Free tools Windows power users keep installed
One-click scans. No signup required.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Short answer: PUP.Optional.BrowserHijack is a Malwarebytes detection category for potentially unwanted browser changes or components. It may identify a genuine browser hijacker, but the detection name alone cannot prove that a particular alert was correct or a false positive. The safest response is to update Malwarebytes, rescan, inspect the detected object, and avoid adding an exclusion until the file or setting has been verified.
What the Malwarebytes detection means
The name has three parts:
- PUP means Potentially Unwanted Program. A PUP is not automatically a destructive virus. It may be intrusive, bundled with other software, difficult to remove, or installed without meaningful consent.
- Optional describes Malwarebytes’ classification of software or behavior that a user may not have knowingly wanted. It does not, by itself, establish malicious intent.
- BrowserHijack indicates a browser-related modification or component. Depending on the detected object, that could involve a homepage, search provider, extension, shortcut, registry entry, redirect, or related setting.
One detection label can cover different types of objects. The full path and scan report matter more than the label alone.
Was this specific alert a false positive?
The title of a Malwarebytes forum thread is not enough to establish the answer. A reliable verdict requires the original scan log, detected path, Malwarebytes version, malware-database version, and any response from Malwarebytes staff. Without those details, three explanations remain possible:
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minute- Confirmed false positive: Malwarebytes incorrectly detected a legitimate browser component or modification, and a database update corrected the detection.
- Correct PUP detection: The item was not necessarily a conventional virus, but it changed browser behavior in an unwanted or intrusive way.
- Unresolved case: The available title does not reveal what was detected or how Malwarebytes ultimately classified it.
Malwarebytes forum staff have handled comparable false-positive reports by reviewing logs or samples, correcting the detection when appropriate, and telling users to update the Malwarebytes database and scan again. See the Malwarebytes false-positive forum and comparable staff responses in the Malwarebytes community. That process should not be mistaken for proof about this particular historical thread.
#1 Best Overall
Signs that the detection may be genuine
A real browser hijacker or unwanted browser component may cause:
- the homepage or new-tab page to change without permission;
- the default search engine to be replaced;
- repeated redirects or altered search results;
- unwanted extensions, toolbars, or notification permissions;
- excessive pop-ups or injected advertising;
- browser settings that revert after you change them;
- unknown software, startup tasks, or scheduled tasks appearing alongside the browser.
An unexpectedly changed homepage can be a sign of malware or an unwanted browser modification, according to Malwarebytes’ browser and virus-scanning guidance. Conversely, the absence of symptoms does not prove that a detection is wrong. Some PUPs are unwanted because of how they were bundled or installed, even when their visible behavior is limited.
What to do first
- Do not immediately restore or exclude the item. A PUP label does not mean harmless, and an exclusion can hide a legitimate future detection.
- Open Malwarebytes and check for updates. Use the application’s current update or security-database control; exact labels and menu locations can vary by release.
- Restart Malwarebytes if prompted.
- Run another Threat Scan or equivalent current scan.
- Save the report if the detection remains. Record the detection name, path, database version, scan date, and whether quarantine succeeded.
- Compare the new result with the original. If the alert disappears after an update, that supports—but does not conclusively prove—a false-positive explanation.
If the detection remains and the object is unfamiliar, quarantine is generally safer than restoring it. Be more cautious before removal when the item belongs to a known vendor, is inside a signed browser installation, is required by a business application, or was downloaded directly from an official vendor. Those circumstances justify verification, not an automatic exclusion.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →How to inspect the browser
After scanning, check the browser and Windows for changes:
- installed extensions and toolbars;
- homepage, startup page, new-tab page, and default search engine;
- notification permissions;
- the browser shortcut’s target and any added command-line URL;
- recently installed applications and bundled software;
- browser policies or a “managed by your organization” notice;
- startup entries and scheduled tasks that may recreate the change.
Do not delete registry entries or run generic command-line cleanup instructions without the exact detected path and operating-system context. Incorrect manual removal can damage Windows or a legitimate application.
If the browser is still hijacked
For continuing redirects, unwanted extensions, or recurring PUP detections:
- Update Malwarebytes and scan again after a reboot.
- Review and remove extensions and recently installed programs you do not recognize.
- Check browser policies, shortcuts, startup items, and scheduled tasks.
- Run Malwarebytes AdwCleaner, downloading it only from Malwarebytes’ official site. Malwarebytes positions AdwCleaner as a free tool for removing adware, PUPs, and browser hijackers.
- Reset the browser or create a clean browser profile if settings remain altered after the responsible software has been removed.
- Scan again and escalate with logs if the detection returns.
A recurring alert can mean that a scheduled task or bundled application is reinstalling the component, a browser policy remains active, synchronization is restoring an extension, or the initial file was removed while the browser profile stayed altered.
Recommended Free Tools
If Malwarebytes already quarantined the item
Restart the browser or computer if Malwarebytes requests it, then check whether the unwanted behavior has stopped. Do not restore the item merely because a browser setting changed; a hijacker may restore itself when launched.
Best Value
If a legitimate application stops working, identify the exact quarantined path and obtain a replacement from the original vendor rather than an unofficial mirror. If Malwarebytes later confirms a false positive, update the database first and restore only the specific item required—not the entire quarantine.
Evidence needed for a false-positive report
A useful report should include:
- Malwarebytes version and malware-database version;
- scan type and date;
- the complete detection name;
- the exact file, registry key, extension, shortcut, or URL detected;
- whether quarantine succeeded and whether the item returned;
- browser symptoms and when they began;
- the scan log or exported report;
- the file’s cryptographic hash, when a file was detected;
- the trusted vendor download source and, where available, digital-signature details.
Submit the information through the Malwarebytes false-positive forum or the current routes in the Malwarebytes Help Center. A database correction is different from a local exclusion: a correction removes or changes an incorrect detection for users generally, while an exclusion affects only one installation and may conceal a later legitimate warning.
Browser Guard is not the same as desktop scanning
Malwarebytes Browser Guard is a free browser extension for blocking malicious sites, phishing, scams, ads, trackers, and some search-hijacking-related threats on supported browsers. It can help prevent future browser-based abuse, but it is not proof that a desktop detection was false and it is not a replacement for a full device scan or AdwCleaner cleanup.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Quick Recap
Common mistakes to avoid
- Assuming “PUP” means harmless.
- Assuming every PUP is a virus.
- Restoring quarantine before checking for a database correction.
- Creating a broad folder exclusion instead of investigating one object.
- Downloading cleanup tools from advertisements, cracks, repacked installers, or unofficial mirrors.
- Resetting the browser without removing the software that may reapply the hijack.
- Assuming old forum menu paths match every current Malwarebytes release.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

