Infanews.com is a browser hijacker that forcibly redirects your web searches and homepage to its own search portal, degrading your browsing experience while exposing you to potentially malicious advertising networks. Unlike straightforward adware, this hijacker modifies critical browser settings and installs persistence mechanisms that prevent casual removal, often requiring manual intervention to fully eradicate. Computer Repair Roswell encounters this threat regularly on both Windows and Mac systems, where users report sudden homepage changes, unfamiliar search engines, and redirects through suspicious intermediate pages before reaching legitimate search results.

Infanews.com — cybersecurity illustration
Photo by Ann H on Pexels
Think You're Infected Right Now? If Infanews.com has taken over your browser, disconnect from your network immediately and avoid entering passwords or sensitive information. The hijacker may log search queries and inject tracking scripts. Follow the removal steps below or call Computer Repair Roswell at (770) 947-1234 for same-day assistance. Our shop is located at 1735 Woodstock Rd, Roswell, GA 30075, and we handle browser hijacker removals daily with a 90-day warranty.

Threat Profile

Attribute Details
Threat Classification Browser Hijacker / Potentially Unwanted Program (PUP)
Family Infanews redirect family
Platforms Affected Windows (all versions), macOS (Safari, Chrome, Firefox)
Browsers Targeted Chrome, Firefox, Edge, Safari, Internet Explorer (legacy)
Distribution Method Software bundles, fake updates, malvertising campaigns
Persistence Mechanisms Browser extension installation, scheduled tasks, modified shortcut targets, registry keys (Windows), Launch Agents (macOS)
Primary Capabilities Search redirection, homepage hijacking, new-tab takeover, ad injection, tracking cookie deployment
Data Collection Search queries, browsing history, clicked links, system information, geolocation data
Monetization Model Pay-per-click advertising revenue, affiliate commissions, data brokerage
Network Behavior Redirects through multiple intermediate domains before reaching search results; connects to ad networks and tracking servers
Removal Difficulty Moderate — requires browser cleanup, extension removal, and persistence mechanism elimination
Risk Level Medium — primarily privacy/performance impact, but exposure to malicious advertising networks increases infection risk

How It Spreads

Infanews.com rarely arrives alone on your system. The hijacker typically bundles with free software installers that use deceptive installation wizards designed to rush users through setup screens without careful review. These bundlers present the browser hijacker as a "recommended" or "optional" component, often pre-checked by default, buried in fine print, or hidden behind an "Advanced" or "Custom" installation option that most users skip. Software download portals and torrent sites frequently repackage legitimate programs with these bundlers, turning what appears to be a simple media player or PDF converter into a delivery vehicle for multiple unwanted programs.

The hijacker also exploits fake system alerts and fraudulent update notifications. You might encounter convincing pop-ups claiming your Flash Player is outdated, your video codec needs updating, or your system requires a critical security patch. Clicking these prompts downloads an installer that appears to provide the promised update but actually installs Infanews.com alongside — or sometimes instead of — any legitimate software. These fake alerts often appear on questionable streaming sites, file-sharing platforms, or websites compromised by malvertising networks.

Common distribution vectors include:

  • Bundled freeware installers from third-party download sites (download.com, softonic.com, and similar aggregators)
  • Fake Flash Player or codec updates on streaming or video sites
  • Malvertising campaigns on legitimate websites whose ad networks have been compromised
  • Torrent bundles where pirated software includes unexpected "extras"
  • Email attachments disguised as invoices, shipping notifications, or document viewers
  • Browser extension marketplaces where the hijacker masquerades as a productivity tool, weather widget, or coupon finder
  • Compromised installer packages for popular utilities that have been repackaged by unauthorized distributors

What It Does On Your Machine

Once installed, Infanews.com immediately modifies your browser configuration to enforce its search portal as your default search engine, homepage, and new-tab page. Every time you open your browser or create a new tab, you'll land on the Infanews.com interface instead of your preferred starting page. When you enter a search query in the address bar or search box, the hijacker intercepts that query and routes it through its own servers before eventually displaying search results — often powered by a legitimate search engine like Bing or Yahoo, but filtered through the hijacker's advertising and tracking infrastructure.

The redirection process typically bounces your browser through several intermediate domains before reaching the final search results page. These redirect hops serve multiple purposes: they obscure the hijacker's backend infrastructure, complicate removal attempts by making it harder to identify the responsible program, and create opportunities for additional ad impressions and tracking cookies. During this journey, your search query, IP address, browser fingerprint, and other identifying information get logged by the hijacker's operators. This data powers targeted advertising campaigns and may be sold to data brokers who aggregate browsing profiles for marketing purposes.

Beyond search hijacking, Infanews.com often injects additional advertisements into web pages you visit, displays pop-under windows, and triggers notification prompts asking for permission to show alerts even when your browser is closed. The hijacker may install browser extensions that prevent you from changing your settings back to normal — when you manually reset your homepage or default search engine, the extension automatically reverts it within seconds or upon next browser launch. Some variants create Windows scheduled tasks or macOS Launch Agents that periodically check whether their browser modifications remain in place, reinstating them if you manage to temporarily clear them.

The performance impact becomes noticeable quickly. Browsers slow down due to constant background communication with tracking servers, pages take longer to load because of injected advertising scripts, and system resources get consumed by persistence processes that monitor your browser configuration. More concerning is the security exposure: the advertising networks Infanews.com connects to typically employ minimal quality control, meaning you're more likely to encounter malicious advertisements promoting fake technical support scams, additional malware downloads disguised as system cleaners, or phishing pages that mimic banking and e-commerce sites.

Typical Infanews.com Artifacts (Windows)
%LOCALAPPDATA%\Infanews\ %APPDATA%\InfanewsUpdater\ %PROGRAMFILES(X86)%\Infanews Search\ // Browser extension folders %LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\[random-ID]\ %APPDATA%\Mozilla\Firefox\Profiles\[profile].default\extensions\[GUID]@infanews.com\ // Registry persistence (Windows) HKCU\Software\Microsoft\Windows\CurrentVersion\RunInfanewsUpdate HKCU\Software\Policies\Google\Chrome\ExtensionInstallForcelist HKLM\SOFTWARE\Policies\Microsoft\Edge\ExtensionInstallForcelist // Scheduled tasks Task Scheduler Library\InfanewsUpdateTask Task Scheduler Library\Infanews Browser Monitor

Manual Removal — Step by Step

01

Disconnect From the Network

Unplug your Ethernet cable or disable Wi-Fi before proceeding. This prevents the hijacker from communicating with its command servers, downloading additional components, or reinstating itself from cloud-based configurations during the removal process. Some browser hijackers attempt to pull fresh copies of their extensions from remote servers when they detect removal attempts.

02

Boot Into Safe Mode With Networking

On Windows 10/11, hold Shift while clicking Restart, then navigate to Troubleshoot → Advanced Options → Startup Settings → Restart → press 5 for Safe Mode with Networking. On macOS, restart and immediately hold Shift until you see the login screen. Safe Mode prevents most startup items and scheduled tasks from running, which stops the hijacker's persistence mechanisms from interfering with removal.

03

Uninstall Suspicious Programs

Open Settings → Apps (Windows) or Applications folder (macOS) and review recently installed programs. Look for entries containing "Infanews," unfamiliar names installed around the time your browser problems started, or suspicious programs you don't remember installing. Uninstall anything related to browser toolbars, search assistants, or optimization utilities that appeared without your explicit consent. Watch the dates — hijackers often install multiple related components simultaneously.

04

Remove Browser Extensions

Open each browser's extension management page (chrome://extensions/ for Chrome, about:addons for Firefox, edge://extensions/ for Edge). Enable "Developer Mode" if available to see hidden extensions. Remove any extensions you didn't deliberately install, especially those with vague names, no ratings, or "Installed by enterprise policy" labels. The Infanews hijacker often installs extensions with generic names like "Search Helper," "News Feed," or random letter combinations. Remove them all and restart the browser.

05

Clean Browser Shortcuts and Reset Settings

Right-click your browser shortcuts (desktop, taskbar, Start Menu) and select Properties. Check the Target field — if anything appears after the .exe path (like --homepage=http://infanews.com), delete that extra text. Then open each browser's settings and manually reset your homepage, search engine, and startup pages to your preferences. In Chrome/Edge, go to Settings → Reset settings → Restore settings to defaults. In Firefox, type about:support in the address bar and click "Refresh Firefox."

06

Delete Hijacker Files and Folders

Open File Explorer and navigate to %LOCALAPPDATA%, %APPDATA%, and %PROGRAMFILES(X86)% (type these into the address bar). Look for folders named "Infanews" or containing recently modified files you don't recognize. Delete these folders completely. On macOS, check ~/Library/Application Support/, ~/Library/LaunchAgents/, and /Library/LaunchAgents/ for related files. You may need to show hidden files (View → Hidden items in Windows, Cmd+Shift+. in macOS Finder).

07

Remove Registry Persistence (Windows Only)

Press Win+R, type regedit, and press Enter. Navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and look for suspicious entries with paths pointing to the folders you just deleted. Delete those entries. Also check HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome and similar policy keys for browser configuration enforcement. Delete any Infanews-related keys, but be cautious — deleting wrong registry entries can cause system instability.

08

Remove Scheduled Tasks

Open Task Scheduler (search for it in the Start Menu) and review the Task Scheduler Library for tasks with names related to Infanews, browser updates, or unfamiliar publishers. Right-click and delete any suspicious tasks. On macOS, check for .plist files in ~/Library/LaunchAgents/ and /Library/LaunchAgents/ with suspicious names — move them to Trash and empty it.

09

Run a Reputable Anti-Malware Scanner

Download Malwarebytes (free version works fine) or another reputable scanner while in Safe Mode. Run a full system scan to catch any components you might have missed, including tracking cookies and associated PUPs. The hijacker often travels with companion adware that won't necessarily appear as "Infanews" in file names. Let the scanner complete, then remove all detected threats.

10

Change Passwords and Reboot

If you entered any passwords while the hijacker was active, change them from a known-clean device or after confirming removal. Browser hijackers primarily log browsing data rather than credentials, but better safe than sorry. Reboot your computer normally (not in Safe Mode), reconnect to the network, and verify that your browser settings remain correct. If Infanews.com reappears, you likely missed a persistence mechanism — repeat the registry and scheduled task checks.

Prevention

  1. Download software only from official sources. Go directly to the developer's website rather than using third-party download portals. Sites like download.com and softonic.com frequently bundle installers with PUPs even when offering legitimate software. If you must use an aggregator, verify the installer's digital signature matches the official publisher.
  2. Always choose Custom/Advanced installation. When installing any free software, never click "Express" or "Recommended" install. Custom installation reveals bundled offers that you can decline. Read each screen carefully — pre-checked boxes often authorize installation of browser toolbars, search hijackers, and other unwanted additions.
  3. Keep Flash Player dead and buried. Adobe discontinued Flash Player in December 2020. Any prompt claiming you need to update Flash is a scam delivering malware. Legitimate websites use HTML5 video that requires no plugins. If a site demands Flash, find your content elsewhere.
  4. Use a reputable ad blocker. Extensions like uBlock Origin prevent malicious advertisements from appearing in the first place, significantly reducing your exposure to hijacker distribution networks. Ad blockers also improve browsing speed and privacy as a bonus.
  5. Review browser extensions monthly. Make a calendar reminder to audit your installed extensions every 30 days. Remove anything you don't actively use. Hijackers sometimes install themselves as extensions that masquerade as helpful utilities, then sit dormant before activating weeks later.
  6. Keep your system and browsers updated. Enable automatic updates for Windows/macOS and all installed browsers. Security patches close vulnerabilities that hijackers exploit to bypass user permission prompts. Most successful infections target unpatched systems running outdated browser versions.
  7. Learn to recognize social engineering. No legitimate website generates urgent pop-ups claiming your system is infected or that you've won a prize. Close these windows without clicking anything inside them (use the X button in the browser tab, not within the pop-up itself). When in doubt, close the browser entirely using Task Manager.
  8. Run periodic scans with anti-malware software. Even if you're careful, schedule weekly scans with Malwarebytes or Windows Defender. Early detection catches hijackers before they establish deep persistence, making removal simpler and reducing the window of data exposure.
Our 90-Day Warranty Guarantee: When Computer Repair Roswell removes Infanews.com or any other malware from your machine, that fix comes with a 90-day warranty. If the same infection reappears within three months through no fault of your own (meaning you haven't deliberately reinstalled it via bundled software), we'll remove it again at no charge. We also provide a written summary of what was removed and recommendations to prevent reinfection. Your satisfaction and security matter to us.

Bring It In

Manual removal works when you catch the hijacker early, but Infanews.com often installs alongside multiple companion threats that complicate cleanup. If your browser still redirects after following these steps, if you're uncomfortable editing the registry, or if you simply want the job done right the first time, Computer Repair Roswell handles these infections daily. We'll perform a thorough cleanup, verify complete removal, optimize your browser performance, and explain exactly what happened so you can avoid it next time. Most browser hijacker removals take 30–60 minutes, and we'll have you back to normal browsing the same day you bring it in.

Our shop is located at 1735 Woodstock Rd, Roswell, GA 30075 — just north of the Roswell Historic District, easy to reach from Alpharetta, Sandy Springs, and East Cobb. Call us at (770) 947-1234 to describe what you're experiencing, and we'll give you a realistic time estimate and upfront pricing before you drive over. No diagnostic fees, no surprise charges, and our 90-day warranty means this problem stays solved. Whether you're dealing with Infanews.com or something worse, we've seen it before and we know how to fix it permanently.