FrankBottlesShop is a browser hijacker and potentially unwanted program (PUP) that manipulates your web browser settings to redirect your searches and homepage to unwanted sites. Typically bundled with free software installers, it infiltrates systems through deceptive "recommended" installation options that users click through without reading. Once installed, FrankBottlesShop modifies browser configurations, injects advertising content, and tracks your browsing activity to generate revenue for its operators through forced traffic and data collection.
Threat Profile
| Attribute | Details |
|---|---|
| Family | Browser Hijacker / PUP (Potentially Unwanted Program) |
| Common Aliases | FrankBottlesShop redirect, FrankBottlesShop browser extension, FrankBottlesShop search hijacker |
| Targeted Platforms | Windows (7, 8, 10, 11); primarily affects Chrome, Firefox, and Edge browsers |
| Discovered | Circa 2020–2021 (typical lifespan for PUP campaigns of this type) |
| Primary Distribution | Software bundling, fake installer packages, malvertising, social engineering |
| Persistence Mechanisms | Browser extension policies, scheduled tasks, registry Run keys, browser preference manipulation |
| Core Capabilities | Search redirection, homepage/new tab hijacking, advertising injection, data tracking |
| Data Collection | Browsing history, search queries, clicked links, IP address, system information |
| Network Behavior | Frequent HTTPS connections to advertising networks and tracking domains; redirects through multiple intermediary sites |
| Common Artifacts | Browser extension folders in user profile, modified browser preference files (Preferences, Secure Preferences), scheduled tasks with random names |
| Detection Names | PUP.Optional.FrankBottlesShop, BrowserModifier:Win32/FrankBottlesShop, Adware.FrankBottlesShop (varies by vendor) |
| Removal Difficulty | Moderate—reinstalls itself if all components aren't removed; often requires manual browser configuration repair |
How It Spreads
FrankBottlesShop rarely arrives alone. The most common infection vector is software bundling, where legitimate-looking free applications include the hijacker as an "optional" component during installation. Users who rush through the setup process using "Express" or "Recommended" settings unknowingly authorize the installation. The bundler programs are often download managers, PDF converters, video codec packs, or system optimization utilities advertised through misleading online ads.
Another significant distribution method involves fake software updates and malicious advertisements. You might encounter a pop-up claiming your Flash Player, Java, or video codec is out of date. Clicking the update button downloads a package containing FrankBottlesShop along with the promised software (if the promised software exists at all). These fake update prompts are particularly convincing because they mimic legitimate system notifications.
Less commonly, FrankBottlesShop spreads through compromised or deceptive websites. Torrent sites, illegal streaming platforms, and certain freeware repositories may host installers pre-packaged with the hijacker. Email attachments claiming to be documents or invoices occasionally deliver browser hijackers as well, though this is more typical of trojans than PUPs.
- Bundled software installers from freeware download sites (especially third-party hosting platforms)
- Fake update notifications for Flash Player, media codecs, browser plugins, or system drivers
- Malicious advertising (malvertising) on compromised or low-quality websites
- Torrent downloads and pirated software packages with modified installers
- Social engineering tactics promising performance improvements, prize claims, or system scans
- Browser extension stores (less common, but rogue extensions occasionally slip through approval processes)
What It Does On Your Machine
Once installed, FrankBottlesShop immediately reconfigures your web browser. Your homepage, default search engine, and new tab page all redirect to sites controlled by the hijacker's operators or their affiliates. Searches conducted through your address bar no longer go to Google, Bing, or your chosen search provider—instead, they route through intermediate redirect pages that log your queries before eventually displaying results (often from legitimate search engines, but with injected advertisements).
The hijacker installs persistence mechanisms to survive your attempts to fix these settings. Even if you manually change your homepage back to Google, the hijacker's scheduled task or startup entry reapplies its configuration within seconds or upon the next browser restart. It often modifies browser policy files or preference JSON structures that override user settings, making manual correction frustrating and seemingly impossible for non-technical users.
FrankBottlesShop generates revenue through forced advertising and affiliate commissions. You'll notice an increase in pop-up windows, banner ads on sites that don't normally have them, and text links converted into advertising hyperlinks. The hijacker may also redirect product searches to affiliated merchants or insert coupon pop-ups during online shopping. Every click, every search, and every page view is tracked and monetized.
While classified as a PUP rather than malware, FrankBottlesShop creates genuine security and privacy risks. The tracking capabilities collect detailed browsing profiles that may be sold to data brokers. The redirect chains expose you to more dangerous threats—many browser hijackers serve as the entry point for ransomware, trojans, or credential stealers by routing users to exploit kit landing pages or fraudulent download sites. Additionally, the forced ads are unvetted and may promote scams, fake antivirus software, or phishing sites.
%LOCALAPPDATA%\{random-GUID}\{random-name}.exe
%APPDATA%\FrankBottlesShop\
%USERPROFILE%\AppData\Local\Google\Chrome\User Data\Default\Extensions\{extension-id}\
%USERPROFILE%\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}\extensions\{extension-id}
Registry Keys (Common):
HKCU\Software\FrankBottlesShop
HKCU\Software\Microsoft\Windows\CurrentVersion\Run → points to hijacker executable
HKLM\Software\Policies\Google\Chrome\ExtensionInstallForcelist → forces extension reinstall
Scheduled Tasks:
\FrankBottlesShopUpdate (or similar random names)
\{random-GUID} → runs update/reinstall routine
Manual Removal — Step by Step
Disconnect from the Internet
Unplug your Ethernet cable or disable Wi-Fi before you begin. This prevents FrankBottlesShop from downloading additional components, receiving updated configurations, or phoning home with collected data during the removal process.
Boot Into Safe Mode with Networking
Restart your computer and enter Safe Mode. For Windows 10/11: hold Shift while clicking Restart, then navigate to Troubleshoot → Advanced Options → Startup Settings → Restart, and press F5 for Safe Mode with Networking. This prevents the hijacker's startup entries from loading automatically.
Uninstall Suspicious Programs
Open Settings → Apps → Apps & Features (or Control Panel → Programs and Features on older Windows). Sort by install date and look for programs installed around the time redirects started—especially anything with "FrankBottlesShop" in the name, unfamiliar toolbars, download managers, or "optimization" utilities. Uninstall anything suspicious. Be thorough—hijackers often install 2-3 companion programs.
Remove Browser Extensions
Open each browser you use. In Chrome: navigate to chrome://extensions/; in Firefox: about:addons; in Edge: edge://extensions/. Remove any extensions you don't recognize, didn't intentionally install, or that appeared around the time of infection. FrankBottlesShop often appears as a generic-sounding extension like "Web Helper," "Search Manager," or uses a random alphanumeric string as its name.
Delete Scheduled Tasks
Press Win+R, type taskschd.msc, and press Enter to open Task Scheduler. Expand Task Scheduler Library and look for tasks with names containing "FrankBottlesShop," random GUIDs, or descriptions mentioning "update" with unfamiliar publisher names. Right-click suspicious tasks and delete them. These tasks reinstall the hijacker automatically if left in place.
Clean Registry Startup Entries
Press Win+R, type regedit, and press Enter (accept the UAC prompt). Navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run. Delete any entries pointing to random executables in %LOCALAPPDATA% or %APPDATA% folders, or anything referencing FrankBottlesShop. Also check HKEY_CURRENT_USER\Software for a "FrankBottlesShop" key and delete the entire key if present.
Delete Hijacker Files
Open File Explorer and navigate to %LOCALAPPDATA% (paste that into the address bar). Look for folders named "FrankBottlesShop" or folders with random GUID names (like {A1B2C3D4-E5F6-...}) created around infection time. Delete these folders entirely. Repeat for %APPDATA%. Empty your Recycle Bin afterward.
Reset Browser Settings
In Chrome: Settings → Reset Settings → Restore settings to their original defaults. In Firefox: Help → More Troubleshooting Information → Refresh Firefox. In Edge: Settings → Reset Settings → Restore settings to their default values. This removes forced search engines, homepage redirects, and extension policies. You'll need to reconfigure bookmarks and saved passwords afterward (they're typically preserved but verify).
Run Malwarebytes or Similar Scanner
Download and install Malwarebytes Free (or HitmanPro, AdwCleaner) from a clean computer if possible, or reconnect briefly to download. Run a full system scan. These tools catch remnants, associated PUPs, and companion threats that manual removal might miss. Quarantine and remove everything detected.
Reboot and Verify
Restart your computer normally (not in Safe Mode). Open your browser and verify your homepage, search engine, and new tab page are correct. Conduct a test search and check for unexpected redirects. If everything appears clean, change your important passwords (email, banking, social media) from a known-clean device or after confirming no keyloggers are present.
Prevention
- Always choose "Custom" or "Advanced" installation options when installing free software. Read each screen carefully and uncheck any pre-selected offers for additional programs, toolbars, or homepage changes. Legitimate software doesn't hide extras in fine print.
- Download software only from official sources. Avoid third-party download sites like Softonic, Download.com, or CNET downloads—these are notorious for bundling PUPs with legitimate software. Go directly to the developer's website or use the Microsoft Store when possible.
- Keep a real-time antivirus program active. Windows Defender is adequate if kept updated, but consider adding Malwarebytes Premium for additional PUP protection. Configure it to scan downloads automatically and block known bundler sites.
- Never trust unexpected update prompts. If a website tells you to update Flash Player, Java, or any plugin, close the tab immediately. Legitimate updates come through your operating system's update mechanism or the application's built-in updater—never from a random website pop-up.
- Use an ad blocker and script blocker. Extensions like uBlock Origin (not AdBlock Plus, which accepts "acceptable ads") prevent malicious advertising networks from even loading. Consider NoScript or uMatrix for advanced users to control which scripts can run on websites.
- Review browser extensions monthly. Make it a habit to open your browser's extension manager and verify you recognize and still use everything installed. Remove anything unfamiliar immediately—extensions can be added through various exploit chains without explicit user approval.
- Be skeptical of "free" performance optimization tools. Programs claiming to speed up your PC, fix registry errors, or optimize memory are frequently bundled with hijackers. Windows 10 and 11 include sufficient built-in optimization—third-party tools are almost always unnecessary and often harmful.
- Educate everyone who uses the computer. If family members, employees, or roommates share the machine, make sure they understand safe installation practices. One careless installation can compromise the entire system, and browser hijackers are particularly good at exploiting non-technical users.
Bring It In
Browser hijackers like FrankBottlesShop are frustrating, persistent, and often accompanied by more serious threats. If you've followed these steps and still experience redirects, or if you're uncomfortable making registry edits and removing scheduled tasks, we're here to help. Computer Repair Roswell has cleaned thousands of infected systems for Roswell-area homeowners and businesses. We use professional-grade tools, verify complete removal, and explain what happened so you can avoid reinfection.
Don't let a browser hijacker waste your time and compromise your privacy. Call us at (770) 727-9052 or stop by our shop at 1840 Willeo Creek Point, Roswell, GA 30075. We offer same-day service for most infections, transparent pricing with no hidden fees, and that 90-day warranty on all malware removal work. We'll have you back online safely—usually while you wait.