Hicanymearry.com is a browser hijacker that forcibly redirects your web searches and homepage settings to its own search portal, monetizing your browsing activity through affiliate commissions and ad revenue. This unwanted software typically arrives bundled with free downloads or through deceptive "update required" prompts, then embeds itself deeply into your browser settings to resist removal. While not technically a virus that replicates itself, browser hijackers like Hicanymearry.com compromise your privacy, slow your browsing experience, and expose you to potentially malicious advertising networks.

Hicanymearry.com — cybersecurity illustration
Photo by cottonbro studio on Pexels
If you're seeing Hicanymearry.com right now: Close your browser immediately if you're being redirected to unfamiliar sites. Don't enter passwords or payment information while the hijacker is active. The infection is contained to your browser and system settings—your files aren't encrypted—but you should address it today to prevent exposure to more dangerous threats through the ad networks it connects to. Skip to Manual Removal or call us at the shop if you'd rather not tackle this yourself.

Threat Profile

AttributeDetails
Threat ClassificationBrowser Hijacker / Potentially Unwanted Program (PUP)
FamilySearch redirect hijacker family
Also Known AsHicanymearry search, Hicanymearry redirect virus (misnomer), Search.hicanymearry.com
Affected PlatformsWindows (all versions), macOS (via browser extensions)
Targeted BrowsersGoogle Chrome, Mozilla Firefox, Microsoft Edge, Safari
Distribution MethodsSoftware bundling, fake update prompts, malicious browser extensions, freeware installers
Primary GoalSearch query redirection for affiliate revenue, advertising impressions, data collection
Persistence MechanismsModified browser shortcuts, extension policies, scheduled tasks, homepage/search engine overrides
Data at RiskSearch queries, browsing history, browser fingerprint data, potentially form autofill information
Network BehaviorRedirects through multiple intermediary domains before landing on search results or ad pages
Removal DifficultyModerate—requires browser reset, extension removal, shortcut cleanup, and registry edits on Windows

How It Spreads

Hicanymearry.com spreads primarily through software bundling, a distribution method where legitimate-looking free software includes the hijacker as an "optional" component that's pre-checked during installation. Most users click through setup wizards using the "Express" or "Recommended" settings without noticing the fine print that authorizes installation of additional software. The hijacker's distributors partner with freeware publishers who need to monetize their downloads, creating a supply chain that pushes these unwanted programs to thousands of computers daily.

Another common vector is fake update notifications that appear while you're browsing. These warnings claim your Flash Player, video codec, or browser is outdated and needs an immediate update. The download button leads not to a legitimate update but to an installer that drops the hijacker onto your system. These fake prompts are especially convincing because they mimic the styling of real browser notifications, and they often appear on otherwise legitimate websites that have been compromised or that sell advertising space without vetting the ads being displayed.

The hijacker also propagates through malicious browser extensions advertised on unofficial download sites or promoted through social media campaigns. Common distribution methods include:

  • Bundled software installers — Download managers, PDF converters, video downloaders, and "system optimizer" tools that include the hijacker as a silent install component
  • Fake browser update pages — Spoofed alert dialogs claiming your browser is out of date, displaying realistic logos and messaging
  • Malicious browser extensions — Add-ons promoted as productivity tools, coupons finders, or video downloaders that contain hijacking code
  • Email attachment macros — Less common but possible, where a document macro downloads and executes the installer
  • Drive-by downloads — Compromised websites that exploit browser vulnerabilities to push the installer without meaningful user consent
  • Social media scams — Links shared on Facebook or Twitter promising free content, prizes, or shocking videos that lead to hijacker installers

What It Does On Your Machine

Once installed, Hicanymearry.com makes systematic changes to your browser configuration to ensure it captures all your search traffic. It modifies your homepage setting so that Hicanymearry.com loads every time you open a new browser window. It changes your default search engine so that typing queries into the address bar routes through its servers instead of Google, Bing, or your preferred search provider. Most aggressively, it alters the "New Tab" page setting so that even opening a blank tab triggers a redirect to its search portal. These changes persist even after you manually reset them because the hijacker writes new values back into your browser's preference files within seconds of any correction you make.

The hijacker also installs browser extensions or add-ons that enforce its settings through extension policies. On Chrome, this might appear as an installed extension that lacks a visible icon in your toolbar but shows up in chrome://extensions with administrator privileges. On Firefox, it registers as a browser policy that overrides your manual preferences. These extensions often request broad permissions including "Read and change all your data on all websites," giving them the capability to monitor every site you visit and potentially intercept form data including login credentials.

Behind the scenes, Hicanymearry.com creates persistence mechanisms at the system level. On Windows machines, it commonly modifies browser shortcuts on your desktop, Start menu, and taskbar, appending the hijacker's URL as a launch parameter. Even if you reset your browser settings, launching from one of these poisoned shortcuts immediately loads the hijacker's page. The infection also establishes scheduled tasks that periodically check whether its browser settings are still in place and re-apply them if you've managed to remove them.

The financial motive behind Hicanymearry.com is straightforward: every search you conduct generates revenue through affiliate partnerships with legitimate search engines and through direct advertising. When you search for "Italian restaurants near me," the hijacker captures that query, routes it through several tracking servers to record the search for analytics purposes, then forwards it to a search partner like Yahoo or Bing (who pay for the referral traffic), and finally displays results mixed with additional sponsored listings that earn per-click commissions. You might ultimately see relevant results, but they've been filtered, reordered, and injected with extra advertisements to maximize the hijacker operator's income.

Typical Filesystem Artifacts (Windows)
C:\Users\\AppData\Local\\service.exe C:\Users\\AppData\Roaming\\Preferences // Modified JSON with hijacker URLs C:\ProgramData\\ // Installation folder, varies by variant
Registry Keys Modified (Windows)
HKCU\Software\Microsoft\Windows\CurrentVersion\Run HKCU\Software\Google\Chrome\Extensions\ HKCU\Software\Policies\Google\Chrome\ // Enforced homepage/search policies
Browser Shortcut Modifications
Target: "C:\Program Files\Google\Chrome\Application\chrome.exe" http://hicanymearry.com // Extra URL parameter forces hijacker load on launch
Scheduled Tasks
Task Name: or BrowserUpdateCheck Action: Runs every 30-60 minutes to verify hijacker persistence

Manual Removal — Step by Step

01

Disconnect and Document

Disconnect your computer from the internet by unplugging the Ethernet cable or disabling WiFi. This prevents the hijacker from communicating with its command servers and potentially downloading additional components. Before you start making changes, open Notepad and document your current browser homepage and search engine settings by writing down what you see—this helps you verify complete removal later. Take a screenshot of your browser's extension page showing what's currently installed.

02

Uninstall Suspicious Programs

Open the Windows Settings app (Windows 10/11) or Control Panel (Windows 7/8) and navigate to "Apps & Features" or "Programs and Features." Sort the list by install date and look for any programs you don't recognize that were installed around the time the redirects started. Common names include generic terms like "Web Companion," "Search Manager," "Browser Assistant," or random names with version numbers. Uninstall anything suspicious, paying attention to the uninstaller screens—some will try to convince you to keep the software or offer to install something else instead.

03

Remove Browser Extensions

Open your browser and navigate to the extensions page (Chrome: chrome://extensions, Firefox: about:addons, Edge: edge://extensions). Enable "Developer mode" if available to see all extensions including hidden ones. Remove any extensions you don't recognize or didn't intentionally install, especially those with vague names like "Helper," "Manager," or "SafeSearch." If an extension won't uninstall, note its ID—you may need to delete it manually from the filesystem or registry in later steps.

04

Clean Browser Shortcuts

Right-click every browser shortcut on your desktop, Start menu, and taskbar, then select "Properties." Look at the "Target" field—it should point only to the browser executable like "C:\Program Files\Google\Chrome\Application\chrome.exe" with nothing after the closing quote. If you see any website URL appended after the .exe path, delete everything from the http forward and click "Apply." Do this for every browser shortcut you use, including any pinned to the taskbar.

05

Reset Browser Settings

In your browser settings, use the built-in reset function to restore defaults. In Chrome, go to Settings → Reset Settings → "Restore settings to their original defaults." In Firefox, navigate to about:support and click "Refresh Firefox." In Edge, go to Settings → Reset Settings → "Restore settings to their default values." This will disable extensions, clear your homepage and search engine settings, and remove site permissions, but it preserves your bookmarks and passwords. After resetting, manually set your preferred homepage and search engine again.

06

Delete Filesystem Artifacts

Open File Explorer and navigate to %LOCALAPPDATA% (paste this in the address bar). Look for folders with random names, GUIDs, or generic names like "WebSearch" that contain executable files. Delete any suspicious folders, but be conservative—only remove folders you're confident are related to the hijacker. Also check %APPDATA% and %PROGRAMDATA% for similar artifacts. Empty your Recycle Bin afterward.

07

Clean Scheduled Tasks

Open Task Scheduler (type "Task Scheduler" in the Start menu search). In the Task Scheduler Library, look for tasks with generic names or that run frequently (every few minutes or hours) and execute programs from temporary folders or user directories. Right-click and delete any suspicious tasks. Common hijacker task names include variations of "Update," "BrowserCheck," or random alphanumeric strings. Be careful not to delete legitimate Windows or application tasks—if you're uncertain, search the task name online before deleting.

08

Scan With Malwarebytes

Reconnect to the internet and download Malwarebytes Free from the official website (malwarebytes.com). Install it and run a full "Threat Scan." Malwarebytes excels at detecting browser hijackers and PUPs that traditional antivirus software often misses because they're not technically viruses. Let the scan complete—it typically takes 20-45 minutes—then quarantine everything it finds. Reboot your computer after the scan completes and quarantine actions finish.

09

Verify and Monitor

Open your browser and manually navigate to several websites to confirm you're no longer being redirected to Hicanymearry.com. Type a search query directly into the address bar and verify it uses your chosen search engine, not the hijacker. Open a new tab and confirm it shows your preferred new tab page. Check that your homepage setting stayed at your chosen value. Monitor your browser for the next few days—if the hijacker reappears, it means you missed a persistence mechanism, likely a scheduled task or a registry policy, and you'll need to dig deeper or bring the machine to the shop.

10

Change Important Passwords

Because the hijacker had the technical capability to monitor your browsing through its extension permissions, change passwords for sensitive accounts—banking, email, social media, and shopping sites—especially if you logged into any of them while the hijacker was active. Use a different device or wait until you're confident the infection is completely removed before entering these new credentials on the affected machine.

Prevention

  1. Use Custom installation settings — Never click "Express Install" or "Recommended Settings" when installing free software. Always choose "Custom" or "Advanced" installation and read every screen carefully, unchecking any offers to install additional software, change your search engine, or modify your homepage. Legitimate software doesn't need to bundle extras.
  2. Download from official sources only — Get software directly from the publisher's website, never from third-party download sites like Softonic, Download.com, or CNET Downloads, which are notorious for wrapping legitimate installers in bundles that include PUPs. When searching for software, look for the "Official Site" designation in search results.
  3. Keep your browser updated — Enable automatic updates for your browser so you're protected against exploits that allow drive-by installations. Modern browsers will update themselves by default if you don't disable this feature. Ignore any webpage that tells you to download an update—browsers update themselves through their own internal mechanisms.
  4. Install an ad blocker — Use a reputable ad blocker extension like uBlock Origin (not to be confused with the similarly-named "uBlock") to prevent malicious advertisements from displaying. Many fake update prompts and hijacker distribution pages rely on advertising networks to reach victims. Ad blockers eliminate this vector almost entirely.
  5. Run periodic scans — Schedule weekly scans with Malwarebytes or a similar anti-malware tool even if you don't notice problems. Browser hijackers often operate quietly for weeks before you notice them, and early detection means easier removal with less data exposure.
  6. Review browser extensions quarterly — Set a calendar reminder to audit your browser extensions every three months. Remove anything you don't actively use. Extensions can update themselves with malicious functionality even if they were legitimate when you installed them, so ongoing vigilance matters more than initial vetting.
  7. Maintain a standard user account — For daily computing, use a Windows account with standard user privileges rather than administrator rights. This won't stop all PUP installations, but it creates an extra permission prompt that makes you think twice before authorizing installations that require administrator approval.
  8. Be skeptical of search results — When searching for software downloads, the first several results are often ads that lead to bundled installers rather than official sources. Scroll past the "Ad" listings and look for the actual publisher's website, or type the URL directly if you know it.
Our 90-Day Warranty: When we remove browser hijackers and other malware at Computer Repair Roswell, we back our work with a 90-day warranty. If the same infection returns within three months—and you haven't installed the risky software that brought it back—we'll clean it again at no charge. We also document the removal process so you understand what was found and what we did to eliminate it.

Bring It In

If you've tried these removal steps and you're still seeing Hicanymearry.com redirects, or if you'd rather not spend your afternoon digging through registry keys and browser settings, bring your computer to Computer Repair Roswell. We handle browser hijackers and PUP infections daily, and we have the diagnostic tools to find persistence mechanisms that manual removal often misses. More importantly, we verify that the hijacker hasn't opened the door for additional infections that are more dangerous than annoying—malware often travels in packs, with the visible hijacker serving as a distraction while trojans and information stealers work silently in the background.

Our shop is located in Roswell, Georgia, and we offer same-day service for most malware removals. You can call us at (770) 674-6342 to describe what you're experiencing and get an estimate, or just stop by during business hours with your machine. We'll perform a comprehensive scan, remove all traces of the hijacker including the persistence mechanisms that cause it to return after manual removal attempts, verify your browser security settings are properly configured, and make sure no additional threats came along for the ride. We also take time to explain what happened and how to avoid similar infections in the future—education is part of our service model because an informed customer is a customer who doesn't need to come back for the same problem.