InstallNow.com is a potentially unwanted program (PUP) and browser hijacker that forcibly redirects users to third-party websites, alters browser settings without permission, and displays aggressive advertising content. While not classified as traditional malware like ransomware or trojans, this threat creates persistent disruptions to normal browsing activity and can expose users to additional security risks through forced redirects to unsafe sites. Users typically encounter InstallNow.com bundled with free software downloads, where it installs alongside legitimate programs without clear disclosure.

InstallNow.com — cybersecurity illustration
Photo by Lucas Andrade on Pexels

This hijacker primarily affects Windows systems and targets all major browsers including Chrome, Firefox, Edge, and Internet Explorer. Once installed, it modifies the default search engine, homepage, and new tab settings to redirect traffic through InstallNow.com and affiliated advertising networks. Beyond the immediate annoyance of unwanted redirects, the program may track browsing activity and collect data about search queries, visited sites, and user behavior to support targeted advertising campaigns.

Think you're infected right now? If your browser keeps redirecting to InstallNow.com or unfamiliar search pages, disconnect from the internet immediately to prevent further data collection. Don't enter passwords or financial information until the threat is removed. Skip to the removal section below for step-by-step instructions, or call Computer Repair Roswell at (770) 941-6038 for same-day assistance.

Threat Profile

AttributeDetails
Threat TypeBrowser Hijacker / Potentially Unwanted Program (PUP)
FamilyAdware/Redirect variants
AliasesInstallNow redirect, InstallNow.com hijacker, InstallNow toolbar
Affected PlatformsWindows 7/8/8.1/10/11 (all major browsers)
Distribution MethodSoftware bundling, deceptive download buttons, fake update prompts
Persistence MechanismBrowser extensions, scheduled tasks, registry modifications, startup entries
Primary CapabilitiesBrowser redirection, search hijacking, advertising injection, tracking cookie deployment
Data CollectionBrowsing history, search queries, IP addresses, geolocation data (typical for family)
Network BehaviorRedirects through multiple intermediary domains before reaching final landing pages
Common ArtifactsBrowser extension files, modified browser preference files, scheduled tasks in %LOCALAPPDATA%
Associated Domainsinstallnow.com and various rotating redirect partners
Removal DifficultyModerate — requires browser cleanup and registry editing

How It Spreads

InstallNow.com primarily distributes through software bundling operations that prey on users who rush through installation processes. Free software download sites frequently package this hijacker with legitimate applications like media players, PDF converters, and system utilities. During installation, the PUP is presented in pre-checked optional offers or buried in "Custom" installation screens that most users skip. The language used in these installers is deliberately confusing, making it unclear that agreeing to the terms will modify browser settings.

Beyond bundled installers, this threat spreads through deceptive advertising tactics on low-quality websites. Users encounter fake "Download" buttons that look like legitimate software download links but actually trigger InstallNow.com installation. Similarly, fake system warning pop-ups claim your browser is "out of date" or "missing critical components," then push the hijacker disguised as a necessary update. These social engineering tactics exploit user trust in standard update notifications.

Common distribution vectors include:

  • Bundled freeware installers from third-party download portals (not official software sites)
  • Fake download buttons on file-sharing and streaming sites that mimic legitimate UI elements
  • Misleading browser update alerts on compromised or malicious websites
  • Email attachments claiming to be software installers for commonly searched programs
  • Torrent and peer-to-peer sharing networks where installers are modified to include PUPs
  • Malvertising campaigns on legitimate sites using compromised ad networks
  • Browser extension stores through extensions masquerading as productivity tools

What It Does On Your Machine

Once installed, InstallNow.com immediately modifies browser configuration files to establish control over your web activity. It changes the default search engine to redirect queries through its own servers before displaying results, allowing the operators to insert sponsored links at the top of search pages and collect data about your search behavior. Your homepage and new tab page are replaced with InstallNow.com or associated landing pages filled with advertisements, affiliate links, and potentially suspicious content.

The hijacker achieves persistence through multiple mechanisms. It installs browser extensions that resist normal removal attempts, recreating themselves if you delete the extension through standard browser settings. Registry entries are created to ensure the hijacker's components load during system startup, and scheduled tasks may periodically re-apply the malicious browser settings even after you've manually corrected them. This redundancy makes casual removal attempts frustrating and often unsuccessful.

Beyond redirects, InstallNow.com typically injects additional advertising content into legitimate websites you visit. This includes pop-up ads, banner advertisements inserted into webpage content, and text-link ads that appear when you hover over certain words. These injected ads slow down page loading, consume bandwidth, and frequently promote questionable products including fake tech support services, dubious system optimizers, and other PUPs that compound the infection.

Typical Filesystem and Registry Artifacts
File System Locations: C:\Users\[Username]\AppData\Local\{Random-GUID}\setup.exe C:\Users\[Username]\AppData\Roaming\InstallNow\config.dat C:\Program Files (x86)\InstallNow\[various DLL files] Browser Extension Locations: Chrome: %LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\[extension-id]\ Firefox: %APPDATA%\Mozilla\Firefox\Profiles\[profile].default\extensions\ Registry Keys: HKCU\Software\InstallNow HKCU\Software\Microsoft\Windows\CurrentVersion\Run\InstallNow HKLM\SOFTWARE\WOW6432Node\InstallNow Scheduled Tasks: \Task Scheduler Library\InstallNow Update Task # May use randomized names like "System Optimization" or "{GUID}"

The data collection component represents a significant privacy concern. While InstallNow.com isn't typically classified as spyware in the traditional sense, it monitors your browsing habits extensively. This includes recording which sites you visit, what you search for, how long you spend on particular pages, and what you click. This information is aggregated and used to build advertising profiles, which may be shared with or sold to third-party marketing networks. Though typically not targeting passwords or financial data directly, the continuous monitoring and data harvesting create substantial privacy violations.

Manual Removal — Step by Step

01

Disconnect and Document Current State

Disconnect your computer from the internet by unplugging the Ethernet cable or disabling Wi-Fi. Take screenshots of your current browser homepage, default search engine, and any suspicious extensions before you begin removal. This documentation helps verify complete cleanup later. Write down any unusual programs you notice in the Start menu or taskbar that you don't recognize installing.

02

Boot to Safe Mode with Networking

Restart your computer and enter Safe Mode to prevent InstallNow.com's startup processes from launching. On Windows 10/11, hold Shift while clicking Restart, then select Troubleshoot > Advanced Options > Startup Settings > Restart, and press F5 for Safe Mode with Networking. On Windows 7/8, tap F8 during startup and select the same option. Safe Mode loads only essential system processes, preventing the hijacker from defending itself during removal.

03

Uninstall Suspicious Programs

Open Control Panel > Programs and Features (or Settings > Apps on Windows 10/11). Sort by installation date and look for recently installed programs you don't recognize, particularly anything installed the same day the redirects started. Uninstall anything named InstallNow, along with unfamiliar toolbars, browser helpers, or system optimizers installed around the same time. Be thorough—hijackers often install multiple related components with different names.

04

Remove Browser Extensions and Reset Settings

Open each installed browser and manually remove suspicious extensions. In Chrome, go to Menu > Extensions > Manage Extensions and remove anything unfamiliar. In Firefox, click Menu > Add-ons and Themes > Extensions. In Edge, go to Menu > Extensions. After removing extensions, reset each browser to defaults: Chrome (Settings > Reset Settings > Restore to defaults), Firefox (Help > More Troubleshooting Information > Refresh Firefox), Edge (Settings > Reset Settings). This clears hijacked homepage and search engine settings.

05

Delete Scheduled Tasks

Press Win+R, type taskschd.msc, and press Enter to open Task Scheduler. Expand Task Scheduler Library and look for tasks related to InstallNow, browser updates, or anything with randomized GUID names created recently. Right-click suspicious tasks and select Delete. Pay special attention to tasks scheduled to run at startup or every few hours, as these are commonly used to reinfect the browser settings.

06

Clean Registry Entries

Press Win+R, type regedit, and press Enter (accept the UAC prompt). Navigate to HKEY_CURRENT_USER\Software and look for an "InstallNow" key—right-click and delete it if present. Check HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run for any InstallNow entries and delete them. Search the registry (Edit > Find) for "installnow" and carefully delete related keys, being cautious not to remove legitimate Windows entries. Create a registry backup before editing (File > Export).

07

Delete Program Files and AppData Folders

Open File Explorer and navigate to C:\Program Files and C:\Program Files (x86)—delete any InstallNow folders. Then go to C:\Users\[YourUsername]\AppData\Local and \AppData\Roaming (enable "Show hidden files" in View options if needed) and delete any InstallNow-related folders. Also check for randomly-named GUID folders (like {A12B34CD-5678-90EF-GHIJ-KLMNOPQRSTUV}) created on the infection date—these often contain hijacker components.

08

Run a Reputable Anti-Malware Scanner

Download and run Malwarebytes Free (from malwarebytes.com) or another reputable scanner like HitmanPro. Perform a full system scan to catch any components manual removal might have missed. These tools maintain updated definitions for PUPs and browser hijackers that often slip past traditional antivirus. Quarantine and remove all detected items, even if they're only flagged as "potentially unwanted" rather than malicious.

09

Clear Browser Data and Check DNS Settings

In each browser, clear all cached data, cookies, and browsing history from the beginning of time. Some hijackers use persistent cookies to track removal. Then verify your DNS settings haven't been changed: open Control Panel > Network and Sharing > Change Adapter Settings, right-click your network connection, select Properties > Internet Protocol Version 4, and ensure DNS is set to "Obtain DNS server address automatically" or uses trusted servers like 8.8.8.8 (Google) or 1.1.1.1 (Cloudflare).

10

Reboot Normally and Verify Cleanup

Restart your computer normally (not in Safe Mode) and reconnect to the internet. Open each browser and verify your homepage, search engine, and new tab page are back to your preferred settings with no automatic redirects. Visit a few normal websites to confirm no injected ads appear. Monitor for the next few days—if redirects return, a component was missed and professional removal may be necessary to locate the persistent mechanism.

Prevention

  1. Download software only from official sources. Avoid third-party download portals like download.com, softonic.com, or cnet downloads. Go directly to the software publisher's official website. Third-party sites frequently bundle PUPs with legitimate installers, while official sites rarely do.
  2. Always choose Custom or Advanced installation. Never click through installers using "Express" or "Recommended" settings. Custom installation reveals bundled offers that you can deselect. Read each screen carefully and uncheck any pre-selected options for toolbars, browser changes, or additional software you didn't request.
  3. Keep browsers and operating system updated. Enable automatic updates for Windows and all browsers. Many hijackers exploit outdated browser vulnerabilities to install themselves. Current versions patch these security holes and include improved defenses against unwanted modifications.
  4. Install a reputable ad-blocker. Browser extensions like uBlock Origin block many of the malicious ad networks that distribute hijackers through malvertising. They also prevent exposure to fake download buttons and misleading system warnings on compromised websites.
  5. Use standard antivirus with real-time protection enabled. Windows Defender (built into Windows 10/11) provides solid baseline protection if kept updated. Consider supplementing with Malwarebytes Premium for additional PUP detection. Ensure real-time scanning is active, not just on-demand scans.
  6. Be skeptical of browser update prompts on websites. Legitimate browser updates come through the browser's built-in update mechanism or direct downloads from google.com/chrome, mozilla.org, or microsoft.com. If a website claims your browser needs updating, close the page and manually check for updates through the browser's Help menu.
  7. Review installed programs monthly. Open Programs and Features periodically and uninstall anything you don't recognize or no longer use. Many PUPs install silently alongside other software and sit dormant before activating, so regular housekeeping catches them before they cause problems.
  8. Create a separate limited user account for daily browsing. Use a non-administrator account for web browsing and email. Many hijackers require administrator privileges to install completely. A limited account forces the UAC prompt, giving you a chance to block unauthorized installations.
Our 90-Day Guarantee: When Computer Repair Roswell removes InstallNow.com or any other malware from your machine, we guarantee it stays gone. If the same threat returns within 90 days, we'll remove it again at no charge. We don't just delete the visible symptoms—we hunt down every persistence mechanism and close the vulnerability that let it in.

Bring It In

If you've followed these steps and still see redirects, or if you're simply not comfortable performing registry edits and system-level changes, bring your computer to Computer Repair Roswell. We're located right here in Roswell, Georgia, and we handle browser hijacker removal dozens of times every month. Our technicians know exactly where these threats hide their backup components and persistence mechanisms. Most hijacker removals are completed same-day, and we'll have you back online with clean browser settings typically within a few hours.

Beyond just removing InstallNow.com, we'll audit your system for other bundled PUPs that likely installed alongside it, verify your antivirus is properly configured, and show you exactly what to watch for during software installations to prevent reinfection. Give us a call at (770) 941-6038 or stop by our shop at 1585 Hembree Road. We'll get your browser back under your control—no redirects, no injected ads, no tracking—with our 90-day guarantee backing the work.