Nathanaeldan Virus


Nathanaeldan is a browser hijacker that causes unauthorized changes in the browser and spams the screen with ads and page-redirects. If Nathanaeldan is currently in your Chrome, Firefox, or another browser, we recommend deleting it immediately to prevent getting the computer exposed to more malware.

The typical Nathanaeldan virus symptom is sudden page-redirects that cause unfamiliar and suspicious sites to load on your browser

The main red flags that you have a browser hijacker such as Nathanaeldan or Home Search Design within your browser (or browsers) is if the usual homepage and/or the default search engine of the browser have been changed. Another very typical hijacker symptom is sudden page-redirects that cause unfamiliar and suspicious sites to load on your browser. Aggressive and frequent generation of ads and unusual pop-ups even when the browser isn’t open are additional common indications that a hijacker may be in the system.

What dangers does Nathanaeldan pose to your cyber-security?

Understandably, if you are experiencing any of this, you are likely to be aggravated and frustrated. However, know that the problem is usually easily solvable provided that you stay calm and complete the necessary steps for removing Nathanaeldan. On the other hand, even if you don’t see the browser changes, the ads, and the page-redirects as a serious problem, it is nevertheless important that you get rid of their source. The hijacker that’s in your system, while likely not harmful on its own, could bring about other, more serious problems.

The main security concern when there’s a hijacker like Nathanaeldan attached to the browser is that the content it spams on the user’s screen may be unsafe and could be linked to fake webpages designed to scam anyone who visits them. Phishing is a very common type of cyber scam and oftentimes a phishing page could look very convincing so that even more experienced users may fall for it. Additionally, some of the ads and redirects that hijackers show could lead to malware-distributing sites where harmful programs are available disguised as regular downloads that the user may be tempted to download, thus allowing their computer to become infected.

All in all, the correct response to encountering Nathanaeldan or any other browser hijacker on the computer is to avoid any of the content  it puts on the screen and to delete the rogue software as soon as possible. Even though it could sometimes be tricky and require some of your time, ultimately we believe that the removal of Nathanaeldan from your PC shouldn’t be too difficult if you make sure to follow the steps we’ve provided in the guide below and/or if you make use of the recommended professional anti-malware tool posted on this page.

Future safety

Once you are done with the removal of Nathanaeldan, remember to be more careful while browsing the web from now on. One of the most common methods hijackers like this one get distributed is with the help of fake/misleading permission pop-ups that show up when the browser is trying to open certain questionable sites. If you don’t pay attention to the pop-up and click Accept on it, this automatically grants the browser-hijacking site different permissions in your browser. Another way frequently used for spreading hijacker components is through the use of file-bundles, which is why you must always pay close attention to the different settings and sections in the installation managers of new programs that you are about to install on your PC. If any bonus elements present in an installer seem unnecessary, you should most definitely uncheck them and perform the installation without them to avoid getting more potentially unwanted apps on your computer.


Type Browser Hijacker
Detection Tool

Remove Nathanaeldan Virus

To try and remove Nathanaeldan quickly you can try this:

  1. Go to your browser’s settings and select More Tools (or Add-ons, depending on your browser).
  2. Then click on the Extensions tab.
  3. Look for the Nathanaeldan extension (as well as any other unfamiliar ones).
  4. Remove Nathanaeldan by clicking on the Trash Bin icon next to its name.
  5. Confirm and get rid of Nathanaeldan and any other suspicious items.

If this does not work as described please follow our more detailed Nathanaeldan removal guide below.

If you have a Windows virus, continue with the guide below.

If you have a Mac virus, please use our How to remove Ads on Mac guide.

If you have an Android virus, please use our Android Malware Removal guide.

If you have an iPhone virus, please use our iPhone Virus Removal guide


Some of the steps will likely require you to exit the page. Bookmark it for later reference.

Reboot in Safe Mode (use this guide if you don’t know how to do it).



Press CTRL + SHIFT + ESC at the same time and go to the Processes Tab (the “Details” Tab on Win 8 and 10). Try to determine which processes are dangerous. 


Right click on each of them and select Open File Location. Then scan the files with our free online virus scanner:

Each file will be scanned with up to 64 antivirus programs to ensure maximum accuracy
This scanner is free and will always remain free for our website's users.
This file is not matched with any known malware in the database. You can either do a full real-time scan of the file or skip it to upload a new file. Doing a full scan with 64 antivirus programs can take up to 3-4 minutes per file.
Drag and Drop File Here To Scan
Drag and Drop File Here To Scan
Analyzing 0 s
Each file will be scanned with up to 64 antivirus programs to ensure maximum accuracy
    This scanner is based on VirusTotal's API. By submitting data to it, you agree to their Terms of Service and Privacy Policy, and to the sharing of your sample submission with the security community. Please do not submit files with personal information if you do not want them to be shared.

    After you open their folder, end the processes that are infected, then delete their folders. 

    Note: If you are sure something is part of the infection – delete it, even if the scanner doesn’t flag it. No anti-virus program can detect all infections. 


    Hold together the Start Key and R. Type appwiz.cpl –> OK.


    You are now in the Control Panel. Look for suspicious entries. Uninstall it/them.

    Type msconfig in the search field and hit enter. A window will pop-up:


    Startup —> Uncheck entries that have “Unknown” as Manufacturer or otherwise look suspicious.


    Hold the Start Key and R –  copy + paste the following and click OK:

    notepad %windir%/system32/Drivers/etc/hosts

    A new file will open. If you are hacked, there will be a bunch of other IPs connected to you at the bottom. Look at the image below:

    hosts_opt (1)

    If there are suspicious IPs below “Localhost” – write to us in the comments.

    Open the start menu and search for Network Connections (On Windows 10 you just write it after clicking the Windows button), press enter.

    1. Right-click on the Network Adapter you are using —> Properties —> Internet Protocol Version 4 (ICP/IP), click  Properties.
    2. The DNS line should be set to Obtain DNS server automatically. If it is not, set it yourself.
    3. Click on Advanced —> the DNS tab. Remove everything here (if there is something) —> OK.

    • After you complete this step, the threat will be gone from your browsers. Finish the next step as well or it may reappear on a system reboot.

    Right click on the browser’s shortcut —> Properties.

    NOTE: We are showing Google Chrome, but you can do this for Firefox and IE (or Edge).


    Properties —–> Shortcut. In Target, remove everything after .exe.

    Browser Hijacker Removal Instructions

    ie9-10_512x512  Remove Nathanaeldan from Internet Explorer:

    Open IE, click  IE GEAR —–> Manage Add-ons.

    pic 3

    Find the threat —> Disable. Go to IE GEAR —–> Internet Options —> change the URL to whatever you use (if hijacked) —> Apply.

    firefox-512 Remove Nathanaeldan from Firefox:

    Open Firefoxclick  mozilla menu  ——-> Add-ons —-> Extensions.

    pic 6

    chrome-logo-transparent-backgroundRemove Nathanaeldan from Chrome:

    Close Chrome. Navigate to:

     C:/Users/!!!!USER NAME!!!!/AppData/Local/Google/Chrome/User Data. There is a Folder called “Default” inside:

    Rename the Folder to Backup Default

    Rename it to Backup Default. Restart Chrome.


    Type Regedit in the windows search field and press Enter.

    Inside, press CTRL and F together and type the threat’s Name. Right click and delete any entries you find with a similar name. If they don’t show up this way, go manually to these directories and delete/uninstall them:

    • HKEY_CURRENT_USER—-Software—–Random Directory. It could be any one of them – ask us if you can’t discern which ones are malicious.
      HKEY_CURRENT_USER—-Software—Microsoft—-Windows—CurrentVersion—Run– Random
      HKEY_CURRENT_USER—-Software—Microsoft—Internet Explorer—-Main—- Random

    If the guide doesn’t help, download the anti-virus program we recommended or try our free online virus scanner. Also, you can always ask us in the comments for help!

    About the author


    Brandon Skies

    Brandon is a researcher and content creator in the fields of cyber-security and virtual privacy. Years of experience enable him to provide readers with important information and adequate solutions for the latest software and malware problems.

    Leave a Comment