HummingExam.com is a browser hijacker that redirects your searches and homepage to a dubious search engine, typically installed without your clear consent through software bundles or deceptive advertisements. Once active, it modifies browser settings across Chrome, Firefox, Edge, and Safari, forcing all queries through its own portal while tracking your search habits and browsing data. While not technically a virus in the traditional sense, this unwanted application manipulates your web experience, exposes you to potentially unsafe sponsored results, and proves remarkably stubborn to remove through normal browser reset procedures.

HummingExam.com — cybersecurity illustration
Photo by Lucas Andrade on Pexels

Users typically discover HummingExam.com after installing a free media converter, PDF tool, or game from a third-party download site. The hijacker embeds itself in browser shortcuts, system policies, and scheduled tasks to ensure it reappears even after you manually change your homepage back. Beyond the annoyance of constant redirects, the real concern lies in data collection—these hijackers log search terms, visited URLs, geolocation data, and device identifiers for advertising profiling, with that information sometimes sold to data brokers or misused by bad actors.

Already infected? Disconnect from Wi-Fi immediately if you've entered passwords or payment information while the hijacker was active. Boot to Safe Mode with Networking and run a full Malwarebytes scan before attempting manual removal. If you're uncomfortable with technical troubleshooting, bring your machine to our Roswell shop—we see hijackers like HummingExam.com daily and can remove them while you wait.

Threat Profile

Attribute Details
Family Browser Hijacker / Potentially Unwanted Program (PUP)
Aliases HummingExam redirect, hummingexam.com virus, HummingExam search hijacker
Platform Windows (7 through 11), macOS (10.12+), Chrome OS (limited)
Discovered Circulating since approximately 2021; variants continue to emerge
Distribution Software bundles (InstallCore, Amonetize), fake update prompts, malvertising networks
Persistence Methods Browser extension policies, shortcut target modification, scheduled tasks, registry Run keys, macOS launch agents
Primary Capabilities Homepage/new-tab redirection, search hijacking, advertising injection, user tracking, settings lockdown
Data at Risk Search queries, browsing history, IP address, geolocation, device identifiers, cookies, typed URLs
Network Behavior Contacts ad-serving domains and affiliate trackers; typical traffic to advertising exchanges and analytics platforms
Artifacts/IoCs Browser policy JSON files, scheduled tasks named with random GUIDs, shortcuts modified with appended arguments, extensions with randomized IDs
Payload Delivery Often delivered alongside adware or system optimizers; may re-download components if only partially removed
Removal Difficulty Moderate—requires cleaning multiple browser profiles, policy folders, and persistence mechanisms across system locations

How It Spreads

HummingExam.com rarely arrives alone or through a clearly-labeled installer. The distribution model relies on users downloading legitimate-seeming software from third-party hosting sites—those "Download Now" buttons for video converters, registry cleaners, or browser toolbars that promise to speed up your system. The installer presents HummingExam.com as an "enhanced search experience" or "recommended browser setting" buried in an EULA paragraph or pre-checked box during the "Custom Installation" phase most people skip past.

Beyond bundled software, this hijacker exploits users' security fatigue. Fake system alerts warn that Flash Player needs updating or that your browser is "out of date and insecure," presenting a download button that actually delivers the hijacker instead of a legitimate update. Malicious advertisements on sketchy streaming sites and torrent portals serve as another common vector, using clickjacking techniques where the visible "Close" button on a pop-up actually triggers a download in the background.

The hijacker spreads through several specific channels:

  • Bundled freeware installers — Media converters, PDF utilities, and download managers hosted on sites like Softonic, Download.com clones, and file-sharing platforms, where the installer includes HummingExam.com as an "offer" in the setup wizard
  • Fake update prompts — Pop-ups mimicking Chrome, Firefox, or Adobe Flash update notifications, particularly on piracy sites and low-quality streaming portals
  • Malvertising campaigns — Poisoned ads on legitimate sites that redirect to landing pages pushing the hijacker as a "required browser component" to view content
  • Browser extension stores — Occasionally appears as a "productivity extension" with vague descriptions and fake reviews, sometimes briefly evading automated store reviews before removal
  • Torrent payloads — Packaged with cracked software or game installers, where users expect some additional components and don't scrutinize the installation process
  • Email attachments in phishing campaigns — Less common, but seen in targeted campaigns disguised as document viewers or file converters sent to small businesses

What It Does On Your Machine

The moment HummingExam.com installs, it begins systematic modification of every browser profile on your system. It rewrites the homepage, default search engine, and new-tab URL to point to hummingexam.com or an intermediary redirect domain. When you type a search query in the address bar or open a new tab, your request goes through their server first—they log it, attach tracking parameters, inject sponsored links into the results, then forward you to a legitimate search engine like Bing or Yahoo to make the experience feel authentic enough that you might not immediately investigate.

The hijacker doesn't stop at simple redirection. It implements policy-based enforcement to prevent you from changing settings back. On Windows machines, it writes Group Policy preferences or registry policies that lock your homepage and search engine at the browser level. When you open Chrome settings and try to change the homepage, the field appears grayed out or reverts immediately after you close settings. Firefox users find their about:config preferences locked or overridden by an enterprise policy file planted in the browser's installation directory. On macOS, the hijacker installs configuration profiles that establish managed browser settings, requiring admin authentication to alter.

Behind the scenes, HummingExam.com establishes multiple persistence mechanisms to survive casual removal attempts. It creates scheduled tasks that check for the hijacker's presence and reinstall components if they're deleted. Browser shortcut files get modified—the Target field receives appended arguments that force the browser to load hummingexam.com on launch regardless of your configured homepage. Some variants install a browser extension with a randomized name and ID, sometimes masquerading as a helpful tool like "Quick Search" or "Fast Start," which users might overlook when reviewing their extension list.

The data collection happens constantly while the hijacker remains active. Every search query, clicked link, and website visit gets transmitted to tracking servers along with your IP address, approximate location derived from that IP, browser version, operating system, screen resolution, and installed fonts—all data points used to fingerprint your device uniquely. This profile gets monetized through advertising networks or sold to data brokers. While the hijacker's privacy policy might technically disclose this collection in vague legal language, the average user never consented in a meaningful way to such comprehensive surveillance.

Typical HummingExam.com Artifacts
Windows: %LOCALAPPDATA%\HummingExam\ %LOCALAPPDATA%\{random-GUID}\hxsvc.exe %APPDATA%\Mozilla\Firefox\Profiles\{profile}\extensions\{random-ID} HKCU\Software\Policies\Google\Chrome\HomepageLocation HKCU\Software\Microsoft\Windows\CurrentVersion\Run\HummingExamUpdater C:\Program Files (x86)\{random name}\uninstall.exe Scheduled Task: \HummingExamUpdate_{GUID} macOS: ~/Library/Application Support/HummingExam/ ~/Library/LaunchAgents/com.hummingexam.agent.plist ~/Library/Application Support/Google/Chrome/Default/Preferences # Modified to enforce search engine and homepage /Library/Managed Preferences/{user}/com.google.Chrome.plist

Manual Removal — Step by Step

01

Disconnect from the network and document current state

Disable Wi-Fi or unplug the Ethernet cable to prevent the hijacker from communicating with command servers or downloading additional components. Take note of your current homepage and default search engine by opening browser settings—screenshot these if possible. This establishes a baseline and helps you verify complete removal later. If you've entered sensitive passwords or payment information while the hijacker was active, make a list of those accounts for credential changes after cleanup.

02

Boot to Safe Mode with Networking

Restart your computer into Safe Mode to prevent the hijacker's scheduled tasks and startup items from loading. On Windows 10/11, hold Shift while clicking Restart, then navigate to Troubleshoot → Advanced Options → Startup Settings → Restart, and select option 5 for Safe Mode with Networking. On macOS, restart while holding the Shift key immediately after the startup chime. Safe Mode loads only essential system components, making it easier to remove persistent malware without interference.

03

Uninstall suspicious programs from Control Panel or Applications

Open Windows Settings → Apps → Installed apps (or Control Panel → Programs and Features on older versions). Sort by install date and look for programs installed around the time the hijacker appeared, especially anything with vague names, publisher names you don't recognize, or descriptions mentioning "search enhancement" or "browser tools." Uninstall HummingExam, any programs with random alphanumeric names, and bundled software you didn't intentionally install. On macOS, check Applications folder and drag suspicious apps to Trash, then empty Trash with Secure Empty Trash if available.

04

Delete browser policies and hijacked shortcuts

Navigate to %LOCALAPPDATA%\Google\Chrome\User Data\ and delete any file named "Policies" or the entire Policies folder if present. For Firefox, check the installation directory (typically C:\Program Files\Mozilla Firefox\distribution\) and remove any policies.json file. Right-click your browser shortcuts (on desktop, taskbar, Start menu), select Properties, and examine the Target field—delete anything after the .exe path, especially URLs or command-line switches. On macOS, check System Preferences → Profiles for any configuration profiles you didn't install and remove them.

05

Remove scheduled tasks and startup entries

Press Win+R, type taskschd.msc, and press Enter to open Task Scheduler. Look in Task Scheduler Library for tasks with names containing HummingExam, random GUIDs, or generic names like "Update Service" created recently. Right-click and delete any suspicious tasks. Then open the Registry Editor (Win+R → regedit) and navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and the same path under HKEY_LOCAL_MACHINE—delete any entries pointing to HummingExam folders or executables in %LOCALAPPDATA% with random names. On macOS, check ~/Library/LaunchAgents/ and /Library/LaunchAgents/ for .plist files and remove unfamiliar ones.

06

Clean browser extensions and reset settings

Open each browser's extension/add-ons manager (chrome://extensions/, about:addons for Firefox, edge://extensions/ for Edge) and remove any extensions you don't recognize, particularly those installed recently with vague names or no reviews. Then reset each browser: in Chrome, go to Settings → Reset settings → Restore settings to their original defaults; in Firefox, Help → More Troubleshooting Information → Refresh Firefox; in Edge, Settings → Reset settings → Restore settings to their default values. This clears hijacked homepages and search engines while preserving bookmarks and passwords in most cases.

07

Manually delete remaining program folders

Even after uninstalling through Control Panel, hijackers often leave folders behind. Navigate to %LOCALAPPDATA%, %APPDATA%, and %PROGRAMFILES% (and Program Files (x86) on 64-bit systems) and look for folders named HummingExam or with random alphanumeric names created around the infection date. Delete these folders entirely. On macOS, check ~/Library/Application Support/ and /Library/Application Support/ for similarly named folders. Empty the Recycle Bin/Trash completely afterward.

08

Run a reputable anti-malware scanner

Reconnect to the internet and download Malwarebytes Free (from malwarebytes.com—be certain you're on the official site). Install and run a full Threat Scan, which typically takes 20-45 minutes depending on drive size. Malwarebytes excels at detecting hijacker remnants, registry keys, and tracking cookies that manual removal might miss. Quarantine all detections, then restart the computer normally (not in Safe Mode) and run a second scan to verify nothing reinstalled itself. Consider running a secondary scan with AdwCleaner or HitmanPro for additional coverage.

09

Verify browser settings and change critical passwords

Open each browser and manually confirm that your homepage, default search engine, and new-tab page are set to your preferences and not reverting to HummingExam.com. Test by opening new tabs and performing searches to ensure no redirects occur. If the hijacker potentially captured login credentials (which is common for these trackers), change passwords for your email, banking, and any accounts you accessed while infected—do this from a clean device or after you're certain the hijacker is fully removed. Enable two-factor authentication where available as an additional layer of security.

10

Reboot normally and monitor for 48 hours

Restart your computer in normal mode and observe behavior for the next two days. Open browsers multiple times, restart the computer a few times, and ensure HummingExam.com doesn't reappear. Check Task Manager (Ctrl+Shift+Esc) for unfamiliar processes consuming network bandwidth or CPU. If the hijacker returns, it indicates a persistence mechanism was missed—at that point, professional removal becomes advisable, as some variants employ rootkit-like techniques or bootkit components that require specialized tools to eliminate completely.

Prevention

  1. Download software only from official sources. Use developers' official websites or the Microsoft Store/Mac App Store rather than third-party download sites. Those "free download" sites bundle installers with hijackers and adware to monetize your click. When you must use a third-party source, carefully select "Custom" or "Advanced" installation and uncheck all offers for toolbars, search engines, or "recommended" software.
  2. Keep browsers and operating systems updated. Enable automatic updates for Windows, macOS, Chrome, Firefox, and Edge. Many hijackers exploit outdated browser vulnerabilities or social-engineer users with fake update prompts precisely because people neglect legitimate updates. Current software closes security holes and often includes enhanced warnings for suspicious extensions.
  3. Use a reputable ad blocker and script blocker. Extensions like uBlock Origin prevent malicious advertisements from loading and block many hijacker installation scripts. Configure the blocker to use additional filter lists that target known malware domains. Script blockers like NoScript or uMatrix (for advanced users) prevent unauthorized code execution, though they require more management of site permissions.
  4. Review browser extensions monthly. Set a calendar reminder to open your extensions page and audit what's installed. Remove anything you don't actively use or don't remember installing. Hijackers often masquerade as helpful extensions with generic names—if you can't recall why you installed something or find no information about its publisher, remove it.
  5. Enable Windows Defender PUA protection. Windows Security includes Potentially Unwanted Application blocking, but it's disabled by default on some systems. Open Windows Security → App & browser control → Reputation-based protection settings → Turn on "Block potentially unwanted apps" for both apps and downloads. This catches many bundled hijackers before they install.
  6. Never disable security warnings for convenience. If Windows SmartScreen or macOS Gatekeeper warns about an unsigned application, take that seriously rather than clicking "Run Anyway." Legitimate software developers sign their applications. If a program requires you to disable security features to install, that's a massive red flag indicating malware or at minimum aggressive adware.
  7. Use a standard user account for daily tasks. Create a non-administrator account for regular computer use, keeping the admin account for deliberate software installations and system changes. Many hijackers struggle to establish deep system persistence without admin privileges, limiting damage to the user profile where cleanup is simpler.
  8. Educate household members and employees. The least tech-savvy user of a shared computer often becomes the infection vector. Spend ten minutes explaining what bundled software looks like, why "Free Download" buttons can't be trusted, and how to recognize fake update prompts. That small investment prevents hours of cleanup later.
Our 90-Day Warranty — When we remove HummingExam.com from your computer, it stays gone. Every malware removal at Computer Repair Roswell comes with a 90-day reinfection warranty. If the same hijacker comes back within three months through no fault of your own, we'll clean it again at no charge. We also take the time to show you how it got in so you can avoid the same trap twice.

Bring It In

If HummingExam.com has turned your browser into an advertising billboard, or if you've followed the removal steps above and the hijacker keeps resurrecting itself, it's time for professional help. We see browser hijackers every single day at our Roswell shop—they're among the most common infections we clean, and we've developed efficient processes to eliminate them completely along with any bundled adware or tracking components they brought along. The removal typically takes 45 minutes to two hours depending on how many browsers and user profiles need cleaning, and we handle it while you wait or drop off your machine for same-day service.

More importantly, we make sure the hijacker didn't act as a gateway for worse threats. Browser hijackers often arrive in bundles with password stealers, cryptocurrency miners, or backdoor trojans that do serious damage while you're distracted by the obvious search redirects. Our malware removal process includes comprehensive scanning for secondary infections, verification that your system files haven't been corrupted, and a walkthrough of what happened so you understand your machine's security posture going forward. Call us at (770) 954-1480 or stop by our Roswell location—we're here to get your browser back under your control and your search habits back to being your own business.