The domain immat.tress.azurewebsites.net represents a browser hijacker that redirects users through a series of deceptive advertising networks, often leading to potentially unwanted programs (PUPs), phishing pages, or further malware downloads. This threat typically manifests as unwanted redirects in web browsers, forcing users to visit advertising portals and affiliate landing pages that generate revenue for the hijacker's operators. While not as destructive as ransomware or banking trojans, browser hijackers like this compromise your browsing experience, expose you to questionable content, and can serve as a gateway to more serious infections.
This particular threat abuses Microsoft Azure's legitimate hosting infrastructure—specifically the azurewebsites.net subdomain space—to host redirect chains that are harder to block through conventional domain blacklisting. Users typically encounter this hijacker after installing bundled freeware, clicking deceptive download buttons on file-sharing sites, or falling victim to malicious browser extensions that modify DNS settings or search engine preferences without consent.
Threat Profile
| Attribute | Details |
|---|---|
| Threat Type | Browser Hijacker / Redirect Malware / PUP (Potentially Unwanted Program) |
| Aliases | Azure-hosted redirect chain, immat.tress hijacker, azurewebsites.net redirect malware |
| Affected Platforms | Windows (all versions), macOS (via browser extensions) |
| Affected Browsers | Google Chrome, Mozilla Firefox, Microsoft Edge, Safari, Opera |
| Distribution Methods | Software bundling, fake download buttons, malicious browser extensions, compromised WordPress sites, deceptive advertising |
| Persistence Mechanisms | Browser extension policies, modified shortcuts (LNK files), scheduled tasks, registry values (Windows), Launch Agents (macOS) |
| Primary Capabilities | Browser redirection, search query hijacking, homepage/new-tab modification, ad injection, tracking cookie installation |
| Associated Domains | Varies; commonly rotates through multiple Azure subdomains and third-party advertising networks |
| Data Collection | Browsing history, search queries, IP addresses, geolocation data, potentially login credentials through phishing redirects |
| Network Behavior | Frequent DNS queries to .azurewebsites.net subdomains, connections to advertising trackers and affiliate networks |
| Payload Delivery | Often delivers secondary PUPs, fake antivirus programs, survey scams, or additional browser hijackers |
| Removal Difficulty | Moderate; requires browser cleanup, extension removal, and system-level persistence elimination |
How It Spreads
The immat.tress.azurewebsites.net hijacker primarily spreads through software bundling—a deceptive practice where free applications include additional "offers" that most users don't notice during installation. When you download a seemingly legitimate program from a third-party download site (not the official developer's website), the installer often contains multiple bundled components. If you click through the installation using "Express" or "Recommended" settings without reading carefully, you consent to installing browser extensions, toolbars, and other modifications that enable the hijacker.
Another common distribution vector involves malicious browser extensions masquerading as useful utilities. These might advertise themselves as PDF converters, video downloaders, weather widgets, or shopping assistants. Once installed, these extensions request broad permissions to "read and change all your data on websites you visit"—permissions that allow them to inject redirect scripts and modify your browser's behavior. Some variants also spread through compromised WordPress websites or malicious advertising networks that exploit vulnerabilities in outdated browsers or plugins.
Common distribution methods include:
- Bundled freeware installers from download portals like Softonic, download.com, or torrent sites
- Fake "Download" buttons on file-sharing websites that install hijackers instead of the desired file
- Malicious browser extensions promoted through deceptive pop-up ads or social media posts
- Email attachments containing dropper scripts disguised as invoices, shipping notices, or document viewers
- Compromised websites that inject redirect scripts through vulnerabilities in outdated CMS platforms
- Fake software updates (especially fake Flash Player or browser update notifications)
- Exploit kits that target unpatched browsers or plugins to install the hijacker without user interaction
What It Does On Your Machine
Once installed, the immat.tress.azurewebsites.net hijacker modifies your browser configuration to force all web traffic through its redirect chain. The most obvious symptom is that your homepage, default search engine, and new tab page all change to unfamiliar addresses—often search portals or advertising landing pages you never authorized. When you attempt to perform a web search, your queries get redirected through multiple intermediate domains before delivering results laden with sponsored links and advertisements.
The hijacker achieves persistence through several mechanisms. In Windows environments, it may create scheduled tasks that reapply browser modifications even after you manually change your settings back. It often modifies browser shortcut files (LNK files) to include command-line parameters that force the browser to load specific URLs on startup. Registry entries under HKCU\Software\Microsoft\Windows\CurrentVersion\Run or similar locations may launch background processes that monitor and reapply the hijacker's settings.
The browser extension component—if present—operates with elevated permissions that allow it to intercept and modify all web traffic. This means the hijacker can inject advertisements into legitimate websites, replace search results with paid links, and collect detailed information about your browsing habits. Some variants install tracking cookies that follow you across multiple websites, building a profile of your interests for targeted advertising. More aggressive versions may attempt to install additional unwanted software or redirect you to phishing pages designed to steal login credentials.
On the filesystem level, you might observe artifacts like these (actual paths vary by infection variant):
Manual Removal — Step by Step
Disconnect from the Internet
Before beginning removal, disconnect your computer from the internet (unplug Ethernet or disable Wi-Fi). This prevents the hijacker from downloading additional components, communicating with command servers, or re-downloading itself during the cleanup process.
Boot Into Safe Mode with Networking
Restart your computer in Safe Mode with Networking. On Windows 10/11, hold Shift while clicking Restart, then navigate to Troubleshoot > Advanced Options > Startup Settings > Restart, and press F5. Safe Mode prevents most auto-starting malware components from loading, making removal easier.
Uninstall Suspicious Programs
Open Settings > Apps > Apps & Features (or Control Panel > Programs and Features on older Windows). Sort by install date and uninstall any unfamiliar programs installed around the time the redirects started. Look for generic names like "Browser Assistant," "Web Helper," or publisher names you don't recognize. Don't skip this step—many hijackers install companion programs.
Remove Malicious Browser Extensions
Open each installed browser and check for suspicious extensions. In Chrome: menu (three dots) > Extensions > Manage Extensions. In Firefox: menu > Add-ons > Extensions. In Edge: menu > Extensions. Remove anything you didn't intentionally install, especially extensions with vague names or that request broad permissions. If an extension won't remove, note its ID (visible in the extensions folder path) for later cleanup.
Reset Browser Settings
In Chrome: Settings > Reset settings > Restore settings to their original defaults. In Firefox: Help > More Troubleshooting Information > Refresh Firefox. In Edge: Settings > Reset settings > Restore settings to their default values. This removes hijacker-imposed search engines, homepages, and startup pages without deleting your bookmarks or passwords.
Check and Fix Browser Shortcuts
Right-click each browser shortcut (on desktop, taskbar, and Start Menu), select Properties, and examine the "Target" field. It should contain ONLY the path to the browser executable—nothing after it. If you see additional URLs or parameters after chrome.exe (or firefox.exe, etc.), delete everything after the closing quote of the executable path. Click Apply, then OK.
Remove Scheduled Tasks and Startup Entries
Press Win+R, type "taskschd.msc" and press Enter to open Task Scheduler. Look through the task list for anything unfamiliar (especially under Microsoft > Windows). Delete suspicious tasks. Then press Win+R, type "msconfig" and check the Startup tab (or use Task Manager > Startup on Windows 10/11). Disable any unfamiliar startup items.
Scan with Reputable Anti-Malware Tools
Download and run Malwarebytes (free version works fine) and perform a full system scan. Also run a scan with Windows Defender or your preferred antivirus. These tools will catch remnant files, registry entries, and related PUPs that manual removal might miss. Remove everything they detect before proceeding.
Clear Browser Data and DNS Cache
In each browser, clear all browsing data (cache, cookies, history) for "all time." Then open Command Prompt as administrator and run these commands: ipconfig /flushdns and netsh winsock reset. This removes any cached redirect paths and resets network settings that the hijacker may have modified.
Restart Normally and Verify
Restart your computer normally (exit Safe Mode). Open your browser and verify that your homepage, search engine, and new tab page are set correctly. Visit a few websites to confirm no redirects occur. If problems persist, the infection may have deeper persistence mechanisms requiring professional removal.
Prevention
- Download software only from official sources. Avoid third-party download sites, torrent portals, and file-sharing platforms. Go directly to the developer's website for any program you need.
- Always choose "Custom" or "Advanced" installation. Never click through installers using Express/Quick/Recommended settings. Read each screen carefully and uncheck any offers for additional software, toolbars, or browser modifications.
- Review browser extension permissions carefully. Before installing any extension, check what permissions it requests. If a simple tool asks to "read and change all your data on websites," that's a red flag. Limit extensions to only those you genuinely need.
- Keep your system and browsers updated. Enable automatic updates for Windows, macOS, and all browsers. Most hijackers exploit outdated software with known vulnerabilities. Patches close these security holes.
- Use a reputable ad blocker. Extensions like uBlock Origin block malicious advertising networks that distribute hijackers. They also prevent you from accidentally clicking deceptive download buttons on legitimate sites.
- Be skeptical of urgent update notifications. Legitimate browser updates happen automatically or through the browser's own update mechanism—never through pop-up ads or emails. If you see a message claiming your Flash Player or browser is out of date, close it and manually check for updates through official channels.
- Maintain a good anti-malware solution. Keep Windows Defender enabled (it's quite effective now) or use a trusted third-party antivirus. Run periodic scans even if you don't notice problems.
- Create regular backups. While browser hijackers don't destroy data like ransomware, having current backups of important files means you can afford to reinstall Windows cleanly if an infection proves stubborn.
When Computer Repair Roswell removes malware from your system, we back our work with a 90-day warranty. If the same infection returns within three months, bring your computer back and we'll re-clean it at no additional charge. We don't just remove the visible symptoms—we hunt down every persistence mechanism to ensure the threat is truly gone.
Bring It In
If you've followed the removal steps above and still experience redirects, unwanted pop-ups, or suspicious browser behavior, the infection may have installed rootkit components or exploited deeper system vulnerabilities that require professional tools and expertise to address. Some hijacker variants install multiple layered persistence mechanisms specifically designed to survive casual removal attempts. At Computer Repair Roswell, we use specialized forensic tools to identify every artifact an infection leaves behind—from registry modifications and scheduled tasks to browser policy files and hidden system drivers.
Don't let a "simple" browser hijacker evolve into a more serious security problem. Many infections start with seemingly minor annoyances but open backdoors for more dangerous malware. Our technicians can typically complete a thorough malware removal in a few hours, restoring your system to clean, safe operation. Call us at (770) 569-2709 or stop by our Roswell location at your convenience. We serve homeowners and small businesses throughout the North Fulton area, and we'll give you an honest assessment of what's needed to secure your computer—no scare tactics, no upselling, just straightforward technical expertise.