GuessWhatNews.com is a browser hijacker that forcibly redirects your web traffic through its domains, manipulates your search results, and tracks your browsing activity to generate advertising revenue. This potentially unwanted program (PUP) typically infiltrates systems bundled with free software downloads, then modifies browser settings without explicit permission. While not a virus in the traditional sense, GuessWhatNews.com degrades browser performance, exposes you to questionable advertising networks, and creates privacy risks through persistent data collection.

GuessWhatNews.com — cybersecurity illustration
Photo by Ann H on Pexels

Users affected by this hijacker report sudden changes to their homepage and default search engine, unexpected redirects when clicking legitimate search results, and an overall sluggish browsing experience. The hijacker proves difficult to remove through standard uninstallation because it deploys multiple persistence mechanisms across browsers and the Windows registry.

Think you're infected right now? Disconnect from the internet if you're entering passwords or accessing financial accounts. GuessWhatNews.com primarily tracks browsing habits, but the advertising networks it connects to may serve malicious content. Don't attempt to "search your way out" of the problem—the hijacker controls what results you see. Skip down to our removal section or call us at (770) 856-1090 for immediate assistance.

Threat Profile

Attribute Details
Threat Classification Browser Hijacker / Potentially Unwanted Program (PUP)
Family Search redirect hijacker family (behavior similar to SearchMine, SearchBaron variants)
Aliases Redirect.GuessWhatNews, GuessWhatNews redirect virus, guesswhatnews.com hijacker
Targeted Platforms Windows 7/8/10/11 (all editions); affects Chrome, Firefox, Edge, Internet Explorer
Distribution Method Software bundling, fake update prompts, deceptive advertisements, freeware installers
Primary Payload Browser extension + registry modifications + scheduled task persistence
Persistence Mechanisms Registry Run keys, browser shortcuts modification, scheduled tasks, extension policies
Data Collection Search queries, browsing history, clicked URLs, geolocation (IP-based), device identifiers
Network Behavior Redirects through multiple domains (guesswhatnews.com → intermediary → search provider/ad page)
Typical Indicators Homepage changed to guesswhatnews.com or search.guesswhatnews.com, new tab page overridden, "Managed by your organization" message in Chrome
Associated Files Browser extension files in user profile directories, randomly-named executables in %LOCALAPPDATA% or %APPDATA%
Removal Difficulty Moderate—requires manual browser reset and registry cleaning after standard removal attempts

How It Spreads

GuessWhatNews.com rarely arrives alone. The operators behind this hijacker partner with software bundling networks that package the unwanted program with legitimate-looking free applications. When users download video converters, PDF tools, system optimizers, or media players from third-party download sites, the installer may include GuessWhatNews.com as an "optional offer" pre-checked by default. Many users click through installation wizards using the "Express" or "Recommended" options without noticing the bundled components.

The hijacker also spreads through deceptive advertising campaigns that mimic legitimate software update notices. You might see convincing fake alerts claiming your Flash Player, Java, or browser needs an urgent security update. Clicking these prompts downloads an installer that appears to update the software but actually delivers the hijacker alongside (or instead of) any legitimate update.

Common distribution vectors include:

  • Software bundling networks: Free download sites (not official vendor pages) that repackage installers with PUPs included
  • Fake update prompts: Pop-ups on sketchy streaming sites or torrent pages claiming critical updates are required
  • Malvertising campaigns: Compromised ad networks serving malicious advertisements on otherwise legitimate websites
  • Email attachments: Less common but documented—phishing emails with "invoice" or "receipt" attachments that download PUP installers
  • Peer-to-peer networks: Cracked software and keygen tools that include browser hijackers as additional payloads
  • Browser extension stores (unauthorized): Fake extensions mimicking popular tools, sometimes briefly available before removal from official stores

What It Does On Your Machine

Once installed, GuessWhatNews.com immediately targets your browser configuration. It modifies the homepage, default search engine, and new tab page settings to point toward its own domains. The hijacker typically installs a browser extension or injects policies that prevent you from changing these settings back through normal methods—when you attempt to restore your preferred homepage, it reverts to GuessWhatNews.com within seconds or after the next browser restart.

The hijacker intercepts your search queries by routing them through its servers before displaying results. This man-in-the-middle position allows it to log everything you search for, inject sponsored results at the top of the page, and redirect you through advertising affiliate networks that generate revenue per click. You'll notice that clicking search results sometimes takes you through one or more intermediate redirects before reaching the intended destination, if you reach it at all. Some clicks lead to advertising landing pages completely unrelated to your search.

Performance degradation is common because the hijacker loads additional scripts, trackers, and advertising content on every page you visit. Your browser may become noticeably slower, tabs may freeze occasionally, and you might see increased memory usage in Task Manager. The hijacker communicates with remote command-and-control servers to receive updated advertising targets and configuration changes, creating constant background network activity.

Typical GuessWhatNews.com Filesystem and Registry Artifacts
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\[random_extension_id]\ %APPDATA%\Mozilla\Firefox\Profiles\[profile]\extensions\{random-guid} HKCU\Software\Microsoft\Windows\CurrentVersion\Run GuessWhatNewsUpdater # Points to updater executable HKLM\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist 1 = "[extension_id];https://clients2.google.com/service/update2/crx" HKCU\Software\Microsoft\Internet Explorer\Main Start Page = "http://guesswhatnews.com/?..." Search Page = "http://search.guesswhatnews.com/?..." C:\Program Files (x86)\[Vendor Name]\ # Service executable folder C:\Users\[username]\AppData\Roaming\[Random]\updater.exe Scheduled Task: "GuessWhatNews Update Task" # Runs hourly to restore settings

The privacy implications deserve serious consideration. GuessWhatNews.com collects your search terms, visited URLs, time stamps, IP address, and browser fingerprint information. This data gets sold to advertising networks and data brokers who build detailed profiles of your interests and online behavior. While the hijacker doesn't typically steal passwords or credit card numbers directly, it creates vulnerabilities by exposing you to additional malware through the questionable advertising networks it partners with. Some users report encountering tech support scams, fake antivirus warnings, and other malicious content after the hijacker redirects them to compromised advertising networks.

Manual Removal — Step by Step

01

Disconnect and Document

Disconnect from your network (unplug ethernet or disable Wi-Fi) to prevent the hijacker from receiving configuration updates during removal. Take a screenshot of your current browser homepage and note any unfamiliar browser extensions before you begin—this documentation helps verify complete removal later. Boot into Safe Mode with Networking by holding Shift while clicking Restart, then selecting Troubleshoot > Advanced Options > Startup Settings > Restart > press F5.

02

Uninstall Suspicious Programs

Open Settings > Apps > Apps & features (Windows 10/11) or Control Panel > Programs > Uninstall a program (Windows 7/8). Sort by installation date and look for programs installed around the time the hijacker appeared. Uninstall anything you don't recognize, especially entries with generic names like "System Updater," "Web Companion," or publisher names you've never heard of. The GuessWhatNews.com hijacker might appear under a completely different program name.

03

Remove Malicious Browser Extensions

Open each browser you use and remove suspicious extensions. In Chrome: three-dot menu > Extensions > Manage Extensions—remove anything unfamiliar. In Firefox: three-bar menu > Add-ons and themes > Extensions—remove unknowns. In Edge: three-dot menu > Extensions—remove suspicious items. If you see "Managed by your organization" in Chrome, the hijacker has installed policy-based extensions that require registry cleaning (covered in step 5).

04

Terminate Persistent Processes

Press Ctrl+Shift+Esc to open Task Manager. Look in the Processes tab for unfamiliar entries running from %LOCALAPPDATA% or %APPDATA% folders with random names. Right-click suspicious processes, select "Open file location," then end the process. Note the file location—you'll need to delete these files manually. Check the Startup tab and disable any entries that appear suspicious or match the program names you uninstalled.

05

Clean the Windows Registry

Press Win+R, type "regedit" and press Enter. Navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and look for entries pointing to random executable names or paths you documented earlier—delete these entries. Check HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\ for "ExtensionInstallForcelist" keys and delete the entire Chrome key if present. Search the registry (Ctrl+F) for "guesswhatnews" and delete any keys or values found. Back up your registry before making changes (File > Export).

06

Delete Scheduled Tasks

Press Win+R, type "taskschd.msc" and press Enter to open Task Scheduler. Click "Task Scheduler Library" and look through the task list for entries with suspicious names (often generic like "Update Task" or including partial strings like "GuessWhat"). Select suspicious tasks, note the "Actions" tab to see what executable they run, then right-click and delete the task. This prevents the hijacker from restoring itself on schedule.

07

Remove Hijacker Files Manually

Navigate to the file locations you documented in step 4. Common locations include C:\Users\[YourName]\AppData\Local\[RandomFolder]\ and C:\Users\[YourName]\AppData\Roaming\[RandomFolder]\. Delete entire folders associated with the hijacker. You may need to show hidden files first (File Explorer > View tab > check "Hidden items"). If deletion fails with "file in use" errors, reboot to Safe Mode and try again.

08

Reset Browser Settings Completely

In Chrome: Settings > Reset and clean up > Restore settings to their original defaults > Reset settings. In Firefox: three-bar menu > Help > More troubleshooting information > Refresh Firefox. In Edge: Settings > Reset settings > Restore settings to their default values. This clears homepage hijacks, search engine changes, and residual extension configurations. You'll need to sign back into websites afterward, but bookmarks are preserved.

09

Scan with Reputable Anti-Malware

Reconnect to your network and download Malwarebytes Free from the official website (malwarebytes.com—don't search for it, as the hijacker may redirect you to fake versions). Run a full "Threat Scan" which typically takes 30-60 minutes. Quarantine everything it finds. Follow up with a Windows Defender full scan (Windows Security > Virus & threat protection > Scan options > Full scan) as a second opinion. Different scanners catch different remnants.

10

Verify Removal and Change Passwords

Restart your computer normally and open your browsers to verify your homepage and search engine have returned to normal. Try searching for a few terms to confirm results aren't being redirected. Check Task Manager (Ctrl+Shift+Esc) to ensure no suspicious processes have reappeared. As a precaution, change passwords for important accounts (email, banking, social media) from a confirmed-clean device, since browser hijackers can theoretically capture credentials through the tracking scripts they inject.

Prevention

  1. Download software only from official sources. Go directly to the vendor's website rather than using third-party download sites like Softonic, Download.com, or CNET Downloads. These aggregator sites often repackage installers with bundled PUPs even for legitimate software.
  2. Always choose "Custom" or "Advanced" installation. Never click through installers using "Express" or "Recommended" options. The Custom path reveals bundled offers and optional components that you can deselect before installation proceeds.
  3. Read each installer screen carefully. Bundled PUPs are legally disclosed but intentionally obscured—look for pre-checked boxes, misleading button labels ("Decline" positioned where you expect "Next"), and fine print mentioning additional software or homepage changes.
  4. Keep Windows and browsers updated. Enable automatic updates for Windows, Chrome, Firefox, and Edge. Security patches close vulnerabilities that hijackers exploit. Legitimate updates never require downloading executables from pop-up prompts.
  5. Use browser security extensions judiciously. A reputable ad blocker (uBlock Origin) and script manager (NoScript or uMatrix for advanced users) prevents many malicious advertisements and drive-by downloads. Install extensions only from official browser stores after reading reviews.
  6. Maintain real-time antivirus protection. Windows Defender provides solid baseline protection if kept updated. Consider adding Malwarebytes Premium for real-time anti-exploit and anti-PUP protection. Configure your antivirus to scan downloads automatically.
  7. Be skeptical of urgent update warnings. If you see a pop-up claiming your browser, Flash Player, or Java needs an immediate update while browsing, close the window and manually check for updates through the software's own menu. Legitimate updates don't ambush you on random websites.
  8. Create standard user accounts for daily use. Run Windows with a standard (non-administrator) account for everyday browsing and work. PUPs and hijackers have more difficulty installing system-wide persistence without administrative privileges. Use your admin account only when intentionally installing trusted software.
Our 90-Day Reinfection Guarantee: When Computer Repair Roswell removes malware from your system, we stand behind our work. If the same threat returns within 90 days through no fault of your own, we'll remove it again at no additional charge. We also provide a written summary of what we found and removed, plus personalized prevention recommendations for your specific situation.

Bring It In

Browser hijackers like GuessWhatNews.com prove frustrating to remove completely because they scatter components across your system and employ multiple persistence tricks. If you've followed these steps but still see redirects, changed homepages that won't stay fixed, or suspicious processes reappearing after reboot, the hijacker likely installed additional components we haven't covered. Some variants install rootkit-like drivers or create Windows services that require specialized removal tools and expertise to eliminate safely.

Computer Repair Roswell has cleaned hundreds of hijacker infections from local customers' machines. We use professional-grade diagnostic tools to identify every component, remove all persistence mechanisms, and verify your browsers are truly clean before returning your computer. Our techs work in Roswell at 1161 Alpharetta Street—call us at (770) 856-1090 to schedule a same-day appointment or drop off your machine. Most hijacker removals are completed within 24 hours, and we'll show you exactly what we found so you understand how it got there and how to avoid it in the future. Don't waste another day fighting redirected searches and unwanted advertisements—bring it in and let us handle it properly.