GladVideoWebsite is a browser hijacker that forcibly redirects your search queries and new tab pages through a series of unfamiliar domains, ultimately funneling you toward advertising networks and potentially malicious websites. Identified primarily as a potentially unwanted program (PUP) affecting Windows systems, this hijacker modifies browser settings in Chrome, Firefox, and Edge without meaningful consent, replacing your homepage and default search engine with glad-video[.]website or related domains. Users typically encounter degraded browsing performance, intrusive advertising, and privacy concerns as the hijacker tracks search queries and browsing habits to build advertising profiles.
Threat Profile
| Attribute | Details |
|---|---|
| Threat Type | Browser Hijacker / Potentially Unwanted Program (PUP) |
| Aliases | Glad-video.website, GladVideo redirect, glad-video[.]website hijacker |
| Platform | Windows 7/8/10/11 (all editions); targets Chrome, Firefox, Edge browsers |
| Primary Distribution | Software bundling, fake installers, misleading browser extensions |
| Persistence Mechanism | Browser extension installation, modified shortcuts with command-line parameters, scheduled tasks, registry run keys |
| Primary Capabilities | Search redirection, homepage replacement, new tab hijacking, advertising injection, browsing data collection |
| Typical Artifacts | Browser extension folders in %LOCALAPPDATA%, modified browser shortcuts, registry keys under HKCU\Software\Policies |
| Network Behavior | Redirects through glad-video[.]website and intermediary tracking domains before landing on ad networks or search aggregators |
| Data Collection | Search queries, visited URLs, browser type/version, IP address, approximate geographic location |
| Advertising Exposure | Moderate to high; may expose users to tech support scams, rogue software offers, and adult content |
| Removal Difficulty | Moderate; requires manual removal of extensions, scheduled tasks, and registry entries in addition to scanning |
| Reinfection Risk | High if original installation vector (bundled software, compromised extension) remains on system |
How It Spreads
GladVideoWebsite primarily arrives through deceptive software bundling practices. Users download what appears to be a legitimate free application—video converters, PDF tools, download managers, or media players—from third-party download sites. During installation, the setup wizard includes pre-checked opt-in boxes or uses confusing "Custom" vs. "Express" installation screens that install the hijacker alongside the desired program. Many users click through these screens quickly without reading the fine print, inadvertently authorizing the browser modifications.
Fake browser extensions represent another common distribution method. Users searching for video downloaders, ad blockers, or theme customization tools may encounter convincing-looking extensions in unofficial repositories or promoted through search engine ads. Once installed, these extensions immediately modify browser settings and begin the redirection behavior. Some variants disguise themselves as legitimate security or productivity tools, making detection more difficult for non-technical users.
Common infection vectors include:
- Software bundles from freeware sites: Download portals like Softonic, CNET Download, and similar aggregators frequently repackage installers with PUP payloads
- Fake software update prompts: Misleading pop-ups claiming your Flash Player, Java, or browser needs updating
- Torrent downloads: Cracked software and media files bundled with installer packages containing hijackers
- Malicious advertising (malvertising): Legitimate websites serving compromised ad networks that push fake download buttons
- Email attachments with embedded links: Phishing emails directing users to download "required" video players or document viewers
- Browser extension marketplaces: While less common in official stores, third-party extension sites host numerous hijacker variants
What It Does On Your Machine
Once installed, GladVideoWebsite immediately takes control of your browser's core navigation settings. Your homepage changes to glad-video[.]website or a related domain without your explicit authorization. Every new tab you open may load this page instead of your previous setting. Most significantly, your default search engine changes—when you type queries into the address bar or search box, your request gets routed through the hijacker's redirection chain rather than going directly to Google, Bing, or your preferred search provider.
This redirection chain serves several purposes for the operators. First, it creates opportunities for advertising revenue: your search query passes through multiple tracking servers that log what you're looking for, building a profile of your interests. This data gets sold to advertising networks or used to serve targeted ads. Second, the redirects themselves generate pay-per-click revenue each time you're bounced through an intermediary domain. Third, the eventual "search results" you see are often manipulated to prioritize affiliate links and sponsored content that generate commission for the hijacker's operators.
The performance impact is noticeable. Browsers take longer to load pages because each navigation request must first contact the hijacker's servers. You'll see increased advertising throughout your browsing session—not just in search results but injected into legitimate websites you visit. Pop-under windows may appear advertising questionable software, tech support services, or adult content. Your browser may feel sluggish as the hijacker's scripts run continuously in the background, monitoring your activity and communicating with remote servers.
Beyond annoyance, GladVideoWebsite poses legitimate privacy and security concerns. The hijacker collects and transmits your browsing data to unknown third parties operating outside normal privacy regulations. The redirection chain may expose you to more dangerous threats: some intermediary sites in the redirect sequence host exploit kits that probe for browser vulnerabilities, while others push tech support scams or rogue antivirus software. Users have reported being redirected to fake security warnings claiming their system is infected, with instructions to call a "support" number or download supposed "fix" tools that are themselves malware.
Manual Removal — Step by Step
Disconnect from the Network
Unplug your ethernet cable or disable WiFi before proceeding. This prevents the hijacker from communicating with its command servers, downloading additional components, or transmitting collected data during the removal process. Work offline until you've completed all removal steps and verified the infection is gone.
Boot Into Safe Mode with Networking
Restart your computer and press F8 (Windows 7) or Shift+F8 (Windows 8/10/11) during boot to access Advanced Boot Options. Select "Safe Mode with Networking" from the menu. This loads Windows with minimal drivers and prevents the hijacker's persistence mechanisms from reactivating, while still allowing you to download security tools if needed.
Uninstall Suspicious Programs
Open Control Panel > Programs and Features (or Settings > Apps on Windows 10/11). Sort by "Installed On" date and look for unfamiliar programs installed around the time the hijacking started. Common names include anything with "Video," "Download," "Converter," "Optimizer," or random strings. Uninstall these completely, but note that the hijacker may not appear in this list at all.
Remove Malicious Browser Extensions
Open each browser you use and navigate to the extensions/add-ons page (chrome://extensions in Chrome, about:addons in Firefox, edge://extensions in Edge). Remove any extensions you don't recognize or didn't intentionally install, particularly those related to video downloading, ad blocking, or search enhancement. The hijacker extension may have a legitimate-sounding name, so when in doubt, remove it—you can always reinstall legitimate extensions later.
Check and Reset Browser Shortcuts
Right-click your browser shortcuts (on desktop, taskbar, and Start menu) and select Properties. Examine the "Target" field—it should end with the browser's .exe filename and nothing else. If you see additional URLs or parameters after the .exe, delete everything after the closing quote around the executable path. Click OK to save. This removes command-line injection that forces the homepage to load on startup.
Delete Scheduled Tasks
Press Win+R, type taskschd.msc, and press Enter to open Task Scheduler. Expand Task Scheduler Library in the left pane and look for tasks with generic names like "BrowserUpdate," "SystemOptimizer," or random character strings. Check the Actions tab for each suspicious task—if it launches executables from temporary folders or %LOCALAPPDATA%, delete the task. This prevents the hijacker from reinstalling itself on the next system boot.
Clean Registry Policies
Press Win+R, type regedit, and press Enter (confirm the UAC prompt). Navigate to HKEY_CURRENT_USER\Software\Policies\Google, HKEY_CURRENT_USER\Software\Policies\Microsoft, and HKEY_LOCAL_MACHINE\Software\Policies. Look for Chrome, Edge, or Firefox keys that contain search provider or homepage settings. If these keys exist and you didn't create them via enterprise policy, delete the entire Policies folder for that browser. This removes forced settings that override your preferences.
Reset Browser Settings
In each affected browser, access the settings menu and find the "Reset settings" or "Restore settings to their original defaults" option (usually under Advanced settings). This clears out any remaining configuration changes the hijacker made, including search providers, homepage settings, and startup behavior. You'll lose some customizations, but extensions and bookmarks typically remain intact. Manually reconfigure your preferred homepage and search engine after the reset.
Run Malwarebytes or Similar Scanner
Download and install Malwarebytes Free (or another reputable anti-malware tool like HitmanPro) and run a full system scan. Even after manual removal, remnants may remain in obscure locations. Let the scanner quarantine everything it finds. Run a second scan after rebooting to verify nothing reappeared. Most hijackers include multiple persistence mechanisms, so automated scanning catches what manual removal might miss.
Reboot and Verify Clean Operation
Restart your computer normally (not in Safe Mode). Reconnect to the internet and open your browser. Verify that your homepage loads correctly, search queries go to your intended search engine, and new tabs open to your preferred page. Monitor the browser for several hours of normal use—if redirects return, additional components remain on your system and professional removal may be necessary.
Prevention
- Download software only from official sources: Get applications directly from the developer's website or verified stores like the Microsoft Store. Avoid third-party download aggregators that repackage installers with bundled PUPs.
- Always choose Custom/Advanced installation: Never click through installers using Express or Recommended settings. Custom installation reveals opt-in checkboxes for additional software, which you should uncheck before proceeding.
- Read installation screens carefully: Bundlers use deceptive UI design—pre-checked boxes, confusing wording, buttons that say "Decline" but are styled to look like secondary options. Take your time and read every screen.
- Install browser extensions only from official stores: Use the Chrome Web Store, Firefox Add-ons repository, or Microsoft Edge Add-ons site exclusively. Read reviews and check the number of users before installing. If an extension requests excessive permissions for its stated function, don't install it.
- Keep your system and browsers updated: Enable automatic updates for Windows and your browsers. Security patches close vulnerabilities that exploit kits use to install hijackers without interaction.
- Use a reputable ad blocker: Extensions like uBlock Origin (not uBlock) prevent malicious advertising networks from displaying fake download buttons and misleading update prompts that distribute hijackers.
- Maintain real-time antivirus protection: Windows Defender provides baseline protection, but consider supplementing it with Malwarebytes Premium or similar tools that specifically target PUPs and hijackers (many traditional antivirus programs ignore PUPs by default).
- Be skeptical of update prompts: Legitimate software updates through the application itself or Windows Update—never through random browser pop-ups. If you see a prompt claiming Flash, Java, or your browser needs updating, close it and check for updates through official channels.
When Computer Repair Roswell removes malware from your system, we don't just delete the infection—we identify how it got there and close that door. Every malware removal service includes a comprehensive security audit, persistence mechanism cleanup, and prevention measures customization. If the same malware family returns within 90 days, we'll remove it again at no charge. That's our commitment to getting it right the first time.
Bring It In
Browser hijackers like GladVideoWebsite are frustrating to remove completely because they scatter components across multiple system locations and often include reinfection mechanisms that casual users miss. If you've followed the steps above and still experience redirects, or if you'd simply prefer professional removal with guaranteed results, bring your machine to our Roswell shop. We'll run a thorough diagnostic, remove the hijacker and any companion PUPs that arrived with it, verify your browser settings are restored to your preferences, and implement security measures to prevent reinfection—typically completed same-day.
Computer Repair Roswell is located at 1394 Canton Road, Roswell, Georgia, serving the North Fulton area with honest, expert computer repair since 2003. Call us at (770) 695-6444 to check availability or schedule a drop-off time. We handle PC and Mac systems, and our technicians are experienced with the full range of malware families affecting home users and small businesses. Don't continue browsing with a compromised system—get it cleaned properly and protect your privacy and security.