Erbi90s.click is a browser hijacker and adware platform that forcibly redirects users through deceptive advertising networks, modifying browser settings without consent and exposing systems to potentially malicious content. This unwanted software typically arrives bundled with free downloads or disguised as legitimate browser extensions, then proceeds to manipulate search results, inject intrusive advertisements, and track browsing activity for monetization purposes. While not technically classified as high-severity malware like ransomware or banking trojans, Erbi90s.click creates significant privacy risks and degrades system performance through aggressive advertising behavior.
The hijacker operates by modifying default search engines, homepage settings, and new tab configurations across Chrome, Firefox, Edge, and other browsers. Users frequently report being redirected through multiple intermediate domains before landing on sponsored search pages or questionable advertising networks. Beyond the immediate annoyance of unwanted redirects, the real danger lies in exposure to potentially unsafe third-party sites that may host exploit kits, phishing pages, or additional malware payloads.
Threat Profile
| Attribute | Details |
|---|---|
| Threat Classification | Browser Hijacker / Adware / Potentially Unwanted Program (PUP) |
| Family | Generic redirect/clickfraud family; behavior consistent with adware-as-a-service platforms |
| Primary Platforms | Windows 7/8/10/11; macOS 10.12+; targets Chrome, Firefox, Edge, Safari browsers |
| Distribution Methods | Software bundling, fake update prompts, deceptive browser extensions, freeware installers |
| Persistence Mechanisms | Browser extension installations, scheduled tasks, registry modifications for homepage/search defaults, Start Menu entries |
| Primary Capabilities | Browser settings modification, search query redirection, ad injection, browsing history collection, cookie tracking |
| Typical Artifacts | Browser extensions with random names, modified browser shortcuts with appended URLs, entries in browser policies folder |
| Network Behavior | Frequent HTTP requests to erbi90s.click and affiliated redirect domains; connections to advertising networks and tracking services |
| Data Theft Risk | Moderate — primarily collects browsing history, search queries, clicked links, and potentially form data |
| Monetization Model | Pay-per-click advertising revenue, affiliate commission from promoted software, data brokerage to advertising networks |
| Removal Difficulty | Moderate — requires manual browser cleanup and extension removal; may reinstall if all components not eliminated |
| Associated Domains | erbi90s.click and numerous rotating redirect domains; changes frequently to evade blocklists |
How It Spreads
Erbi90s.click relies heavily on deceptive distribution tactics that exploit user inattention during software installations. The most common infection vector is software bundling, where the hijacker components hide within the installation packages of legitimate free software. Download sites that offer "accelerated downloaders" or custom installers are particularly notorious for this practice. Users who rush through installation wizards using the "Express" or "Recommended" options unknowingly grant permission for multiple bundled programs, including browser hijackers like Erbi90s.click.
Fake browser update prompts represent another significant distribution method. Users visiting compromised or malicious websites encounter convincing pop-ups claiming their browser, Flash Player, or video codec requires an urgent update. Clicking "Update Now" downloads an installer that deploys the hijacker alongside or instead of any legitimate software. These fake prompts have become increasingly sophisticated, mimicking official browser styling and using convincing technical language to create urgency.
Additional distribution vectors include:
- Malicious browser extensions — Disguised as productivity tools, shopping helpers, or video downloaders in official web stores or third-party sites
- Email attachments and links — Phishing campaigns directing users to download "required security updates" or "document viewers"
- Torrent and peer-to-peer networks — Cracked software, keygens, and pirated content frequently bundled with adware families
- Compromised websites — Drive-by downloads triggered when visiting sites with exploitable vulnerabilities or malicious advertising (malvertising)
- Social engineering on social media — Posts promising free gifts, celebrity news, or shocking videos that redirect through hijacker installation pages
- Tech support scam follow-up — Victims of previous scams may have hijackers installed during fraudulent "remote assistance" sessions
What It Does On Your Machine
Once installed, Erbi90s.click immediately targets your browser configuration files to establish persistent control over your web experience. The hijacker modifies your homepage, default search engine, and new tab page settings to redirect through its own domains before eventually landing on affiliated search engines or advertising portals. This redirection chain serves multiple purposes: it generates click-through revenue for the operators, obscures the true destination to avoid browser security warnings, and makes manual cleanup more difficult by creating multiple layers of configuration changes.
The most disruptive symptom users notice is the constant stream of unwanted advertisements injected into legitimate websites. Erbi90s.click employs various ad-injection techniques including pop-unders (ads that open behind your browser window), in-text advertising (double-underlined keywords that trigger pop-ups on hover), banner insertions on pages that normally don't display ads, and interstitial pages that appear between legitimate page loads. These advertisements significantly degrade browsing performance, consume bandwidth, and frequently promote questionable products including fake system optimizers, dubious browser extensions, and potentially unwanted programs.
Behind the scenes, the hijacker actively monitors and collects your browsing behavior. This includes URLs visited, search queries entered, links clicked, time spent on pages, and in some variants, form data like email addresses entered into web forms. This information feeds into advertising profiles sold to data brokers and used to target you with increasingly specific promotional content. While the collected data is ostensibly "anonymized," the aggregation of browsing history creates detailed profiles that can often be de-anonymized through correlation with other data sources.
Browser performance degradation becomes noticeable as Erbi90s.click consumes system resources maintaining its redirection infrastructure and communication with advertising networks. You may experience slower page loading, increased memory usage, browser freezing or crashing, and excessive disk activity as the hijacker writes tracking data to local storage. The constant network requests to advertising servers also drain laptop batteries faster and consume mobile data plans for infected portable devices.
Manual Removal — Step by Step
Disconnect From the Internet
Unplug your Ethernet cable or disable Wi-Fi to prevent the hijacker from downloading additional components or sending collected data to remote servers. This also stops the constant ad-serving requests that make troubleshooting more difficult. Leave the connection disabled throughout the removal process until you've verified the system is clean.
Uninstall Suspicious Programs
Open Settings > Apps > Apps & features (Windows 11) or Control Panel > Programs and Features (Windows 10 and earlier). Sort by installation date and look for programs installed around the time redirects started appearing. Uninstall anything unfamiliar, especially items with random names, publisher listed as "Unknown," or descriptions like "Browsing Enhancement" or "Shopping Helper." On Mac, check Applications folder and drag suspicious items to Trash, then empty Trash.
Remove Malicious Browser Extensions
Open each installed browser and navigate to the extensions/add-ons manager (chrome://extensions for Chrome, about:addons for Firefox, edge://extensions for Edge). Remove any extensions you didn't intentionally install, especially those lacking descriptions, showing generic icons, or requesting excessive permissions. Don't be fooled by legitimate-sounding names—hijackers often use names like "Web Security" or "Fast Search" to appear trustworthy.
Reset Browser Settings Manually
Access your browser's settings and manually change your homepage, search engine, and new tab page back to your preferred choices. In Chrome/Edge, check Settings > On startup, Settings > Search engine, and Settings > Appearance. In Firefox, check Options > Home and Options > Search. Look for any unusual entries in the "Manage search engines" list and remove them. Clear browsing data including cookies and cached files from the beginning of time.
Check and Repair Browser Shortcuts
Right-click your browser shortcuts on the desktop, taskbar, and Start menu, then select Properties. In the Target field, verify it points only to the browser executable (like "C:\Program Files\Google\Chrome\Application\chrome.exe") with no URLs appended after it. If you see additional text after the .exe, delete everything after the closing quotation mark. Click OK to save changes. Repeat for all browser shortcuts.
Clean Registry Entries (Windows, Advanced Users)
Press Win+R, type regedit, and press Enter. Navigate to HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main and verify "Start Page" shows your preferred homepage. Check HKEY_CURRENT_USER\Software\Policies for any subkeys related to Chrome, Edge, or Firefox—these shouldn't exist unless set by a legitimate organization. Delete policy entries that reference erbi90s.click or unfamiliar domains. Create a registry backup before making changes.
Check Scheduled Tasks
Open Task Scheduler (search for it in the Start menu) and review tasks in the Task Scheduler Library. Look for tasks with random names, no description, or actions that launch browsers with URL parameters. Right-click suspicious tasks and select Delete. On Mac, check ~/Library/LaunchAgents and /Library/LaunchAgents for .plist files with random names and delete them.
Scan With Reputable Anti-Malware Software
Reconnect to the internet and download Malwarebytes Free or another reputable scanner. Run a full system scan—not a quick scan—to detect any remaining components or related threats. Quarantine all detected items. Consider running a second-opinion scan with AdwCleaner or HitmanPro to catch variants that single scanners might miss. Each tool uses different detection signatures and may find different components.
Reset Browser to Factory Defaults (If Necessary)
If redirects persist after previous steps, perform a complete browser reset. In Chrome/Edge, go to Settings > Reset settings > Restore settings to their original defaults. In Firefox, go to Help > More Troubleshooting Information > Refresh Firefox. This removes all extensions, resets settings, but preserves bookmarks and passwords. You'll need to re-customize your browser afterward.
Change Passwords and Reboot
If you entered passwords while the hijacker was active, change them now starting with email, banking, and critical accounts. Use a different device if possible, or wait until you've verified the infection is completely removed. Finally, restart your computer and test browsing behavior. Visit several common sites and perform searches to verify no redirects occur. Monitor for several days as some hijacker components may attempt to reinstall from remaining fragments.
Prevention
- Always choose Custom installation options when installing free software. Review each screen carefully and decline any bundled offers, toolbars, browser extensions, or "recommended" additional software. Legitimate programs don't require you to install other programs.
- Download software only from official sources — the developer's website or verified app stores. Avoid third-party download sites like Softonic, Download.com aggregators, and torrent networks where bundling is standard practice. When possible, verify the installer's digital signature before running it.
- Keep browsers and operating systems updated with automatic updates enabled. Security patches close vulnerabilities that hijackers exploit for drive-by installations. Check for updates weekly even if auto-update is enabled, as critical patches sometimes require manual intervention.
- Install reputable ad-blocking and anti-tracking extensions like uBlock Origin or Privacy Badger. These prevent malicious advertising networks from serving fake update prompts and reduce exposure to compromised ad networks that distribute hijackers through malvertising campaigns.
- Be skeptical of browser update prompts that appear on websites. Legitimate browser updates occur through the browser's built-in update mechanism, not via pop-ups on random websites. When in doubt, close the page and manually check for updates in the browser's settings.
- Review installed browser extensions regularly (monthly at minimum). Remove extensions you no longer use or don't remember installing. Check permissions for remaining extensions—be suspicious of extensions requesting access to "all websites" or "your data on all websites" unless absolutely necessary for their function.
- Educate family members who share the computer about installation risks, especially children and less tech-savvy users. Create separate user accounts with standard (non-administrator) privileges for family members, which prevents many hijackers from gaining system-level persistence.
- Maintain regular backups of important data so you can restore to a clean state if infection occurs. While browser hijackers rarely destroy data, having backups provides confidence to perform aggressive cleanup procedures without fear of losing critical files.
Bring It In
If you've followed these manual removal steps and still experience redirects, performance issues, or suspect incomplete removal, bring your computer to Computer Repair Roswell. Browser hijackers frequently install multiple components that reinstall each other if even one piece remains. Our technicians have specialized tools that detect these hiding techniques and perform thorough removal that addresses root causes, not just symptoms. We'll also check for additional threats that may have arrived alongside the hijacker, as bundled installations rarely include just one unwanted program.
We're located in Roswell, Georgia, and handle these infections routinely—often completing the service same-day for drop-offs before noon. Call us at (770) 727-9614 to describe your symptoms and get an estimate, or stop by during business hours. Beyond removal, we'll explain exactly how the infection occurred and provide specific recommendations tailored to your computing habits to prevent future incidents. Don't let a browser hijacker continue degrading your system performance and compromising your privacy—professional removal is more affordable than most people expect and eliminates the frustration of recurring redirects.