iAmadsNews.com is a browser hijacker that forces your web browser to redirect through its domain, generating revenue through unwanted advertisements and affiliate traffic. This persistent threat modifies your browser settings without permission, changes your default search engine, and bombards you with pop-ups and sponsored links that disrupt normal browsing. While not technically a virus, it exhibits malicious behavior by resisting removal attempts and collecting browsing data to fuel its advertising operations.

iAmadsNews.com — cybersecurity illustration
Photo by Adventure Studio on Pexels
Think you're infected right now? Disconnect from the internet immediately to prevent further data collection. Do not enter passwords or financial information until the infection is removed. Call us at (770) 594-2630 or bring your computer to our Roswell shop — we can typically remove browser hijackers same-day.

Threat Profile

Attribute Details
Threat Family Browser Hijacker / Redirect Malware
Aliases iAmadsNews redirect, iAmadsNews.com hijacker, Ads by iAmadsNews
Platform Windows, macOS (affects Chrome, Firefox, Edge, Safari)
Classification PUP (Potentially Unwanted Program), Adware
Distribution Method Software bundling, fake updates, malicious browser extensions, freeware installers
Persistence Mechanism Browser extension installation, homepage/search engine override, scheduled tasks, registry modifications (Windows)
Primary Capabilities Search redirection, browser settings hijacking, advertising injection, tracking cookie deployment, affiliate click fraud
Data Collection Browsing history, search queries, clicked links, IP addresses, geolocation data, system information
Payload Delivery May download additional PUPs, adware toolbars, fake system optimizers, or redirect to malicious sites
Network Behavior Frequent connections to ad networks, tracking domains, and affiliate redirect chains
Typical Artifacts Browser extension folders, JSON preference modifications, registry Run keys, scheduled tasks with random names
Removal Difficulty Moderate — uses multiple persistence methods and may reinstall itself if not completely removed

How It Spreads

The iAmadsNews hijacker primarily spreads through deceptive software bundling — a technique where legitimate-looking free programs include hidden additional installations. When users rush through installer screens clicking "Next" repeatedly, they unknowingly consent to installing the hijacker alongside the software they actually wanted. These bundled packages often disguise the hijacker installation in the "Custom" or "Advanced" options that most people skip.

Fake update notifications represent another common infection vector. You might encounter convincing-looking alerts claiming your Flash Player, Java, or browser needs an urgent update. Clicking these fraudulent warnings downloads an installer that includes the hijacker. These fake updates appear on legitimate-looking websites that have been compromised or specifically designed to distribute PUPs.

Once the initial infection occurs, the hijacker can download additional unwanted programs without your knowledge, creating a cascading effect where one PUP invites others to join the party on your system.

  • Software bundles: Free download sites packaging the hijacker with video converters, PDF tools, media players, and system utilities
  • Fake browser extensions: Seemingly useful add-ons that promise ad-blocking, video downloading, or coupon finding but actually hijack your settings
  • Malvertising campaigns: Compromised advertisements on legitimate websites that redirect to hijacker installers
  • Torrent and piracy sites: Cracked software downloads that include hijackers as part of the "crack" package
  • Email attachments: Less common but possible — malicious attachments that deploy the hijacker as part of a multi-stage infection
  • Compromised websites: Drive-by downloads from hacked sites that exploit browser vulnerabilities to install the hijacker without explicit consent

What It Does On Your Machine

Once installed, iAmadsNews.com immediately takes control of your browser configuration. It overwrites your homepage setting to point to its domain or an intermediate redirect page, changes your default search engine to one that funnels all queries through its tracking system, and sets a new tab page that displays sponsored content. These changes occur across all your installed browsers — Chrome, Firefox, Edge, and Safari are all vulnerable. When you try to reverse these settings manually, the hijacker often reinstalls them within seconds or after the next reboot.

The search redirection mechanism is particularly insidious. When you perform a web search, your query first passes through iAmadsNews.com's servers, where it gets logged for tracking purposes. The hijacker then redirects you through one or more intermediate domains before finally delivering search results — usually from a legitimate search engine like Bing or Yahoo, but with the results page modified to include additional sponsored links at the top. This redirection chain accomplishes two goals: it generates affiliate revenue for each search performed, and it collects detailed data about your search habits.

Beyond search manipulation, the hijacker injects advertisements into websites you visit. You'll notice extra banners appearing on pages that normally don't have them, pop-under windows opening when you click anywhere on a page, and text links suddenly appearing highlighted on common words. These injected ads slow down page loading, consume bandwidth, and create security risks since the ad content comes from unvetted third-party sources that may contain actual malware.

The data collection component runs continuously in the background. iAmadsNews.com tracks every website you visit, every search term you enter, products you view while shopping, videos you watch, and how long you spend on each page. This information gets compiled into a browsing profile that's valuable to advertisers and may be sold to data brokers. While the hijacker doesn't typically steal passwords or credit card numbers directly, the collected data can reveal sensitive information about your interests, health concerns, financial situation, and personal relationships.

Typical filesystem and registry artifacts (Windows example):
C:\Users\[Username]\AppData\Local\iAmadsNews\ # Main program folder C:\Users\[Username]\AppData\Local\iAmadsNews\service.exe C:\Users\[Username]\AppData\Roaming\iAmadsNewsData\ C:\Users\[Username]\AppData\Local\Google\Chrome\User Data\Default\Extensions\[random-extension-id]\ HKCU\Software\Microsoft\Windows\CurrentVersion\Run"iAmadsNews Updater" HKLM\SOFTWARE\Policies\Google\Chrome\HomepageLocation"http://iamadsnews.com" HKCU\Software\Microsoft\Internet Explorer\Main"Start Page" C:\Windows\System32\Tasks\iAmadsNewsTask[Random] # Scheduled task for persistence

Manual Removal — Step by Step

01

Disconnect from the Internet

Unplug your ethernet cable or disable Wi-Fi to prevent the hijacker from communicating with its command servers, downloading additional components, or transmitting collected data. This also stops new ads from loading, making the removal process smoother.

02

Uninstall Suspicious Programs

Open Control Panel (Windows) or Applications folder (Mac) and look for recently installed programs you don't recognize, especially those installed around the time the redirects started. Common names include variations of "iAmadsNews," "Web Companion," "Search Manager," or random names with version numbers. Uninstall anything suspicious, noting that the hijacker may use a completely different program name.

03

Boot Into Safe Mode With Networking

Restart your computer in Safe Mode to prevent the hijacker's background processes from running. On Windows 10/11, hold Shift while clicking Restart, then navigate to Troubleshoot > Advanced Options > Startup Settings > Restart, and select Safe Mode with Networking. This limits what can run while still allowing you to download removal tools if needed.

04

Remove Browser Extensions

Open each installed browser and navigate to the extensions/add-ons manager. Remove any extensions you don't recognize or didn't intentionally install. The hijacker often installs extensions with generic names like "Helper," "Utility," or random letter combinations. In Chrome, check chrome://extensions; in Firefox, about:addons; in Edge, edge://extensions.

05

Reset Browser Settings

Manually reset your homepage, default search engine, and new tab page in each browser's settings. Then perform a full browser reset to restore default settings while preserving bookmarks and passwords. In Chrome, go to Settings > Reset Settings > Restore settings to their original defaults. For Firefox, use about:support and click "Refresh Firefox." This removes hijacker-imposed policies and preference locks.

06

Delete Hijacker Files and Folders

Navigate to %LOCALAPPDATA% (Windows) or ~/Library/Application Support (Mac) and delete any folders related to iAmadsNews or suspicious folders created around the infection date. Check %APPDATA% and %PROGRAMFILES% as well. Use File Explorer's search function to look for "iamadsnews" across your entire C: drive and delete all matches.

07

Clean Registry Entries (Windows)

Press Win+R, type "regedit" and search (Ctrl+F) for "iamadsnews" — delete any keys or values found. Check HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run for suspicious entries. Also examine browser policy keys under HKLM\SOFTWARE\Policies\Google\Chrome, Microsoft\Edge, and Mozilla\Firefox for hijacker-created policies. Make a registry backup before making changes.

08

Remove Scheduled Tasks

Open Task Scheduler (search for it in the Start menu) and look through the Task Scheduler Library for tasks with suspicious names or those that run executables from unusual locations like %LOCALAPPDATA%. Delete any tasks that reference iAmadsNews or run programs you've already deleted. The hijacker commonly creates tasks with random alphanumeric names scheduled to run at login.

09

Run Malwarebytes and ADWCleaner

Download and run Malwarebytes Free (not just the trial) to perform a thorough scan. Follow up with ADWCleaner, which specializes in browser hijackers and PUPs. Let both tools quarantine everything they find. These free scanners catch persistence mechanisms and registry entries that manual removal might miss, and they're specifically designed to handle hijacker reinstallation tricks.

10

Reboot Normally and Verify

Restart your computer normally (not in Safe Mode) and immediately check whether your browser settings have stayed clean. Open each browser and verify your homepage, search engine, and new tab page remain as you set them. Perform a test search and confirm you're not being redirected through iAmadsNews.com. Monitor for pop-ups over the next few hours. If redirects return, the hijacker has a persistence mechanism you missed — bring it to us.

Prevention

  1. Always choose Custom installation: When installing free software, never click "Express" or "Recommended" installation. Select "Custom" or "Advanced" and carefully read each screen, unchecking any bundled offers for additional software, toolbars, or browser changes.
  2. Download only from official sources: Get software directly from the developer's website, not from download aggregator sites like Softonic, Download.com, or CNET Downloads, which often wrap installers with bundled PUPs. For open-source software, use the official GitHub releases or the project's main website.
  3. Keep your browser and OS updated: Enable automatic updates for Windows/macOS and all browsers. Security patches close vulnerabilities that hijackers exploit for drive-by installations. An updated browser is significantly harder to compromise without explicit user action.
  4. Install a reputable ad-blocker: Use uBlock Origin (not to be confused with AdBlock Plus) to block malicious ads and prevent redirects to hijacker distribution sites. Most hijacker infections start with a malicious advertisement that wouldn't have loaded with proper ad-blocking in place.
  5. Review installed extensions monthly: Make it a habit to audit your browser extensions once a month. Remove anything you don't actively use. Hijackers often disguise themselves as legitimate-looking extensions that sit dormant before activating, and previously safe extensions can be sold to malicious actors who update them with hijacker code.
  6. Don't trust update notifications: If you see a pop-up claiming you need to update Flash, Java, your browser, or video codecs, close it and manually check for updates through the official application or Windows Update. Legitimate updates don't arrive via random website pop-ups.
  7. Use a standard user account: Don't run Windows as an administrator for daily activities. A standard user account prevents many installations from occurring without explicit permission through a UAC prompt, adding a crucial layer of protection against automatic hijacker installations.
  8. Run periodic scans with Malwarebytes: Even if you think your system is clean, run a full Malwarebytes scan monthly. Early detection catches hijackers before they fully establish persistence mechanisms, making removal much simpler and preventing data collection.
Our 90-Day Warranty: When Computer Repair Roswell removes malware from your system, that specific infection stays gone. If the same threat returns within 90 days through no fault of your own, we'll remove it again at no charge. We don't just clean the symptoms — we eliminate the root cause and explain how to avoid reinfection.

Bring It In

Browser hijackers like iAmadsNews.com are frustrating because they're designed to be hard to remove completely. They scatter pieces across your system, create multiple persistence methods, and often download companion PUPs that reinstall each other if you miss even one component. What looks like successful removal can turn into whack-a-mole when the redirects return after a reboot because a hidden scheduled task or registry policy you didn't know to check reinstalls everything.

We see these infections daily at our Roswell shop and can typically clean them in under an hour while you wait. We'll verify complete removal by monitoring your system for reinstallation attempts, check for any companion infections the hijacker may have brought along, and review your browser settings to ensure nothing else is modifying them. Call (770) 594-2630 or stop by at 1755 Woodstock Rd, Roswell, GA 30075. We're open Monday through Saturday and can often see walk-ins same-day. Bring your infected computer in and leave with clean browsers, no redirects, and clear instructions on how this happened so it won't happen again.