MeetSurveyTop is a browser hijacker that forcibly redirects your web searches and homepage to unfamiliar search engines, bombards you with unwanted advertisements, and degrades your browsing experience to generate advertising revenue for its operators. Once installed—typically bundled with free software downloads or disguised as a helpful browser extension—it reconfigures your browser settings without permission and resists standard uninstallation attempts. While not classified as a virus in the traditional sense, this potentially unwanted program (PUP) exhibits intrusive behavior that warrants immediate removal to restore normal browser function and protect your privacy.
Threat Profile
| Attribute | Details |
|---|---|
| Threat Family | Browser Hijacker / Potentially Unwanted Program (PUP) |
| Aliases | Meet Survey Top, MeetSurvey Top redirect, survey-related search hijacker |
| Platform | Windows (all versions); macOS (via browser extensions); affects Chrome, Firefox, Edge, Safari |
| Distribution Method | Software bundling, fake update prompts, deceptive advertising, freeware installers |
| Persistence Mechanism | Browser extension with administrative permissions, scheduled tasks (Windows), modified browser shortcuts, registry Run keys (Windows) |
| Primary Capabilities | Homepage/new tab hijacking, search engine replacement, redirect chains, ad injection, browsing data collection |
| Data Collection | Search queries, visited URLs, IP address, browser type, clickstream data, potentially form inputs |
| Network Behavior | Redirects through multiple affiliate domains before landing on sponsored search results or advertising pages |
| Typical Artifacts | Browser extension labeled "MeetSurveyTop" or similar, modified browser shortcut targets, scheduled tasks with random names |
| User Impact | Degraded browser performance, unwanted advertisements, privacy exposure, potential exposure to malvertising |
| Removal Difficulty | Moderate—resists standard uninstallation; often reinstalls itself if all persistence mechanisms aren't addressed |
| Associated Risks | Secondary malware delivery through malicious ads, phishing page exposure, privacy violation, system slowdown |
How It Spreads
MeetSurveyTop rarely arrives alone or announces itself honestly. The most common infection vector is software bundling, where the hijacker piggybacks on legitimate-looking free software installers. When users rush through installation wizards using the "Express" or "Recommended" settings, they unknowingly agree to install additional programs—including MeetSurveyTop—that were pre-checked in the installer's fine print. This deceptive practice has become standard operating procedure for many free download sites and third-party software repositories.
The hijacker also spreads through fake browser update notifications that appear while you're browsing. These convincing pop-ups mimic legitimate Chrome or Firefox update prompts, complete with official-looking logos and urgent language about security patches. Clicking "Update Now" doesn't update anything—it downloads the hijacker instead. Once you've granted permission to install what you thought was a browser update, MeetSurveyTop embeds itself deeply into your system.
Common distribution channels include:
- Bundled freeware and shareware from download portals like Softonic, download.com, or similar aggregator sites
- Fake software update notifications displayed on compromised or low-quality websites
- Malicious browser extensions promoted through deceptive advertising or search engine manipulation
- Email attachments disguised as documents that trigger the installation of a dropper when macros are enabled
- Torrents and cracked software packages where the hijacker is bundled with pirated programs or key generators
- Malvertising campaigns on legitimate websites where compromised ad networks serve infected advertisements
- Social engineering tactics on social media platforms linking to "must-have" browser tools or productivity extensions
What It Does On Your Machine
Once installed, MeetSurveyTop immediately takes control of your browser configuration. Your homepage changes to an unfamiliar search engine—often a generic-looking page designed to mimic Google or Bing—and every new tab you open displays the same hijacked page. When you attempt to search the web using your address bar or the hijacked search page, your queries get routed through a series of redirect domains before landing on a search results page filled with sponsored links and advertisements. These aren't legitimate search results curated by reputable algorithms; they're paid placements designed to generate revenue for the hijacker's operators every time you click.
The hijacker doesn't stop at redirecting searches. It injects additional advertisements into websites you visit—banner ads, pop-unders, text-link ads, and interstitial pages that appear between legitimate pages you're trying to access. These injected ads slow down page loading, consume bandwidth, and increase the risk of exposure to malicious advertising (malvertising) that could lead to more serious infections. The extension grants itself extensive permissions to "read and change all your data on the websites you visit," which means it can monitor every site you browse, every form you fill out, and potentially every password you enter if the site doesn't use adequate encryption.
Behind the scenes, MeetSurveyTop establishes multiple persistence mechanisms to prevent easy removal. On Windows systems, it typically creates scheduled tasks that reinstall the browser extension if you manage to delete it manually. It modifies browser shortcut files—the icons on your desktop and taskbar—by appending malicious URLs to the target field, so even launching a "clean" browser immediately loads the hijacker's page. Registry entries in the Windows Run key ensure components launch at startup, and the extension itself often lacks a conventional uninstall option in your browser's extension manager.
The privacy implications are significant. MeetSurveyTop collects detailed information about your browsing habits—websites visited, search terms entered, links clicked, time spent on pages—and transmits this data to remote servers. While the operators claim this data is "anonymized" and used only for marketing purposes, you have no meaningful control over how it's stored, who it's shared with, or whether it might be combined with other data sources to identify you personally. In an era of increasing data breaches and identity theft, handing over your browsing history to unknown third parties represents an unacceptable privacy risk.
Manual Removal — Step by Step
Disconnect and Document
Disconnect your computer from the internet—unplug the Ethernet cable or disable Wi-Fi. This prevents the hijacker from communicating with its command servers and potentially downloading additional components during the removal process. Take a screenshot or write down the exact name of any suspicious browser extensions you see before proceeding, as this information helps ensure complete removal.
Boot into Safe Mode with Networking
Restart your computer in Safe Mode with Networking, which loads Windows with only essential drivers and services, preventing most malware from launching automatically. On Windows 10/11, hold Shift while clicking Restart, then navigate to Troubleshoot > Advanced Options > Startup Settings > Restart, and press F5 when the options appear. This gives you a cleaner environment to work in without the hijacker actively resisting your efforts.
Uninstall Suspicious Programs
Open Control Panel > Programs > Programs and Features (or Settings > Apps on Windows 10/11) and sort the list by installation date. Look for any programs you don't recognize that were installed around the time your browser problems started—names like "MeetSurveyTop," "Survey Helper," or random alphanumeric strings. Right-click and uninstall these programs. Some may claim they failed to uninstall; note which ones and continue to the next step.
Remove Browser Extensions
Open each browser you use and navigate to its extension/add-on manager (chrome://extensions/ for Chrome/Edge, about:addons for Firefox, or through the browser's menu). Disable and remove any extensions you don't recognize, especially those with vague names, no reviews, or suspicious permission requests. Don't just disable them—click Remove. MeetSurveyTop often installs under names that sound helpful like "Search Assistant" or "Fast Search" to avoid detection.
Check and Fix Browser Shortcuts
Right-click on your browser shortcuts (on desktop, taskbar, and Start menu), select Properties, and examine the Target field. If you see any URLs appended after the .exe path (especially URLs containing "meetsurveytop" or unfamiliar domains), delete everything after the closing quotation mark following chrome.exe or firefox.exe. Click Apply and OK. This prevents the hijacker from launching automatically even with a clean browser installation.
Delete Scheduled Tasks
Press Windows+R, type taskschd.msc, and press Enter to open Task Scheduler. Browse through the Task Scheduler Library and look for tasks with suspicious names—especially those containing "MeetSurveyTop," random GUID-like strings, or names that don't correspond to programs you recognize. Right-click any suspicious tasks and select Delete. Pay special attention to tasks scheduled to run at logon or at regular intervals.
Clean Registry Entries
Press Windows+R, type regedit, and press Enter (click Yes if prompted by User Account Control). Navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run. Look for entries referencing MeetSurveyTop or unfamiliar executable paths in %APPDATA% or %LOCALAPPDATA%. Right-click suspicious entries and delete them. Be cautious here—only delete entries you're confident are related to the hijacker.
Reset Browser Settings
In each affected browser, navigate to Settings and look for the "Reset settings" or "Restore settings to their original defaults" option (usually under Advanced settings). This removes the hijacker's configuration changes while preserving your bookmarks and saved passwords. In Chrome/Edge, this is at chrome://settings/reset. In Firefox, use about:support and click "Refresh Firefox." Accept the prompts and allow the browser to restart.
Scan with Reputable Anti-Malware
Reconnect to the internet and download Malwarebytes (free version is sufficient) or another reputable anti-malware tool if you don't already have one installed. Run a full system scan—not a quick scan. These tools have specific detection signatures for browser hijackers and can identify remnants that manual removal might miss. Quarantine or delete any threats found, then restart your computer normally (not in Safe Mode).
Verify and Monitor
After restarting normally, open your browser and verify that your homepage and search engine are back to normal. Visit a few websites and confirm you're not seeing excessive ads or unexpected redirects. Check your browser extensions list one more time. Monitor your system for the next few days—if the hijacker returns, you likely missed a persistence mechanism and should consider bringing the computer in for professional cleaning to ensure complete removal.
Prevention
- Always use Custom/Advanced installation settings when installing free software. Read each screen carefully and uncheck any boxes offering to install additional programs, browser toolbars, or change your homepage. The few extra seconds this takes can save hours of cleanup work.
- Download software only from official sources. Avoid third-party download sites that bundle installers with additional software. Go directly to the developer's website or use the Microsoft Store, Mac App Store, or verified distribution channels. If you must use a download aggregator, read the installer screens obsessively.
- Keep your browser and operating system updated through official update mechanisms only. Never click "Update Now" buttons on random websites. Legitimate updates come through Windows Update, your browser's built-in updater, or (for third-party software) the application's own update checker—never through pop-ups while browsing.
- Install a reputable ad blocker and script blocker. Extensions like uBlock Origin (not AdBlock Plus, which allows "acceptable ads") prevent many malicious advertisements from loading in the first place. Consider NoScript or uMatrix if you're comfortable with a stricter security posture, though these require more manual configuration.
- Review browser extension permissions before installing. If a simple "dark mode" extension requests permission to "read and change all your data on the websites you visit," that's a red flag. Extensions should request only the minimum permissions necessary for their stated function. When in doubt, don't install it.
- Maintain a robust security suite with real-time protection enabled. Windows Defender (now Microsoft Defender) is adequate for most users if kept updated, but consider supplementing it with Malwarebytes Premium or a similar anti-malware tool that specifically targets PUPs and browser hijackers.
- Create a standard user account for daily browsing. Reserve your administrator account for software installation and system maintenance. Many browser hijackers require administrative privileges to install their persistence mechanisms; using a standard account forces the system to prompt you before making system-level changes.
- Be skeptical of too-good-to-be-true offers. Free VPN services, download accelerators, video converters, and registry cleaners are common carriers for browser hijackers and worse. If you need these tools, research reputable paid alternatives or open-source projects with established track records.
When we remove MeetSurveyTop or any other malware at Computer Repair Roswell, we guarantee our work for 90 days. If the same threat returns within that window—meaning we didn't get it all the first time—we'll fix it again at no additional charge. That's our commitment to getting it done right.
Bring It In
If you've worked through the manual removal steps and still see signs of MeetSurveyTop—unexpected redirects, persistent unwanted ads, or browser settings that keep reverting—you're dealing with a stubborn infection that's established deeper persistence than typical. Some variants of this hijacker install kernel-level components or modify system files in ways that require specialized tools and expertise to address safely. Attempting to manually delete critical system files without proper identification can cause Windows stability problems that are worse than the hijacker itself.
Bring your computer to Computer Repair Roswell at 1235 Hembree Road in Roswell, or give us a call at (770) 569-2002. We handle browser hijackers, adware, and more serious malware infections every week. Our technicians will thoroughly clean your system, verify that all persistence mechanisms are removed, and make sure you're not dealing with secondary infections that the hijacker may have introduced. We'll also review your browser configuration and security settings to help prevent reinfection. Most malware removals are completed same-day, and with our 90-day warranty, you can be confident the problem is actually solved—not just temporarily suppressed.