reset Chromium-based MS Edge:

  1. Click on Menu and select Settings.
  2. On the left side, pick Reset settings.
  3. Select Restore settings to their default values.
  4. Confirm with Reset.
  5. This will disable extensions and reset startup pages but will not delete bookmarks, saved passwords, or browsing history.Reset Chromium Edge

Remove from Mozilla Firefox (FF)

Remove dangerous extensions:

  1. Open Mozilla Firefox browser and click on the Menu (three horizontal lines at the top-right of the window).
  2. Select Add-ons.
  3. In here, select the unwanted extension and click Remove.Remove extensions from Firefox

Reset the homepage:

  1. Click three horizontal lines at the top right corner to open the menu.
  2. Choose Settings.
  3. Under Home, set your preferred homepage and new tab settings.

Clear cookies and site data:

  1. Click Menu and pick Settings.
  2. Go to Privacy & Security section.
  3. Scroll down to locate Cookies and Site Data.
  4. Click on Clear Data...
  5. Select Cookies and Site Data and Temporary cached files and pages, then click Clear.Clear cookies and site data from Firefox

Reset Mozilla Firefox

If clearing the browser as explained above did not help, reset Mozilla Firefox:

  1. Open Mozilla Firefox browser and click the Menu.
  2. Go to Help and then choose Troubleshooting Information.Reset Firefox 1
  3. Under Give Firefox a tune up section, click on Refresh Firefox...
  4. Once the pop-up shows up, confirm the action by pressing on Refresh Firefox.Reset Firefox 2

Remove from Google Chrome

Delete malicious extensions from Google Chrome:

  1. Open Google Chrome, click on the Menu (three vertical dots at the top-right corner) and select More tools > Extensions.
  2. In the newly opened window, you will see all the installed extensions. Uninstall all suspicious extensions related to the unwanted program by clicking Remove.Remove extensions from Chrome

Clear cache and web data from Chrome:

  1. Click on Menu and pick Settings.
  2. Under Privacy and security, select Clear browsing data.
  3. Select Browsing history, Cookies and other site data, as well as Cached images and files.
  4. Click Clear data.Clear cache and web data from Chrome

Change your homepage:

  1. Click menu and choose Settings.
  2. Look for a suspicious site in the On startup section.
  3. Click on Open a specific or set of pages and click on three dots to find the Remove option.

Reset Google Chrome:

If the previous methods did not help you, reset Google Chrome to eliminate all the unwanted components:

  1. Click on Menu and select Settings.
  2. In the Settings, scroll down and click Advanced.
  3. Scroll down and locate Reset and clean up section.
  4. Now click Restore settings to their original defaults.
  5. Confirm with Reset settings.Reset Chrome 2

Delete from Safari

Remove dangerous extensions:

  1. Open Safari, click Safari in the menu at the top-left of the screen, and select Preferences.
  2. Go to the Extensions tab, look for any suspicious entries, and click Uninstall to remove them.Remove extensions from Safari

Clear history and website data:

  1. Click Safari in the menu and pick Clear History.
  2. Set Clear to all history and confirm with Clear History.Clear history from Safari

Reset Safari:

  1. Click Safari in the menu and select Preferences > Advanced.
  2. Enable Show Develop menu in menu bar.
  3. From the menu bar, click Develop and select Empty Caches.Reset Safari

Did this guide help?

3 comments

  1. Leonido

    never realized that it was fake search - thanks for informing me!

  2. Alexandr1985

    Just detected this on my computer, too. Im not wasting my time, gotta get some protection. Hopefully, SpyHunter will meet my expectations.

  3. Dana

    my kids surf through suspicious gaming websites and always install some PUPs! I am so annoyed... This is not the first time, I am tired. Which anti-spyware is the best? Im using Windows

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.