MeetHornyMum.com is a browser hijacker and potentially unwanted program (PUP) that redirects users to adult dating scam sites while modifying browser settings without consent. This threat typically arrives bundled with free software downloads and immediately takes control of your homepage, search engine, and new tab page. While not technically a virus in the traditional sense, MeetHornyMum.com engages in aggressive tracking, displays intrusive advertisements, and exposes users to further malware through deceptive pop-ups and redirects to unsafe websites.

MeetHornyMum.com — cybersecurity illustration
Photo by Ann H on Pexels

The hijacker operates by installing browser extensions and modifying system settings to maintain persistence, making it difficult to remove through normal uninstallation procedures. Users typically notice sudden changes to their browser behavior, including unexpected redirects to dating sites, adult content, and fake security warnings designed to frighten them into downloading additional unwanted software.

Think you're infected right now? Disconnect from the internet immediately if you're seeing persistent redirects or pop-ups. Do not enter any personal information, credit card details, or passwords on any site you've been redirected to. Close your browser completely (use Task Manager if necessary), then follow the removal steps below or call us at (770) 679-0297 for same-day assistance. We're located in Roswell and can typically resolve browser hijacker infections within 1-2 hours.

Threat Profile

Attribute Details
Threat Type Browser Hijacker, Potentially Unwanted Program (PUP), Redirect Malware
Family Adult dating scam redirector family
Aliases MeetHornyMum redirect, MeetHornyMum.com hijacker, Horny Mum browser hijacker
Affected Platforms Windows 7/8/10/11, macOS; affects Chrome, Firefox, Edge, Safari
Distribution Method Software bundling, fake updates, malicious advertisements, torrent downloads
Primary Payload Browser settings modification, forced redirects, tracking cookie installation
Persistence Mechanism Browser extensions, scheduled tasks, registry modifications (Windows), launch agents (macOS)
Data Collection Browsing history, search queries, IP address, geolocation, device identifiers
Common Symptoms Homepage changed to MeetHornyMum.com or affiliate sites, unwanted redirects, excessive pop-ups, new toolbars appearing
Damage Potential Medium — privacy invasion, exposure to scams, secondary malware installation, system slowdown
Network Behavior Connects to advertising networks and affiliate tracking servers; typical for this family to rotate through multiple domains
Removal Difficulty Moderate — requires browser cleanup, extension removal, and system-level persistence elimination

How It Spreads

MeetHornyMum.com primarily distributes through software bundling, a deceptive practice where legitimate-looking free software includes additional unwanted programs in the installation package. Users downloading video converters, PDF readers, download managers, or codec packs from third-party sites frequently encounter this hijacker hidden in "recommended" or "custom" installation options. The installers are designed with confusing interfaces that make declining the bundled software difficult, often using pre-checked boxes, misleading button labels, or requiring users to navigate through multiple screens to opt out.

Fake software updates represent another major distribution vector. Users encounter pop-ups claiming their Flash Player, Java, or browser needs an urgent security update. These fraudulent update prompts appear on compromised websites or are injected by existing adware already on the system. Clicking "Update Now" triggers the hijacker installation instead of any legitimate software update.

Common infection vectors include:

  • Bundled freeware and shareware — Download managers, media players, screen recorders, and other utilities from sites like Softonic, Download.com, or Brothersoft often include this hijacker
  • Malicious advertising campaigns — Malvertising on legitimate sites can trigger drive-by downloads or deceptive "Your system is infected" warnings that lead to the hijacker
  • Torrent downloads — Pirated software, movies, and games frequently contain bundled PUPs and hijackers in the crack/keygen files
  • Fake Flash Player updates — Pop-ups on streaming or adult sites claiming Flash needs updating (Flash was discontinued in 2020, making all such prompts fraudulent)
  • Email attachments — Less common for this specific threat, but some variants arrive as attachments disguised as invoices or documents
  • Compromised browser extensions — Legitimate-looking extensions in web stores that contain hidden redirect functionality

What It Does On Your Machine

Once installed, MeetHornyMum.com immediately modifies your browser configuration to force redirects through its network of affiliate sites. The hijacker changes your homepage, default search engine, and new tab page to either MeetHornyMum.com directly or to intermediate redirect domains that ultimately lead to adult dating scam sites. These modifications occur at multiple levels—browser preferences, browser policy settings, and sometimes system registry entries—making simple browser resets ineffective.

The hijacker installs browser extensions or add-ons that maintain control even if you manually change your settings back. Every time you open a new tab or perform a web search, the extension intercepts the request and redirects you through advertising networks that generate revenue for the hijacker's operators. These redirects rarely send you to the actual site you intended to visit. Instead, you're routed through a chain of affiliate links designed to register clicks and impressions before eventually (sometimes) allowing you to reach your destination.

Beyond redirects, MeetHornyMum.com aggressively collects browsing data. The hijacker tracks every search query, website visit, link clicked, and page viewed. This data includes personally identifiable information like IP addresses, approximate location based on IP geolocation, browser fingerprints, and device identifiers. The collected information gets sold to advertising networks, data brokers, or used to generate targeted scam campaigns. Users often notice a sudden increase in spam emails, phone calls about "extended car warranties," or targeted phishing attempts shortly after infection.

The hijacker also serves as a delivery platform for additional unwanted software. Pop-ups and fake security warnings appear claiming your system is infected with viruses or that your Windows license has expired. These misleading alerts attempt to trick users into downloading fake antivirus programs, calling tech support scam numbers, or providing credit card information for unnecessary "repair services." The adult dating sites themselves are designed to extract money through fake profile subscriptions, requiring credit card details for "age verification" that leads to recurring charges users never authorized.

Typical filesystem and registry artifacts (Windows example):
Browser Extensions: C:\Users\\AppData\Local\Google\Chrome\User Data\Default\Extensions\\ C:\Users\\AppData\Roaming\Mozilla\Firefox\Profiles\.default\extensions\{}.xpi Registry Modifications: HKCU\Software\Microsoft\Internet Explorer\Main\Start Page = "http://meethornymum.com" HKCU\Software\Policies\Google\Chrome\HomepageLocation HKLM\Software\Policies\Mozilla\Firefox\Homepage\URL Scheduled Tasks: C:\Windows\System32\Tasks\Update # Task executes hourly to re-apply browser settings Supporting Files: %APPDATA%\\config.json %LOCALAPPDATA%\Temp\\installer.exe

Manual Removal — Step by Step

01

Disconnect from the Internet and Document Symptoms

Unplug your ethernet cable or disable WiFi to prevent the hijacker from downloading additional components or communicating with command servers. Take screenshots of any redirects, pop-ups, or changed settings you've noticed—this documentation helps verify complete removal later. Write down what your homepage and search engine were changed to.

02

Boot into Safe Mode with Networking

Restart your computer and boot into Safe Mode with Networking (press F8 during startup on older Windows versions; on Windows 10/11, hold Shift while clicking Restart, then navigate to Troubleshoot > Advanced > Startup Settings > Restart > press 5 or F5). Safe Mode prevents most malware from loading automatically, making removal easier and more effective.

03

Uninstall Suspicious Programs

Open Control Panel > Programs and Features (or Settings > Apps on Windows 10/11) and sort by installation date. Look for any programs installed around the time the redirects started, especially those you don't recognize or didn't intentionally install. Common names include anything with "Search," "Helper," "Updater," or random strings. Uninstall anything suspicious, but note that the hijacker often doesn't appear in the programs list at all.

04

Remove Malicious Browser Extensions

Open each browser you use and check installed extensions thoroughly. In Chrome, go to the three-dot menu > Extensions > Manage Extensions. In Firefox, click the menu > Add-ons and themes. In Edge, click the three-dot menu > Extensions. Remove any extensions you don't recognize, didn't install yourself, or that have suspicious permissions (especially those that can "read and change all your data on websites"). MeetHornyMum.com extensions often have generic names or claim to be productivity tools.

05

Reset Browser Settings to Defaults

In each browser, perform a settings reset to remove hijacker configurations. Chrome: Settings > Advanced > Reset settings > Restore settings to original defaults. Firefox: Help > More troubleshooting information > Refresh Firefox. Edge: Settings > Reset settings > Restore settings to default. This removes the changed homepage, search engine, and startup pages, though it also removes saved passwords and cookies, so ensure you have credentials backed up.

06

Delete Scheduled Tasks and Startup Entries

Open Task Scheduler (search for it in the Start menu), expand Task Scheduler Library, and look for tasks with suspicious names or that run executables from temporary folders or AppData locations. Delete any tasks you don't recognize. Also check Startup items: press Ctrl+Shift+Esc to open Task Manager, go to the Startup tab, and disable any entries related to the hijacker or that reference random executable names in your user AppData folder.

07

Clean Registry Entries (Advanced Users)

Press Win+R, type "regedit," and press Enter to open Registry Editor. Navigate to HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main and verify the "Start Page" value is correct. Check HKEY_CURRENT_USER\Software\Policies\Google\Chrome and HKEY_LOCAL_MACHINE\Software\Policies for any hijacker-created policies. Delete suspicious keys carefully—incorrectly modifying the registry can cause system instability. If uncomfortable with this step, skip to the next step and let security software handle it.

08

Run Malwarebytes or Similar Reputable Scanner

Download Malwarebytes Free (from malwarebytes.com only—not from third-party download sites) and run a full system scan. Malwarebytes effectively detects browser hijackers, PUPs, and adware that traditional antivirus might miss. Allow it to quarantine or delete all detected items. Follow up with a scan using your regular antivirus software as well, since different scanners catch different components.

09

Change Passwords from a Clean Device

If the hijacker was present for more than a day or two, assume your browsing data was compromised. From a different device (not the infected computer), change passwords for critical accounts: email, banking, social media, shopping sites. Enable two-factor authentication where available. Don't reuse passwords across sites—this is a good opportunity to implement a password manager.

10

Reboot Normally and Verify Removal

Restart your computer normally (exit Safe Mode) and reconnect to the internet. Open your browsers and verify that your homepage, search engine, and new tab page are correct. Search for something benign and confirm you're not redirected. Monitor your system over the next few days for any return of symptoms—browser hijackers sometimes have multiple persistence mechanisms that reactivate after removal attempts. If redirects return, the infection likely requires professional removal.

Prevention

  1. Download software only from official sources. Avoid third-party download sites like Softonic, Download.com, CNET Downloads, or any "free software portal." These sites frequently bundle PUPs with legitimate installers. Always download directly from the software developer's website.
  2. Always choose "Custom" or "Advanced" installation options. Never click "Express Install" or "Recommended Settings" when installing free software. Custom installations reveal bundled programs and allow you to deselect unwanted additions. Read every screen carefully—decline offers for toolbars, browser extensions, or unfamiliar programs.
  3. Keep your actual software updated through official channels. Enable automatic updates for Windows, your browsers, and all legitimate software. This reduces the temptation to click on fake update pop-ups. Remember that legitimate software updates never arrive through random website pop-ups—they come through the program itself or Windows Update.
  4. Use a reputable ad blocker. Extensions like uBlock Origin (not to be confused with the compromised "AdBlock" variants) block malicious advertisements that lead to PUP downloads. Ad blockers also prevent drive-by download attempts from compromised websites.
  5. Maintain real-time antivirus protection. Windows Defender (now Microsoft Defender) is adequate for most users if kept updated. Supplement it with periodic scans using Malwarebytes Free. Ensure real-time protection is enabled and definitions are current.
  6. Be skeptical of urgent warnings and offers. Legitimate software companies don't use pop-ups claiming "Your computer is infected!" or "You've won a prize!" Close these immediately without clicking. Real security alerts come from your installed antivirus software, not from websites.
  7. Review browser extensions monthly. Hijackers sometimes arrive as seemingly legitimate extensions that later update to include malicious code. Periodically audit your browser extensions and remove any you don't actively use or don't remember installing.
  8. Avoid pirated content. Torrents for cracked software, movies, and games are frequent infection vectors. The "crack" or "keygen" file often contains bundled malware. If you need expensive software, look for legitimate free alternatives or student discounts rather than risking infection.
Our 90-Day Warranty — When Computer Repair Roswell removes browser hijackers and malware from your system, we guarantee our work for 90 days. If the same infection returns within that period through no fault of your own (not from re-downloading infected software or clicking suspicious links), we'll remove it again at no charge. We also provide a written summary of what was found and removed, along with specific prevention recommendations for your situation.

Bring It In

Browser hijackers like MeetHornyMum.com often prove more stubborn than they initially appear. While the manual removal steps above work for straightforward infections, hijackers frequently install multiple components across different system locations, and missing even one allows the entire infection to regenerate. Many variants also download secondary malware—keyloggers, information stealers, or additional adware—that continues operating even after the visible hijacker is removed. If you've attempted removal and still see redirects, pop-ups, or changed browser settings, the infection has deeper roots that require professional tools and expertise.

Computer Repair Roswell specializes in malware removal for both PCs and Macs, with particular expertise in browser hijackers, adware, and PUP families. We're located in Roswell at 1324 Hembree Road and open Monday through Saturday. Bring your computer in for a free diagnostic—we'll identify exactly what's infected your system, provide a clear explanation of what happened and how to prevent it, and in most cases complete the cleaning the same day. Call us at (770) 679-0297 or stop by. We'll get your browser back to normal and ensure nothing malicious is lurking in the background stealing your data.