Hicanymearry.com is a browser hijacker that forcibly redirects your web searches and homepage settings to its own search portal, monetizing your browsing activity through affiliate commissions and ad revenue. This unwanted software typically arrives bundled with free downloads or through deceptive "update required" prompts, then embeds itself deeply into your browser settings to resist removal. While not technically a virus that replicates itself, browser hijackers like Hicanymearry.com compromise your privacy, slow your browsing experience, and expose you to potentially malicious advertising networks.
Threat Profile
| Attribute | Details |
|---|---|
| Threat Classification | Browser Hijacker / Potentially Unwanted Program (PUP) |
| Family | Search redirect hijacker family |
| Also Known As | Hicanymearry search, Hicanymearry redirect virus (misnomer), Search.hicanymearry.com |
| Affected Platforms | Windows (all versions), macOS (via browser extensions) |
| Targeted Browsers | Google Chrome, Mozilla Firefox, Microsoft Edge, Safari |
| Distribution Methods | Software bundling, fake update prompts, malicious browser extensions, freeware installers |
| Primary Goal | Search query redirection for affiliate revenue, advertising impressions, data collection |
| Persistence Mechanisms | Modified browser shortcuts, extension policies, scheduled tasks, homepage/search engine overrides |
| Data at Risk | Search queries, browsing history, browser fingerprint data, potentially form autofill information |
| Network Behavior | Redirects through multiple intermediary domains before landing on search results or ad pages |
| Removal Difficulty | Moderate—requires browser reset, extension removal, shortcut cleanup, and registry edits on Windows |
How It Spreads
Hicanymearry.com spreads primarily through software bundling, a distribution method where legitimate-looking free software includes the hijacker as an "optional" component that's pre-checked during installation. Most users click through setup wizards using the "Express" or "Recommended" settings without noticing the fine print that authorizes installation of additional software. The hijacker's distributors partner with freeware publishers who need to monetize their downloads, creating a supply chain that pushes these unwanted programs to thousands of computers daily.
Another common vector is fake update notifications that appear while you're browsing. These warnings claim your Flash Player, video codec, or browser is outdated and needs an immediate update. The download button leads not to a legitimate update but to an installer that drops the hijacker onto your system. These fake prompts are especially convincing because they mimic the styling of real browser notifications, and they often appear on otherwise legitimate websites that have been compromised or that sell advertising space without vetting the ads being displayed.
The hijacker also propagates through malicious browser extensions advertised on unofficial download sites or promoted through social media campaigns. Common distribution methods include:
- Bundled software installers — Download managers, PDF converters, video downloaders, and "system optimizer" tools that include the hijacker as a silent install component
- Fake browser update pages — Spoofed alert dialogs claiming your browser is out of date, displaying realistic logos and messaging
- Malicious browser extensions — Add-ons promoted as productivity tools, coupons finders, or video downloaders that contain hijacking code
- Email attachment macros — Less common but possible, where a document macro downloads and executes the installer
- Drive-by downloads — Compromised websites that exploit browser vulnerabilities to push the installer without meaningful user consent
- Social media scams — Links shared on Facebook or Twitter promising free content, prizes, or shocking videos that lead to hijacker installers
What It Does On Your Machine
Once installed, Hicanymearry.com makes systematic changes to your browser configuration to ensure it captures all your search traffic. It modifies your homepage setting so that Hicanymearry.com loads every time you open a new browser window. It changes your default search engine so that typing queries into the address bar routes through its servers instead of Google, Bing, or your preferred search provider. Most aggressively, it alters the "New Tab" page setting so that even opening a blank tab triggers a redirect to its search portal. These changes persist even after you manually reset them because the hijacker writes new values back into your browser's preference files within seconds of any correction you make.
The hijacker also installs browser extensions or add-ons that enforce its settings through extension policies. On Chrome, this might appear as an installed extension that lacks a visible icon in your toolbar but shows up in chrome://extensions with administrator privileges. On Firefox, it registers as a browser policy that overrides your manual preferences. These extensions often request broad permissions including "Read and change all your data on all websites," giving them the capability to monitor every site you visit and potentially intercept form data including login credentials.
Behind the scenes, Hicanymearry.com creates persistence mechanisms at the system level. On Windows machines, it commonly modifies browser shortcuts on your desktop, Start menu, and taskbar, appending the hijacker's URL as a launch parameter. Even if you reset your browser settings, launching from one of these poisoned shortcuts immediately loads the hijacker's page. The infection also establishes scheduled tasks that periodically check whether its browser settings are still in place and re-apply them if you've managed to remove them.
The financial motive behind Hicanymearry.com is straightforward: every search you conduct generates revenue through affiliate partnerships with legitimate search engines and through direct advertising. When you search for "Italian restaurants near me," the hijacker captures that query, routes it through several tracking servers to record the search for analytics purposes, then forwards it to a search partner like Yahoo or Bing (who pay for the referral traffic), and finally displays results mixed with additional sponsored listings that earn per-click commissions. You might ultimately see relevant results, but they've been filtered, reordered, and injected with extra advertisements to maximize the hijacker operator's income.
Manual Removal — Step by Step
Disconnect and Document
Disconnect your computer from the internet by unplugging the Ethernet cable or disabling WiFi. This prevents the hijacker from communicating with its command servers and potentially downloading additional components. Before you start making changes, open Notepad and document your current browser homepage and search engine settings by writing down what you see—this helps you verify complete removal later. Take a screenshot of your browser's extension page showing what's currently installed.
Uninstall Suspicious Programs
Open the Windows Settings app (Windows 10/11) or Control Panel (Windows 7/8) and navigate to "Apps & Features" or "Programs and Features." Sort the list by install date and look for any programs you don't recognize that were installed around the time the redirects started. Common names include generic terms like "Web Companion," "Search Manager," "Browser Assistant," or random names with version numbers. Uninstall anything suspicious, paying attention to the uninstaller screens—some will try to convince you to keep the software or offer to install something else instead.
Remove Browser Extensions
Open your browser and navigate to the extensions page (Chrome: chrome://extensions, Firefox: about:addons, Edge: edge://extensions). Enable "Developer mode" if available to see all extensions including hidden ones. Remove any extensions you don't recognize or didn't intentionally install, especially those with vague names like "Helper," "Manager," or "SafeSearch." If an extension won't uninstall, note its ID—you may need to delete it manually from the filesystem or registry in later steps.
Clean Browser Shortcuts
Right-click every browser shortcut on your desktop, Start menu, and taskbar, then select "Properties." Look at the "Target" field—it should point only to the browser executable like "C:\Program Files\Google\Chrome\Application\chrome.exe" with nothing after the closing quote. If you see any website URL appended after the .exe path, delete everything from the http forward and click "Apply." Do this for every browser shortcut you use, including any pinned to the taskbar.
Reset Browser Settings
In your browser settings, use the built-in reset function to restore defaults. In Chrome, go to Settings → Reset Settings → "Restore settings to their original defaults." In Firefox, navigate to about:support and click "Refresh Firefox." In Edge, go to Settings → Reset Settings → "Restore settings to their default values." This will disable extensions, clear your homepage and search engine settings, and remove site permissions, but it preserves your bookmarks and passwords. After resetting, manually set your preferred homepage and search engine again.
Delete Filesystem Artifacts
Open File Explorer and navigate to %LOCALAPPDATA% (paste this in the address bar). Look for folders with random names, GUIDs, or generic names like "WebSearch" that contain executable files. Delete any suspicious folders, but be conservative—only remove folders you're confident are related to the hijacker. Also check %APPDATA% and %PROGRAMDATA% for similar artifacts. Empty your Recycle Bin afterward.
Clean Scheduled Tasks
Open Task Scheduler (type "Task Scheduler" in the Start menu search). In the Task Scheduler Library, look for tasks with generic names or that run frequently (every few minutes or hours) and execute programs from temporary folders or user directories. Right-click and delete any suspicious tasks. Common hijacker task names include variations of "Update," "BrowserCheck," or random alphanumeric strings. Be careful not to delete legitimate Windows or application tasks—if you're uncertain, search the task name online before deleting.
Scan With Malwarebytes
Reconnect to the internet and download Malwarebytes Free from the official website (malwarebytes.com). Install it and run a full "Threat Scan." Malwarebytes excels at detecting browser hijackers and PUPs that traditional antivirus software often misses because they're not technically viruses. Let the scan complete—it typically takes 20-45 minutes—then quarantine everything it finds. Reboot your computer after the scan completes and quarantine actions finish.
Verify and Monitor
Open your browser and manually navigate to several websites to confirm you're no longer being redirected to Hicanymearry.com. Type a search query directly into the address bar and verify it uses your chosen search engine, not the hijacker. Open a new tab and confirm it shows your preferred new tab page. Check that your homepage setting stayed at your chosen value. Monitor your browser for the next few days—if the hijacker reappears, it means you missed a persistence mechanism, likely a scheduled task or a registry policy, and you'll need to dig deeper or bring the machine to the shop.
Change Important Passwords
Because the hijacker had the technical capability to monitor your browsing through its extension permissions, change passwords for sensitive accounts—banking, email, social media, and shopping sites—especially if you logged into any of them while the hijacker was active. Use a different device or wait until you're confident the infection is completely removed before entering these new credentials on the affected machine.
Prevention
- Use Custom installation settings — Never click "Express Install" or "Recommended Settings" when installing free software. Always choose "Custom" or "Advanced" installation and read every screen carefully, unchecking any offers to install additional software, change your search engine, or modify your homepage. Legitimate software doesn't need to bundle extras.
- Download from official sources only — Get software directly from the publisher's website, never from third-party download sites like Softonic, Download.com, or CNET Downloads, which are notorious for wrapping legitimate installers in bundles that include PUPs. When searching for software, look for the "Official Site" designation in search results.
- Keep your browser updated — Enable automatic updates for your browser so you're protected against exploits that allow drive-by installations. Modern browsers will update themselves by default if you don't disable this feature. Ignore any webpage that tells you to download an update—browsers update themselves through their own internal mechanisms.
- Install an ad blocker — Use a reputable ad blocker extension like uBlock Origin (not to be confused with the similarly-named "uBlock") to prevent malicious advertisements from displaying. Many fake update prompts and hijacker distribution pages rely on advertising networks to reach victims. Ad blockers eliminate this vector almost entirely.
- Run periodic scans — Schedule weekly scans with Malwarebytes or a similar anti-malware tool even if you don't notice problems. Browser hijackers often operate quietly for weeks before you notice them, and early detection means easier removal with less data exposure.
- Review browser extensions quarterly — Set a calendar reminder to audit your browser extensions every three months. Remove anything you don't actively use. Extensions can update themselves with malicious functionality even if they were legitimate when you installed them, so ongoing vigilance matters more than initial vetting.
- Maintain a standard user account — For daily computing, use a Windows account with standard user privileges rather than administrator rights. This won't stop all PUP installations, but it creates an extra permission prompt that makes you think twice before authorizing installations that require administrator approval.
- Be skeptical of search results — When searching for software downloads, the first several results are often ads that lead to bundled installers rather than official sources. Scroll past the "Ad" listings and look for the actual publisher's website, or type the URL directly if you know it.
Bring It In
If you've tried these removal steps and you're still seeing Hicanymearry.com redirects, or if you'd rather not spend your afternoon digging through registry keys and browser settings, bring your computer to Computer Repair Roswell. We handle browser hijackers and PUP infections daily, and we have the diagnostic tools to find persistence mechanisms that manual removal often misses. More importantly, we verify that the hijacker hasn't opened the door for additional infections that are more dangerous than annoying—malware often travels in packs, with the visible hijacker serving as a distraction while trojans and information stealers work silently in the background.
Our shop is located in Roswell, Georgia, and we offer same-day service for most malware removals. You can call us at (770) 674-6342 to describe what you're experiencing and get an estimate, or just stop by during business hours with your machine. We'll perform a comprehensive scan, remove all traces of the hijacker including the persistence mechanisms that cause it to return after manual removal attempts, verify your browser security settings are properly configured, and make sure no additional threats came along for the ride. We also take time to explain what happened and how to avoid similar infections in the future—education is part of our service model because an informed customer is a customer who doesn't need to come back for the same problem.