Infacom is a browser hijacker and potentially unwanted program (PUP) that forcibly modifies web browser settings to redirect users through unwanted search engines and advertising networks. First identified in the mid-2010s, this software typically arrives bundled with free software downloads and immediately takes control of your homepage, default search provider, and new tab page without meaningful consent. While not as destructive as ransomware or banking trojans, Infacom degrades browsing performance, exposes users to potentially malicious advertising, and creates privacy concerns through aggressive tracking of search queries and browsing habits.

Infacom — cybersecurity illustration
Photo by Ann H on Pexels

The primary danger of Infacom lies not in direct file destruction but in the ecosystem it creates: users subjected to endless redirects, exposure to scam advertisements, and the collection of browsing data for monetization purposes. Many victims report significant browser slowdowns, unexpected toolbars appearing in their browsers, and an inability to navigate to their intended search engines even after manually changing settings. The hijacker employs persistence mechanisms that make it resurface even after apparently successful removal attempts.

Think you're infected right now? Disconnect from the internet if you're seeing constant redirects or pop-ups. Don't enter passwords or financial information until the infection is cleared. Call us at (770) 637-1435 for same-day service, or skip to the removal section below if you want to attempt cleaning it yourself first.

Threat Profile

Attribute Details
Threat Family Browser Hijacker / Potentially Unwanted Program (PUP)
Common Aliases Infacom Search, Infacom Toolbar, Search.infacom-media.com
Affected Platforms Windows (all versions from XP through 11); primarily targets Chrome, Firefox, Edge, Internet Explorer
First Documented Approximately 2014–2015
Distribution Method Software bundling (freeware installers), fake update prompts, misleading download buttons on file-sharing sites
Persistence Mechanisms Browser extension/add-on installation, registry modifications, scheduled tasks, browser policy enforcement
Primary Capabilities Homepage/search engine hijacking, redirect injection, advertising injection, browsing data collection, toolbar installation
Typical Artifacts Browser extensions with random names, modified Preferences/user.js files in browser profiles, Run registry keys, AppData folders with randomized names
Network Behavior Redirects through search.infacom-media.com and affiliated domains; contacts ad-serving networks; may beacon user activity to tracking servers
Data at Risk Browsing history, search queries, clicked links, potentially form data depending on variant
Removal Difficulty Moderate — standard antivirus often misses it; requires browser reset and manual cleanup of persistence mechanisms
Reinfection Risk High if users continue downloading from bundled software sources without caution

How It Spreads

Infacom spreads almost exclusively through deceptive software bundling practices. The hijacker is packaged with legitimate-seeming freeware applications—often video converters, PDF creators, download managers, or system optimization utilities downloaded from third-party hosting sites. During installation, the setup wizard uses dark patterns to obtain consent: pre-checked boxes buried in lengthy terms of service, "Express Installation" options that hide bundled software, or misleading button layouts where "Decline" actually means "Accept."

Users who rush through installation screens by repeatedly clicking "Next" inadvertently agree to install Infacom alongside their intended program. By the time the installation completes, the browser hijacker has already modified browser shortcuts, installed extensions, and established persistence mechanisms. The parent application may function exactly as advertised, giving users no immediate indication that anything malicious occurred.

Common infection vectors include:

  • Bundled freeware installers from download portals like Softonic, Download.com (in its earlier days), or lesser-known file-sharing sites
  • Fake "Update Required" prompts on websites claiming your Flash Player, Java, or media codec is out of date
  • Misleading download buttons on torrent sites or file-hosting services where the actual download is a tiny link while large green buttons lead to bundled installers
  • Pirated software installers modified to include PUPs alongside cracked applications or key generators
  • Malvertising campaigns that push drive-by downloads of "system optimization" tools containing Infacom
  • Email attachments disguised as legitimate software or document viewers (less common for this specific threat)

What It Does On Your Machine

Once installed, Infacom immediately modifies your browser configuration to redirect all search activity through its controlled search portals. When you open your browser, instead of seeing your chosen homepage (Google, Bing, a blank page), you're taken to search.infacom-media.com or a related domain. The search bar becomes trapped—even if you manually change your search engine settings in the browser preferences, Infacom's background processes revert the changes within minutes or upon the next browser restart.

The hijacker achieves this control through multiple simultaneous tactics. It installs browser extensions or add-ons that override user settings at the extension API level. It modifies browser configuration files directly, writing new default values into Chrome's Preferences file or Firefox's prefs.js. It may alter browser shortcut targets (the .lnk files on your desktop and taskbar) to append command-line parameters that force a specific homepage. Some variants even employ Windows Group Policy settings or registry keys that enforce browser configurations at the operating system level, making them extremely resistant to manual changes.

Beyond the visible search redirects, Infacom tracks your browsing activity extensively. It logs search terms you enter, websites you visit, links you click, and the time spent on each page. This data gets transmitted to remote servers where it's analyzed for advertising profiles and potentially sold to data brokers. The hijacker injects additional advertisements into legitimate websites you visit, often displaying pop-unders, banner ads in unusual positions, or interstitial advertisements before allowing you to access your intended page. These ads frequently promote questionable products—aggressive "system cleaner" software, fake antivirus programs, or even potentially fraudulent services.

Typical Infacom Filesystem and Registry Artifacts
C:\Users\[Username]\AppData\Local\Infacom\ # Main program folder with executables and configuration C:\Users\[Username]\AppData\Roaming\Mozilla\Firefox\Profiles\[profile]\prefs.js user_pref("browser.startup.homepage", "http://search.infacom-media.com"); user_pref("browser.search.defaultenginename", "Infacom Search"); C:\Users\[Username]\AppData\Local\Google\Chrome\User Data\Default\Preferences # JSON file modified to set homepage and search provider HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run Infacom Update Service → C:\Users\[Username]\AppData\Local\Infacom\updater.exe HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome HomepageLocation → http://search.infacom-media.com C:\Users\[Username]\AppData\Local\Google\Chrome\User Data\Default\Extensions\[random-id]\ # Browser extension folder with obfuscated JavaScript Task Scheduler: \Infacom Update Task # Scheduled task configured to run updater.exe at login and every 3 hours

Performance degradation is another hallmark of Infacom infections. The hijacker consumes system resources through constant background processes that monitor for setting changes and communicate with remote servers. Users report browsers taking significantly longer to start, pages loading more slowly due to injected advertising scripts, and occasional browser crashes when the hijacker's code conflicts with legitimate website functionality. The infection also increases security risks: the redirected search results may include phishing sites or malware distribution points that wouldn't appear in legitimate search engines' filtered results.

Manual Removal — Step by Step

01

Disconnect from the Internet

Unplug your Ethernet cable or disable Wi-Fi to prevent the hijacker from receiving commands, downloading additional components, or uploading collected browsing data. This also stops the constant flow of intrusive advertisements while you work on removal.

02

Boot into Safe Mode with Networking

Restart your computer and press F8 repeatedly during boot (or hold Shift while clicking Restart on Windows 10/11, then navigate to Troubleshoot > Advanced Options > Startup Settings > Restart > press 5 for Safe Mode with Networking). Safe Mode prevents Infacom's auto-start processes from launching, making removal much easier.

03

Uninstall Suspicious Programs

Open Control Panel > Programs and Features (or Settings > Apps on Windows 10/11). Sort by install date and look for unfamiliar programs installed around the time your browser problems started. Uninstall anything named Infacom, as well as any suspicious "toolbars," "search assistants," "download managers," or programs you don't recognize. Be thorough—the installer may have added multiple related programs.

04

Remove Browser Extensions and Reset Settings

Open each affected browser and remove all unfamiliar extensions (Chrome: three-dot menu > Extensions > Manage Extensions; Firefox: three-bar menu > Add-ons and Themes > Extensions). Then reset each browser completely: Chrome Settings > Reset settings > Restore settings to their original defaults; Firefox Help > More Troubleshooting Information > Refresh Firefox. This removes hijacker configurations while preserving bookmarks.

05

Clean Registry Persistence Mechanisms

Press Win+R, type "regedit," and press Enter. Navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. Delete any entries referencing Infacom or suspicious AppData paths. Also check HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome and similar policy keys for Firefox/Edge, deleting any hijacker-imposed policies.

06

Remove Scheduled Tasks

Press Win+R, type "taskschd.msc," and press Enter to open Task Scheduler. Expand Task Scheduler Library and look through the list for any tasks containing "Infacom," "update," or unfamiliar names with random characters. Right-click suspicious tasks and select Delete. These scheduled tasks often resurrect the hijacker even after file removal.

07

Delete Infacom Program Folders

Open File Explorer and navigate to C:\Users\[YourUsername]\AppData\Local\ and \AppData\Roaming\. Show hidden files (View > Hidden items checkbox). Look for folders named Infacom or folders with random alphanumeric names created around your infection date. Delete these entire folders. Also check C:\Program Files\ and C:\Program Files (x86)\ for any Infacom directories.

08

Fix Browser Shortcuts

Right-click each browser shortcut on your desktop and taskbar, select Properties, and examine the Target field. It should end with the browser's .exe file path and nothing else. If you see additional URLs or parameters after the .exe, delete everything after the closing quotation mark following the executable path. Click OK to save.

09

Scan with Reputable Anti-Malware Tools

Reconnect to the internet and download Malwarebytes (free version works fine) or another reputable scanner like HitmanPro. Run a full system scan to catch any components you may have missed. These tools specifically target PUPs and browser hijackers that traditional antivirus often overlooks. Quarantine or delete everything they find.

10

Reboot and Verify Clean Operation

Restart your computer normally (not in Safe Mode). Open your browsers and verify they start with your intended homepage and use your preferred search engine. Perform several searches and visit various websites to confirm no redirects occur. Check Task Manager (Ctrl+Shift+Esc) for any suspicious processes consuming resources. If problems persist, the infection may be more deeply rooted than typical Infacom variants.

Prevention

  1. Download software only from official sources. Get programs directly from the developer's website rather than third-party download portals. If you must use a hosting site, scrutinize every installation screen and choose "Custom" or "Advanced" installation to see what's being bundled.
  2. Read every installer screen carefully. Never use "Express" or "Recommended" installation options for free software. Uncheck any pre-checked boxes offering toolbars, search engine changes, homepage modifications, or "partner offers." Take the extra thirty seconds—it prevents hours of cleanup.
  3. Keep browsers and security software current. Enable automatic updates for your browsers and maintain active antivirus protection. Modern browsers have improved protection against hijacker techniques, but only if they're running current versions with the latest security patches.
  4. Use browser security extensions sparingly but wisely. Consider installing uBlock Origin (not just "uBlock") to block malicious advertisements and reduce exposure to drive-by download attempts. Avoid installing multiple security extensions, which can conflict and actually reduce protection.
  5. Be skeptical of update prompts on websites. Legitimate software updates come through the application itself or Windows Update—not through pop-ups on random websites. If a site claims you need to update Flash, Java, or a codec, close the page and check directly with the software vendor if genuinely concerned.
  6. Avoid pirated software and key generators. These are overwhelmingly bundled with malware, PUPs, and hijackers. The "free" cracked program costs far more in time, data loss, and repair expenses than a legitimate license would have.
  7. Create a limited user account for daily use. Running Windows with administrator privileges gives malware unrestricted access to system areas. A standard user account prevents many hijackers from installing system-level persistence mechanisms without triggering a UAC prompt.
  8. Educate family members who use your computer. Many Infacom infections occur when well-meaning but less tech-savvy family members install "helpful" software. Brief household members on the risks of free software bundles and establish a policy of checking with you before installing anything.
Our 90-Day Warranty: When we remove Infacom or any other infection from your computer, it stays gone. Every malware removal service comes with our 90-day reinfection warranty—if the same problem comes back within three months, we'll fix it again at no charge. That's our commitment to doing the job right the first time.

Bring It In

While the steps above work for straightforward Infacom infections, browser hijackers can be surprisingly persistent, and many infections include additional PUPs that weren't immediately obvious. If you've followed the removal steps but still experience redirects, slowdowns, or suspicious browser behavior, the infection may have deeper roots than typical variants. Some hijackers install kernel-mode drivers, modify system-level DNS settings, or establish file-replacement mechanisms that rewrite cleaned files within minutes.

Computer Repair Roswell has cleaned thousands of hijacker infections from Roswell-area computers. We'll thoroughly scan your system with professional-grade tools, verify complete removal of all components, optimize browser performance, and check for any additional security issues the hijacker may have introduced. Give us a call at (770) 637-1435 or stop by our shop at 1650 Hembree Road, Suite 101, Roswell, GA 30076. Most hijacker removals are completed same-day, and we'll show you exactly what we found and how to avoid reinfection. Your browser should work for you, not against you—let's get it back to normal.