Fibber.media.com is a browser hijacker that forcibly redirects web traffic through its search portal while modifying browser settings without user consent. This potentially unwanted program typically arrives bundled with freeware installers and immediately takes control of your homepage, default search engine, and new tab page across Chrome, Firefox, Edge, and other browsers. While not a traditional virus that replicates itself, Fibber.media.com exhibits malicious behavior by persisting through standard removal attempts and exposing users to questionable advertising networks.
The hijacker generates revenue for its operators by manipulating search results and injecting sponsored links into legitimate queries. Beyond the annoyance factor, Fibber.media.com creates genuine security concerns by tracking your browsing habits, potentially selling this data to third parties, and redirecting you through intermediate servers that could expose you to more serious threats. Users typically notice the infection when their browser suddenly starts opening to an unfamiliar search page or when search queries produce suspiciously commercial-heavy results.
Threat Profile
| Attribute | Details |
|---|---|
| Threat Family | Browser Hijacker / PUP (Potentially Unwanted Program) |
| Aliases | Fibber Media Redirect, Fibber.media Search Hijacker, FibberMedia PUP |
| Platforms Affected | Windows 7/8/10/11, macOS 10.12+; targets Chrome, Firefox, Edge, Safari |
| First Documented | Variants of this family appeared circa 2019-2020 |
| Distribution Method | Software bundling, fake installers, malicious advertising, update prompts |
| Persistence Mechanisms | Browser extensions, scheduled tasks, registry Run keys (Windows), launch agents (macOS), policy modifications |
| Primary Capabilities | Homepage/search redirection, search query interception, ad injection, tracking cookie deployment, browser settings lockdown |
| Indicators of Compromise | Homepage changed to fibber.media.com or similar domains, unknown browser extensions, new scheduled tasks with random names, modified browser shortcut targets |
| Network Behavior | Contacts ad-serving domains, third-party tracking services; redirects through intermediary servers before showing search results |
| Data Collection | Search queries, browsing history, clicked links, IP address, browser fingerprint, potentially form data |
| Removal Difficulty | Moderate — resists standard browser reset procedures, reinstalls components if incomplete removal attempted |
| Payload Association | Often arrives with additional PUPs, adware bundles, or aggressive browser toolbars |
How It Spreads
Fibber.media.com predominantly spreads through deceptive software bundling—a practice where the hijacker is packaged alongside legitimate-looking free software. Users downloading video converters, PDF tools, download managers, or pirated software from third-party download sites frequently encounter installers that have been repackaged to include the hijacker. The installation wizard presents the unwanted components in pre-checked boxes buried in "Custom" or "Advanced" installation options that most users skip entirely, clicking straight through to "Express" or "Recommended" installation.
Beyond bundling, this hijacker exploits user trust through fake update notifications. You might see convincing-looking browser alerts claiming your Flash Player, Chrome, or Java needs updating, with a download button that actually delivers the hijacker instead of a legitimate update. Malicious advertising networks also play a role, where clicking certain ads—even on otherwise legitimate websites—triggers automatic downloads or redirects to pages hosting the installer.
Common distribution vectors include:
- Freeware bundlers from download portals like Softonic, Download.com (when improperly vetted), or torrent sites packaging "cracked" software
- Fake system alerts warning of outdated plugins or security threats, designed to look like legitimate OS or browser notifications
- Malicious browser extensions promoted through search ads or social media, promising features like video downloading or coupon finding
- Email attachments disguised as invoices or shipping notifications that execute installer scripts
- Compromised websites injecting drive-by download scripts that exploit browser vulnerabilities or trick users with social engineering
- Peer-to-peer networks where executable files are mislabeled as movies, games, or productivity software
What It Does On Your Machine
Once executed, Fibber.media.com immediately targets your browser configuration. The hijacker modifies browser shortcuts, adding command-line parameters that force your browser to load its search portal on startup. It installs a helper extension or add-on—sometimes with a generic name like "Utility Helper" or "Search Enhancer"—that maintains control even if you manually change your homepage back. These extensions frequently request broad permissions to "read and change all your data on the websites you visit," which they use to inject advertising content and monitor your browsing.
The search redirection creates a revenue stream for the operators through a multi-step process. When you enter a search query, your request first goes to Fibber.media.com servers, which log the query alongside your IP address and other identifying information. The server then either displays its own search results page filled with sponsored links (where the operators earn pay-per-click revenue) or redirects you through several intermediary advertising networks before eventually landing you on a legitimate search engine like Bing or Yahoo. Each redirect generates a small payment to the affiliate network chain.
The persistence mechanisms make casual removal attempts fail. On Windows systems, the hijacker typically creates scheduled tasks that reinstall components at system startup or specific time intervals. These tasks run with system-level privileges and execute scripts that restore the hijacker's browser extensions, reset the modified shortcuts, and re-establish registry entries pointing to the malicious search page. On macOS, launch agents serve a similar purpose, running maintenance scripts that check whether the hijacker components are still active.
%APPDATA%\ChromeExtension_{random-guid}\
%PROGRAMFILES(X86)%\SearchHelper\
; Common binary locations
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
"FibberService" = "%LOCALAPPDATA%\FibberMedia\svc.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run
"SearchMaintenance" = (binary data)
Scheduled Task: \FibberUpdate or \ChromeUpdateTask{random}
; Triggers: Daily at logon, every 4 hours
Browser shortcut targets modified to:
"C:\Program Files\Google\Chrome\Application\chrome.exe" --homepage="http://fibber.media.com/"
Beyond the immediate browsing disruption, the data collection aspect poses privacy risks. The hijacker tracks which sites you visit, what you search for, and which links you click. This behavioral data gets aggregated and often sold to advertising networks, data brokers, or used to build detailed user profiles. While the operators claim data is "anonymized," IP addresses and browser fingerprints can frequently be correlated with specific individuals, especially when combined with other data sources. Some variants have been observed attempting to intercept form data, though this capability varies significantly across different versions of the hijacker.
Manual Removal — Step by Step
Disconnect from Network and Boot to Safe Mode
Unplug your ethernet cable or disable Wi-Fi to prevent the hijacker from communicating with command servers or downloading additional components. Restart your computer and press F8 (Windows 7) or hold Shift while clicking Restart (Windows 8/10/11), then select "Safe Mode with Networking" from the boot options. On Mac, restart while holding the Shift key. Safe Mode prevents most startup items and scheduled tasks from running, making removal easier.
Uninstall Suspicious Programs
Open Control Panel → Programs and Features (or Settings → Apps on Windows 10/11). Sort by install date and look for programs installed around the time the hijacking started. Uninstall anything unfamiliar, especially items with names like "Search Helper," "Browser Utility," "Media Enhancer," or publisher names you don't recognize. On Mac, check Applications folder and drag suspicious apps to Trash, then empty Trash while holding Option key.
Remove Malicious Browser Extensions
Open each installed browser and navigate to the extensions/add-ons manager (chrome://extensions/ for Chrome, about:addons for Firefox, edge://extensions/ for Edge). Remove any extensions you didn't intentionally install, paying special attention to those with vague names or requesting excessive permissions. Don't just disable them—click "Remove" to fully delete. Check all browsers on your system, not just your primary one.
Delete Scheduled Tasks and Startup Entries
Press Win+R, type "taskschd.msc" and press Enter to open Task Scheduler. Expand Task Scheduler Library and examine recent tasks, especially those with random names or triggering multiple times daily. Delete any suspicious entries (right-click → Delete). Next, press Win+R again, type "msconfig" and check the Startup tab (or use Task Manager → Startup tab on Windows 8+), disabling any unrecognized entries. On Mac, go to System Preferences → Users & Groups → Login Items and remove suspicious entries.
Clean Registry Entries (Windows Only)
Press Win+R, type "regedit" and navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. Look for entries pointing to the folders you identified earlier or containing "fibber" or other suspicious terms in the value data. Right-click and delete those entries. Also check HKEY_CURRENT_USER\Software for folders named after the hijacker. Make a registry backup before editing (File → Export) in case you need to revert changes.
Delete Hijacker File Directories
Navigate to %LOCALAPPDATA%, %APPDATA%, and %PROGRAMFILES(X86)% (type these into File Explorer's address bar) and delete any folders associated with the hijacker—look for "FibberMedia," "SearchHelper," or folders with random GUID names created around the infection date. You may need to show hidden files (View → Hidden Items checkbox) and take ownership of some folders if you get permission errors. On Mac, check ~/Library/Application Support/ and /Library/Application Support/.
Reset Browser Shortcuts
Right-click your browser shortcuts (on desktop, taskbar, and Start menu), select Properties, and examine the Target field. If you see anything after the .exe path (especially URLs or --homepage flags), delete everything after the closing quotation mark of the executable path. Click OK to save. Create fresh shortcuts from the browser's installation folder if needed to ensure they're clean.
Run Reputable Anti-Malware Scanners
Download and run Malwarebytes (free version is fine) and perform a full system scan. Also run a scan with your existing antivirus if you have one. Consider a second opinion from HitmanPro or AdwCleaner, which specialize in PUPs and browser hijackers. Allow these tools to quarantine everything they find. Don't skip this step—manual removal often misses persistence mechanisms that these tools catch.
Reset Browser Settings Completely
In Chrome, go to Settings → Advanced → Reset and clean up → Restore settings to original defaults. In Firefox, type about:support in the address bar and click "Refresh Firefox." In Edge, go to Settings → Reset settings → Restore settings to default values. This clears any lingering configuration changes the hijacker made. You'll need to reconfigure bookmarks sync and preferences afterward, but it ensures a clean slate.
Change Passwords and Monitor Accounts
Since the hijacker tracked your browsing and potentially intercepted form data, change passwords for important accounts—email, banking, social media—from a known-clean device or after confirming your system is clean. Enable two-factor authentication wherever possible. Monitor bank and credit card statements for unusual activity over the next few weeks. If you suspect significant data theft, consider placing a fraud alert with credit bureaus.
Prevention
- Download software only from official sources. Get programs directly from the developer's website or verified app stores (Microsoft Store, Mac App Store). Avoid third-party download portals like Softonic, CNET Downloads, or file-sharing sites that repackage installers with bundled PUPs. When you must use these sites, scrutinize every installation screen.
- Always choose Custom/Advanced installation. Never click through Express or Recommended installation options when installing free software. The Custom path reveals pre-checked boxes for bundled software, which you can then uncheck. Read each screen carefully—deceptive installers sometimes use confusing language like "I do not want to decline" double-negatives.
- Keep your system and browsers updated. Enable automatic updates for Windows/macOS and all browsers. Most hijackers exploit outdated software vulnerabilities. Modern browsers include enhanced protection against malicious extensions and configuration tampering that older versions lack.
- Use a reputable ad blocker. Browser extensions like uBlock Origin block malicious advertising networks that distribute hijackers through compromised ad slots. This reduces exposure to drive-by downloads and fake update prompts disguised as ads.
- Maintain active antivirus/anti-malware protection. Use Windows Defender (built into Windows 10/11) at minimum, or a reputable third-party solution. Supplement with periodic scans using Malwarebytes. Real-time protection catches many hijackers before they execute.
- Scrutinize browser extension requests. Before installing any extension, research it. Check the developer, read reviews (especially recent negative ones), and examine what permissions it requests. Extensions asking to "read and change all your data" should be treated with extreme caution unless from a well-established developer.
- Educate everyone who uses your computers. Family members or employees who don't understand these risks can inadvertently install hijackers. Brief training on recognizing bundled software, fake updates, and suspicious download prompts significantly reduces infection risk in shared environments.
- Enable browser security features. Turn on "Safe Browsing" in Chrome/Edge, "Phishing and Malware Protection" in Firefox, and similar features in Safari. These warn you before visiting known malicious sites or downloading flagged files, catching many hijacker distribution pages before infection occurs.
Bring It In
Browser hijackers like Fibber.media.com frustrate even technically competent users because they're specifically designed to resist casual removal attempts. The multi-layered persistence, the browser-specific configuration tampering, the scheduled tasks that resurrect deleted components—these aren't accidents. They're deliberate obstacles created by people who profit from your confusion. If you've followed the manual steps above and still see redirects, or if you're simply not comfortable editing the registry and task scheduler, that's completely reasonable. This is what we do every day.
Bring your machine to our Roswell shop at 1341 Canton Road or give us a call at (770) 691-6776. We'll run a comprehensive diagnostic—not just a quick scanner, but a methodical examination of startup routines, browser configurations, scheduled tasks, and network behavior. We'll explain exactly what we find in plain language, quote you a fair price before we proceed, and have you back up and running typically within 24 hours. For most hijacker removals, we're talking about a same-day turnaround with our 90-day re-infection warranty included. Don't spend your weekend fighting with Task Scheduler when you could spend an hour here and actually solve the problem.