Hickmous.com is a browser hijacker that forcibly redirects your web searches and homepage to its own search portal, generating revenue through manipulated traffic and advertising. This potentially unwanted program (PUP) installs itself through bundled software packages and misleading browser extensions, then locks down your browser settings to prevent easy removal. While not as destructive as ransomware or banking trojans, Hickmous.com degrades your browsing experience, exposes you to questionable advertisements, and tracks your online activity to build behavioral profiles for monetization.

Hickmous.com — cybersecurity illustration
Photo by Adventure Studio on Pexels

Once established, the hijacker modifies your default search engine, homepage, and new tab page across Chrome, Firefox, Edge, and other browsers. It employs persistence mechanisms that restore these unwanted changes even after you manually revert them, creating a frustrating cycle for users attempting DIY removal. The redirected searches often route through multiple intermediate domains before landing on legitimate search engines—a technique that allows the operators to collect referral commissions and behavioral data along the way.

Think you're infected right now? Disconnect from Wi-Fi or unplug your ethernet cable immediately. Do not enter passwords or financial information in your browser until the hijacker is removed. Browser hijackers monitor your activity and can redirect you to phishing sites designed to steal credentials. Skip to the removal section if you need to act quickly, or bring your machine to our Roswell shop for same-day service.

Threat Profile

Threat Type Browser Hijacker / Potentially Unwanted Program (PUP)
Aliases Hickmous redirect, Hickmous.com search hijacker, Search.hickmous.com
Affected Platforms Windows 7/8/10/11, macOS 10.12+
Affected Browsers Google Chrome, Mozilla Firefox, Microsoft Edge, Safari, Opera
First Observed Late 2018 (variants continue to circulate)
Primary Distribution Software bundlers, fake software updates, deceptive advertisements
Persistence Mechanisms Browser extension policies, scheduled tasks, registry Run keys (Windows), Launch Agents (macOS)
Core Capabilities Search redirection, homepage manipulation, ad injection, tracking cookie deployment, settings enforcement
Data Collection Search queries, browsing history, clicked links, geographic location, device identifiers
Network Behavior Connections to hickmous.com, search.hickmous.com, and various advertising networks; may proxy through multiple redirect domains
Removal Difficulty Moderate — browser hijackers typically require both system-level and browser-specific cleanup steps
Associated Risks Exposure to malicious ads, phishing page redirects, privacy erosion, potential secondary malware downloads

How It Spreads

Hickmous.com reaches your computer primarily through software bundling—the practice of packaging unwanted programs alongside legitimate free software. When you download a PDF converter, video codec, or system utility from a third-party download site, the installer often includes "optional offers" for browser toolbars, search helpers, or system optimizers. These offers appear in installation wizards with pre-checked boxes, misleading button layouts, or deliberately confusing language that tricks users into accepting them. The hijacker's authors pay software distributors to include their product, creating a financial incentive for this deceptive practice.

Beyond bundled installers, the hijacker exploits user trust through fake update notifications. You might see a convincing pop-up claiming your Flash Player, Java runtime, or video codec needs updating—clicking "Update" actually downloads the hijacker instead. Some variants also spread through malicious browser extensions advertised as productivity tools, coupon finders, or download managers. These extensions request broad permissions during installation, which users often grant without reading, then immediately begin modifying browser behavior.

Common infection vectors include:

  • Software bundles from download portals: Sites like Softonic, Download.com alternatives, and torrent aggregators frequently repackage installers with PUPs
  • Fake update alerts: Mimics of legitimate Adobe, Microsoft, or codec update prompts that appear on sketchy streaming sites or as pop-unders
  • Malicious browser extensions: Chrome Web Store and Firefox Add-ons occasionally host hijacker extensions before review teams remove them; off-store extensions carry higher risk
  • Email attachments with macro scripts: Less common for this specific hijacker, but Office documents with embedded scripts can download and install browser hijackers as part of a payload
  • Compromised advertising networks: Malvertising campaigns on legitimate sites can redirect users to pages that push installation prompts using social engineering
  • Peer-to-peer file sharing: Cracked software and pirated media often bundle multiple PUPs, with browser hijackers being among the most common passengers

What It Does On Your Machine

Once installed, Hickmous.com immediately takes control of your browser configuration. It changes your default search engine to search.hickmous.com, replaces your homepage with its portal page, and hijacks the new tab function so every new tab opens to its domain. These changes persist across browser restarts and resist manual correction through browser settings because the hijacker reinstalls its configuration via system-level hooks. In Chrome, this often involves manipulating the Preferences file and Local State configuration; in Firefox, it modifies prefs.js and user.js files directly or through browser policies.

The hijacker's revenue model centers on search redirect monetization. When you perform a search through the hijacked browser, your query routes through Hickmous.com's servers before reaching a legitimate search engine (typically Yahoo or Bing under a partnership agreement). This routing allows the operators to claim referral commissions for search traffic and inject sponsored results at the top of your results page. These sponsored links often lead to affiliate marketing sites, potentially unwanted software downloads, or occasionally phishing pages designed to harvest credentials. The hijacker may also inject advertisements directly into web pages you visit, replacing legitimate ads with its own inventory to capture additional revenue.

Behind the scenes, Hickmous.com deploys tracking mechanisms to build a behavioral profile of your browsing habits. It uses a combination of cookies, browser storage APIs, and server-side fingerprinting to collect your search terms, visited URLs, time spent on pages, clicked links, and device information. This data gets aggregated and sold to advertising networks or used to serve targeted ads through the hijacker's own channels. While the privacy policy (when one exists) typically claims data is "anonymized," the granular detail collected often allows for re-identification when cross-referenced with other data sources.

System-level persistence ensures the hijacker survives basic removal attempts. On Windows machines, it typically creates scheduled tasks that re-apply browser configurations at login or periodic intervals. It may also install a stub executable in a hidden folder that monitors browser processes and restores hijacker settings when it detects changes. On macOS, similar functionality comes from Launch Agents or Launch Daemons that execute scripts to modify browser plists and preference files. The hijacker usually avoids traditional antivirus detection by not exhibiting outright malicious behaviors—it doesn't encrypt files, steal banking credentials directly, or damage system files—allowing it to operate in a legal gray area that complicates automatic detection.

Typical filesystem and registry artifacts for Hickmous.com hijacker:
Windows locations: %LOCALAPPDATA%\Hickmous\hickmous_updater.exe %APPDATA%\Mozilla\Firefox\Profiles\[random].default\prefs.js %LOCALAPPDATA%\Google\Chrome\User Data\Default\Preferences %PROGRAMFILES(X86)%\HickmousHelper\ Windows Registry keys: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\HickmousUpdater HKLM\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist HKCU\Software\Mozilla\Firefox\Extensions Windows Scheduled Tasks: Task Scheduler Library\HickmousUpdate Task Scheduler Library\HickmousBrowserCheck macOS locations: ~/Library/Application Support/Hickmous/ ~/Library/LaunchAgents/com.hickmous.helper.plist ~/Library/Application Support/Google/Chrome/Default/Preferences Note: Exact paths may vary by variant and installation method

Manual Removal — Step by Step

01

Disconnect from the network

Unplug your ethernet cable or disable Wi-Fi to prevent the hijacker from receiving configuration updates or downloading additional components during removal. This also stops real-time tracking of your removal attempts, which some sophisticated hijackers use to adapt their persistence mechanisms.

02

Boot to Safe Mode with Networking

Restart your computer into Safe Mode (hold Shift while clicking Restart on Windows 10/11, then navigate Troubleshoot → Advanced → Startup Settings → Restart → press F5). Safe Mode loads only essential drivers and prevents the hijacker's startup tasks from executing, making it easier to delete files and modify settings without interference. Reconnect to the internet once in Safe Mode—you'll need it for downloading scanning tools.

03

Uninstall suspicious programs

Open Settings → Apps → Apps & Features (or Control Panel → Programs and Features on Windows 7/8). Sort by install date and look for unfamiliar programs installed around the time your browser problems began. Common names include variations of "Hickmous," "Web Helper," "Search Protect," or generic names like "System Updater." Uninstall anything you don't recognize and didn't intentionally install, but exercise caution with legitimate software—when in doubt, search the program name online first.

04

Remove malicious browser extensions

Open each browser you use and navigate to the extensions/add-ons management page (chrome://extensions, about:addons in Firefox, edge://extensions). Remove any extensions you don't recognize, didn't install yourself, or that lack proper developer information. Pay special attention to extensions with names related to search helpers, download managers, or productivity tools installed recently. Don't just disable them—fully remove them, as disabled extensions can sometimes reactivate.

05

Delete scheduled tasks

Open Task Scheduler (search for it in the Start menu), expand Task Scheduler Library, and look for entries with suspicious names containing "hickmous," "update," "browser," or random alphanumeric strings created by unknown publishers. Right-click and delete these tasks. On macOS, navigate to ~/Library/LaunchAgents/ and /Library/LaunchAgents/ (system-wide) and delete any .plist files you don't recognize, particularly those with "hickmous" or generic names in their filenames.

06

Clean registry Run keys (Windows only)

Press Win+R, type "regedit," and press Enter to open the Registry Editor. Navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. Look for entries you don't recognize, particularly those pointing to paths in %LOCALAPPDATA%, %APPDATA%, or %PROGRAMFILES% containing "hickmous" or random folder names. Right-click suspicious entries and delete them. Create a registry backup first (File → Export) in case you need to undo changes.

07

Remove the hijacker's files

Navigate to %LOCALAPPDATA% (paste this into Windows Explorer's address bar) and %APPDATA%, then look for folders named "Hickmous," "HickmousHelper," or folders with GUIDs or random names created on the infection date. Delete these entire folders. On macOS, check ~/Library/Application Support/ for similar folders. Also check Program Files and Program Files (x86) for any related directories. Empty your Recycle Bin afterward to fully remove the files.

08

Reset browser settings completely

In Chrome, go to Settings → Reset settings → Restore settings to their original defaults. In Firefox, type about:support in the address bar, then click "Refresh Firefox." In Edge, Settings → Reset settings → Restore settings to their default values. This removes hijacked homepage/search settings, clears extension-installed configurations, and resets your new tab page. You'll need to reconfigure your preferences and re-add legitimate extensions afterward, but it ensures no hijacker configurations remain.

09

Scan with Malwarebytes and a second-opinion scanner

Download Malwarebytes (from malwarebytes.com only—avoid third-party download sites) and run a full Threat Scan. Follow up with a second scan using either Hitman Pro or AdwCleaner to catch anything the first scan missed. Browser hijackers often install alongside other PUPs, so multiple scanners improve your odds of complete removal. Quarantine or delete everything flagged by these tools.

10

Change passwords from a clean device

If you entered passwords while the hijacker was active, change them immediately—but do it from a different device or after you're confident the infection is gone. Browser hijackers track keystrokes on some sites and can redirect login pages to phishing clones. Prioritize email, banking, and any accounts with financial access. Enable two-factor authentication where available to add a layer of protection against credential theft.

11

Reboot normally and verify removal

Restart your computer in normal mode and immediately check your browser's homepage, search engine, and new tab page. Perform a test search and verify it goes directly to your chosen search engine without routing through Hickmous.com or redirect chains. Open Task Manager (Ctrl+Shift+Esc) and review running processes for anything suspicious. If the hijacker returns, you likely missed a persistence mechanism—consider professional removal at that point.

Prevention

  1. Download software only from official sources. Avoid third-party download sites like Softonic, CNET Download, and Brothersoft, which frequently bundle PUPs with their installers. Get software directly from the developer's website or from Microsoft Store, Mac App Store, or verified repositories. When you must use a download aggregator, choose the "Direct Download Link" option rather than the site's installer wrapper.
  2. Use the custom/advanced installation option. Never click through installation wizards on Express or Recommended settings. Choose Custom or Advanced installation and read every screen carefully. Uncheck boxes for optional software, toolbars, browser changes, or homepage modifications. Legitimate software respects your choice to decline bundled offers; if an installer won't let you proceed without accepting extras, find a different source for the software.
  3. Keep browsers and extensions minimal and updated. Install only extensions you actively use from official stores (Chrome Web Store, Firefox Add-ons, Microsoft Edge Add-ons). Review your extension list monthly and remove anything you haven't used in 90 days. Enable automatic updates for your browser so security patches install promptly—many hijackers exploit outdated browser vulnerabilities to bypass permissions.
  4. Deploy reputable ad-blocking and anti-tracking extensions. Tools like uBlock Origin (not uBlock) and Privacy Badger reduce your exposure to malicious advertisements and tracking scripts that serve as infection vectors. Configure them to block third-party scripts by default on unfamiliar sites. This won't prevent bundled software infections, but it dramatically reduces drive-by download attempts from compromised ad networks.
  5. Treat update prompts with skepticism. Legitimate software updates arrive through the application itself or through Windows Update/Mac Software Update, not as pop-up windows on websites. When you see an update prompt while browsing, close it and manually check for updates through the software's official update mechanism. Never download "required codecs" or "missing plugins" from streaming sites.
  6. Run periodic scans even when nothing seems wrong. Schedule a monthly Malwarebytes scan during off-hours. Browser hijackers and other PUPs can operate silently for weeks before becoming obtrusive, and early detection prevents them from entrenching persistence mechanisms. Free versions of Malwarebytes and AdwCleaner work fine for on-demand scanning.
  7. Create a standard user account for daily work. On Windows, run as a standard user rather than an administrator for everyday tasks. Many hijackers require administrative privileges to install system-level persistence mechanisms; standard accounts limit what software can install without explicit authorization. This single change prevents a significant percentage of automated PUP installations.
  8. Back up your browser profile regularly. Bookmark exports and password manager backups let you recover quickly from browser infections without losing important data. Store these backups separately from your browser profile folder so infections can't corrupt them. Cloud-synced password managers like Bitwarden or 1Password provide additional protection since they're isolated from browser-level hijackers.
Our 90-day warranty: When Computer Repair Roswell removes a browser hijacker from your system, we guarantee it stays gone. If the same infection returns within 90 days through no fault of your own, we'll remove it again at no charge. We don't just clean the visible symptoms—we dig out the persistence mechanisms and close the security gaps that allowed the infection in the first place.

Bring It In

Browser hijackers like Hickmous.com occupy a frustrating middle ground—more persistent than simple adware but less immediately threatening than ransomware, which makes them easy to procrastinate on addressing. That procrastination costs you in privacy erosion, potential exposure to worse threats through malicious advertising, and the compounding frustration of fighting with your own computer. If you've tried the manual removal steps above and the hijacker keeps returning, or if you're simply not comfortable editing registries and deleting system files, professional removal is the efficient solution.

Bring your computer to our Roswell shop at 1394 Canton Road (we're in the Roswell Plaza shopping center, same building as Happy Belly). No appointment necessary—we handle most browser hijacker removals same-day, typically within 2-3 hours depending on how deeply the infection has embedded itself. Call us at (770) 637-1435 if you have questions about symptoms or want a quote, or just stop by during business hours. We'll clean the infection, verify all persistence mechanisms are gone, update your security software, and show you exactly what allowed the hijacker in so you can avoid it going forward. That's the level of thoroughness that comes with our 90-day warranty—we don't consider the job done until your machine is genuinely clean and you understand how to keep it that way.