Hizens.xyz is a browser hijacker that forces unwanted changes to your web browser's search engine, homepage, and new-tab page, redirecting all searches through its own domain. This particular hijacker belongs to a widespread family of search-redirect threats that generate revenue by routing user traffic through affiliate advertising networks. While not as destructive as ransomware or data-stealing trojans, Hizens.xyz compromises your browsing experience, exposes you to potentially malicious advertising, and can serve as a foothold for additional unwanted software installations.
Like most browser hijackers, Hizens.xyz typically arrives bundled with free software downloads or disguised as a helpful browser extension. Once installed, it modifies browser settings in ways that resist simple removal attempts, often reinstalling itself even after you manually change your homepage back. The hijacker tracks your search queries and browsing habits to profile your interests for targeted advertising, raising significant privacy concerns beyond the nuisance factor.
Threat Profile
| Attribute | Details |
|---|---|
| Threat Family | Browser Hijacker / Potentially Unwanted Program (PUP) |
| Primary Aliases | Hizens.xyz redirect, Hizens search hijacker, Hizens.xyz virus |
| Affected Platforms | Windows 7/8/10/11; affects Chrome, Firefox, Edge, and other Chromium-based browsers |
| Distribution Method | Software bundling, fake updates, malicious browser extensions, deceptive pop-up advertisements |
| Persistence Mechanisms | Browser extension installation, modified browser shortcuts, scheduled tasks, registry modifications, browser policies |
| Primary Capabilities | Search redirection, homepage hijacking, new-tab replacement, tracking cookie deployment, advertisement injection |
| Data Collection | Search queries, browsing history, clicked links, IP address, geographic location, system information |
| Typical Artifacts | Browser extensions with randomized names, modified browser preference files, tracking cookies, scheduled tasks for reinstallation |
| Network Behavior | Persistent DNS queries to Hizens.xyz and associated advertising domains, HTTP redirects through multiple affiliate networks |
| Associated Risks | Privacy violation, exposure to malvertising, additional PUP installations, reduced browser performance, potential phishing exposure |
| Removal Difficulty | Moderate — uses multiple persistence mechanisms that must all be addressed |
| Damage Potential | Low to moderate — primarily nuisance and privacy concerns, but can facilitate more serious infections |
How It Spreads
Hizens.xyz rarely arrives alone or announces itself honestly. The most common infection vector is software bundling, where the hijacker is packaged with legitimate-looking free software downloaded from third-party hosting sites. During installation, users who click through setup screens quickly without reading the fine print inadvertently agree to install "additional offers" that include the browser hijacker. These bundled installers often use deceptive interface designs that make the unwanted components appear to be part of the main program or pre-check opt-in boxes in low-contrast text.
Another significant distribution method involves fake browser update notifications. Users visiting compromised websites or sites hosting malicious advertising may encounter pop-ups claiming their browser is out of date or that a critical security update is required. Clicking these deceptive prompts downloads an installer that appears to update the browser but actually installs Hizens.xyz and potentially other unwanted programs. Some variants also spread through malicious browser extensions advertised as productivity tools, ad-blockers, or video downloaders that instead hijack browser settings.
Common distribution methods include:
- Free software bundles — Download managers, PDF converters, video players, and other utilities from third-party sites that package the hijacker as an "optional offer"
- Fake update notifications — Deceptive pop-ups mimicking legitimate browser or Flash Player update prompts
- Malicious browser extensions — Extensions offering desirable features but containing hijacker code in their permissions and background scripts
- Malvertising campaigns — Compromised advertising networks serving malicious ads that trigger drive-by downloads or social engineering attacks
- Email attachments — Less common, but some variants distribute through phishing emails with infected attachments masquerading as documents or invoices
- Torrent and peer-to-peer files — Cracked software and pirated content frequently bundled with browser hijackers and other PUPs
What It Does On Your Machine
Once installed, Hizens.xyz immediately modifies your browser configuration to redirect all search activity through its own domain. When you type a search query into your browser's address bar or use the search box, instead of going directly to your chosen search engine like Google or Bing, your query first passes through Hizens.xyz. The hijacker logs your search terms and other identifying information, then redirects you through one or more intermediate advertising affiliate networks before eventually delivering search results (often from a legitimate search engine, making the hijacking less obvious to casual users).
The hijacker typically changes three critical browser settings: your default search engine, your homepage (the page that loads when you open your browser), and your new-tab page (what appears when you open a new tab). Even if you manually change these settings back to your preferences, the hijacker uses various persistence mechanisms to revert them. It may install a browser extension with elevated permissions that continuously monitors and resets these settings, modify browser policy files that override user preferences, or create scheduled tasks that reapply the hijacker configuration at regular intervals.
Beyond search redirection, Hizens.xyz actively tracks your browsing activity. It deploys tracking cookies and may inject scripts into web pages you visit to monitor which links you click, how long you spend on different sites, and what content interests you. This behavioral data builds an advertising profile used to target you with specific ads—or sold to third-party data brokers. The hijacker may also inject additional advertisements into web pages, display pop-up ads even on sites that normally don't have them, or replace legitimate ads with its own, redirecting advertising revenue away from content creators.
The presence of Hizens.xyz often correlates with degraded browser performance. Users typically notice slower page loading times, increased memory usage, and occasional browser freezing or crashes. Each redirect adds latency to your searches, and the continuous tracking and ad injection consume system resources. More concerning, browser hijackers like Hizens.xyz sometimes serve as delivery mechanisms for additional unwanted software, with their affiliate networks occasionally distributing more aggressive adware, fake security scanners, or even malware through the advertising streams they control.
Manual Removal — Step by Step
Disconnect from the Network
Unplug your ethernet cable or disable Wi-Fi before beginning removal. This prevents the hijacker from communicating with its command servers, downloading additional components, or uploading your browsing data. Some browser hijackers attempt to reinstall themselves by downloading fresh copies during removal attempts, so working offline eliminates this possibility.
Uninstall Suspicious Programs
Open Control Panel > Programs and Features (or Settings > Apps on Windows 10/11) and sort by installation date. Look for programs installed around the time the browser redirects started, especially those you don't recognize or didn't intentionally install. Uninstall anything suspicious, particularly programs with generic names, no publisher information, or names suggesting browser enhancement or update functionality.
Remove Malicious Browser Extensions
In Chrome, navigate to chrome://extensions/ and enable "Developer mode" in the top-right corner to see extension IDs. Remove any extensions you don't recognize, didn't install, or that have suspicious permissions (especially those requesting access to "read and change all your data on websites you visit"). Repeat this process for all browsers installed on your system—Firefox (about:addons), Edge (edge://extensions/), etc.
Reset Browser Search and Homepage Settings
In Chrome, go to Settings > Search engine and set your preferred default search engine, then click "Manage search engines" and remove any entries related to Hizens.xyz. Next, visit Settings > On startup and configure your preferred startup behavior, removing any Hizens.xyz URLs. Check Settings > Appearance and ensure "Show home button" displays your chosen homepage. Perform equivalent steps in Firefox (Options > Home, Options > Search) and other browsers.
Check Browser Shortcut Properties
Right-click your browser's desktop or taskbar shortcut and select Properties. Examine the "Target" field—it should end with the browser executable (chrome.exe, firefox.exe, etc.) and nothing else. If you see any URLs or additional parameters after the .exe, delete them and click Apply. Some hijackers append their redirect URL to the shortcut target so the hijacker loads every time you launch the browser.
Remove Browser Policies and Scheduled Tasks
Press Win+R, type "taskschd.msc" and press Enter to open Task Scheduler. Review the Task Scheduler Library for any suspicious tasks (especially those running browser executables or executables from temporary folders) and delete them. Next, press Win+R again, type "regedit" and navigate to HKEY_CURRENT_USER\Software\Policies\Google\Chrome (or equivalent for other browsers). If you see keys setting DefaultSearchProviderSearchURL, HomepageLocation, or other forced settings, delete the entire browser key under Policies. Restart your computer.
Delete Residual Files
Press Win+R, type "%localappdata%" and press Enter. Look for folders with random names, GUID-format names (long strings of letters and numbers in curly braces), or names suggesting browser helpers or updaters. Delete any suspicious folders. Check %programfiles% and %programfiles(x86)% for similar suspicious folders. Empty the Recycle Bin when finished.
Scan with Reputable Anti-Malware Software
Reconnect to the internet and download a reputable anti-malware scanner if you don't already have one. Malwarebytes Free is an excellent choice for detecting and removing browser hijackers and PUPs. Run a full system scan and remove everything it identifies. Consider running a second scan with a different tool (like AdwCleaner, also from Malwarebytes) for additional detection coverage, as no single scanner catches everything.
Perform a Full Browser Reset
For thorough removal, reset each affected browser to factory defaults. In Chrome, go to Settings > Reset settings > Restore settings to their original defaults. This removes extensions, clears temporary data, and resets all browser settings while preserving your bookmarks and passwords. Firefox and Edge have similar reset options in their respective settings menus. This step ensures any lingering hijacker configurations are eliminated.
Verify Removal and Monitor
Restart your computer and test your browsers. Search for something and verify you're not being redirected through Hizens.xyz. Check that your homepage, new-tab page, and default search engine remain set to your preferences. Monitor your system over the next few days—if the hijacker returns, you may have missed a persistence mechanism or have a deeper infection requiring professional assistance.
Prevention
- Download software only from official sources. Avoid third-party download sites like Softonic, Download.com, or CNET Downloads that are notorious for bundling PUPs with legitimate software. Always download from the software developer's official website or verified app stores. When you must use a third-party source, scrutinize every installation screen.
- Choose custom installation and read every screen. Never click "Express Install" or "Recommended Settings" when installing software. Always select "Custom" or "Advanced" installation and read each screen carefully. Uncheck any boxes offering to install additional software, browser toolbars, or change your homepage/search engine settings. Legitimate software doesn't require bundled extras.
- Keep your browser and operating system updated. Enable automatic updates for Windows and all installed software, especially browsers. Many browser hijackers exploit outdated software vulnerabilities to install themselves without user interaction. Regular updates patch these security holes and often include improved detection of malicious extensions.
- Install reputable browser security extensions. Use extensions like uBlock Origin (ad blocker that also blocks many malicious sites) and consider enabling Chrome's Enhanced Safe Browsing or Firefox's Enhanced Tracking Protection. These tools warn you before visiting sites known to distribute malware and block many malicious scripts from executing.
- Scrutinize browser extension permissions. Before installing any browser extension, review what permissions it requests. Be extremely suspicious of extensions requesting permission to "read and change all your data on websites you visit"—very few legitimate extensions require this level of access. Read user reviews and check the developer's reputation before installing.
- Avoid clicking suspicious ads and pop-ups. Never click "Update Now" pop-ups or download prompts that appear while browsing. Legitimate updates happen through your operating system's update mechanism or the application's built-in updater. If you see a flash player update prompt, close it—Flash Player is discontinued and any update notification is malicious.
- Maintain a reputable antivirus solution. Install quality antivirus software that includes real-time protection against PUPs and browser hijackers. Windows Defender (built into Windows 10/11) provides decent basic protection, but dedicated solutions like Malwarebytes Premium, Bitdefender, or Kaspersky offer superior detection rates for potentially unwanted programs.
- Regular system scans and maintenance. Schedule weekly scans with your anti-malware software even if you haven't noticed problems. Review your browser extensions monthly and remove anything you no longer use. Check your installed programs list quarterly and uninstall unfamiliar applications. Proactive hygiene prevents small infections from becoming major problems.
When we remove malware from your computer, it stays removed. Every malware removal service includes our 90-day reinfection warranty. If the same threat returns within 90 days, we'll remove it again at no additional charge. We stand behind our work because we do it right the first time.
Bring It In
If you've followed the removal steps above and still experience browser redirects, or if you're uncomfortable performing manual removal procedures, bring your computer to Computer Repair Roswell. Browser hijackers like Hizens.xyz often install alongside more dangerous threats—what looks like a simple redirect problem may indicate a deeper infection that requires professional tools and expertise to resolve completely. Our technicians have removed thousands of browser hijackers from Windows and Mac systems and can typically complete the work same-day.
We're located in Roswell, Georgia, and we work on all types of computers—Windows PCs, Macs, laptops, and desktops. Call us at (770) 685-9593 to describe what you're experiencing, and we'll give you an honest assessment of whether you need professional help or can handle it yourself. No appointment necessary for diagnostic evaluation—just bring your computer in during business hours and we'll identify the exact scope of the infection before quoting any work. We believe in transparent pricing and won't proceed with any repairs without your explicit approval of the costs involved.