Igggames.co is a deceptive browser hijacker and potentially unwanted program (PUP) that modifies your web browser settings without consent, redirecting searches and homepage traffic through dubious third-party servers. While marketed as a gaming portal offering "free downloads," this threat primarily exists to generate advertising revenue by forcing users through sponsored search results, injecting advertisements into legitimate pages, and tracking browsing behavior for data resale. Users typically discover they're infected when their browser suddenly defaults to igggames.co or related domains, search queries get rerouted through unfamiliar engines, and a flood of pop-up ads appears on sites that normally don't display them.
This hijacker falls into the broader category of adware-bundled browser manipulators—programs that blur the line between aggressive marketing software and outright malicious code. Though Igggames.co doesn't encrypt files like ransomware or steal banking credentials like a trojan, it degrades system performance, compromises privacy through persistent tracking, and creates security vulnerabilities by exposing users to malvertising networks known to distribute more dangerous payloads. The presence of this hijacker often indicates other unwanted programs came along for the ride during installation.
Threat Profile
| Threat Type | Browser Hijacker / Potentially Unwanted Program (PUP) |
| Common Aliases | Igggames redirect, igggames.com hijacker, igg-games browser modifier |
| Affected Platforms | Windows (7/8/10/11), macOS; targets Chrome, Firefox, Edge, Safari |
| First Observed | Variants active since approximately 2018-2019 |
| Distribution Method | Software bundling, fake codec installers, pirated game repackaging, malvertising |
| Persistence Mechanisms | Browser extension/add-on installation, modified shortcut targets, scheduled tasks, registry Run keys (Windows), launch agents (macOS) |
| Primary Capabilities | Homepage/search engine replacement, search redirection, ad injection, browsing data collection, affiliate click fraud |
| Data at Risk | Browsing history, search queries, IP address, approximate location, clicked links, potentially form data |
| Network Behavior | Frequent connections to ad-serving domains, affiliate tracking networks, data collection endpoints; typical domains include variations of igggames domains and third-party ad networks |
| File System Footprint | Browser extension folders, %APPDATA%/%LOCALAPPDATA% subdirectories with randomized names, modified browser configuration files |
| Detection Names | PUP.Optional.IggGames, Adware.IggGames, BrowserModifier:Win32/IggGames (varies by antivirus vendor) |
| Removal Difficulty | Moderate — typically requires manual browser cleanup plus registry/extension removal; may reinstall if all components not addressed |
How It Spreads
Igggames.co primarily spreads through software bundling, where the hijacker payload is packaged alongside legitimate-looking free software, pirated games, or media players. Users download what they believe to be a standalone installer—often for a game crack, video codec, or download manager—and rush through the installation wizard using "Next, Next, Finish" clicks without reading disclosure screens. The hijacker components are pre-selected in "Recommended" or "Express" installation modes, and only users who choose "Custom" or "Advanced" installation and actively uncheck additional offers avoid infection.
The connection to gaming is deliberate. The operators behind this hijacker specifically target users searching for free or pirated games, knowing this demographic often downloads files from sketchy sources and may have security software disabled to bypass anti-piracy protections. Fake game download sites with names similar to legitimate gaming forums bundle the hijacker into their installers, and peer-to-peer torrent files frequently include it as part of the "crack" package. By the time users realize their browser has been modified, they've often forgotten which specific download triggered it.
Common distribution vectors include:
- Bundled freeware installers: Download managers, PDF converters, video players, and system optimizers that include "partner offers" in their setup wizards
- Pirated game repacks: Cracked game installers downloaded from torrent sites or file-sharing platforms, where the hijacker is presented as part of the crack or keygen
- Fake codec/player prompts: Deceptive messages on streaming sites claiming you need to install a "video codec" or "Flash player update" to watch content
- Malvertising campaigns: Compromised ad networks serving malicious advertisements that trigger drive-by downloads or redirect to fake software update pages
- Fake download buttons: Deceptive "Download" buttons on file-sharing sites that install the hijacker instead of the intended file
- Browser extension stores: Occasionally distributed through fake or compromised browser extensions in official stores, disguised as gaming toolbars or download helpers
What It Does On Your Machine
Once installed, Igggames.co immediately modifies your browser configuration to establish persistence and begin generating revenue for its operators. The most visible change is homepage and new-tab hijacking—every time you open your browser or create a new tab, you're redirected to igggames.co or a related domain instead of your chosen homepage. Your default search engine gets replaced with a custom search provider that routes queries through affiliate tracking systems before displaying results, allowing the hijacker operators to earn money from every search you perform and every ad you click.
The hijacker installs persistence mechanisms at multiple system levels to survive user removal attempts. On Windows systems, it typically creates scheduled tasks that check for and reinstall browser modifications at regular intervals. Browser shortcuts on your desktop and Start menu get modified with appended command-line parameters that force the browser to load the hijacker's homepage on startup—even if you manually change settings within the browser, the shortcut modification overrides your preferences. Registry Run keys ensure associated helper processes launch at system boot, ready to reapply hijacker settings if you manage to remove the browser extension.
Beyond the obvious redirections, Igggames.co engages in more invasive monetization activities. It injects additional advertisements into legitimate web pages you visit, overlaying banners and pop-ups on sites that don't normally display them. This ad injection happens at the browser level, meaning ads appear even on secure HTTPS sites. The hijacker also tracks your browsing behavior—recording which sites you visit, what you search for, which links you click, and how long you spend on different pages. This data gets transmitted to remote servers where it's aggregated, analyzed, and either used to target more effective ads at you or sold to third-party data brokers.
System performance typically degrades noticeably after infection. Browsers consume excessive memory and CPU resources due to the constant background scripts injecting ads and tracking behavior. Page load times increase because every page request gets routed through additional redirect chains. Network bandwidth suffers from the continuous data transmission to tracking servers. Users commonly report browsers becoming sluggish, freezing temporarily when loading pages, or crashing unexpectedly—all symptoms of the resource overhead this hijacker introduces.
Manual Removal — Step by Step
Disconnect Network and Document Symptoms
Before making any changes, disconnect from the internet (unplug Ethernet or disable Wi-Fi) to prevent the hijacker from updating its components or downloading additional payloads during removal. Take screenshots of the hijacked homepage, any unfamiliar extensions, and modified browser settings—this documentation helps confirm complete removal later and assists technicians if you need professional help.
Boot to Safe Mode with Networking
Restart your computer in Safe Mode to prevent the hijacker's startup processes from launching. On Windows 10/11, hold Shift while clicking Restart, then navigate to Troubleshoot > Advanced Options > Startup Settings > Restart, and press F5 for Safe Mode with Networking. On macOS, restart and hold Shift immediately after hearing the startup chime. Safe Mode loads only essential system services, making it easier to remove malware components.
Uninstall Suspicious Programs
Open Control Panel (Windows) or Applications folder (macOS) and uninstall any programs you don't recognize or didn't intentionally install, especially anything with "Games," "Download," "Manager," "Optimizer," or random names in the title. Check installation dates—anything installed around the time your browser problems started is suspect. On Windows, also check Settings > Apps & Features for Microsoft Store apps that might be involved.
Remove Browser Extensions and Reset Settings
Open each affected browser and manually remove all extensions you didn't install. In Chrome, go to chrome://extensions/; in Firefox, about:addons; in Edge, edge://extensions/. Remove anything unfamiliar, especially extensions with vague names or poor ratings. Then reset browser settings: in Chrome, go to Settings > Reset Settings > Restore settings to original defaults. In Firefox, about:support > Refresh Firefox. This clears hijacker modifications to search engines, homepages, and startup pages.
Fix Modified Shortcuts
Right-click each browser shortcut (desktop, taskbar, Start menu) and select Properties. In the Target field, remove anything after the .exe filename—it should end with chrome.exe, firefox.exe, or msedge.exe with no URLs appended. If you see http://igggames.co/ or similar URLs after the executable path, delete them. Also verify the Start In field points to the browser's installation directory, not a random folder.
Clean Registry and Scheduled Tasks (Windows)
Press Win+R, type taskschd.msc, and press Enter to open Task Scheduler. Look through the task list for anything related to IggGames, browser updates from non-Microsoft/Google sources, or tasks with random names scheduled to run at login or regular intervals—delete these. Then press Win+R again, type regedit, and navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\...same path. Delete any entries pointing to unfamiliar executables in %APPDATA% or %LOCALAPPDATA% subdirectories.
Delete Remaining File Artifacts
Navigate to %LOCALAPPDATA% (paste into File Explorer address bar) and look for folders with random names or anything containing "igg," "games," or recently created folders you don't recognize. Common hiding spots include subdirectories within the user's AppData\Local and AppData\Roaming folders. Delete suspicious folders entirely. Also check C:\Program Files and C:\Program Files (x86) for unfamiliar applications and remove those folders.
Run Malwarebytes or Similar Scanner
Reconnect to the internet and download Malwarebytes Free (from malwarebytes.com—verify the URL) or another reputable anti-malware tool. Run a full system scan, not a quick scan. The scan will likely detect remaining components, browser hijacker registry entries, and potentially other PUPs that came bundled with Igggames.co. Quarantine and remove everything detected, then run a second scan to confirm the system is clean.
Change Passwords and Check for Data Theft
Since the hijacker tracked your browsing and potentially captured form data, change passwords for important accounts—starting with email, banking, and any site where you've entered credentials recently. Use a different, clean device if possible. Check your browser's saved passwords (chrome://settings/passwords or equivalent) and remove any you don't recognize—some hijackers harvest stored credentials.
Reboot Normally and Verify Removal
Restart the computer in normal mode and verify the browser opens to your chosen homepage without redirects. Search for something generic and confirm results come from your selected search engine, not a hijacker proxy. Monitor system performance and network activity over the next few hours—if redirects return or new suspicious extensions appear, deeper infection remains and professional help is recommended.
Prevention
- Always use Custom/Advanced installation modes when installing any free software, and read each screen carefully. Uncheck any pre-selected offers for additional programs, browser toolbars, or homepage changes. Legitimate software doesn't hide these options—only PUP distributors do.
- Download software only from official sources—the developer's website or verified app stores like Microsoft Store, Mac App Store, or reputable repositories. Third-party download sites frequently bundle PUPs with legitimate installers, even for well-known software. If you must use download aggregators, verify the installer's digital signature before running it.
- Avoid pirated software and game cracks entirely. Beyond the legal and ethical issues, cracked software is the single most common infection vector for browser hijackers, adware, and worse. The "free" game isn't worth the hours of cleanup, potential data theft, and system instability that typically follow.
- Keep browsers and security software updated. Browser vendors regularly patch vulnerabilities that allow drive-by installations, and modern browsers now warn about or block many PUP installers. Enable automatic updates for your browser and operating system, and maintain reputable antivirus software with real-time protection enabled.
- Review installed extensions monthly. Set a calendar reminder to check your browser extensions every 30 days and remove anything you don't actively use. Malicious extensions sometimes get added through software bundles or compromised websites, and dormant extensions can be remotely updated with malicious code.
- Be skeptical of "required" updates when browsing. Legitimate software updates come through official channels—Windows Update, Mac App Store, or the application's built-in updater. If a website claims you need to install Flash Player, a video codec, or a browser update to view content, close the page immediately; it's almost certainly a PUP or malware installer.
- Use an ad blocker and script blocker like uBlock Origin or similar browser extensions. While not foolproof, these tools block many malvertising campaigns and deceptive download buttons that lead to hijacker installers. Configure them to block third-party scripts by default on unfamiliar sites.
- Create a standard (non-admin) user account for daily computing tasks. Many PUPs require administrator privileges to install system-wide persistence mechanisms. Running as a standard user forces installation prompts that give you a chance to cancel the process before damage occurs.
When Computer Repair Roswell removes browser hijackers or any malware from your system, the work is covered by our 90-day reinfection warranty. If the same threat returns within 90 days through no fault of your own (not from downloading more pirated software, for example), we'll clean it again at no charge. We also provide guidance on safe computing practices so you can avoid these problems going forward.
Bring It In
Browser hijackers like Igggames.co are frustrating, time-consuming problems that often hide deeper than they initially appear. While the manual removal steps above work for straightforward infections, many cases involve multiple bundled PUPs, rootkit-level persistence, or system damage that requires professional tools and experience to fully resolve. If you've attempted removal and still see redirects, if your browser crashes constantly, or if you're simply not comfortable editing the registry and scheduled tasks yourself, don't waste more hours fighting it.
Computer Repair Roswell specializes in malware removal for residential and small-business clients throughout the Roswell, Georgia area. We'll diagnose the infection, remove all components (not just the visible browser modifications), verify your system is clean, and optimize performance so it runs better than before the infection. Most browser hijacker removals are completed same-day, often while you wait. Call us at (770) 415-0368 or stop by our shop at 1735 Woodstock Road. We're open Monday through Saturday, and we're happy to answer questions about your specific situation—no obligation, just honest advice about whether you need professional help or can handle it yourself.