GroupMeToday is a browser hijacker and potentially unwanted program (PUP) that forcibly redirects users to specific websites, typically search engines or advertising portals that generate revenue for its operators. This threat modifies browser settings without permission, changes your default search engine, and bombards you with intrusive advertisements while tracking your browsing activity. While not as destructive as ransomware or banking trojans, GroupMeToday degrades system performance, exposes you to further malware through deceptive ads, and compromises your online privacy by harvesting search queries and browsing patterns.
Like most browser hijackers, GroupMeToday typically arrives bundled with legitimate-looking freeware downloads or disguised as a helpful browser extension. Once installed, it establishes persistence mechanisms that make it frustratingly difficult to remove through normal uninstall procedures, often reinstalling itself even after you think you've cleared it from your system.
Threat Profile
| Attribute | Details |
|---|---|
| Threat Type | Browser Hijacker, Potentially Unwanted Program (PUP) |
| Malware Family | Adware/Search Hijacker category |
| Aliases | GroupMe Today, GroupMeToday extension, Search.groupmetoday.com hijacker |
| Affected Platforms | Windows (all versions), macOS; primarily targets Chrome, Firefox, Edge, Safari |
| Primary Distribution | Software bundling, deceptive browser extension installations, fake update prompts |
| Persistence Mechanisms | Browser extension policies, Windows scheduled tasks, registry Run keys, browser shortcut modification |
| Primary Capabilities | Search redirection, homepage/new tab hijacking, ad injection, browsing data collection, affiliate fraud |
| Data at Risk | Search queries, browsing history, clicked URLs, IP address, device identifiers, potentially form autofill data |
| Network Behavior | Frequent connections to ad servers, redirect domains, and tracking analytics platforms |
| Common Indicators | Changed homepage/search engine, excessive pop-up ads, slow browser performance, unauthorized toolbars |
| Removal Difficulty | Moderate — reinstalls itself if all components aren't removed; registry and scheduled task cleanup required |
| Severity Rating | Medium (privacy compromise and gateway to additional malware, but not immediately destructive) |
How It Spreads
GroupMeToday rarely announces itself honestly during installation. Instead, it piggybacks on software you actually want, using deceptive installation tactics that exploit the fact that most people click "Next" repeatedly without reading each screen. The operators behind browser hijackers pay legitimate software developers to bundle their PUPs with free utilities, download managers, video converters, and PDF tools. During installation, a pre-checked box or misleadingly worded screen slips GroupMeToday onto your system alongside the program you intended to install.
Another common infection vector involves fake browser update notifications that appear while you're browsing. These convincing pop-ups claim your Chrome, Firefox, or other browser is "out of date" and urge you to download an "urgent security update." Clicking the prompt downloads an executable that installs GroupMeToday instead of any legitimate update. Compromised websites hosting pirated software, key generators, or adult content frequently deploy these fake update screens.
GroupMeToday also spreads through:
- Malicious browser extensions — Advertised as productivity tools, weather widgets, or shopping assistants in third-party extension marketplaces or promoted through social media ads
- Email attachments — Malicious ZIP files or executables disguised as invoices, shipping confirmations, or document viewers that contain PUP installers
- Torrent downloads — Popular movies, games, or software titles whose installers have been modified to include browser hijackers
- Drive-by downloads — Compromised or malicious websites that exploit browser vulnerabilities or use social engineering to trigger automatic downloads
- Fake codec installers — Pop-ups claiming you need to install a "special player" or "codec pack" to view video content
- System optimization tools — Free registry cleaners, driver updaters, or PC speed-up utilities that bundle GroupMeToday in their installation packages
What It Does On Your Machine
Once GroupMeToday establishes itself on your system, it immediately reconfigures your web browsers. Your homepage gets redirected to a search portal controlled by the hijacker — typically something like search.groupmetoday.com or a similar domain. Your default search engine changes to route all queries through this portal, allowing the operators to inject sponsored results, track what you search for, and redirect you to advertising partners who pay for traffic. Every new tab you open may also default to this hijacked page instead of your preferred blank page or speed dial.
The visual annoyance is just the surface problem. GroupMeToday injects advertising scripts into websites you visit, creating pop-ups, banner ads, and inline text links that weren't part of the original page. These ads slow down page loading, consume bandwidth, and often promote questionable products or additional PUPs. More concerning, the injected ads sometimes link to malicious websites that attempt drive-by downloads or phishing schemes. You might click what looks like a legitimate download button only to trigger another malware installer.
Behind the scenes, GroupMeToday collects extensive data about your browsing behavior. It logs which websites you visit, what search terms you enter, which links you click, and how long you spend on various pages. This data gets transmitted to remote servers for behavioral profiling and sold to advertising networks or data brokers. While the hijacker typically doesn't target banking credentials or passwords directly, it creates the infrastructure that makes such theft easier for other malware components that might follow.
GroupMeToday's persistence mechanisms make casual removal attempts futile. Even after you uninstall the program through Windows Settings or delete the browser extension, scheduled tasks automatically reinstall it within hours or at the next system restart. Registry keys enforce browser policies that prevent you from changing your homepage or default search engine back to your preferences. Browser shortcuts get modified with command-line parameters that force navigation to the hijacker's homepage. This multi-layered approach means successful removal requires hunting down every component systematically.
Manual Removal — Step by Step
Disconnect From the Network and Document Current State
Before making any changes, disconnect your computer from the internet by unplugging the ethernet cable or disabling Wi-Fi. This prevents GroupMeToday from downloading additional components or updating its persistence mechanisms while you're removing it. Open Notepad and jot down which browser(s) you're seeing the hijacker in, what your homepage has been changed to, and any unusual programs you've noticed in your system tray. This documentation helps verify complete removal later.
Boot Into Safe Mode With Networking
Restart your computer and boot into Safe Mode, which loads Windows with minimal drivers and services, preventing GroupMeToday's startup processes from launching. On Windows 10/11, hold Shift while clicking Restart, then navigate to Troubleshoot > Advanced Options > Startup Settings > Restart, then press 5 for Safe Mode with Networking. Safe Mode with Networking allows you to download scanning tools if needed while still blocking most malware startup mechanisms. On macOS, restart and hold Shift immediately after hearing the startup chime.
Uninstall GroupMeToday and Related Programs
Open Windows Settings > Apps > Apps & features (or Control Panel > Programs and Features on older Windows versions). Sort the list by install date to identify recently added programs. Look for GroupMeToday, GroupMe Today, or any unfamiliar programs installed around the time your browser problems started — PUPs often travel in packs, so you may see multiple suspicious entries. Uninstall each one, carefully reading each screen during uninstallation because some PUP uninstallers try to trick you into keeping components. Decline all offers to keep "useful features" or install "alternative recommendations."
Remove Browser Extensions and Reset Browser Settings
Open each affected browser and navigate to its extensions/add-ons page (chrome://extensions in Chrome, about:addons in Firefox, edge://extensions in Edge). Remove GroupMeToday and any extensions you don't recognize or didn't intentionally install. Then reset your browser to default settings: in Chrome, go to Settings > Reset and clean up > Restore settings to their original defaults; in Firefox, type about:support in the address bar and click "Refresh Firefox." This clears the hijacked homepage, search engine, and startup pages while preserving your bookmarks and passwords.
Delete Scheduled Tasks That Reinstall the Hijacker
Press Windows+R, type taskschd.msc, and press Enter to open Task Scheduler. Click "Task Scheduler Library" in the left pane and carefully review the task list for anything containing "GroupMeToday," "Update," or unfamiliar publisher names. Right-click suspicious tasks and select Delete. Pay special attention to tasks that run at logon or daily — these are GroupMeToday's primary reinstallation mechanism. If you're unsure about a task, note its name and search online to verify it's not a legitimate Windows component before deleting.
Clean Registry Keys and Browser Policies
Press Windows+R, type regedit, and press Enter (click Yes at the UAC prompt). Navigate to HKEY_CURRENT_USER\Software and HKEY_LOCAL_MACHINE\SOFTWARE and delete any keys named "GroupMeToday" or obviously related variants. Then check HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome and HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Mozilla\Firefox for any ExtensionInstallForcelist or other policy entries that might reinstall the extension — delete these entire policy folders if present. Be extremely careful in the registry: only delete keys you're confident are related to GroupMeToday, as removing wrong entries can break Windows.
Delete Leftover Folders and Files
Open File Explorer and navigate to C:\Users\[YourUsername]\AppData\Local and C:\Users\[YourUsername]\AppData\Roaming (if you don't see AppData, enable "Hidden items" in the View tab). Look for folders named GroupMeToday or suspicious randomly-named folders created around your infection date. Delete these folders entirely. Also check C:\Program Files and C:\Program Files (x86) for any GroupMeToday installation directories. Empty your Recycle Bin afterward to ensure the files can't restore themselves.
Run Malwarebytes and a Secondary Scanner
Reconnect to the internet temporarily and download Malwarebytes (the free version works fine for one-time cleanup). Install it, update its definitions, and run a full Threat Scan — this catches components you might have missed and identifies any additional PUPs that rode in with GroupMeToday. After Malwarebytes finishes and quarantines anything it finds, run a second scan with a different tool like HitmanPro or AdwCleaner for verification. Multiple scanners catch different detection signatures, so this two-tool approach improves your chances of complete removal.
Check Browser Shortcuts for Command-Line Hijacking
Right-click your browser shortcuts (on desktop, taskbar, and Start menu) and select Properties. Look at the "Target" field — it should contain only the path to the browser executable, like "C:\Program Files\Google\Chrome\Application\chrome.exe" with nothing after it. If you see additional text after the .exe (especially URLs or unusual parameters), delete everything after chrome.exe, click Apply, then OK. Hijackers often append their homepage URL to the shortcut target, forcing their page to load even after you've cleaned everything else.
Reboot Normally and Verify Removal
Restart your computer normally (not in Safe Mode) and test each browser. Your homepage, new tab page, and default search engine should now reflect your chosen settings. Perform a few searches and browse normally for 15-20 minutes, watching for pop-up ads, redirects, or the hijacked pages reappearing. Check Task Manager (Ctrl+Shift+Esc) for unfamiliar processes running in the background. If everything looks clean and performs normally, removal was successful. If GroupMeToday returns, you likely missed a persistence mechanism — at this point, professional assistance can save you hours of frustration.
Prevention
- Download software only from official sources. Avoid third-party download sites, torrent repositories, and "free software" aggregators that bundle PUPs with legitimate programs. When you need a free utility, go directly to the developer's website rather than searching "download [program name]" and clicking the first result.
- Use Custom/Advanced installation for every program. Never click through an installer using Express/Recommended settings. Custom installation reveals bundled software offers that you can decline by unchecking boxes. Read every screen — PUP installers use confusing language like "I do NOT want to decline" to trick you into accepting unwanted software.
- Keep browsers and operating system updated through official channels. Enable automatic updates in Windows and your browsers so you receive legitimate security patches immediately. If you see an "update available" pop-up while browsing, close it and manually check for updates through the browser's Help menu or Windows Settings — legitimate updates never require downloading files from random websites.
- Install reputable browser extensions only from official stores. Get Chrome extensions exclusively from the Chrome Web Store, Firefox add-ons from addons.mozilla.org, and so on. Read reviews carefully and check how many users have installed an extension — millions of users and years of history indicate relative safety, while brand-new extensions with few users carry higher risk.
- Deploy ad-blocking and script-blocking extensions. Tools like uBlock Origin (not AdBlock Plus, which accepts paid ads) prevent many malicious ad networks from loading. Consider NoScript or similar extensions that block JavaScript by default on untrusted sites, though these require more technical comfort to use without breaking legitimate websites.
- Maintain active antivirus software with real-time protection. Windows Defender provides decent baseline protection if you keep it updated, but third-party solutions like Bitdefender or Kaspersky offer stronger detection of PUPs and browser hijackers. Ensure real-time protection stays enabled — scheduled scans alone won't catch threats during installation.
- Create a non-administrator daily-use account. Using Windows with a standard user account instead of an administrator account prevents many hijackers from installing without explicitly prompting you for admin credentials. When installation prompts appear unexpectedly, they're much more suspicious if they're asking for elevation when you didn't intentionally launch an installer.
- Be skeptical of aggressive advertising and urgency tactics. Legitimate companies don't use pop-ups claiming your computer is infected or your software is dangerously outdated. If an offer creates artificial urgency ("Act now! Limited time!") or seems too good to be true (premium software free, amazing deals unavailable elsewhere), it's probably delivering something you don't want alongside what it promises.
Bring It In
Browser hijackers like GroupMeToday frustrate people precisely because they're designed to resist casual removal attempts. You can spend hours following guides, deleting files, and editing the registry, only to have everything reappear after a restart because you missed one scheduled task or policy entry. That's not a reflection on your technical ability — it's malware doing exactly what its creators intended. If you've attempted removal and GroupMeToday keeps coming back, or if you simply don't want to risk making your situation worse by editing system files, bring your computer to our Roswell shop.
We see dozens of browser hijacker infections every month, and we've developed systematic procedures that eliminate them completely without the trial-and-error that wastes your time. Most PUP removals take us 45-90 minutes, and we'll have you back up and running the same day if you drop off in the morning. Call (770) 667-9472 to check our current turnaround time, or stop by our shop at 550 Sun Valley Drive during business hours — we're happy to take a quick look and give you an honest assessment of what needs to be done and what it'll cost. No surprises, no upselling services you don't need, just straightforward repair work that fixes the problem.