Default Search virus – a browser hijacker that might take over your Google Chrome or another web browser

Default Search is a potentially unwanted application[1] that typically arrives on the system unexpectedly and changes the settings of the installed web browser. Besides setting homepage address to find.defaultsearch.info and appending a customized search engine, the virus also appends the “Managed by your organization” status to Google Chrome, Mozilla Firefox, Safari, or another web browser.
Due to browser hijacking practice, users are forced to use a customized search engine, which pulls all search results from Yahoo and injects sponsored links into them. In other words, if you are using Default Search as your main provider, you will be shown ads at the top of search results, whether you like it or not. It is also important to note that the PUP secretly gathers information about users' online habits and shares it with third-parties for more profits.
| Name | Default Search |
|---|---|
| Type | Browser hijacker, potentially unwanted program |
| IP address | 195.154.42.103 |
| Distribution | Software bundles, deceptive ads, fake updates, third party websites |
| Symptoms | Unknown extension or application is installed on the system; homepage and new tab address are set to find.defaultsearch.info; a customized search engine is applied; search results are filled with sponsored links; overall increased amount of advertisement |
| Risks | Installation of other potentially unwanted programs, information disclosure to unknown parties, financial losses |
| Removal | You can uninstall potentially unwanted programs by following the manual guide below or by scanning the computer with powerful anti-malware |
| Optional steps | Computer infections can cause significant damage to system files or disrupt default or user-set settings. To revert these changes and remediate the OS, perform a full system scan with FortectIntego repair software |
As mentioned in the introduction, the Default Search virus typically shows up on the system uninvited – users find it one day when they open their web browser. While it is widely believed that such apps simply install themselves, it is not true at all, and it is a consequence of users' actions.
Most commonly, software bundling is at fault – a deceptive marketing technique that allows offering optional components within a single installer. Nonetheless, the Default Search browser hijacker can also be installed through other means, as some PUPs are delivered through legitimate sources (such as Google Chrome web store), or fake update prompts for Flash Player or other popular software.
Instead of seeing the regular Google.com or another provider that they have chosen, users will quickly see that all the searchers are being redirected to Yahoo. While it is a legitimate search provider, and that is precisely where the results are pulled from, it has nothing to do with the Default Search hijack. The hijacker authors simply participate in the company's affiliate program, where almost anyone can enroll. If you prefer Yahoo, simply set it as your default engine, so you can avoid unwanted ads being shown to you constantly.
It is also important to note that the Default Search virus gathers various info about users who have it installed. For example, the following data might be collected, shared, or sold:
- IP address
- Internet Service Provider (ISP)
- Unique device identifiers
- Search terms
- Browsing history
- Links clicked, etc.
The app belongs to a broader family of potentially unwanted programs that set the “Managed by your organization” setting on the web browser, preventing an easy Default Search removal. The feature, which is also used by Custom Search, Comet Search, and Mazy Search, is typically used by corporations to set restrictions to certain workstations and is not meant to be used by browser hijackers. With the help of this setting, developers can receive profits from pay-per-click and other schemes as long as the app is installed on the system.

This creates a rather frustrating experience for end-users, however, as not only they have to deal with altered browser settings, inability to find relevant information, and background data tracking, but are also unable to remove Default Search virus easily.
Since the PUP typically comes as an extension, its termination can be performed when it is removed from the web browser. For more information on that, please check the bottom section of the article. Keep in mind that if you found the PUP on your machine seemingly out of nowhere, there could be other threats that are invisible to you. Thus, you should scan your computer with anti-malware (such as SpyHunterCombo Cleaner or MalwarebytesMalwarebytes) and then repair virus damage with FortectIntego.
An easy way to prevent PUP installation
As already explained, potentially unwanted programs arrive on the system seemingly out of nowhere. Stealthy distribution mechanics are very common among PUPs – that is precisely one of the reasons for their name. Most commonly, such apps provide very little to no benefit for end-users and sometimes might even posses malicious qualities (for example, scareware[2] apps attempt to intimidate users by showing fake scan results about the system's health to make them purchase the license, which seemingly then removes all the bogus problems).
Thus, it is always a good idea to avoid browser hijackers, adware, and other suspicious programs. Here are some tips from experts:[3]
- Always download apps and their updates from official sources;
- When dealing with third-party websites, be aware that software bundling is extremely common;
- Never download anything from sites that offer pirated software or cracks, as you could infect your machine with threats like Mmpa ransomware;
- Research the app you are about to install – read forum posts, user reviews, etc.;
- Always pick Advanced/Custom settings during the installation instead of Recommended/Quick ones;
- Install powerful security software that would detect and warn you about PUPs and malware.

Wondering how to remove Default Search virus? Follow these steps
Many users start searching for Default Search removal instructions, as they cannot do so in a regular way. Since the app comes as an extension, all you would have to do usually would access the settings of your web browser and delete the extension that hijacked it. Unfortunately, the setting to delete the add-on is usually grayed out. Thus, the first thing you should do is reset your web browser – we explain how below.
If you are unsuccessful, you should go to the following location on your machine and delete the “Google” folder:
C:\Users\[username]\AppData\Local
This should allow you to remove Default Search once and for all. If still no luck, however, you should employ SpyHunterCombo Cleaner, MalwarebytesMalwarebytes, or another anti-malware that would do the job for you. In case your machine is having issues after all the malware and PUPs are deleted, you can attempt to fix virus damage with FortectIntego.
Uninstall from Windows
Uninstall from Windows 10/8:
- Type Control Panel into the Windows search box and open the result.
- Under Programs, select Uninstall a program.

Uninstall from Windows 7/XP:
- Click on Windows Start > Control Panel (Windows XP users should click on Add/Remove Programs).
- In Control Panel, select Programs > Uninstall a program.

Remove the unwanted program:
- In the Programs and Features window, look for any recently installed suspicious entries, select them, and click Uninstall.
- If User Account Control appears, click Yes to confirm, then complete the removal.

Delete from macOS
Remove the unwanted application:
- From the menu bar, select Go > Applications.
- In the Applications folder, look for any suspicious entries, then drag them to Trash (or right-click and pick Move to Trash).

Delete leftover files and folders:
- Select Go > Go to Folder.
- Enter /Library/Application Support and remove any suspicious folders related to the unwanted program.
- Repeat the same check in the /Library/LaunchAgents and /Library/LaunchDaemons folders, deleting any suspicious entries.

- Finally, empty the Trash to permanently remove the leftovers.
Reset Internet Explorer
Remove dangerous add-ons:
- Open Internet Explorer, click on the Gear icon (IE menu) on the top-right corner of the browser
- Pick Manage Add-ons.
- You will see a Manage Add-ons window. Here, look for suspicious plugins. Click on these entries and select Disable.

Change your homepage if it was altered:
- Open IE and click on the Gear icon.
- Select Internet Options.
- In the General tab, delete the Home page address and replace it by your preferred one (for example, Google.com).
- Click Apply and then select OK.

Delete temporary files:
- Press on the Gear icon and select Internet Options.
- Under Browsing history, click Delete...
- Select relevant fields and press Delete.

Reset Internet Explorer:
- Click on Gear icon > Internet options and select Advanced tab.
- Select Reset.
- In the new window, check Delete personal settings and select Reset.

Remove from Microsoft Edge
Delete unwanted extensions from MS Edge:
- Select Menu (three horizontal dots at the top-right of the browser window) and pick Extensions.
- From the list, pick the extension and click on the Gear icon.
- Click Remove.

Clear cookies and other browser data:
- Click on the Menu (three horizontal dots at the top-right of the browser window) and select Settings > Privacy, search, and services..
- Under Clear browsing data, pick Choose what to clear.
- Select Cookies and other site data and Cached images and files. (apart from passwords, although you might want to include Media licenses as well, if applicable) and click on Clear.

Restore new tab and homepage settings:
- Click the menu icon and choose Settings.
- Then find On startup section.
- Click Remove next to any suspicious startup page.
Reset MS Edge if the above steps did not work:
- Press on Ctrl + Shift + Esc to open Task Manager.
- Click on More details arrow at the bottom of the window.
- Select Details tab.
- Now scroll down and locate every entry with Microsoft Edge name in it. Right-click on each of them and select End Task to stop MS Edge from running.

Instructions for Chromium-based Edge
Delete extensions from MS Edge (Chromium):
- Open Edge and click select Settings > Extensions.
- Delete unwanted extensions by clicking Remove.

Clear cache and site data:
- Click on Menu and go to Settings.
- Select Privacy, search and services.
- Under Clear browsing data, pick Choose what to clear.
- Under Time range, pick All time.
- Select Clear now.

Reset Chromium-based MS Edge:
- Click on Menu and select Settings.
- On the left side, pick Reset settings.
- Select Restore settings to their default values.
- Confirm with Reset.
- This will disable extensions and reset startup pages but will not delete bookmarks, saved passwords, or browsing history.

Remove from Mozilla Firefox (FF)
Remove dangerous extensions:
- Open Mozilla Firefox browser and click on the Menu (three horizontal lines at the top-right of the window).
- Select Add-ons.
- In here, select the unwanted extension and click Remove.

Reset the homepage:
- Click three horizontal lines at the top right corner to open the menu.
- Choose Settings.
- Under Home, set your preferred homepage and new tab settings.
Clear cookies and site data:
- Click Menu and pick Settings.
- Go to Privacy & Security section.
- Scroll down to locate Cookies and Site Data.
- Click on Clear Data...
- Select Cookies and Site Data and Temporary cached files and pages, then click Clear.

Reset Mozilla Firefox
If clearing the browser as explained above did not help, reset Mozilla Firefox:
- Open Mozilla Firefox browser and click the Menu.
- Go to Help and then choose Troubleshooting Information.

- Under Give Firefox a tune up section, click on Refresh Firefox...
- Once the pop-up shows up, confirm the action by pressing on Refresh Firefox.

Remove from Google Chrome
Delete malicious extensions from Google Chrome:
- Open Google Chrome, click on the Menu (three vertical dots at the top-right corner) and select More tools > Extensions.
- In the newly opened window, you will see all the installed extensions. Uninstall all suspicious extensions related to the unwanted program by clicking Remove.

Clear cache and web data from Chrome:
- Click on Menu and pick Settings.
- Under Privacy and security, select Clear browsing data.
- Select Browsing history, Cookies and other site data, as well as Cached images and files.
- Click Clear data.

Change your homepage:
- Click menu and choose Settings.
- Look for a suspicious site in the On startup section.
- Click on Open a specific or set of pages and click on three dots to find the Remove option.
Reset Google Chrome:
If the previous methods did not help you, reset Google Chrome to eliminate all the unwanted components:
- Click on Menu and select Settings.
- In the Settings, scroll down and click Advanced.
- Scroll down and locate Reset and clean up section.
- Now click Restore settings to their original defaults.
- Confirm with Reset settings.

Delete from Safari
Remove dangerous extensions:
- Open Safari, click Safari in the menu at the top-left of the screen, and select Preferences.
- Go to the Extensions tab, look for any suspicious entries, and click Uninstall to remove them.

Clear history and website data:
- Click Safari in the menu and pick Clear History.
- Set Clear to all history and confirm with Clear History.

Reset Safari:
- Click Safari in the menu and select Preferences > Advanced.
- Enable Show Develop menu in menu bar.
- From the menu bar, click Develop and select Empty Caches.

Did this guide help?
Be the first to comment