Metkpwt.com is a browser hijacker that forces unwanted redirects to potentially malicious advertising networks and dubious search engines. Once installed, this intrusive program modifies browser settings without consent, replacing your homepage and default search provider with unfamiliar domains designed to generate revenue through forced traffic and data collection. While not technically a virus in the traditional sense, browser hijackers like Metkpwt.com create serious security and privacy concerns by exposing users to malvertising, tracking their browsing habits, and potentially introducing additional malware through deceptive advertisements.
This hijacker typically targets Windows users across all major browsers—Chrome, Firefox, Edge, and even older Internet Explorer installations. What makes Metkpwt.com particularly frustrating is its persistence: simply changing your homepage back doesn't solve the problem because the hijacker reinstalls its settings through registry modifications, scheduled tasks, or browser extension abuse. The constant redirects slow down browsing, expose sensitive search data to unknown third parties, and significantly increase the risk of landing on phishing sites or pages hosting drive-by download attacks.
Threat Profile
| Attribute | Details |
|---|---|
| Threat Family | Browser Hijacker / PUP (Potentially Unwanted Program) |
| Common Aliases | Metkpwt redirect, Metkpwt.com virus, Metkpwt browser hijacker |
| Targeted Platforms | Windows 7/8/10/11 (all browsers); occasional macOS variants reported |
| First Documented | 2018-2019 timeframe (variants continue to evolve) |
| Primary Distribution | Software bundling, fake browser updates, malicious advertisements, deceptive download buttons |
| Persistence Mechanisms | Browser extensions, registry Run keys, scheduled tasks, browser policy settings, shortcut target modification |
| Primary Capabilities | Search redirection, homepage hijacking, new tab override, ad injection, tracking cookie deployment, referral traffic monetization |
| Known File Artifacts | Random folder names in %APPDATA% or %LOCALAPPDATA%, browser extension directories with GUID-style names, modified browser shortcuts |
| Network Behavior | Redirects through multiple intermediary domains before landing on ad networks; DNS queries to randomly-generated subdomains; frequent connections to tracking analytics services |
| Data Collected | Search queries, browsing history, clicked links, IP address, approximate location, device information, potentially credentials entered on hijacked search pages |
| Removal Difficulty | Moderate—requires browser cleanup, registry editing, and potential removal of hidden scheduled tasks; sometimes bundled with multiple PUPs that reinfect each other |
| Related Threats | Often distributed alongside adware families like Pirrit, bundled with other hijackers like Searchmine or MyWay, may download additional PUPs post-installation |
How It Spreads
Metkpwt.com doesn't typically spread through traditional exploit kits or zero-day vulnerabilities. Instead, it relies on social engineering and deceptive distribution tactics that trick users into installing it voluntarily—though certainly not knowingly. The most common vector is software bundling, where the hijacker is packaged alongside legitimate-looking free software downloaded from third-party hosting sites. When users rush through installation wizards using "Express" or "Recommended" settings, they unknowingly consent to installing bundled PUPs that include the Metkpwt components.
Another effective distribution method involves fake browser update prompts that appear while visiting compromised or malicious websites. These convincing pop-ups claim your browser is out of date and needs an urgent security update. Clicking "Update Now" downloads an installer that may include a legitimate browser update but also silently installs the hijacker alongside it. Video streaming sites, free software repositories, and torrent-related pages are common hosts for these deceptive prompts.
The hijacker also spreads through these additional vectors:
- Malicious browser extensions: Seemingly useful tools for weather, coupons, or news that request excessive permissions and then modify browser settings
- Fake download buttons: Disguised as legitimate download links on file-sharing sites, these buttons install unwanted programs instead of the file you actually wanted
- Email attachments with macros: Less common for hijackers, but some campaigns use Office documents with macros that download PUP installers
- Compromised software update mechanisms: Outdated software (especially Java, Flash alternatives, media players) with poor update security can be exploited to push hijackers
- Pay-per-install affiliate networks: Free software developers partner with PPI networks that pay them for each bundled installation, creating financial incentive to distribute hijackers aggressively
- Pirated software packages: Cracked applications and key generators frequently bundle multiple PUPs including browser hijackers as a monetization strategy
What It Does On Your Machine
Once Metkpwt.com establishes itself on your system, it immediately targets your web browsers as its primary habitat. The hijacker modifies core browser settings including your homepage, default search engine, and new tab page—redirecting them all to Metkpwt.com or an intermediate redirection page. When you attempt to perform searches, your queries are routed through the hijacker's infrastructure before (sometimes) forwarding to a legitimate search engine like Bing or Google, with all your search terms captured along the way. The results pages you eventually see are often injected with additional sponsored links that weren't part of the original search results.
Beyond simple redirection, Metkpwt.com deploys tracking mechanisms throughout your browsing session. Persistent cookies, browser storage objects, and in some cases actual spyware components monitor which sites you visit, what you search for, what you click on, and how long you spend on various pages. This data feeds into advertising profiles that can be sold to marketing networks or used to serve increasingly targeted (and intrusive) advertisements. Some variants inject additional ads directly into legitimate websites you visit, displaying pop-unders, in-text link ads, and banner advertisements on pages that normally wouldn't contain them.
The hijacker establishes multiple persistence mechanisms to ensure it survives basic removal attempts. Browser extensions are installed with randomized names and descriptions, making them difficult to identify in your extension manager. Windows registry keys are created to launch components at startup, and scheduled tasks may be configured to periodically reinstall the hijacker if you manage to remove the browser extension. Some sophisticated variants even modify your browser's shortcut targets, adding command-line parameters that force the homepage to redirect regardless of your configured settings.
Performance impact is another significant concern. The constant background processes, network connections to advertising servers, and resource-intensive ad injection scripts slow down both your browser and overall system responsiveness. Many users report their browsers taking significantly longer to start, pages loading more slowly, and occasional freezing when the hijacker communicates with its command infrastructure. The redirections themselves add multiple hops to every search query, introducing latency and frustration into what should be instantaneous operations.
Manual Removal — Step by Step
Disconnect from the Network
Before beginning the removal process, disconnect your computer from the internet by unplugging the Ethernet cable or disabling Wi-Fi. This prevents the hijacker from downloading additional components, phoning home with collected data, or re-installing itself from a remote server during the cleanup process. Work offline throughout the entire removal procedure.
Boot into Safe Mode with Networking
Restart your computer and boot into Safe Mode to prevent the hijacker's startup items from launching. On Windows 10/11, hold Shift while clicking Restart, then navigate to Troubleshoot > Advanced Options > Startup Settings > Restart, and select option 5 (Safe Mode with Networking). This limited environment makes it easier to remove persistent threats that normally defend themselves when running in normal mode.
Uninstall Suspicious Programs
Open Settings > Apps > Apps & Features (or Control Panel > Programs and Features on older Windows). Sort by install date and look for any programs you don't recognize that were installed around the time redirects started. Uninstall anything suspicious, paying special attention to programs with random names, developer names you don't recognize, or descriptions that mention browser enhancement, search assistance, or web optimization. Common disguises include generic names like "Web Companion," "Browser Assistant," or branded names that sound legitimate but aren't from recognized companies.
Remove Malicious Browser Extensions
Open each browser you have installed and examine the extensions list. In Chrome, navigate to chrome://extensions/; in Firefox, go to about:addons; in Edge, visit edge://extensions/. Remove any extensions you didn't intentionally install, especially those with vague descriptions, excessive permissions, or installation dates that coincide with the hijacker's arrival. Don't just disable them—fully remove them, as disabled extensions can be re-enabled by the hijacker's scheduled tasks.
Reset Browser Settings
Each browser needs its settings manually reset to remove hijacker modifications. In Chrome, go to Settings > Reset settings > Restore settings to their original defaults. In Firefox, navigate to about:support and click "Refresh Firefox." In Edge, visit Settings > Reset settings > Restore settings to their default values. This removes unauthorized homepage changes, search engine modifications, and startup page overrides, though you'll need to reconfigure your preferred settings afterward.
Check and Repair Browser Shortcuts
Right-click on each browser shortcut (on desktop, taskbar, and Start menu), select Properties, and examine the Target field. The target should only contain the path to the browser executable—nothing else. If you see additional text after the .exe file (especially URLs or command-line switches you don't recognize), delete everything after the closing quotation mark that ends the executable path. Apply the changes and repeat for all browser shortcuts on your system.
Clean Registry Startup Items
Press Win+R, type "regedit" and hit Enter to open Registry Editor (accept the UAC prompt). Navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and examine each entry. Delete any values that reference executable files in %LOCALAPPDATA% or %APPDATA% folders with random GUID-style names. Also check HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run for system-wide startup entries. Be cautious—only delete entries you're certain are related to the hijacker, as legitimate programs also use these locations.
Remove Scheduled Tasks
Open Task Scheduler by typing "taskschd.msc" in the Run dialog (Win+R). Expand Task Scheduler Library and look for tasks with suspicious names, especially those in Microsoft > Windows folders that don't look like legitimate Windows components. Examine the Actions tab for any task—if it references an executable in %LOCALAPPDATA% or attempts to install browser extensions, right-click the task and delete it. Common hijacker task names include variations of "BrowserMaintenance," "UpdateChecker," or random alphanumeric strings.
Scan with Reputable Anti-Malware Tools
Reconnect to the internet and download Malwarebytes Free (from malwarebytes.com—use official sources only). Install it, update the definitions, and run a full system scan. Malwarebytes is particularly effective at detecting PUPs and browser hijackers that traditional antivirus might miss. Quarantine everything it finds. Follow up with a second-opinion scan using HitmanPro or AdwCleaner for comprehensive coverage, as no single tool catches everything.
Delete Leftover Folders and Files
After the scans complete, manually browse to %LOCALAPPDATA% and %APPDATA% (type these into File Explorer's address bar) and look for folders with random GUID names or anything that matches the file paths identified in the scans. Delete these folders entirely. Check your user profile's Downloads folder for any suspicious installers and delete those as well. Empty the Recycle Bin to permanently remove all quarantined items.
Change Important Passwords
If you entered any passwords while the hijacker was active—especially for email, banking, or other sensitive accounts—change those passwords immediately from a confirmed clean device (or after completing all other removal steps). Browser hijackers can capture form data, and you cannot know with certainty what information was transmitted during the infection period. Use strong, unique passwords and enable two-factor authentication where available.
Restart and Verify Complete Removal
Restart your computer normally (not in Safe Mode) and test your browsers. Verify that your homepage, search engine, and new tab page are set to your preferences without reverting to Metkpwt.com. Search for a few terms and confirm the results come from your chosen search engine without intermediary redirects. Monitor your system for the next few days—if redirects return, you likely missed a persistence mechanism and should consider professional removal assistance.
Prevention
- Download software only from official sources. Avoid third-party download sites, torrent repositories, and file-sharing platforms that bundle legitimate software with PUPs. When you need free software, go directly to the developer's official website rather than searching for downloads on general software aggregators.
- Always choose Custom/Advanced installation. Never click through installers using Express or Recommended settings. Custom installation reveals bundled offers, letting you uncheck unwanted additions. Read every screen carefully—pre-checked boxes and decline/accept button placement are deliberately designed to be confusing.
- Keep your browser and operating system updated. Enable automatic updates for Windows and all browsers. Current software patches vulnerabilities that hijackers and more serious malware exploit for drive-by installations. Outdated browsers are significantly more vulnerable to forced extension installations.
- Use a reputable ad-blocker and script-blocker. Extensions like uBlock Origin prevent malicious advertisements from loading and can block many of the fake update prompts and deceptive download buttons that distribute hijackers. Configure it to block third-party scripts by default on unfamiliar sites.
- Review browser extensions regularly. Make it a monthly habit to audit your installed extensions. Remove anything you don't actively use, don't remember installing, or that requests permissions beyond what its stated function requires. Extension compromise is an increasingly common distribution method.
- Be skeptical of browser update prompts. Legitimate browser updates happen automatically in the background or come from the browser's own update mechanism—not from random websites you're visiting. If a site claims your browser is out of date, manually check for updates through the browser's own settings menu rather than clicking the prompt.
- Run periodic scans with anti-malware tools. Even if you don't see symptoms, run Malwarebytes or a similar tool monthly to catch PUPs before they become problematic. Many hijackers have quiet periods where they gather data without obvious symptoms, then activate aggressively later.
- Use DNS-level filtering. Configure your home router or individual devices to use DNS services like Cloudflare's 1.1.1.2 (with malware filtering) or Quad9. These services block known malicious domains at the DNS level, preventing many hijacker command-and-control communications even if the software gets installed.
When Computer Repair Roswell removes malware from your system, we back our work with a 90-day guarantee. If the same threat returns within three months, we'll re-clean your computer at no additional charge. We also include optimization, security hardening, and prevention education with every malware removal service—because keeping threats off your machine in the first place is always better than removing them after the fact.
Bring It In
If you've followed these removal steps and still see redirects to Metkpwt.com—or if the process seems too complex or risky to handle yourself—bring your computer to Computer Repair Roswell. Browser hijackers frequently travel with companions: additional PUPs, rootkit components that hide processes from Task Manager, or even actual trojans that download themselves while you're distracted by the obvious redirects. Our technicians have the forensic tools and experience to identify every component of a multi-layered infection and remove them all without damaging your system or losing your data.
We're located right here in Roswell, Georgia, and we work on both PCs and Macs with all varieties of malware, PUPs, and system infections. Most browser hijacker removals are completed same-day, and we'll also identify and close the security gap that let the infection in initially—whether that's outdated software, missing security updates, or risky browsing configurations. Call us at (770) 954-1115 or stop by our shop. We'll get your browser back under your control, not the hijacker's, and make sure your system is hardened against similar threats going forward.