Goblins.online.biz is a browser hijacker that forcibly redirects web traffic through its domain while modifying browser settings without consent. This potentially unwanted program (PUP) typically infiltrates systems bundled with free software downloads, then proceeds to alter your homepage, default search engine, and new tab page to funnel searches through advertising networks. While not a virus in the traditional sense, Goblins.online.biz degrades browsing performance, exposes users to unreliable advertising content, and creates privacy concerns by tracking search queries and browsing habits.
Users infected with this hijacker often notice their browsers opening to unfamiliar pages, search results redirecting through multiple intermediary sites, and difficulty reverting settings to their preferred configurations. The persistence mechanisms employed make simple browser resets ineffective in many cases, requiring thorough removal of both the browser extension components and supporting files installed on the system.
Threat Profile
| Attribute | Details |
|---|---|
| Threat Family | Browser Hijacker / Potentially Unwanted Program (PUP) |
| Common Aliases | Goblins Online, Goblins.online redirect, GoblinsOnline.biz hijacker |
| Platforms Affected | Windows (all versions), macOS; targets Chrome, Firefox, Edge, Safari |
| Discovered | Active variants circulating since 2020-2021 |
| Primary Distribution | Software bundling, fake update prompts, deceptive download buttons on freeware sites |
| Persistence Mechanisms | Browser extension installation, scheduled tasks, registry Run keys, browser policy manipulation |
| Primary Capabilities | Search redirection, homepage modification, new tab hijacking, ad injection, browsing data collection |
| Data Collection | Search queries, visited URLs, IP address, browser type, geographic location, click patterns |
| Network Behavior | Redirects through multiple intermediary domains before reaching search results; communicates with advertising tracking servers |
| Typical File Locations | Browser extension directories, %APPDATA% subfolders, %LOCALAPPDATA% with randomized folder names |
| Common Symptoms | Changed homepage/search engine, slow browser performance, unexpected toolbars, increased pop-up ads |
| Removal Difficulty | Moderate — manual removal possible but requires multiple steps across browser settings and system files |
How It Spreads
Goblins.online.biz primarily spreads through software bundling, a distribution tactic where the hijacker is packaged alongside legitimate free software. When users download video converters, PDF utilities, download managers, or similar freeware from third-party hosting sites, the installation wizard includes pre-checked options to install "recommended" components. These bundled items are frequently disguised with vague descriptions like "enhanced search experience" or "web optimization tool." Users who click through installation prompts without reading carefully or selecting custom installation options unknowingly authorize the hijacker's installation.
The hijacker also exploits user trust through fake update notifications. Victims browsing certain websites encounter convincing pop-ups claiming their Flash Player, browser, or video codec needs updating. Clicking "Update Now" initiates a download that installs the hijacker rather than legitimate software. Similarly, deceptive advertising on file-sharing sites and torrent platforms presents multiple "Download" buttons, with the legitimate download link obscured among fake buttons that trigger hijacker installations.
Common distribution vectors include:
- Bundled installers from freeware/shareware download portals (Softonic, Download.com, CNET Downloads when hosting third-party installers)
- Fake software update notifications for Flash Player, media codecs, or browser components
- Malicious advertising (malvertising) on legitimate websites, redirecting to hijacker download pages
- Torrent file attachments packaged with pirated software or media content
- Email attachments disguised as document viewers or file extractors
- Compromised browser extensions that update silently to include hijacker functionality
- Fake download buttons on file-hosting and streaming sites designed to confuse users
What It Does On Your Machine
Once installed, Goblins.online.biz immediately modifies browser configurations to ensure all web searches and new tab actions route through its domain. The hijacker changes your homepage setting, default search engine, and new tab page URL to point to goblins.online.biz or an intermediary redirect domain. When you attempt to search using the address bar or initiate a new tab, your query passes through the hijacker's servers before eventually displaying results—typically from a legitimate search engine like Bing or Yahoo, but only after the hijacker has logged your search terms and injected additional advertising.
The hijacker establishes persistence through multiple mechanisms. It installs browser extensions or add-ons with permissions to "read and change all your data on websites you visit," allowing comprehensive monitoring of browsing activity. On the system level, it creates scheduled tasks that periodically verify the hijacker components remain active, reinstalling browser settings if you manually revert them. Registry modifications under the Run and RunOnce keys ensure the hijacker reinitializes after system reboots. Some variants manipulate browser policies—normally used by IT administrators in enterprise environments—to lock homepage and search engine settings, graying out the options in your browser's settings menu.
The hijacker actively collects browsing data to build advertising profiles. Every search query, visited URL, and clicked link gets transmitted to remote tracking servers. This data collection extends beyond simple analytics; the hijacker monitors time spent on pages, shopping behaviors, geographic location, and device characteristics. This information feeds advertising networks that display targeted pop-ups, inject ads into legitimate websites, and redirect shopping links through affiliate programs that generate revenue for the hijacker's operators.
Performance degradation is another common consequence. The constant background communication with advertising servers consumes bandwidth and system resources. Browsers launch more slowly, pages take longer to load, and systems with limited RAM may experience noticeable slowdowns. The injected advertisements themselves—often poorly optimized scripts—further tax browser performance. Users frequently report browser crashes, frozen tabs, and unresponsive pages when the hijacker's ad injection mechanisms conflict with legitimate website code.
Manual Removal — Step by Step
Disconnect Network and Document Current State
Disconnect from the internet (unplug Ethernet or disable Wi-Fi) to prevent the hijacker from receiving new instructions or downloading additional components during removal. Take note of which browsers are affected and screenshot your current homepage/search engine settings so you can verify complete removal later. Write down any unfamiliar programs you see in the Start menu or Applications folder—you'll check for these again after removal.
Uninstall Suspicious Programs via Control Panel
Open Control Panel (Windows) or Applications folder (Mac) and carefully review installed programs sorted by installation date. Look for unfamiliar programs installed around the time the hijacking started. Common names include variations of "Goblins," "Web Helper," "Search Manager," or random names with recent install dates. Uninstall anything suspicious. On Windows, use "Programs and Features" or Settings > Apps. On Mac, drag applications to Trash, then empty it.
Remove Browser Extensions and Add-ons
Open each affected browser and navigate to the extensions/add-ons management page (Chrome: chrome://extensions, Firefox: about:addons, Edge: edge://extensions). Enable "Developer mode" if needed to reveal all extensions. Remove any extension you don't recognize or didn't intentionally install, paying special attention to extensions with permissions to "read and change all your data." Remove extensions even if they have innocent-sounding names—hijackers often disguise themselves as productivity tools or ad blockers.
Reset Browser Settings Manually
In each browser's settings, manually change your homepage, default search engine, and new tab page back to your preferred choices. In Chrome/Edge, check Settings > On startup, Settings > Search engine, and Settings > Privacy and security > Site settings. In Firefox, check Options > Home and Options > Search. If these settings are grayed out or immediately revert after changing, the hijacker has implemented policy locks—proceed to the next step to address this.
Remove Registry Persistence Mechanisms (Windows)
Press Win+R, type "regedit" and press Enter to open Registry Editor. Navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run. Look for entries referencing Goblins, random character strings pointing to AppData locations, or unfamiliar executables. Right-click and delete suspicious entries. Also check HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome and HKEY_LOCAL_MACHINE\Software\Policies\Mozilla for policy entries that lock browser settings—delete these policy keys if present.
Delete Scheduled Tasks
Open Task Scheduler (type "task scheduler" in Windows search). Expand Task Scheduler Library and review scheduled tasks for anything suspicious installed recently. Look for tasks with names like "GoblinsUpdate," tasks pointing to executables in %APPDATA% or %LOCALAPPDATA%, or tasks running with high frequency (every few minutes). Right-click suspicious tasks and delete them. On Mac, check Launch Agents and Launch Daemons folders in ~/Library and /Library for .plist files referencing unfamiliar applications.
Delete Hijacker Files and Folders
Navigate to %APPDATA% (type in Windows Explorer address bar) and look for folders with names related to Goblins or recently created folders with random names. Common locations include %APPDATA%\GoblinsOnline, %LOCALAPPDATA%\[random-name], and subfolders within browser user data directories. Delete these entire folders. Empty the Recycle Bin afterward. On Mac, check ~/Library/Application Support/ for similar folders.
Scan with Reputable Anti-Malware Tools
Reconnect to the internet and download Malwarebytes Free (from malwarebytes.com—verify the URL carefully). Run a full system scan to catch any components you might have missed. Malwarebytes specializes in detecting PUPs and browser hijackers. Quarantine or delete everything it finds. Consider following up with a scan using your primary antivirus software as well, though traditional antivirus programs sometimes miss PUPs classified as "potentially" unwanted rather than outright malicious.
Perform Complete Browser Reset
After removing all components, reset each affected browser to factory defaults. This clears any lingering configuration changes. In Chrome/Edge: Settings > Reset settings > Restore settings to original defaults. In Firefox: Help > More troubleshooting information > Refresh Firefox. Note that this will remove all extensions and reset all settings, but bookmarks and passwords typically remain. You'll need to reinstall legitimate extensions afterward.
Change Passwords and Verify Removal
Since the hijacker monitored your browsing activity, change passwords for important accounts (email, banking, shopping) from a confirmed-clean device or after verifying removal. Restart your computer and test your browsers thoroughly—open new tabs, perform searches, and verify your homepage loads correctly. Monitor for several days to ensure settings don't revert. If problems persist, the hijacker may have installed rootkit-level components requiring professional assistance.
Prevention
- Download software only from official sources. Avoid third-party download sites like Softonic or Brothersoft. Get applications directly from the developer's website or official app stores (Microsoft Store, Mac App Store). These sources screen for bundled PUPs more rigorously than aggregator sites.
- Always choose "Custom" or "Advanced" installation options. Never click through installer wizards using "Express" or "Recommended" settings. Custom installation reveals bundled components and pre-checked boxes for additional software. Uncheck everything except the program you actually want to install.
- Keep your browser and operating system updated. Browser hijackers sometimes exploit outdated software vulnerabilities. Enable automatic updates for your OS, browsers, and browser extensions. Most modern browsers patch aggressively; staying current significantly reduces infection risk.
- Install a reputable ad blocker. Extensions like uBlock Origin (not to be confused with the compromised "uBlock") block malicious advertising that can redirect to hijacker downloads. Ad blockers also prevent the fake update pop-ups that trick users into downloading hijackers disguised as legitimate software updates.
- Use DNS-level filtering. Services like Cloudflare's 1.1.1.1 for Families or OpenDNS block known malicious domains at the network level. Configuring these on your router provides protection for all devices on your network before threats reach individual computers.
- Review browser extensions monthly. Periodically audit your installed extensions and remove anything you don't actively use. Legitimate extensions sometimes get sold to malicious actors who transform them into data collectors or hijackers through "updates." Minimize your extension count to reduce this attack surface.
- Be skeptical of urgent update notifications. Legitimate software updates happen through built-in update mechanisms, not pop-up windows while browsing random websites. If you see an update notification, close it and manually check for updates through the application's own settings menu or the official website.
- Educate household members and employees. Many infections occur because family members or coworkers don't recognize installation tricks. Brief training on identifying deceptive download buttons and suspicious installers prevents infections more effectively than any security software.
Bring It In
Browser hijackers like Goblins.online.biz frustrate even technically proficient users with their persistence mechanisms and locked settings. If you've followed the removal steps above and your browser still redirects searches, settings still revert, or you're simply not comfortable editing the registry and removing scheduled tasks, we're here to help. At Computer Repair Roswell, we handle these infections daily—usually same-day—and we can eliminate not just the hijacker but also any secondary infections it may have downloaded while active on your system.
Call us at (770) 359-9020 or stop by our Roswell shop at 1650 Hembree Road. We'll run comprehensive scans with professional-grade tools, verify complete removal, and explain exactly how the infection occurred so you can avoid it in the future. Most hijacker removals are completed while you wait or within 24 hours for drop-offs. Your browser should work for you, not against you—let's get it back to normal.