Konohi.who.com is a browser hijacker that forcibly redirects your web searches and homepage to a search engine you never asked for. Unlike outright malware that steals banking credentials or encrypts your files for ransom, this hijacker operates in a legal gray area—bundled with free software installers and designed to generate advertising revenue by controlling your browsing experience. While not technically a virus, it's unwanted, intrusive, and frustratingly difficult to remove through normal means because it modifies multiple browser settings and reinstalls itself if you miss even one component.
Most people encounter Konohi.who.com after installing a seemingly legitimate program—often a PDF converter, video downloader, or system optimizer—that buried the hijacker's installation consent in a pre-checked box during setup. Once installed, it takes over Chrome, Firefox, Edge, or Safari, replacing your preferred search engine with its own redirect chain that routes queries through affiliate networks before eventually landing on Yahoo, Bing, or another major search provider. The hijacker collects your search terms and browsing habits along the way, building an advertising profile that gets sold to third-party networks.
Threat Profile
| Attribute | Details |
|---|---|
| Threat Classification | Browser Hijacker / Potentially Unwanted Program (PUP) |
| Affected Platforms | Windows (7/8/10/11), macOS (10.12+) |
| Targeted Browsers | Google Chrome, Mozilla Firefox, Microsoft Edge, Safari |
| Primary Distribution | Software bundling, fake update prompts, freeware installers |
| Persistence Mechanism | Browser extension policies, scheduled tasks, modified shortcuts, registry entries (Windows), LaunchAgents (macOS) |
| Data Collection | Search queries, browsing history, clicked links, IP address, approximate location |
| Typical Behavior | Homepage/new-tab redirection, search engine replacement, injected advertisements, tracking cookie installation |
| Payload Capabilities | Settings enforcement (prevents manual changes), extension auto-reinstallation, affiliate link injection |
| Common Filesystem Artifacts | Browser policy folders, scheduled task XML files, extension folders with randomized GUIDs |
| Network Indicators | DNS queries to konohi.who.com, redirect chains through affiliate domains, tracker pixel requests |
| Removal Difficulty | Moderate—requires multi-step process across browsers, extensions, scheduled tasks, and system policies |
| Associated Families | Search.yahoo.com redirectors, MyWay/Mindspark family variants, generic Yahoo redirect hijackers |
How It Spreads
The Konohi.who.com hijacker almost never arrives alone or through direct user choice. Its creators rely on deceptive distribution tactics that exploit the average person's tendency to click through software installations quickly without reading each screen. The most common infection vector is software bundling—legitimate-looking free programs that include the hijacker as an "optional offer" buried in the advanced or custom installation settings. If you choose the express or typical installation path, you're automatically consenting to everything bundled with the main program.
Many users report encountering this hijacker after downloading video converters, PDF tools, download managers, or registry cleaners from third-party software sites rather than the official developer websites. These download portals repackage free software with installer wrappers that monetize each installation by including multiple potentially unwanted programs. The installers often use dark patterns—pre-checked boxes, confusing decline buttons labeled "Skip this essential security feature," or multi-page setups where the hijacker consent appears on page three of five in small print.
Beyond software bundles, Konohi.who.com spreads through several additional channels:
- Fake browser update warnings: Pop-ups claiming "Your Chrome is out of date—click here to update" that actually download an installer containing the hijacker alongside or instead of a legitimate update
- Malicious advertisements: Legitimate websites occasionally serve compromised ads that trigger drive-by downloads or lead to installer pages designed to look like official software sources
- Freeware download sites: Platforms like Softonic, Download.com, or CNET Downloads that bundle additional software with their custom installers, often without clear disclosure
- Torrent and crack sites: Pirated software packages frequently include browser hijackers as a revenue source for the distributors
- Email attachments disguised as documents: Occasionally distributed through spam campaigns where an executable is disguised as a PDF or DOC file with a double extension like "invoice.pdf.exe"
- Compromised browser extensions: Legitimate-looking extensions in official stores that later get updated with hijacker functionality after accumulating users
What It Does On Your Machine
Once Konohi.who.com establishes itself on your system, it immediately takes control of your browser's search and navigation functions. When you open your browser, your homepage—regardless of what you set it to—now loads Konohi.who.com or goes through a redirect chain that eventually lands on a search page. When you type searches into the address bar or open a new tab, those queries get routed through the hijacker's servers before showing you results. This routing serves multiple purposes: it tracks what you're searching for, it inserts affiliate links into the results (so the hijacker operators earn commission when you click certain links), and it builds an advertising profile tied to your browser's unique identifier.
The hijacker installs persistence mechanisms that make it extremely difficult to remove through normal means. If you manually change your homepage back to Google or blank, the hijacker changes it back within seconds or after the next browser restart. If you try to remove the extension responsible, it either blocks the removal, requires an administrator password you don't have, or simply reinstalls itself from a scheduled task or policy file. On Windows systems, it typically creates a scheduled task that runs every few minutes to verify the hijacker components are still in place and reinstall them if they've been removed. On macOS, it uses LaunchAgents or LaunchDaemons to achieve the same self-healing behavior.
Beyond the obvious redirects, Konohi.who.com may inject additional advertisements into pages you visit, slow down your browsing as it loads tracking scripts, and expose you to further potentially unwanted programs. The search results pages it shows—often branded as Yahoo or Bing results—include extra sponsored links at the top that weren't placed there by those legitimate search engines. Your browsing becomes noticeably slower because every page load now includes requests to multiple tracking and advertising domains. Your privacy degrades because your search history and browsing patterns are being collected and potentially sold to data brokers.
In some variants, the hijacker also modifies browser shortcuts on your desktop and taskbar, adding command-line parameters that force the browser to load the hijacker's homepage even if you've cleaned the browser settings themselves. You'll see this in shortcut properties as extra text after the browser executable path, something like chrome.exe "http://konohi.who.com/?params". Additionally, it may install multiple browser extensions working together—one that handles the search redirection, another that blocks access to browser settings, and a third that monitors for removal attempts and triggers reinstallation.
Manual Removal — Step by Step
Disconnect from the Internet
Unplug your Ethernet cable or disable Wi-Fi to prevent the hijacker from communicating with its command servers, downloading additional components, or receiving updated reinstallation instructions while you're working on removal. This also stops ongoing data collection during the cleaning process.
Boot to Safe Mode with Networking
Restart your computer into Safe Mode to prevent the hijacker's scheduled tasks and startup items from running. On Windows 10/11, hold Shift while clicking Restart, then navigate Troubleshoot → Advanced → Startup Settings → Restart → press 5 for Safe Mode with Networking. On macOS, restart and immediately hold Shift until you see the login screen. Safe Mode will let you download tools later while preventing the hijacker from actively defending itself.
Uninstall Suspicious Programs
Open Control Panel → Programs and Features (Windows) or Applications folder (macOS) and look for recently installed programs you don't recognize, especially anything installed the same day you first noticed the browser hijacking. Common names include various combinations of "Search," "Helper," "Updater," or "Manager" along with random-looking names. Uninstall anything suspicious, noting that the hijacker may use a completely different name than "Konohi" in the programs list.
Delete Scheduled Tasks and Startup Items
Open Task Scheduler (Windows: search "task scheduler" in Start menu) and examine the Task Scheduler Library for any tasks you didn't create, particularly those running frequently or with suspicious names. Delete tasks related to browser updaters, search helpers, or unknown publishers. Then check startup programs in Task Manager → Startup tab and disable anything associated with the hijacker. On macOS, check System Preferences → Users & Groups → Login Items and remove suspicious entries, then examine /Library/LaunchAgents and ~/Library/LaunchAgents folders for .plist files related to the hijacker.
Remove Browser Extensions and Reset Settings
In each browser, go to the extensions/add-ons page (chrome://extensions for Chrome, about:addons for Firefox, edge://extensions for Edge) and remove any extensions you didn't intentionally install. Then reset each browser: Chrome and Edge have a "Restore settings to defaults" option in Settings → Reset; Firefox has "Refresh Firefox" in Help → More Troubleshooting Information. This removes the hijacker's settings modifications while preserving your bookmarks and passwords. Be thorough—check all browsers installed on your system, not just the one you primarily use.
Fix Modified Browser Shortcuts
Right-click each browser shortcut on your desktop, taskbar, and Start menu, select Properties, and examine the Target field. If it shows anything after the .exe path (like a URL or extra parameters), delete everything after the closing quote mark around the executable path. The Target should end with something like chrome.exe" with nothing following the quote. Apply the changes and repeat for all browser shortcuts.
Delete Hijacker Folders
Navigate to the locations shown in the terminal section earlier and delete any folders related to the hijacker. Check both AppData\Local and AppData\Roaming folders under your user profile (Windows), or ~/Library/Application Support (macOS). Enable viewing of hidden files if needed. Delete the entire folder containing the hijacker's executable and support files. Also clear your browser cache and cookies through each browser's settings to remove tracking data.
Scan with Malwarebytes
Reconnect to the internet (still in Safe Mode) and download Malwarebytes Free from the official malwarebytes.com website. Install and run a full "Threat Scan" which typically catches browser hijackers that manual removal might have missed. Let it quarantine everything it finds. Follow up with a scan using your regular antivirus if you have one, or consider a second opinion from HitmanPro or AdwCleaner (both free tools specializing in PUPs and hijackers). Multiple scanners catch different remnants.
Check for Policy Modifications
Open Registry Editor (Windows: type regedit in Start menu) and navigate to HKEY_CURRENT_USER\Software\Policies and HKEY_LOCAL_MACHINE\Software\Policies. Look for keys under Google\Chrome, Microsoft\Edge, or Mozilla\Firefox that you didn't create. Delete any policy keys related to homepage, search provider, or extension installation. On macOS, check for configuration profiles in System Preferences → Profiles and remove any you didn't install. These policies can silently reapply hijacker settings even after a browser reset.
Reboot and Verify Clean State
Restart your computer normally (not in Safe Mode) and test your browsers. Open each one, verify your homepage is what you set, perform a test search to ensure it goes through your chosen search engine without redirection, and check that new tabs open to your preferred page. Monitor for 24-48 hours to ensure nothing reinstalls itself. If redirects return, you missed a persistence mechanism—repeat the scheduled task and startup item checks in steps 4 and 9.
Prevention
- Always choose Custom/Advanced installation when installing any free software, and read each screen carefully. Uncheck any boxes offering to install additional programs, browser toolbars, or change your search settings. If a program won't let you decline bundled offers, find the software elsewhere or choose a different program entirely.
- Download software only from official developer websites, not from third-party download portals. If you need a free PDF converter, go to the developer's own site rather than through Download.com or Softonic. These portals repackage installers with additional bundled software and make revenue from each installation.
- Keep your operating system and browsers updated through their official update mechanisms. Never click on pop-ups claiming your browser is out of date—close them and manually check for updates in your browser's settings menu. Legitimate updates never come through random website pop-ups.
- Install and maintain reputable security software with real-time protection enabled. Windows Defender (built into Windows 10/11) provides adequate baseline protection if kept updated. Consider adding Malwarebytes Premium for an additional layer specifically targeting PUPs and hijackers that traditional antivirus sometimes misses.
- Use an ad blocker and script blocker in your browser to prevent malicious advertisements and drive-by download attempts. uBlock Origin (free) blocks most malicious ad networks while allowing acceptable ads on sites you want to support. This prevents many infection vectors before they reach you.
- Review your browser extensions quarterly and remove anything you don't actively use or don't remember installing. Browser extensions can be legitimate when installed but get sold to advertising companies that then push updates converting them to hijackers or adware. If you didn't install it, remove it.
- Create a standard user account for daily use rather than using an administrator account. Many PUPs and hijackers require administrator privileges to install their persistence mechanisms. Running as a standard user forces an elevation prompt, giving you a chance to block the installation before it happens.
- Be skeptical of free versions of commercial software found on unfamiliar sites. If a program normally costs money but you found a "free" version on a random website, it's either pirated (illegal) or bundled with unwanted programs (at best) or actual malware (at worst). Pay for software you need or find truly free alternatives with good reputations.
Bring It In
If you've tried the manual removal steps and still see redirects, or if you're simply not comfortable editing the registry and digging through system folders, bring your computer to our Roswell shop. We encounter browser hijackers like Konohi.who.com weekly, and we've developed efficient removal procedures that clean the infection thoroughly while preserving all your personal files, settings, and legitimate programs. Most hijacker removals take 45-90 minutes depending on how many browsers are affected and how deeply the persistence mechanisms are buried.
We're located at 1322 Hembree Road in Roswell, open Monday through Friday 9 AM to 6 PM and Saturdays 10 AM to 4 PM. Call us at (770) 927-1665 to check our current wait time or schedule a drop-off appointment. We service both PC and Mac systems, and we'll explain exactly what we found and how to prevent reinfection when you pick up your machine. Our diagnostic is free with repair, and we'll give you an honest assessment even if the fix turns out to be simpler than you thought—we're here to solve your problem, not sell you services you don't need.