Gstudent.anmi.com is a browser hijacker that forcibly redirects your web searches and homepage to a Chinese-language search portal. This potentially unwanted program (PUP) typically arrives bundled with freeware installers and immediately reconfigures Chrome, Firefox, Edge, or other browsers to funnel your search queries through its own server. While not a virus in the traditional sense, it compromises your browsing privacy, exposes you to aggressive advertising, and can track your search habits for monetization purposes. Users across the United States have reported this hijacker persisting even after attempting to change their browser settings back.
Like most browser hijackers, Gstudent.anmi.com generates revenue through search redirects and affiliate marketing. Each search you perform through its portal earns money for the operators. The hijacker modifies critical browser configurations—including default search engine, new tab page, and homepage—then employs persistence mechanisms to prevent you from reverting these changes. Beyond the annoyance factor, the redirected searches may lead to low-quality results, sketchy sponsored links, or even malicious sites depending on your query.
Threat Profile
| Attribute | Details |
|---|---|
| Family | Browser Hijacker / Search Redirect |
| Aliases | Gstudent redirect, Anmi.com hijacker, Gstudent.anmi search virus |
| Platform | Windows (all versions); also affects macOS via extension bundles |
| First Observed | Approximately 2019–2020 (variants still active) |
| Distribution Method | Software bundling, fake updaters, deceptive download buttons, potentially pirated software installers |
| Targeted Browsers | Google Chrome, Mozilla Firefox, Microsoft Edge, Internet Explorer (legacy systems) |
| Persistence Mechanism | Browser extension (managed/forced install), Group Policy overrides, registry modifications for default search provider, scheduled tasks restoring settings |
| Primary Behavior | Homepage/new-tab hijacking, search query redirection to gstudent.anmi.com, injection of tracking scripts |
| Data Collection | Search queries, browsing history, clicked URLs, geographic location (IP-based), device identifiers |
| Network Traffic | HTTPS connections to gstudent.anmi.com and associated CDN domains; beaconing to tracking endpoints on page loads |
| Payload Delivery | Typically installs via MSI/EXE wrapper that drops browser extension files and helper executables |
| Removal Difficulty | Moderate—requires manual extension removal, settings reset, and cleanup of scheduled tasks or Group Policy overrides |
How It Spreads
Gstudent.anmi.com spreads almost exclusively through software bundling—a deceptive practice where legitimate-looking freeware installers quietly include additional "offers" during setup. Users downloading video converters, PDF tools, download managers, or pirated software from third-party sites are the primary targets. The hijacker is presented as an "optional" component during installation, but the checkbox is often pre-checked, buried in an "Advanced" or "Custom" installation screen that most people skip, or worded confusingly ("Enhance your search experience with our partner search engine").
Beyond bundling, the hijacker also spreads through fake software update prompts that appear on sketchy websites. These mimics of Adobe Flash or Java update dialogs convince users to download an executable that installs the hijacker instead of—or alongside—the claimed update. Torrent sites, free streaming portals, and shady download aggregators are common hosts for these fake updaters. Once you run the installer, the hijacker deploys silently in the background while the "real" software (if any) installs normally.
- Bundled freeware/shareware installers: Video downloaders, codec packs, PDF converters, system optimizers from non-official sources
- Fake update notifications: Fraudulent Flash, Java, Chrome, or media player update prompts on low-quality websites
- Malvertising: Malicious ads on legitimate sites that trigger drive-by downloads when clicked
- Pirated software cracks/keygens: Warez sites bundle hijackers and worse into activation tools
- Trojanized browser extensions: Extensions uploaded to third-party extension stores (or even briefly to Chrome Web Store before takedown)
What It Does On Your Machine
Once installed, Gstudent.anmi.com immediately modifies your browser configuration. Your homepage and new tab page are changed to gstudent.anmi.com or a redirect URL leading there. Your default search engine—the one invoked when you type a query in the address bar—is replaced with a search provider that routes all queries through the hijacker's server. In Chrome, this is enforced via an extension with administrator privileges or via Group Policy settings that prevent you from changing it back manually. In Firefox, the hijacker modifies prefs.js or installs a browser extension that overrides user preferences on every startup.
Each search query you enter is sent to the hijacker's backend server before being forwarded (often) to a legitimate search engine like Baidu or Bing. This man-in-the-middle position lets the operators log your searches, inject sponsored results at the top of the page, and track which links you click. The hijacker also injects JavaScript tracking beacons into pages you visit, building a profile of your browsing habits. This data is monetized through affiliate marketing (the hijacker earns commissions when you click certain sponsored results) or sold to advertising networks.
Beyond search hijacking, Gstudent.anmi.com often installs a helper executable on disk that acts as a watchdog process. This executable runs at startup and monitors your browser settings. If you manually reset your homepage or default search engine, the watchdog detects the change within seconds and reverts it back to the hijacker's values. This creates the frustrating loop where users change settings, close the browser, reopen it, and find everything hijacked again. Some variants also install scheduled tasks that re-apply the hijacker settings periodically or reinstall the browser extension if you manage to delete it.
Manual Removal — Step by Step
Disconnect from the Internet
Unplug your Ethernet cable or turn off Wi-Fi. This prevents the hijacker from beaconing home, downloading additional components, or receiving configuration updates that might complicate removal. Work offline until the cleanup is complete.
Boot into Safe Mode with Networking
Restart your computer and press F8 (Windows 7) or hold Shift while clicking Restart (Windows 8/10/11) to access the boot options menu. Select "Safe Mode with Networking." This loads only essential drivers and prevents the hijacker's watchdog process from starting automatically, making removal much easier.
Uninstall Suspicious Programs
Open Settings > Apps (or Control Panel > Programs and Features on older Windows). Sort by install date. Look for any program installed around the same time the hijacking began—especially anything with "Gstudent," "Search Enhance," "WebNavigator," or generic names like "Updater" or "Helper." Uninstall it. The hijacker may also hide under a legitimate-sounding name, so scrutinize unfamiliar entries installed recently.
Remove the Browser Extension
Open Chrome and navigate to chrome://extensions/. Enable "Developer mode" in the top-right corner to see extension IDs. Look for any extension you didn't intentionally install, especially those that cannot be disabled (grayed-out toggle). Note the extension's folder name (the long ID string), then quit Chrome completely. Navigate to C:\Users\<YourName>\AppData\Local\Google\Chrome\User Data\Default\Extensions\ and delete the folder matching that ID. Repeat for Firefox (about:addons) and Edge (edge://extensions/).
Delete the Hijacker's Installation Folder
Open File Explorer and navigate to C:\Users\<YourName>\AppData\Local\. Look for a folder with a random GUID name (curly braces with letters/numbers) created around the infection date. Inside you'll likely find executables named "gstudent_helper.exe," "updater.exe," or similar. Delete the entire folder. If Windows says the file is in use, reboot into Safe Mode again or use Task Manager to end any process running from that folder first.
Clean the Windows Registry and Scheduled Tasks
Press Win+R, type regedit, and press Enter. Navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and delete any value referencing the hijacker executable. Also check HKEY_CURRENT_USER\Software\Policies\Google\Chrome for forced homepage/search settings and delete the entire Chrome key if present (it will be recreated cleanly). Then press Win+R, type taskschd.msc, and open Task Scheduler. Look for tasks named "GstudentTask" or anything suspicious scheduled at logon—delete them.
Reset Browser Settings
In Chrome, go to Settings > Reset settings > Restore settings to their original defaults. This clears the hijacked homepage, search engine, and startup pages in one action. In Firefox, type about:support in the address bar and click "Refresh Firefox." In Edge, go to Settings > Reset settings > Restore settings to their default values. This won't delete your bookmarks or saved passwords, but it will remove extensions and custom settings.
Run Malwarebytes or Another Reputable Scanner
Download Malwarebytes Free (from malwarebytes.com only) and run a full system scan. Even if you've manually removed the obvious components, hijackers often drop additional tracking cookies, registry keys, or helper files that a good anti-malware tool will catch. Quarantine and delete anything it finds. Consider running a second-opinion scanner like HitmanPro or AdwCleaner for thoroughness.
Change Passwords for Sensitive Accounts
If you logged into email, banking, or other critical accounts while the hijacker was active, change those passwords from a known-clean device (or after completing this removal and rebooting). Browser hijackers can log form data and keystrokes related to search queries. While Gstudent.anmi.com is primarily a search redirect, treat any credentials entered during the infection period as potentially compromised.
Reboot Normally and Verify Removal
Restart your computer in normal mode (not Safe Mode). Reconnect to the internet. Open your browser and check that your homepage, new tab page, and default search engine are back to your preferred settings (or the browser defaults). Perform a test search in the address bar—it should go through Google, Bing, or whatever you've chosen, not gstudent.anmi.com. If the hijacker reappears, you likely missed a scheduled task or a secondary watchdog process; return to steps 5 and 6.
Prevention
- Download software only from official sources. Get Chrome from google.com/chrome, VLC from videolan.org, and so on. Third-party download sites (Softonic, Download.com, CNET) often bundle PUPs into their custom installers even for legitimate programs.
- Always choose "Custom" or "Advanced" installation. Never click through an installer on "Express" or "Recommended" mode. Read every screen. Uncheck any pre-ticked boxes offering toolbars, browser changes, or "partner offers."
- Keep a reputable anti-malware tool running. Free versions of Malwarebytes or Windows Defender (built into Windows 10/11) catch most browser hijackers during installation if real-time protection is enabled. Update definitions daily.
- Use an ad-blocker with anti-malvertising lists. Extensions like uBlock Origin block the malicious ads and fake download buttons that lead to hijacker installers. This reduces the risk of accidental clicks on deceptive "Download" buttons.
- Avoid pirated software and cracks. Warez sites are the number-one distribution vector for bundled malware. If you can't afford software, look for legitimate free alternatives (GIMP instead of Photoshop, LibreOffice instead of Microsoft Office) rather than risking keygens and cracked installers.
- Disable or delete Adobe Flash. Flash reached end-of-life in December 2020. Any prompt to "update Flash" today is guaranteed to be malicious. Uninstall Flash Player entirely if it's still on your system.
- Enable click-to-play plugins in your browser. This prevents random scripts from executing automatically when you visit a page, reducing drive-by download risks. Most modern browsers have moved to this model by default.
- Review installed extensions periodically. Once a month, check your browser's extension list and remove anything you don't recognize or no longer use. Hijackers sometimes sneak in and sit dormant for weeks before activating.
Bring It In
If the manual removal steps above feel overwhelming, or if the hijacker keeps coming back no matter what you try, it's time to let professionals handle it. Browser hijackers like Gstudent.anmi.com are deliberately designed to resist casual removal attempts—watchdog processes, Group Policy overrides, and hidden scheduled tasks make self-service cleanup a frustrating game of whack-a-mole. Our technicians at Computer Repair Roswell have the tools and experience to eliminate hijackers completely, usually in under an hour. We'll also check for any secondary infections (hijackers rarely travel alone) and optimize your system so it boots faster and runs cleaner than before.
We're located right here in Roswell, Georgia, and we've been rescuing local computers from malware since 2004. Bring your laptop or desktop to our shop—no appointment needed—or give us a call at (770) 695-6720 to describe what's happening. We offer free diagnostics, transparent flat-rate pricing, and same-day service for most malware removals. You'll leave with a machine that's genuinely clean, not just temporarily hijacker-free, and you'll know exactly how to avoid this mess in the future. Stop fighting with gstudent.anmi.com and let us handle it for good.