Jevons.xyz is a browser hijacker that forcibly redirects your web searches and homepage to its own search portal, generating revenue for its operators through sponsored links and ad traffic. Unlike destructive malware that encrypts files or steals banking credentials, this hijacker primarily monetizes your browsing activity by inserting itself between you and legitimate search engines. While not the most dangerous threat circulating today, Jevons.xyz proves frustratingly persistent—resetting your browser settings manually often fails because the hijacker reinstalls itself through hidden extensions, scheduled tasks, or registry modifications that survive a simple uninstall.

Jevons.xyz — cybersecurity illustration
Photo by John (Giannis) Tekeridis on Pexels

Users typically discover Jevons.xyz when their default search engine suddenly changes without permission, or when every new tab opens to an unfamiliar search page decorated with sponsored advertisements. The hijacker affects Chrome, Firefox, Edge, and other Chromium-based browsers, modifying their configuration files and preferences databases to maintain control even after you attempt to restore your preferred settings.

Think you're infected right now? Disconnect from the internet immediately if you're in the middle of noticing suspicious redirects or unwanted toolbars. Don't enter passwords or financial information until you've removed the hijacker—some variants bundle with credential-stealing components. Skip to the removal section below, or call us at (770) 679-9864 if you need immediate assistance in Roswell.

Threat Profile

Attribute Details
Threat Type Browser Hijacker / Potentially Unwanted Program (PUP)
Family Search-redirect hijacker cluster (behavior similar to SearchMine, Conduit variants)
Aliases Jevons Search, Jevons.xyz Redirect, SearchJevons
Affected Platforms Windows 7/8/10/11, macOS (via browser extensions)
Target Browsers Chrome, Firefox, Edge, Opera, Brave (Chromium-based browsers primarily)
Distribution Method Software bundling, fake update prompts, freeware installers, malicious browser extensions
Persistence Mechanism Browser extension policies, registry Run keys, scheduled tasks, shortcut target modification
Primary Payload Search/homepage redirection, advertisement injection, tracking cookie installation
Data Collection Search queries, visited URLs, browser fingerprint, IP address, geolocation (typical for this family)
Network Behavior Communicates with jevons.xyz domain and associated ad networks; may connect to additional tracking domains
Common Artifacts Browser extension folders with randomized names, modified Preferences/Secure Preferences files, shortcut target parameters
Removal Difficulty Moderate—requires browser cleanup, extension removal, and elimination of persistence mechanisms

How It Spreads

Jevons.xyz rarely arrives alone. The hijacker typically bundles with free software downloads from third-party hosting sites—those "Download" buttons on freeware portals that aren't actually the software you want. When you install a video converter, PDF tool, or system optimizer from an unverified source, the installer's "Express" or "Recommended" setup path quietly includes browser modifications presented in tiny print or pre-checked boxes. By the time the installation wizard completes, Jevons.xyz has already altered your browser configuration and installed monitoring extensions.

Fake update notifications represent another common vector. You're browsing a streaming site or torrent portal when a popup warns that your Flash Player, Chrome browser, or video codec is "out of date" and needs immediate updating. The download button leads not to a legitimate update but to a payload that installs the hijacker alongside whatever decoy software appeared in the fake prompt. These social engineering tactics exploit users' good security instincts—keeping software updated—by mimicking the appearance of genuine update notifications.

Distribution channels include:

  • Bundled freeware installers — Download managers, media players, PDF converters, and screen recorders packaged with the hijacker in multi-program installers
  • Fake browser extensions — Extensions promoted as ad-blockers, VPNs, coupon-finders, or video downloaders that actually redirect searches
  • Malicious advertisements — Drive-by downloads initiated through compromised ad networks on otherwise legitimate websites
  • Fake software update prompts — Notifications mimicking Adobe Flash, Java, browser updates, or codec installers
  • Torrent bundles and cracked software — Pirated applications repackaged with hijacker components as "bonus" utilities
  • Email attachments in phishing campaigns — Less common but documented, typically disguised as document viewers or file unlockers

What It Does On Your Machine

Once installed, Jevons.xyz immediately modifies your browser's configuration to redirect all search activity through its own servers. Your homepage changes to jevons.xyz or a related domain, your default search engine switches to the hijacker's portal, and new tabs open to pages filled with sponsored search results and advertisements. These modifications happen at multiple levels—the browser extension, the preferences database, the shortcut targets, and sometimes through Group Policy or registry entries—ensuring that simply changing settings through the browser interface won't stick.

The hijacker generates revenue through a combination of search monetization and affiliate advertising. When you search for anything through the redirected search box, the results page displays a mix of legitimate search results (often pulled from Google or Bing APIs) and heavily weighted sponsored links. Clicking any result may route through multiple redirect chains, with each hop generating affiliate commissions for the hijacker's operators. Even when you click what appears to be a normal search result, your click may pass through tracking servers that record your interest before forwarding you to the destination.

Beyond search redirection, Jevons.xyz variants often inject additional advertisements into web pages you visit, displaying banners and popups that weren't part of the original site. The hijacker tracks your browsing activity to build a profile of your interests, recording search terms, visited URLs, time spent on pages, and items you click. While this data collection mirrors what legitimate advertising platforms do, you never consented to Jevons.xyz's monitoring, and you have no visibility into who receives your browsing history or how they use it.

Typical Filesystem and Registry Artifacts
# Browser extension folders (Chrome/Edge example): %LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\kpnmlfaejgoajbcnhfplpjgeaokgjdgp %LOCALAPPDATA%\Microsoft\Edge\User Data\Default\Extensions\ahdmpfgjocdehlofbebogmnjdlipnmkj # Modified preference files: %LOCALAPPDATA%\Google\Chrome\User Data\Default\Preferences %LOCALAPPDATA%\Google\Chrome\User Data\Default\Secure Preferences # Scheduled tasks for persistence: C:\Windows\System32\Tasks\Jevons Updater C:\Windows\System32\Tasks\Browser Configuration Service # Registry Run keys (variants may use randomized names): HKCU\Software\Microsoft\Windows\CurrentVersion\Run\BrowserAssistant HKLM\Software\Microsoft\Windows\CurrentVersion\Run\SearchHelper # Desktop/Start Menu shortcut target modification: Target: "C:\Program Files\Google\Chrome\Application\chrome.exe" --homepage=http://jevons.xyz

Manual Removal — Step by Step

01

Disconnect from the Internet

Unplug your Ethernet cable or disable WiFi before proceeding. This prevents the hijacker from downloading additional components during removal and stops any active data transmission to its command servers. Work offline until you've completed all removal steps and verified the system is clean.

02

Boot into Safe Mode with Networking

Restart your computer and press F8 (Windows 7) or Shift+Restart (Windows 8/10/11) to access recovery options. Select "Safe Mode with Networking" from the boot menu. This loads Windows with minimal drivers and prevents most hijacker components from launching automatically, making removal significantly easier.

03

Uninstall Suspicious Programs

Open Control Panel → Programs and Features (or Settings → Apps on Windows 10/11). Sort by "Installed On" date and look for unfamiliar programs installed around the time Jevons.xyz appeared. Remove anything you don't recognize, especially entries with publishers like "Browser Assistant," "Search Helper," or generic names containing random characters. Don't worry about removing legitimate software accidentally—you can reinstall it later if needed.

04

Remove Browser Extensions Across All Browsers

Open each installed browser and navigate to its extensions/add-ons manager (chrome://extensions for Chrome, about:addons for Firefox, edge://extensions for Edge). Remove any extensions you didn't intentionally install, paying special attention to those with vague names like "Useful Search," "Better Browsing," or extensions installed on the date you first noticed the hijacker. Toggle "Developer mode" in Chrome to reveal extension IDs, then manually delete their folders from %LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\ to prevent reinstallation.

05

Reset Browser Settings Without Losing Bookmarks

In Chrome/Edge, go to Settings → Reset settings → "Restore settings to their original defaults." In Firefox, type about:support in the address bar and click "Refresh Firefox." This resets your homepage, search engine, and new tab page while preserving bookmarks and passwords. After resetting, manually verify that your default search engine is set to Google, Bing, or your preferred legitimate provider, and that your homepage is what you intended.

06

Check and Repair Desktop Shortcuts

Right-click your browser shortcuts (on desktop, taskbar, and Start menu) and select Properties. In the "Target" field, remove anything after chrome.exe, firefox.exe, or msedge.exe—the target should end with .exe with no additional URLs or parameters. Hijackers often append "--homepage=http://jevons.xyz" or similar strings to force their page to load even after you've cleaned the browser. Fix all shortcuts, click Apply, then OK.

07

Remove Scheduled Tasks and Registry Persistence

Press Win+R, type "taskschd.msc" and press Enter to open Task Scheduler. Look through the task list for entries containing "Browser," "Search," "Updater," or "Assistant" that you don't recognize. Right-click and delete suspicious tasks. Then press Win+R again, type "regedit," navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, and delete any entries pointing to random executable files in Temp or AppData directories.

08

Run Malwarebytes or Similar Scanner

Download Malwarebytes Free (from malwarebytes.com, not a third-party site) and run a full system scan. Let it quarantine everything it finds—these tools are specifically updated to detect browser hijacker components that manual removal might miss, including leftover registry keys, tracking cookies, and hidden browser policies. If you prefer alternatives, HitmanPro and AdwCleaner (by Malwarebytes) also work well for hijacker removal.

09

Clear Browser Data and Check DNS Settings

In each browser, clear all browsing data (cookies, cache, site data) from "the beginning of time." Some hijackers persist through cached redirects. Then open Command Prompt as Administrator and type "ipconfig /flushdns" to clear your DNS cache. Finally, check your network adapter's DNS settings (Control Panel → Network and Sharing Center → Change adapter settings → right-click your connection → Properties → IPv4) and ensure it's set to "Obtain DNS server address automatically" unless you intentionally use a custom DNS.

10

Reboot Normally and Verify Removal

Restart your computer in normal mode and reconnect to the internet. Open your browser and verify that your homepage, search engine, and new tab page are all set to your preferences. Perform several searches and verify you're not being redirected. Check Task Manager (Ctrl+Shift+Esc) for any suspicious processes consuming resources. If redirects persist, the hijacker may have installed a component you missed—at that point, professional removal becomes the most time-efficient option.

Prevention

  1. Download software only from official sources. Get Chrome from google.com/chrome, VLC from videolan.org, and other programs directly from their publishers. Third-party download sites bundle hijackers into even legitimate software installers.
  2. Always choose "Custom" or "Advanced" installation. Never click through an installer using Express/Recommended settings. Custom installation reveals optional bundled software and browser modifications, letting you uncheck everything except the program you actually want.
  3. Keep a real-time antivirus running. Windows Defender is adequate for most users; Bitdefender, ESET, and Kaspersky are excellent paid alternatives. Real-time protection blocks many hijacker downloads before they execute, but only if you keep definitions updated.
  4. Install an ad-blocker with anti-malware lists. uBlock Origin (not uBlock, different project) blocks malicious advertisements and fake download buttons that lead to hijackers. Configure it with the "uBlock filters - Badware risks" list enabled.
  5. Ignore all browser update prompts except from your browser itself. Chrome, Firefox, and Edge update themselves automatically. Any popup telling you to update your browser—especially on a random website—is a scam. Close the page immediately.
  6. Review installed extensions monthly. Browser extensions update automatically and can change ownership. An extension you installed legitimately six months ago may have been sold to an ad company that converted it into a hijacker through an update.
  7. Use browser profiles carefully. If you use Chrome or Edge profiles for work vs. personal browsing, minimize extensions in your work profile and avoid logging into the work profile on unfamiliar computers where hijackers might sync across your devices.
  8. Be immediately suspicious of sudden browser behavior changes. If your homepage changes, searches redirect, or new toolbars appear without your action, assume infection and investigate the same day. Hijackers that persist for weeks become harder to remove as they install additional components.
Our 90-Day Reinfection Guarantee: When we remove browser hijackers and other malware at Computer Repair Roswell, we back our work with a 90-day warranty. If the same threat returns within three months, bring your machine back and we'll clean it again at no additional charge. We're that confident in our removal process—and we'll show you how to avoid reinfection going forward.

Bring It In

Manual removal works for straightforward Jevons.xyz infections, but many hijackers bundle with additional threats—adware, trojans, or data-stealing components—that hide deeper in your system. If you've followed these steps and still see redirects, or if you simply don't have time to work through registry edits and extension hunting while you're trying to run a business, we'll handle it efficiently. Our technicians remove dozens of hijacker infections every month in our Roswell shop, and we've built a systematic process that eliminates the threat and its persistence mechanisms in a single session.

Call us at (770) 679-9864 or stop by 1750 Powder Springs Road, Suite 190, Marietta, GA 30064 (we're the Roswell-area shop serving the northern suburbs). We'll run a full diagnostic, remove Jevons.xyz and any bundled threats, verify your browsers are clean, and walk you through prevention steps so you can recognize these installers before they execute. Most hijacker removals complete same-day, and you'll leave with a machine that behaves like you own it again—because you do.