GiftsForFreeNow.com is a browser hijacker and potentially unwanted program (PUP) that forcibly redirects your web searches and homepage to a dubious search portal promising "free gifts" and deals. Despite its tempting name, this hijacker exists solely to generate revenue through forced advertising, affiliate commissions, and data collection from your browsing habits. Users typically don't install it intentionally—it arrives bundled with free software installers or masquerading as a browser extension offering coupon features. Once active, it's remarkably stubborn about staying installed, modifying browser settings and resisting standard uninstallation attempts.
Threat Profile
| Attribute | Details |
|---|---|
| Threat Type | Browser Hijacker, Potentially Unwanted Program (PUP) |
| Family | Search redirect malware / Adware-supported hijackers |
| Common Aliases | Gifts For Free Now, GiftsForFree redirect, GiftsFreeNow toolbar |
| Affected Platforms | Windows (all versions); primarily targets Chrome, Firefox, Edge, Safari on macOS |
| Distribution Method | Software bundling, fake Flash updates, deceptive browser extension prompts |
| Persistence Mechanisms | Browser extension installation, modified shortcut targets, scheduled tasks, registry modifications (Windows) |
| Primary Capabilities | Homepage/search hijacking, forced redirects, affiliate click fraud, tracking cookie installation, advertisement injection |
| Data at Risk | Browsing history, search queries, IP address, geographic location, clicked links, potentially form data |
| Network Behavior | Frequent connections to ad networks, redirect chains through multiple domains, tracking pixel requests |
| Typical File Locations | Browser extension directories, %APPDATA%\local folders with randomized names, Program Files subfolders |
| Removal Difficulty | Moderate—resists simple browser resets and may reinstall itself from hidden components |
| Associated Risks | Privacy invasion, exposure to scam advertisements, performance degradation, potential secondary malware installation |
How It Spreads
GiftsForFreeNow.com doesn't spread through sophisticated exploits or security vulnerabilities. Instead, it relies on deception and user inattention during routine software installations. The hijacker's distributors partner with free software publishers who include it as an "optional offer" buried in installer wizards. When you rush through clicking "Next" on a free video converter, PDF tool, or download manager, you're often agreeing to install multiple additional programs without realizing it.
The installation process is deliberately misleading. Bundled installers typically present GiftsForFreeNow as a helpful browser extension that will "enhance your shopping experience" or "find you the best deals automatically." The checkboxes to decline these offers are often pre-selected for installation, use confusing language ("I do not want to miss out on exclusive savings"), or appear in unexpected locations within the installer interface. Some variants even install through fake browser update prompts that appear on questionable websites, claiming your Flash Player or video codec needs updating.
Common distribution vectors include:
- Software bundles from free download sites like Softonic, Download.com, or various freeware portals that repackage legitimate programs with added "sponsors"
- Fake update notifications on streaming sites, torrent pages, or adult content sites claiming you need a video player update
- Malicious advertisements that trigger automatic downloads or misleading "Download" buttons on file-sharing sites
- Browser extension galleries where the hijacker appears as a legitimate coupon or deal-finding tool
- Compromised installers for popular utilities downloaded from unofficial mirror sites rather than the developer's website
- Email attachments disguised as documents that execute installers when opened
What It Does On Your Machine
Once installed, GiftsForFreeNow.com immediately modifies your browser configuration to redirect all search activity through its portal. Your homepage changes to the GiftsForFreeNow.com domain, and your default search engine switches to a custom search provider that routes queries through the hijacker's servers before eventually displaying results from a legitimate search engine like Google or Bing. This routing allows the hijacker to track every search you perform, inject additional advertisements into the results, and collect valuable data about your interests and browsing patterns.
The hijacker typically installs persistence mechanisms that make it difficult to remove through normal means. It may create scheduled tasks that reapply the hijacked settings if you manage to change them manually. Windows shortcuts to your browsers often get modified with additional command-line parameters that force the browser to load the hijacker's homepage on startup. Registry entries ensure the browser extension reinstalls itself even after you remove it through browser settings. Some variants install a local proxy configuration that routes all web traffic through a filtering system, allowing even deeper control over your browsing experience.
Performance degradation is noticeable. Your browser runs slower because the hijacker injects JavaScript into every page you visit, scanning for opportunities to replace legitimate ads with its own or to insert additional promotional content. Pages take longer to load due to the redirect chains and the numerous third-party tracking scripts being loaded. Your computer may also exhibit increased CPU usage as the hijacker's background processes monitor your activity and communicate with remote advertising servers.
Beyond the immediate annoyance, GiftsForFreeNow.com poses genuine privacy risks. The hijacker's privacy policy—if one even exists—typically includes broad language permitting the collection and sharing of your browsing data with unnamed "partners" and "advertisers." This data collection goes well beyond what legitimate search engines do. Every clicked link, search term, and visited website gets logged and associated with your IP address and browser fingerprint. This information has commercial value and may be sold to data brokers or used to build detailed profiles for targeted advertising. In some cases, hijackers have been caught collecting more sensitive information like usernames and email addresses from form data, though this varies by variant.
Manual Removal — Step by Step
Disconnect and Document
Disconnect your computer from the internet by unplugging the Ethernet cable or disabling Wi-Fi. This prevents the hijacker from downloading additional components or communicating with command servers during removal. Write down or screenshot your current browser settings (homepage, search engine) so you can verify they're restored later.
Uninstall Suspicious Programs
Open Settings > Apps (Windows 10/11) or Control Panel > Programs and Features (Windows 7/8). Sort by installation date and look for unfamiliar programs installed around the time the hijacker appeared. Uninstall anything containing "GiftsForFreeNow," "Browser Assistant," "Deals Finder," or similar names. Also remove any programs you don't recognize or didn't intentionally install.
Remove Browser Extensions
Open each affected browser and navigate to the extensions/add-ons manager (chrome://extensions/ in Chrome, about:addons in Firefox, edge://extensions/ in Edge). Remove ALL extensions you didn't deliberately install, paying particular attention to anything mentioning shopping, deals, coupons, or free gifts. Disable "Developer mode" in Chrome if it's enabled, as hijackers sometimes use this to reinstall extensions.
Reset Browser Settings
In each browser's settings menu, find the option to reset settings to defaults. In Chrome: Settings > Reset settings > Restore settings to original defaults. In Firefox: Help > More Troubleshooting Information > Refresh Firefox. In Edge: Settings > Reset settings > Restore settings to default values. This removes hijacked homepages, search engines, and startup pages while preserving bookmarks and passwords.
Check Browser Shortcuts
Right-click your browser shortcuts (desktop, taskbar, Start menu) and select Properties. In the Target field, verify it ends with the browser executable name (like chrome.exe or firefox.exe) with no additional URLs or parameters afterward. If you see any website addresses appended, delete everything after the .exe and click Apply. Repeat for all browser shortcuts.
Delete Scheduled Tasks
Open Task Scheduler (search for it in the Start menu). Look through the Task Scheduler Library for any tasks with suspicious names or publishers. Delete tasks related to "GiftsForFreeNow," "Update," "Browser," or anything created by an unknown publisher around the infection date. Be careful not to delete legitimate Windows or application tasks.
Clean Registry Entries (Advanced)
Press Win+R, type regedit, and press Enter. Navigate to HKEY_CURRENT_USER\Software and look for a "GiftsForFreeNow" key—delete it if found. Also check HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run for any suspicious startup entries. Only delete entries you're certain are malicious; incorrect registry modifications can cause system instability.
Remove Leftover Files
Open File Explorer and navigate to %LOCALAPPDATA% (paste this in the address bar). Look for folders named "GiftsForFreeNow" or with random-looking names created around the infection date. Delete suspicious folders. Repeat for %APPDATA%. Also check your browser profile folders for any remaining extension directories.
Run Reputable Anti-Malware
Reconnect to the internet and download Malwarebytes Free from the official website. Run a full system scan to catch any components you might have missed and to check for additional unwanted programs that may have installed alongside the hijacker. Quarantine and remove everything it identifies as a threat.
Verify and Monitor
Reboot your computer and open your browsers. Verify that your homepage and search engine are what you expect and that no GiftsForFreeNow pages appear. Monitor your browser over the next few days for any signs of the hijacker returning. If it reappears, additional hidden components remain and professional removal may be necessary.
Prevention
- Download software only from official sources. Always get programs directly from the developer's website rather than third-party download portals. These aggregate sites frequently repackage clean software with bundled PUPs to generate revenue.
- Choose Custom/Advanced installation every time. Never use Express or Recommended installation options for free software. Custom installation reveals the bundled programs being offered and gives you checkboxes to decline them. Read every screen carefully before clicking Next.
- Keep one reputable anti-malware tool running. Install Malwarebytes, Windows Defender (built into Windows 10/11), or another trusted security suite and keep it updated. Real-time protection can block PUP installations before they complete.
- Use an ad blocker with anti-malware lists. Browser extensions like uBlock Origin block not just advertisements but also many of the malicious scripts and fake download buttons that distribute hijackers. Enable the malware protection filter lists in its settings.
- Ignore update prompts from websites. Legitimate software updates come through the application itself or Windows Update, never through pop-ups while browsing. If a website claims you need to update Flash, Java, or a video codec, close the page immediately—Flash is actually discontinued and no longer receives updates.
- Review browser extensions monthly. Periodically check your installed extensions and remove anything you don't actively use. Hijackers sometimes install dormant extensions that activate later or that get sold to malicious actors in subsequent updates.
- Create a Standard user account for daily use. Using a Windows account without administrator privileges prevents many hijackers from installing system-wide persistence mechanisms. They can still affect your browser, but removal becomes simpler.
- Enable browser security features. Modern browsers have built-in protections against malicious extensions and deceptive sites. Ensure these are enabled in your browser's privacy and security settings and never disable them for convenience.
Bring It In
Browser hijackers like GiftsForFreeNow.com can be stubborn, and the manual removal process above requires comfort with system utilities and registry editing that many people understandably prefer to avoid. Even when you successfully remove the visible components, hidden persistence mechanisms can bring the hijacker back within hours or days. If you've attempted removal and the hijacker keeps returning, or if you're simply not comfortable working with Task Scheduler and the Windows Registry, professional help is the faster and safer option.
At Computer Repair Roswell, we handle browser hijacker removal daily and have the tools and experience to eliminate even the most persistent variants. We'll clean your browsers, remove all associated files and registry entries, scan for additional malware that may have installed alongside the hijacker, and verify that your system is genuinely clean before returning it to you. We're located right here in Roswell, Georgia, and we typically complete malware removal within 24 hours. Call us at (770) 856-1467 or stop by our shop—we'll get your browsing experience back to normal.