InstallNow.com is a potentially unwanted program (PUP) and browser hijacker that forcibly redirects users to third-party websites, alters browser settings without permission, and displays aggressive advertising content. While not classified as traditional malware like ransomware or trojans, this threat creates persistent disruptions to normal browsing activity and can expose users to additional security risks through forced redirects to unsafe sites. Users typically encounter InstallNow.com bundled with free software downloads, where it installs alongside legitimate programs without clear disclosure.
This hijacker primarily affects Windows systems and targets all major browsers including Chrome, Firefox, Edge, and Internet Explorer. Once installed, it modifies the default search engine, homepage, and new tab settings to redirect traffic through InstallNow.com and affiliated advertising networks. Beyond the immediate annoyance of unwanted redirects, the program may track browsing activity and collect data about search queries, visited sites, and user behavior to support targeted advertising campaigns.
Threat Profile
| Attribute | Details |
|---|---|
| Threat Type | Browser Hijacker / Potentially Unwanted Program (PUP) |
| Family | Adware/Redirect variants |
| Aliases | InstallNow redirect, InstallNow.com hijacker, InstallNow toolbar |
| Affected Platforms | Windows 7/8/8.1/10/11 (all major browsers) |
| Distribution Method | Software bundling, deceptive download buttons, fake update prompts |
| Persistence Mechanism | Browser extensions, scheduled tasks, registry modifications, startup entries |
| Primary Capabilities | Browser redirection, search hijacking, advertising injection, tracking cookie deployment |
| Data Collection | Browsing history, search queries, IP addresses, geolocation data (typical for family) |
| Network Behavior | Redirects through multiple intermediary domains before reaching final landing pages |
| Common Artifacts | Browser extension files, modified browser preference files, scheduled tasks in %LOCALAPPDATA% |
| Associated Domains | installnow.com and various rotating redirect partners |
| Removal Difficulty | Moderate — requires browser cleanup and registry editing |
How It Spreads
InstallNow.com primarily distributes through software bundling operations that prey on users who rush through installation processes. Free software download sites frequently package this hijacker with legitimate applications like media players, PDF converters, and system utilities. During installation, the PUP is presented in pre-checked optional offers or buried in "Custom" installation screens that most users skip. The language used in these installers is deliberately confusing, making it unclear that agreeing to the terms will modify browser settings.
Beyond bundled installers, this threat spreads through deceptive advertising tactics on low-quality websites. Users encounter fake "Download" buttons that look like legitimate software download links but actually trigger InstallNow.com installation. Similarly, fake system warning pop-ups claim your browser is "out of date" or "missing critical components," then push the hijacker disguised as a necessary update. These social engineering tactics exploit user trust in standard update notifications.
Common distribution vectors include:
- Bundled freeware installers from third-party download portals (not official software sites)
- Fake download buttons on file-sharing and streaming sites that mimic legitimate UI elements
- Misleading browser update alerts on compromised or malicious websites
- Email attachments claiming to be software installers for commonly searched programs
- Torrent and peer-to-peer sharing networks where installers are modified to include PUPs
- Malvertising campaigns on legitimate sites using compromised ad networks
- Browser extension stores through extensions masquerading as productivity tools
What It Does On Your Machine
Once installed, InstallNow.com immediately modifies browser configuration files to establish control over your web activity. It changes the default search engine to redirect queries through its own servers before displaying results, allowing the operators to insert sponsored links at the top of search pages and collect data about your search behavior. Your homepage and new tab page are replaced with InstallNow.com or associated landing pages filled with advertisements, affiliate links, and potentially suspicious content.
The hijacker achieves persistence through multiple mechanisms. It installs browser extensions that resist normal removal attempts, recreating themselves if you delete the extension through standard browser settings. Registry entries are created to ensure the hijacker's components load during system startup, and scheduled tasks may periodically re-apply the malicious browser settings even after you've manually corrected them. This redundancy makes casual removal attempts frustrating and often unsuccessful.
Beyond redirects, InstallNow.com typically injects additional advertising content into legitimate websites you visit. This includes pop-up ads, banner advertisements inserted into webpage content, and text-link ads that appear when you hover over certain words. These injected ads slow down page loading, consume bandwidth, and frequently promote questionable products including fake tech support services, dubious system optimizers, and other PUPs that compound the infection.
The data collection component represents a significant privacy concern. While InstallNow.com isn't typically classified as spyware in the traditional sense, it monitors your browsing habits extensively. This includes recording which sites you visit, what you search for, how long you spend on particular pages, and what you click. This information is aggregated and used to build advertising profiles, which may be shared with or sold to third-party marketing networks. Though typically not targeting passwords or financial data directly, the continuous monitoring and data harvesting create substantial privacy violations.
Manual Removal — Step by Step
Disconnect and Document Current State
Disconnect your computer from the internet by unplugging the Ethernet cable or disabling Wi-Fi. Take screenshots of your current browser homepage, default search engine, and any suspicious extensions before you begin removal. This documentation helps verify complete cleanup later. Write down any unusual programs you notice in the Start menu or taskbar that you don't recognize installing.
Boot to Safe Mode with Networking
Restart your computer and enter Safe Mode to prevent InstallNow.com's startup processes from launching. On Windows 10/11, hold Shift while clicking Restart, then select Troubleshoot > Advanced Options > Startup Settings > Restart, and press F5 for Safe Mode with Networking. On Windows 7/8, tap F8 during startup and select the same option. Safe Mode loads only essential system processes, preventing the hijacker from defending itself during removal.
Uninstall Suspicious Programs
Open Control Panel > Programs and Features (or Settings > Apps on Windows 10/11). Sort by installation date and look for recently installed programs you don't recognize, particularly anything installed the same day the redirects started. Uninstall anything named InstallNow, along with unfamiliar toolbars, browser helpers, or system optimizers installed around the same time. Be thorough—hijackers often install multiple related components with different names.
Remove Browser Extensions and Reset Settings
Open each installed browser and manually remove suspicious extensions. In Chrome, go to Menu > Extensions > Manage Extensions and remove anything unfamiliar. In Firefox, click Menu > Add-ons and Themes > Extensions. In Edge, go to Menu > Extensions. After removing extensions, reset each browser to defaults: Chrome (Settings > Reset Settings > Restore to defaults), Firefox (Help > More Troubleshooting Information > Refresh Firefox), Edge (Settings > Reset Settings). This clears hijacked homepage and search engine settings.
Delete Scheduled Tasks
Press Win+R, type taskschd.msc, and press Enter to open Task Scheduler. Expand Task Scheduler Library and look for tasks related to InstallNow, browser updates, or anything with randomized GUID names created recently. Right-click suspicious tasks and select Delete. Pay special attention to tasks scheduled to run at startup or every few hours, as these are commonly used to reinfect the browser settings.
Clean Registry Entries
Press Win+R, type regedit, and press Enter (accept the UAC prompt). Navigate to HKEY_CURRENT_USER\Software and look for an "InstallNow" key—right-click and delete it if present. Check HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run for any InstallNow entries and delete them. Search the registry (Edit > Find) for "installnow" and carefully delete related keys, being cautious not to remove legitimate Windows entries. Create a registry backup before editing (File > Export).
Delete Program Files and AppData Folders
Open File Explorer and navigate to C:\Program Files and C:\Program Files (x86)—delete any InstallNow folders. Then go to C:\Users\[YourUsername]\AppData\Local and \AppData\Roaming (enable "Show hidden files" in View options if needed) and delete any InstallNow-related folders. Also check for randomly-named GUID folders (like {A12B34CD-5678-90EF-GHIJ-KLMNOPQRSTUV}) created on the infection date—these often contain hijacker components.
Run a Reputable Anti-Malware Scanner
Download and run Malwarebytes Free (from malwarebytes.com) or another reputable scanner like HitmanPro. Perform a full system scan to catch any components manual removal might have missed. These tools maintain updated definitions for PUPs and browser hijackers that often slip past traditional antivirus. Quarantine and remove all detected items, even if they're only flagged as "potentially unwanted" rather than malicious.
Clear Browser Data and Check DNS Settings
In each browser, clear all cached data, cookies, and browsing history from the beginning of time. Some hijackers use persistent cookies to track removal. Then verify your DNS settings haven't been changed: open Control Panel > Network and Sharing > Change Adapter Settings, right-click your network connection, select Properties > Internet Protocol Version 4, and ensure DNS is set to "Obtain DNS server address automatically" or uses trusted servers like 8.8.8.8 (Google) or 1.1.1.1 (Cloudflare).
Reboot Normally and Verify Cleanup
Restart your computer normally (not in Safe Mode) and reconnect to the internet. Open each browser and verify your homepage, search engine, and new tab page are back to your preferred settings with no automatic redirects. Visit a few normal websites to confirm no injected ads appear. Monitor for the next few days—if redirects return, a component was missed and professional removal may be necessary to locate the persistent mechanism.
Prevention
- Download software only from official sources. Avoid third-party download portals like download.com, softonic.com, or cnet downloads. Go directly to the software publisher's official website. Third-party sites frequently bundle PUPs with legitimate installers, while official sites rarely do.
- Always choose Custom or Advanced installation. Never click through installers using "Express" or "Recommended" settings. Custom installation reveals bundled offers that you can deselect. Read each screen carefully and uncheck any pre-selected options for toolbars, browser changes, or additional software you didn't request.
- Keep browsers and operating system updated. Enable automatic updates for Windows and all browsers. Many hijackers exploit outdated browser vulnerabilities to install themselves. Current versions patch these security holes and include improved defenses against unwanted modifications.
- Install a reputable ad-blocker. Browser extensions like uBlock Origin block many of the malicious ad networks that distribute hijackers through malvertising. They also prevent exposure to fake download buttons and misleading system warnings on compromised websites.
- Use standard antivirus with real-time protection enabled. Windows Defender (built into Windows 10/11) provides solid baseline protection if kept updated. Consider supplementing with Malwarebytes Premium for additional PUP detection. Ensure real-time scanning is active, not just on-demand scans.
- Be skeptical of browser update prompts on websites. Legitimate browser updates come through the browser's built-in update mechanism or direct downloads from google.com/chrome, mozilla.org, or microsoft.com. If a website claims your browser needs updating, close the page and manually check for updates through the browser's Help menu.
- Review installed programs monthly. Open Programs and Features periodically and uninstall anything you don't recognize or no longer use. Many PUPs install silently alongside other software and sit dormant before activating, so regular housekeeping catches them before they cause problems.
- Create a separate limited user account for daily browsing. Use a non-administrator account for web browsing and email. Many hijackers require administrator privileges to install completely. A limited account forces the UAC prompt, giving you a chance to block unauthorized installations.
Bring It In
If you've followed these steps and still see redirects, or if you're simply not comfortable performing registry edits and system-level changes, bring your computer to Computer Repair Roswell. We're located right here in Roswell, Georgia, and we handle browser hijacker removal dozens of times every month. Our technicians know exactly where these threats hide their backup components and persistence mechanisms. Most hijacker removals are completed same-day, and we'll have you back online with clean browser settings typically within a few hours.
Beyond just removing InstallNow.com, we'll audit your system for other bundled PUPs that likely installed alongside it, verify your antivirus is properly configured, and show you exactly what to watch for during software installations to prevent reinfection. Give us a call at (770) 941-6038 or stop by our shop at 1585 Hembree Road. We'll get your browser back under your control—no redirects, no injected ads, no tracking—with our 90-day guarantee backing the work.