MenusWithPrice.com presents itself as a helpful browser extension that displays restaurant menus and pricing information, but security researchers have identified it as a browser hijacker and potentially unwanted program (PUP). Once installed, this extension modifies browser settings without proper consent, redirects search queries through suspicious intermediary servers, and injects unwanted advertisements into your browsing sessions. While not as destructive as ransomware or banking trojans, MenusWithPrice.com represents a privacy invasion and performance degradation that can expose users to more serious threats through forced redirects to malicious advertising networks.

MenusWithPrice.com — cybersecurity illustration
Photo by Ann H on Pexels

Users typically discover they have this hijacker when their homepage suddenly changes, search results start appearing on unfamiliar domains, or their browser becomes noticeably slower with increased ad clutter. The extension often arrives bundled with free software downloads, making it difficult to identify the exact source of infection. Understanding how this threat operates and how to completely remove it is essential for restoring your browser's normal functionality and protecting your privacy.

Think you're infected right now? Disconnect from Wi-Fi or unplug your ethernet cable immediately. Browser hijackers like MenusWithPrice.com track your search queries and browsing habits in real-time. The steps below will walk you through complete removal, but if you're seeing persistent redirects or your browser won't respond to changes, call us at (770) 667-9487 — we can remote in or have you bring the machine to our Roswell shop today.

Threat Profile

Attribute Details
Threat Type Browser Hijacker, Potentially Unwanted Program (PUP), Adware
Family Generic browser extension hijacker family
Primary Aliases MenusWithPrice, Menus With Price extension, Search.menuswithprice.com
Affected Platforms Windows (all versions), macOS; targets Chrome, Firefox, Edge, Safari
Distribution Method Software bundling, fake updates, deceptive download buttons, freeware installers
Persistence Mechanisms Browser extension installation, policy modifications, scheduled tasks (Windows), launch agents (macOS)
Primary Capabilities Search redirection, homepage hijacking, new tab replacement, advertising injection, browsing data collection
Data at Risk Search queries, browsing history, clicked links, cookies, potentially form data
Network Behavior Connects to advertising networks and tracking domains; redirects through intermediary search engines
Typical Artifacts Browser extension folders, modified browser shortcuts, registry keys (Windows), preference files (macOS)
Removal Difficulty Moderate — fights removal through reinstallation tactics and hidden persistence
Reinfection Risk High if bundled software source remains installed or unsafe browsing habits continue

How It Spreads

MenusWithPrice.com spreads primarily through software bundling, a deceptive practice where potentially unwanted programs are packaged with legitimate free software. When users download video converters, PDF creators, media players, or other utilities from third-party download sites, the installer includes MenusWithPrice.com as an "optional" component. However, this option is often pre-checked and hidden in "Custom" or "Advanced" installation screens that most users skip by clicking "Next" repeatedly through the default "Express" installation process.

The hijacker also propagates through fake update notifications that appear while browsing questionable websites. These alerts mimic legitimate browser or Flash Player update prompts but actually deliver the MenusWithPrice extension or its installer package. Social engineering plays a significant role — the installation screens often present the extension as a helpful tool for finding restaurant information, obscuring its true behavior of hijacking browser settings and tracking user activity.

Common distribution vectors include:

  • Freeware and shareware bundles from download portals like Softonic, Download.com, or file-sharing sites
  • Fake software update notifications appearing on streaming sites, torrent pages, or ad-heavy content sites
  • Deceptive download buttons on file-hosting services that lead to PUP installers instead of the intended file
  • Malvertising campaigns where compromised ad networks serve installation prompts disguised as security alerts
  • Email attachments with executable installers masquerading as documents or media files (less common for this specific threat)
  • Infected USB drives or external storage devices shared between systems
  • Browser extension stores using misleading descriptions and fake reviews to appear legitimate

What It Does On Your Machine

Once MenusWithPrice.com establishes itself on your system, it immediately modifies your browser configuration to maintain control over your search and browsing experience. The hijacker changes your default search engine to search.menuswithprice.com or redirects searches through this intermediary before sending them to legitimate search engines like Bing or Yahoo. This redirection serves two purposes: it allows the operators to track every search query you make, and it creates opportunities to inject sponsored results or advertisements into your search results page before you see them.

The extension also replaces your new tab page and homepage with MenusWithPrice.com or related domains. Every time you open your browser or launch a new tab, you're forced to load this page, which generates advertising revenue for the operators and increases exposure to potentially dangerous sponsored links. The hijacker modifies browser shortcut files on Windows systems, appending the malicious URL to the target path so that even if you manually reset your homepage in settings, the browser launch shortcut overrides your preference.

Beyond the visible changes, MenusWithPrice.com operates in the background collecting extensive browsing data. The extension monitors which websites you visit, how long you spend on each page, what you search for, and what links you click. This information is aggregated and typically sold to advertising networks or data brokers. While the privacy policy may technically disclose this data collection in vague legal language, the reality is that your entire browsing session becomes a monetization opportunity for unknown third parties. The data collection includes cookies and tracking pixels that follow you across websites, building a detailed profile of your interests, habits, and potentially sensitive information.

Typical MenusWithPrice.com Artifacts
Windows Registry Keys: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\MenusWithPrice HKLM\Software\Policies\Google\Chrome\ExtensionInstallForcelist HKCU\Software\MenusWithPrice File System Locations: %LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\[random-id]\ %APPDATA%\Mozilla\Firefox\Profiles\[profile].default\extensions\ %PROGRAMFILES(X86)%\MenusWithPrice\ %TEMP%\[random]\menuswithprice_setup.exe Browser Preference Modifications: Chrome: Preferences file → homepage, search_provider_override Firefox: prefs.js → browser.startup.homepage, keyword.URL Scheduled Tasks (Windows): \MenusWithPrice Update Task \MenusWithPrice Browser Update

Performance degradation is another immediate consequence of MenusWithPrice.com infection. The constant redirection through intermediary servers adds latency to every search and page load. The injection of additional advertisements increases the amount of content your browser must download and render, consuming more memory and CPU cycles. Users frequently report browser crashes, freezing, and unresponsive tabs after this hijacker installs itself. The extension may also conflict with legitimate security software or ad-blockers, creating additional stability problems that make regular browsing frustrating and time-consuming.

Manual Removal — Step by Step

01

Disconnect from the Internet

Unplug your ethernet cable or disable Wi-Fi to prevent the hijacker from communicating with its command servers, downloading additional components, or reinstalling itself during the removal process. This isolation also stops the ongoing collection of your browsing data.

02

Uninstall Suspicious Programs

Open Windows Settings > Apps > Apps & features (or Control Panel > Programs and Features on older systems). Sort by installation date and look for MenusWithPrice, unknown programs installed around the same time your browser problems started, or anything from unfamiliar publishers. Uninstall all suspicious entries. On macOS, check Applications folder and drag suspicious apps to Trash, then empty it.

03

Remove the Browser Extension

Open your browser's extension management page (chrome://extensions/ in Chrome/Edge, about:addons in Firefox, Safari > Preferences > Extensions in Safari). Look for MenusWithPrice or any extensions you don't recognize or didn't intentionally install. Click Remove on each suspicious extension. Don't just disable them — complete removal is necessary.

04

Reset Browser Settings

In Chrome/Edge, go to Settings > Reset settings > Restore settings to their original defaults. In Firefox, type about:support in the address bar and click "Refresh Firefox." This removes the homepage hijack, search engine changes, and clears extension-imposed policies. You'll need to sign back into websites afterward, but your bookmarks will remain.

05

Check and Repair Browser Shortcuts

Right-click your browser shortcut (on desktop, taskbar, or Start menu), select Properties, and examine the Target field. It should end with the .exe filename — if you see a URL appended after the .exe, delete everything after the closing quotation mark following chrome.exe or firefox.exe. Click OK to save. Repeat for all browser shortcuts.

06

Remove Persistence Mechanisms

Press Windows + R, type "taskschd.msc" and press Enter to open Task Scheduler. Look in the Task Scheduler Library for any tasks related to MenusWithPrice or with suspicious names like "Browser Update" from unknown publishers. Right-click and delete these tasks. They're designed to reinstall the hijacker automatically.

07

Clean Registry Entries (Windows)

Press Windows + R, type "regedit" and press Enter (requires administrator privileges). Navigate to HKEY_CURRENT_USER\Software\ and look for a MenusWithPrice folder — right-click and delete it. Also check HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run for any MenusWithPrice entries and delete them. Be cautious editing the registry — only remove entries you're certain are related to this threat.

08

Delete Leftover Files and Folders

Open File Explorer and navigate to C:\Program Files, C:\Program Files (x86), %LOCALAPPDATA%, and %APPDATA% (type these paths in the address bar). Look for folders named MenusWithPrice or with random names created around your infection date. Delete these folders completely. Also check your browser's user data folders for leftover extension directories.

09

Scan with Reputable Anti-Malware

Reconnect to the internet and download Malwarebytes Free (from the official malwarebytes.com site). Run a full system scan to catch any components you might have missed and to check for additional PUPs that may have been bundled with MenusWithPrice. Quarantine and remove all detected threats. Consider also running a scan with your existing antivirus software for a second opinion.

10

Change Your Passwords

Since MenusWithPrice.com tracks browsing activity and may have captured login pages you visited, change passwords for important accounts — especially banking, email, and any accounts accessed while the hijacker was active. Use a different device or wait until you've confirmed complete removal before changing critical passwords.

11

Restart and Verify

Restart your computer normally (not in Safe Mode). Open your browser and verify that your homepage and search engine are back to your preferred settings. Visit a few websites and confirm that you're not seeing unexpected redirects or excessive advertisements. Check Task Manager (Ctrl+Shift+Esc) for any suspicious processes still running.

Prevention

  1. Download software only from official sources. Avoid third-party download sites like Softonic, Download.com, or file-hosting services that bundle PUPs with legitimate software. Always get installers directly from the software developer's official website.
  2. Always choose Custom or Advanced installation. When installing any free software, never accept the Express or Quick installation option. Custom installation reveals bundled offers and allows you to uncheck unwanted programs before they install. Read every screen carefully during installation.
  3. Keep your browser and operating system updated. Enable automatic updates for Windows, macOS, and your browsers. Security patches close vulnerabilities that hijackers and malware exploit. An updated system is significantly harder to compromise than one running outdated software.
  4. Install a reputable ad-blocker and extension manager. Extensions like uBlock Origin block malicious advertising networks that distribute PUPs. Regularly review your installed extensions and remove any you don't recognize or no longer need. Limit browser extensions to those absolutely necessary.
  5. Be skeptical of update notifications while browsing. Legitimate software updates happen through the program itself or Windows Update — not through pop-ups on random websites. If you see an update prompt on a website, close it and manually check for updates through the official software.
  6. Use standard user accounts for daily activities. Don't run as an administrator for regular browsing and work. Many PUPs require administrator privileges to install system-wide persistence mechanisms. A standard account forces an authentication prompt, giving you a chance to block unwanted installations.
  7. Read reviews and research unfamiliar extensions. Before installing any browser extension, search for reviews from reputable tech sites. Look for complaints about hijacking behavior, unwanted ads, or data collection. If an extension has few reviews or only suspiciously positive ones, avoid it.
  8. Maintain regular backups. While browser hijackers don't typically encrypt files like ransomware, having current backups of your important data protects you from all types of malware. Use Windows File History, macOS Time Machine, or a cloud backup service with versioning capabilities.
Our Guarantee: When Computer Repair Roswell removes malware from your system, it stays gone. We don't just delete the visible infection — we hunt down every persistence mechanism, repair damaged system files, and verify complete removal. If the same threat reappears within 90 days, we'll fix it again at no charge. That's our commitment to your digital security.

Bring It In

Browser hijackers like MenusWithPrice.com may seem like minor annoyances compared to ransomware or identity theft trojans, but they represent a gateway to more serious infections and a constant privacy violation. If you've followed the removal steps above and still see redirects, if your browser crashes frequently, or if you're just not comfortable editing the registry and Task Scheduler, we're here to help. Our technicians have removed thousands of PUPs, hijackers, and complex malware infections from systems throughout North Atlanta.

We're located on Alpharetta Street in Roswell, open Monday through Friday 10 AM to 6 PM, and Saturday 10 AM to 4 PM. Call us at (770) 667-9487 to describe what you're experiencing — we can often remote into your system for immediate diagnosis, or you can bring your machine to our shop for same-day cleaning. Most hijacker removals are completed while you wait, and we'll show you exactly what we found and how we secured your system. Don't let a browser hijacker continue tracking your every click and slowing your computer. Let's get your machine cleaned up properly and keep it that way.