GukThwaalsoExinfo is a browser hijacker that forcibly redirects search queries and homepage settings through a series of unfamiliar search engines, generating ad revenue for its operators while degrading your browsing experience. This PUP (potentially unwanted program) typically arrives bundled with freeware installers and immediately modifies browser configurations across Chrome, Firefox, Edge, and other popular browsers. Once installed, it proves remarkably persistent, resisting standard uninstallation attempts and reappearing even after seemingly successful removal.
Users infected with GukThwaalsoExinfo report constant redirects to suspicious search portals, altered new-tab pages, and a flood of intrusive advertisements that weren't present before. The hijacker doesn't encrypt files or steal banking credentials like more aggressive malware, but it does collect browsing data, slow system performance, and expose you to potentially malicious sites through forced redirects.
Threat Profile
| Attribute | Details |
|---|---|
| Family | Browser Hijacker / PUP |
| Alternative Names | Guk.Thwaalso.Exinfo, GukThwaalso redirect, Thwaalso search hijacker |
| Platforms Affected | Windows 7/8/10/11, macOS (limited variants), all major browsers |
| Discovery Period | Active variants identified 2019–present |
| Distribution Method | Software bundling, fake updates, deceptive download buttons, torrents |
| Persistence Mechanisms | Browser extension policies, scheduled tasks, registry Run keys, shortcut target modification |
| Primary Capabilities | Search redirection, homepage hijacking, new-tab replacement, ad injection, tracking cookie installation |
| Data Collection | Search queries, browsing history, clicked links, system information, geolocation data |
| Network Behavior | Establishes connections to third-party ad networks, tracking domains, and redirect chains; typical for this hijacker family |
| Common Redirect Domains | Multiple intermediary search engines before reaching final destination (often legitimate search with affiliate parameters) |
| File System Presence | Browser extension folders, %APPDATA% subdirectories, %LOCALAPPDATA% installer remnants |
| Removal Difficulty | Moderate — standard removal fails; requires manual browser reset and registry cleaning |
How It Spreads
GukThwaalsoExinfo rarely travels alone. The hijacker's distributors partner with freeware developers who need monetization options, offering payment in exchange for bundling the hijacker with legitimate installers. When you download a free PDF converter, video codec pack, or system optimizer from a third-party download site, the installer presents multiple screens of checkboxes and "recommended" add-ons. GukThwaalsoExinfo hides in these screens, often pre-checked or described with misleading language like "Enhanced Search Experience" or "Optimized Browser Settings."
The bundling technique exploits user behavior during installation. Most people click "Next" rapidly without reading each screen, especially when the installer uses dark patterns like putting the "Decline" option in small gray text while highlighting "Accept" in bright colors. Some variants employ even more deceptive tactics, such as split installations where declining the bundled offer on one screen doesn't prevent a second component from installing through a later prompt.
Beyond software bundling, GukThwaalsoExinfo spreads through several additional vectors:
- Fake update notifications — Websites display pop-ups claiming your Flash Player, Chrome, or Java is out of date, with a download button that delivers the hijacker instead of legitimate software
- Torrent files and cracked software — Pirated applications frequently include hijackers as part of the "crack" or keygen, which users willingly run with administrator privileges
- Malicious advertisements — Compromised ad networks occasionally serve malvertising that exploits browser vulnerabilities or tricks users into downloading "required" components
- Email attachments — Less common for this specific hijacker, but some variants arrive as .zip or .exe attachments in emails disguised as invoices, shipping notifications, or software licenses
- Extension marketplaces — Though major stores like Chrome Web Store screen submissions, some hijackers slip through with legitimate-looking descriptions, then update to hijacking behavior after approval
- Search engine poisoning — The hijacker's affiliates occasionally use SEO manipulation to rank malicious downloads highly for popular search terms like "free video converter download"
What It Does On Your Machine
Upon installation, GukThwaalsoExinfo immediately targets your browser configuration files. It modifies the default search engine setting, changing it from Google or Bing to an unfamiliar search portal with names that try to sound legitimate. Your homepage gets replaced, and every new tab opens to the hijacker's designated page rather than your preferred setting. These changes persist even when you manually reset them through browser settings because the hijacker installs policy overrides or browser extensions with elevated permissions that reapply the changes.
The redirects follow a predictable but frustrating pattern. When you type a search query into the address bar, the request gets intercepted and sent through multiple redirect hops. You might see the URL bar flash through two or three different domains before finally landing on a search results page. This redirect chain serves multiple purposes: it obscures the hijacker's infrastructure, allows multiple parties to collect your search data, and triggers additional ad impressions at each hop. The final search results page displays legitimate results (often powered by Yahoo or Bing in the background) but injected with additional sponsored results and tracking parameters that generate revenue for the hijacker's operators.
Performance degradation becomes noticeable quickly. Each redirect adds latency to your searches, making browsing feel sluggish. The hijacker's background processes consume CPU cycles monitoring your browser activity and communicating with command servers. Memory usage increases because the hijacker often runs a helper process outside the browser to reinstall itself if you delete the extension. You'll notice higher data usage as well, since the hijacker continuously transmits information about your browsing habits to remote servers.
Data collection represents another significant concern. GukThwaalsoExinfo monitors every website you visit, every search term you enter, and every link you click. This information gets packaged with your IP address, browser type, operating system, and approximate location based on your IP, then transmitted to the hijacker's servers. While the operators claim this data gets anonymized and used only for "improving user experience," it typically gets sold to advertising networks and data brokers. The privacy implications extend beyond mere annoyance—your search history might reveal medical conditions, financial situations, or personal interests you'd prefer to keep private.
Manual Removal — Step by Step
Disconnect and Boot to Safe Mode
Unplug your ethernet cable or disable WiFi immediately to prevent the hijacker from receiving updates or reinstalling components from remote servers. Restart your computer and tap F8 (Windows 7) or hold Shift while selecting Restart (Windows 8/10/11) to access the boot menu. Select "Safe Mode with Networking" so you can download scanning tools if needed, but the limited startup environment will prevent most hijacker processes from launching.
Uninstall Suspicious Programs
Open Control Panel (search for it in the Start menu) and go to "Programs and Features" or "Add or Remove Programs." Sort by installation date and look for anything installed around the time redirects started. Uninstall any programs you don't recognize, especially those with generic names like "System Optimizer," "PC Cleaner," or anything containing "Guk" or "Thwaalso." Right-click and select Uninstall, following all prompts completely.
Remove Browser Extensions Manually
Open each browser you use and access its extensions or add-ons page (typically chrome://extensions for Chrome, about:addons for Firefox, edge://extensions for Edge). Look for any extensions you didn't intentionally install, paying special attention to those with vague names or no ratings. Remove these extensions completely. If the "Remove" button is grayed out, the extension was installed via enterprise policy and you'll need to address that in the registry (covered in step 6).
Delete Scheduled Tasks
Open Task Scheduler by searching for it in the Start menu. Expand "Task Scheduler Library" and look through the list for tasks with names like "GukThwaalso," "Browser Configuration," "Update Service," or anything else suspicious. Right-click any hijacker-related tasks and select Delete. Check the properties of questionable tasks first to see what program they're running—if it points to a folder in AppData with a random name, it's almost certainly malicious.
Clean Registry Run Keys
Press Windows+R to open the Run dialog, type "regedit" and press Enter. Navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and look for any entries that reference GukThwaalso, unknown GUIDs in AppData\Local, or suspicious executable names. Right-click and delete these entries. Repeat for HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run. Make sure you're only deleting hijacker entries—removing legitimate startup programs could cause issues with other software.
Remove Forced Browser Policies
Still in Registry Editor, navigate to HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome (or the equivalent path for your browser). Look for keys named "ExtensionInstallForcelist," "HomepageLocation," or "DefaultSearchProviderName." If these keys exist and you didn't create them through corporate policy, delete the entire Chrome key under Policies. This removes the mechanism the hijacker uses to reinstall itself even after you've removed the extension. Repeat for any other browsers under the Policies folder.
Delete Hijacker Files and Folders
Open File Explorer and enable viewing of hidden files (View tab → Options → View → Show hidden files). Navigate to C:\Users\[YourUsername]\AppData\Local and look for folders with random GUID names or anything containing "Guk" or "Thwaalso." Delete these entire folders. Do the same in AppData\Roaming and check C:\Program Files and C:\Program Files (x86) for any folders installed by the hijacker. If Windows prevents deletion because a file is in use, you'll need to identify and terminate the process in Task Manager first.
Reset Browser Settings Completely
Open your browser and navigate to its reset settings option (usually under Settings → Advanced → Reset). Choose "Restore settings to their original defaults" which will disable all extensions, clear temporary data, and reset your homepage and search engine. This won't delete your bookmarks or saved passwords. Repeat for every browser installed on your system, even ones you don't regularly use, since the hijacker often infects all browsers simultaneously.
Scan with Reputable Anti-Malware
Download Malwarebytes Free (from malwarebytes.com directly, not a download portal) and run a full system scan. Let it remove everything it finds. Follow up with a scan using your regular antivirus if you have one, or download Microsoft Safety Scanner as a second opinion. These tools catch remnants that manual removal might miss, including registry entries in less obvious locations and browser cache files that could re-trigger the infection.
Change Passwords and Verify Removal
Since the hijacker tracked your browsing activity, change passwords for important accounts (email, banking, social media) from a known-clean device if possible, or after verifying the infection is gone. Reboot your computer normally and test browsing behavior. Search for something in your browser's address bar—the results should go directly to your chosen search engine without redirects. Open several new tabs to confirm they show your designated new-tab page. Monitor for a few days to ensure the hijacker doesn't reappear.
Prevention
- Download software only from official sources. Get programs directly from the developer's website, not from third-party download portals like download.com, softonic.com, or similar aggregators. These sites frequently bundle PUPs with legitimate installers, even when the original software is clean. If you must use a download site, carefully examine every installer screen and decline all optional offers.
- Choose Custom installation every time. Never click "Express" or "Recommended" installation when installing software. Custom or Advanced installation modes reveal bundled components that express installation auto-accepts. Read each screen, uncheck any pre-checked boxes for additional software, and decline browser modifications explicitly. This takes thirty extra seconds but prevents hours of removal work.
- Keep browsers and operating system updated. Enable automatic updates for Windows and all browsers you use. Updates patch security vulnerabilities that some hijackers exploit for installation. Browser updates also improve built-in protection against malicious extensions and sites, reducing the chance that a hijacker successfully modifies your configuration even if it gets onto your system.
- Install and maintain reputable security software. Use Windows Defender at minimum (it's built-in and effective), or invest in a quality third-party antivirus. Consider adding Malwarebytes Premium for real-time protection against PUPs specifically. Configure the software to scan downloads automatically and block known malicious sites. Update definitions daily to catch new hijacker variants.
- Review browser extensions quarterly. Open your extensions page once every few months and remove anything you don't actively use or don't remember installing. Hijackers sometimes sneak in during other installations or update legitimate extensions to add hijacking behavior. If you notice an extension you don't recognize, remove it immediately and run a full scan.
- Be skeptical of update notifications. Legitimate software updates through the application itself or through Windows Update—not through pop-ups on random websites. If a website tells you to update Flash, Java, or your browser, close the page and check for updates through the official application or the vendor's website. Flash is actually discontinued entirely, so any Flash update notification is definitely fake.
- Use browser protections. Enable Chrome's "Safe Browsing" (or equivalent in other browsers), which warns before you visit known malicious sites. Consider using browser extensions like uBlock Origin that block malicious ads and tracking, reducing exposure to malvertising. Some browsers like Brave include aggressive anti-tracking features by default.
- Avoid pirated software and suspicious torrents. Cracked software, keygens, and pirated content are extremely high-risk for bundled malware including hijackers. The money you save isn't worth the time spent dealing with infections and the risk of more serious malware. If you absolutely can't afford software, look for legitimate free alternatives rather than pirated versions of commercial software.
When we remove browser hijackers, trojans, or other malware from your system, that work comes with a 90-day warranty. If the same infection returns within three months, we'll clean it again at no additional charge. We also provide specific guidance for your situation to prevent reinfection, and we're here to answer questions even after your service is complete.
Bring It In
Manual removal works for many people, but GukThwaalsoExinfo and similar hijackers evolve constantly with new persistence mechanisms. If you've followed these steps and still see redirects, or if the technical steps feel overwhelming, bring your computer to our Roswell shop. We handle these infections daily and have specialized tools that catch remnants manual removal misses. More importantly, we verify that nothing more serious came bundled with the hijacker—sometimes browser hijackers arrive alongside credential stealers or remote access trojans that represent much bigger threats.
Computer Repair Roswell is located on Alpharetta Street in Roswell, Georgia, and we offer same-day service for malware removal with no appointment necessary during business hours. Call us at (770) 637-1434 or stop by with your infected machine. We'll run a thorough diagnostic, remove the hijacker and any other infections we find, optimize your system's performance, and show you exactly what we discovered so you understand what happened. Most importantly, we'll make sure your machine is truly clean before you take it home, not just temporarily free of symptoms. The peace of mind is worth the drive.