Metrium.oldeb.com is a browser hijacker that forcibly redirects search queries and new tab pages through its own search engine, generating revenue for its operators through forced advertising and search result manipulation. This potentially unwanted program (PUP) typically infiltrates systems bundled with freeware installers or disguised software updates, modifying browser settings without meaningful user consent. While not as destructive as ransomware or banking trojans, Metrium.oldeb.com degrades browsing performance, exposes users to questionable advertisements, and creates privacy concerns through data collection.
Users infected with this hijacker often notice their homepage has changed to metrium.oldeb.com or that searches automatically route through this domain before being redirected to legitimate search engines like Google or Bing. The hijacker makes these changes persistent, preventing users from simply resetting their browser preferences through normal means.
Threat Profile
| Attribute | Details |
|---|---|
| Threat Family | Browser Hijacker / Potentially Unwanted Program (PUP) |
| Common Aliases | Metrium Search, Oldeb Search Redirect, Metrium.oldeb.com Hijacker |
| Affected Platforms | Windows (all versions); primarily targets Chrome, Firefox, Edge, and Internet Explorer |
| Distribution Method | Software bundling, fake update prompts, deceptive download buttons on freeware sites |
| Persistence Mechanisms | Browser extension installation, scheduled tasks, registry modifications, browser policy enforcement |
| Primary Capabilities | Homepage/search engine modification, new tab hijacking, search query redirection, ad injection, browsing data collection |
| Data Collection | Search queries, browsing history, clicked links, IP address, browser fingerprint, potentially form data |
| Typical Artifacts | Browser extensions with randomized names, registry keys under HKCU\Software policies, scheduled tasks for reinstallation |
| Network Behavior | Constant communication with metrium.oldeb.com and affiliated ad-serving domains; redirects through multiple intermediary domains |
| System Impact | Moderate — slower browsing, increased bandwidth usage, browser crashes, exposure to malvertising |
| Removal Difficulty | Moderate — reinstalls itself if browser extensions and scheduled tasks aren't completely removed |
| Risk to Data | Low to moderate — primarily privacy concern rather than data destruction; collected browsing data sold to advertisers |
How It Spreads
Metrium.oldeb.com relies almost exclusively on deceptive distribution methods that trick users into installing it alongside legitimate-looking software. The most common vector is software bundling, where the hijacker is packaged with free utilities, media players, PDF converters, or download managers. During installation, users who click through setup wizards without reading carefully — particularly those who choose "Express" or "Recommended" installation options — unknowingly agree to install the hijacker along with their intended program.
Fake update prompts represent another major distribution channel. Users visiting compromised or ad-heavy websites encounter pop-ups claiming their Flash Player, Java, video codec, or browser is out of date. Clicking "Update Now" downloads an installer that includes the hijacker. These fake updates often appear convincing, mimicking the look of legitimate software update notifications.
Distribution channels include:
- Bundled freeware installers from third-party download sites that repackage legitimate software with additional "offers"
- Fake browser update notifications on websites serving malvertising or compromised through advertising networks
- Deceptive download buttons on file-sharing and software download portals that lead to hijacker installers rather than the intended file
- Torrent files for pirated software or media that include the hijacker as part of the "crack" or "keygen" package
- Email attachments disguised as documents or utilities, though less common for this particular threat family
- Malicious browser extensions promoted through social engineering or listed in browser extension marketplaces with misleading descriptions
What It Does On Your Machine
Once installed, Metrium.oldeb.com immediately modifies browser configurations to establish control over your web browsing experience. The hijacker changes your default homepage to metrium.oldeb.com or a related domain, replaces your default search engine, and takes over new tab behavior. When you open your browser or launch a new tab, you're presented with the hijacker's search interface rather than your chosen homepage or blank page.
The core functionality revolves around search manipulation. When you enter a search query, it routes through metrium.oldeb.com before being redirected — sometimes through several intermediate domains — to a legitimate search engine like Google or Bing. During this process, the hijacker injects sponsored results, modifies search rankings to prioritize affiliate links, and tracks what you're searching for. This generates revenue for the operators through pay-per-click advertising and affiliate commissions when users click manipulated results.
Beyond search redirection, the hijacker typically installs a browser extension or helper object that enforces these settings and prevents easy removal. If you manually change your homepage back to Google or blank it out, the extension reverts the change within seconds or upon browser restart. This persistence mechanism often works in tandem with registry modifications and scheduled tasks that reinstall the hijacker if you manage to remove the browser component.
Privacy invasion represents a significant concern with Metrium.oldeb.com. The hijacker collects detailed browsing data including search queries, visited URLs, time stamps, IP address, browser version, operating system details, and potentially even data entered into forms. This information is typically aggregated and sold to advertising networks or data brokers, though the terms of service (if present at all) rarely make these practices clear to users.
Manual Removal — Step by Step
Disconnect Network and Document Settings
Disconnect from the internet either by unplugging your Ethernet cable or disabling Wi-Fi. Open your affected browsers and write down (on paper or phone) what your homepage, search engine, and new tab settings currently show. Take screenshots of any unfamiliar browser extensions. This documentation helps verify complete removal later.
Boot Into Safe Mode with Networking
Restart your computer and enter Safe Mode with Networking (press F8 or Shift+F8 during boot on older systems, or use Settings > Update & Security > Recovery > Advanced startup on Windows 10/11). Safe Mode prevents the hijacker's background services and scheduled tasks from running, making removal easier and more complete.
Uninstall Suspicious Programs
Open Control Panel > Programs and Features (or Settings > Apps on Windows 10/11). Sort by installation date and look for programs installed around the time the hijacking started. Remove anything you don't recognize, particularly items with names like "Metrium," "Search Assistant," "Web Companion," or generic names like "System Utility v1.2." Legitimate software rarely has vague names or refuses to uninstall cleanly.
Remove Browser Extensions Manually
Open each installed browser and navigate to the extensions page (chrome://extensions/ for Chrome, about:addons for Firefox, edge://extensions/ for Edge). Remove all extensions you didn't intentionally install. Pay special attention to extensions with random names, those requesting excessive permissions, or any added on the same date your hijacking started. Don't just disable them — remove them completely.
Delete Scheduled Tasks
Press Win+R, type "taskschd.msc" and press Enter to open Task Scheduler. Expand Task Scheduler Library in the left pane and look through the list for tasks with names containing "Metrium," "Update," or unfamiliar publisher names. Right-click suspicious tasks and select Delete. Check specifically under Microsoft > Windows for tasks that seem out of place — hijackers often hide reinstallation tasks in legitimate-looking folders.
Clean Registry Browser Policies
Press Win+R, type "regedit" and press Enter. Navigate to HKEY_CURRENT_USER\Software\Policies and delete any subkeys for Chrome, Firefox, or Edge if present (these policies shouldn't exist on a consumer system unless managed by an organization). Also check HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and delete any entries with "Metrium" or unfamiliar executable paths pointing to AppData\Local folders.
Delete Hijacker Files
Open File Explorer and navigate to C:\Users\[YourUsername]\AppData\Local and C:\Users\[YourUsername]\AppData\Roaming. Look for folders with random GUID names (long strings of letters and numbers in curly braces) or folders named "Metrium," "MetriumData," or similar. Delete these entire folders. Also check Program Files and Program Files (x86) for any Metrium-related directories.
Run Malwarebytes or Similar Scanner
Download and install Malwarebytes Free (from malwarebytes.com — use a clean device if your browser is still compromised). Run a full Threat Scan, which takes 20-40 minutes depending on your drive size. Quarantine everything it finds. If you prefer alternatives, Emsisoft Emergency Kit or HitmanPro work well for second opinions. Avoid free "removal tools" from unknown sources claiming to target this specific hijacker.
Reset Browser Settings
In each browser, access settings and perform a full reset (Chrome: Settings > Reset settings > Restore defaults; Firefox: about:support > Refresh Firefox; Edge: Settings > Reset settings > Restore defaults). This clears residual homepage/search settings and removes any lingering hijacker configurations that survived extension removal. You'll need to re-enter saved passwords if you don't use a password manager.
Reboot, Reconnect, and Verify
Restart your computer normally (not Safe Mode). Reconnect to the internet and open your browsers. Verify that your homepage is no longer metrium.oldeb.com, search queries go directly to your chosen engine without redirects, and new tabs behave normally. Monitor Task Manager (Ctrl+Shift+Esc) for a few days to ensure no suspicious processes restart. If problems return within 24-48 hours, a rootkit-level component may remain, requiring professional removal.
Prevention
- Always choose Custom/Advanced installation when installing free software. Read each screen carefully and uncheck any "recommended" toolbars, search engines, or browser modifications. Legitimate software doesn't require you to install unrelated programs.
- Download software only from official sources. Avoid third-party download sites like download.com, softonic.com, or similar aggregators that repackage installers with bundled PUPs. Go directly to the software publisher's website or use the Microsoft Store for Windows applications.
- Keep your browser and operating system updated through official channels only. Real updates never arrive as pop-ups while browsing or as email attachments. Windows updates come through Windows Update; browser updates arrive through the browser's built-in updater.
- Install a reputable ad blocker like uBlock Origin to prevent malvertising and fake download buttons that lead to hijacker installers. Ad blockers also reduce exposure to the advertising networks that fund and distribute these threats.
- Use a standard user account for daily computing rather than an administrator account. This limits malware's ability to make system-wide changes and install persistent components. Only elevate privileges when intentionally installing software you trust.
- Maintain an anti-malware tool with real-time protection enabled. While not perfect, modern anti-malware solutions catch many bundled PUPs during installation. Keep definitions updated and don't disable protection even temporarily for software that "requires" it — that's a red flag.
- Review browser extensions regularly. Visit your extensions page monthly and remove anything you don't actively use or don't remember installing. Extensions can update themselves with new malicious code after initially appearing legitimate.
- Be skeptical of urgent prompts. Legitimate software doesn't use scare tactics claiming your system is "at risk" or that you "must update immediately." These pressure tactics indicate malicious intent.
Bring It In
While determined users can remove Metrium.oldeb.com manually, the process requires comfort with registry editing, file system navigation, and troubleshooting skills that many people understandably don't want to develop. One missed scheduled task or registry policy can cause the hijacker to reinstall itself hours after you think you've removed it. If you've attempted removal and still see redirects, or if the technical steps above feel overwhelming, we're here to help.
Computer Repair Roswell has cleaned hundreds of hijacked browsers from Roswell-area computers. We'll remove Metrium.oldeb.com and any accompanying threats, verify your system is clean using multiple scanning tools, and explain what happened so you can avoid reinfection. Most browser hijacker removals take 1-2 hours, and we can often handle them same-day if you call ahead. Our shop is located in Roswell, Georgia, and we're open Monday through Saturday. Call (770) 856-1550 or stop by — we'll get your browser back to normal and your privacy back under your control.