FifensLive is a browser hijacker and potentially unwanted program (PUP) that infiltrates Windows systems to commandeer web browser settings and redirect user traffic through compromised search engines. Once installed, this intrusive application modifies homepage settings, default search providers, and new tab behavior across Chrome, Firefox, Edge, and other browsers to force visitors through advertising-laden intermediate pages. Beyond the obvious annoyance of constant redirects, FifensLive collects browsing data including search queries, visited URLs, and click patterns—information often monetized through affiliate networks or sold to third-party advertisers. The software employs persistence mechanisms that make standard uninstallation ineffective, regenerating itself even after users believe they've removed it.

FifensLive — cybersecurity illustration
Photo by Ann H on Pexels

Like many browser hijackers in its class, FifensLive typically bundles with freeware downloads or disguises itself as a legitimate browser extension offering enhanced search capabilities or security features. Users rarely install it intentionally. Instead, it arrives through deceptive installer packages where the PUP is pre-selected in "recommended" installation options that most people click through without reading. The result is a degraded browsing experience, privacy exposure, and in some cases, secondary malware infections delivered through the hijacker's redirect infrastructure.

Think you're infected right now? Disconnect from the internet immediately (unplug Ethernet or disable Wi-Fi) to prevent further data transmission. Don't enter passwords or financial information on this machine until you've verified it's clean. The removal steps below will walk you through the complete process, but if you'd rather have professionals handle it, call us at (770) 695-6860—we can often address browser hijackers same-day at our Roswell location.

Threat Profile

Attribute Details
Threat Classification Browser Hijacker / PUP (Potentially Unwanted Program)
Family Generic browser hijacker cluster with adware characteristics
Known Aliases FifensLive, Fifens Live Search, Fifens Live Toolbar
Platforms Affected Windows 7/8/8.1/10/11 (all editions); targets all Chromium-based and Mozilla browsers
Distribution Method Software bundling, fake browser updates, misleading advertisements, installer injection
Persistence Mechanisms Browser extension installation, registry modifications, scheduled tasks, browser policy manipulation
Primary Capabilities Homepage/search redirection, new tab hijacking, browsing data collection, advertisement injection, affiliate revenue generation
Data at Risk Search queries, browsing history, clicked links, approximate location (via IP), device identifiers
Network Behavior Establishes HTTPS connections to ad networks and tracking domains; typical redirect chains involve 2-4 intermediate domains before landing page
Common Artifacts Browser extensions with generic names, modified Preferences/Secure Preferences files, persistent registry policies
Removal Difficulty Moderate—standard uninstall often insufficient; requires manual cleanup of browser configuration and registry entries
Severity Rating Medium (privacy invasion and system degradation rather than direct data destruction)

How It Spreads

FifensLive primarily spreads through software bundling, the practice of packaging unwanted programs with legitimate free software. When users download popular freeware—video converters, PDF tools, download managers, screen recorders—from third-party hosting sites, they often receive installer packages that have been repackaged to include additional "offers." FifensLive appears as a pre-checked option during installation, buried in "Custom" or "Advanced" settings screens that most users skip. The language is deliberately confusing: phrases like "Enhance your browsing experience with Fifens Live Search" or "Set Fifens as your trusted homepage" sound benign enough that even careful users sometimes miss the implications.

The hijacker also spreads through fake update notifications. Users encounter browser pop-ups or system tray messages claiming their "browser security plugin is out of date" or "video codec needs updating." Clicking the update button downloads FifensLive instead of the promised legitimate software. These fake updates often appear on streaming sites, torrent pages, or adult content platforms where users are already conditioned to expect plugin requests. The visual design mimics legitimate browser or Windows notifications closely enough to fool many victims.

Additional distribution vectors include:

  • Malvertising campaigns where legitimate websites unknowingly serve infected advertisements that trigger drive-by downloads when clicked
  • Email attachments disguised as invoices, shipping notifications, or document viewers that execute installer payloads
  • Compromised browser extensions where previously legitimate add-ons are sold to malicious actors who update them to include hijacker code
  • Peer-to-peer networks where cracked software installers are modified to include the PUP
  • Tech support scam sites that offer "free system scans" which then recommend installing FifensLive as a "security tool"
  • Social media links promising free content, games, or utilities that redirect to bundled installers

What It Does On Your Machine

Once executed, FifensLive immediately targets your web browsers. It installs itself as an extension (often with enterprise policy enforcement to prevent easy removal) and modifies browser configuration files to hijack three critical settings: the homepage URL, the default search engine, and the new tab page. Every time you open your browser or create a new tab, you're redirected through FifensLive's search portal rather than your chosen homepage. When you perform searches, queries route through the hijacker's servers before (sometimes) forwarding to a legitimate search engine like Bing or Yahoo—but not before logging your search terms and inserting sponsored results at the top of the page.

The browsing experience degrades noticeably. Page loads slow down because each request bounces through redirect chains. You'll see unfamiliar advertisements injected into legitimate websites—banner ads that weren't there before, pop-unders that open when you click anywhere on a page, and text links where previously there was plain text. Some users report that clicking a search result opens not just the intended page but also 2-3 additional tabs containing advertisements or affiliate offers. The constant redirects and ad injections consume bandwidth, drain battery life on laptops, and make simple web browsing frustrating.

Behind the scenes, FifensLive establishes persistence by creating scheduled tasks that monitor browser processes and reapply hijacked settings if you manually correct them. It writes entries to the Windows registry that restore the extension after you've removed it. In some variants, the program installs a Windows service that runs at startup, ensuring the hijacker reactivates even after a clean boot. The software also collects telemetry: every search query, every clicked link, time spent on pages, and approximate location derived from your IP address. This data feeds back to servers controlled by the operators, where it's aggregated, analyzed for advertising value, and potentially sold to data brokers.

FifensLive doesn't encrypt your files like ransomware or steal passwords like a banking trojan, but it does create security vulnerabilities. The redirect infrastructure can be leveraged to deliver more dangerous payloads—we've seen cases where initial browser hijacker infections led to exposure to tech support scams, fake antivirus warnings, and even trojan downloads. The modified browser settings also bypass certain security protections: if the hijacker forces browsers to accept self-signed certificates or disable warnings about insecure sites, you become more vulnerable to man-in-the-middle attacks and phishing.

Typical FifensLive Artifacts (Windows 10/11 Example)
Browser Extension Folder: %LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\[random-32-char-id]\ # Extension manifest.json will reference "fifens" or similar identifiers Browser Preferences Modified: %LOCALAPPDATA%\Google\Chrome\User Data\Default\Preferences %LOCALAPPDATA%\Google\Chrome\User Data\Default\Secure Preferences # Contains hijacked homepage/search URLs in JSON format Registry Policies (blocks user changes): HKLM\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist HKCU\Software\Policies\Microsoft\Edge\ExtensionInstallForcelist # Forces extension reinstall even after removal Scheduled Task: \Microsoft\Windows\FifensUpdate # Runs every 30-60 minutes to reapply settings Startup Registry Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\FifensLive Value: %APPDATA%\FifensLive\updater.exe Persistence Service (if present): sc query FifensService # May appear as generic name like "Browser Update Service"

Manual Removal — Step by Step

01

Disconnect and Document

Before making any changes, disconnect your computer from the internet by unplugging the Ethernet cable or disabling Wi-Fi. Take screenshots of your current browser homepage and search settings so you can verify successful removal later. Note any unfamiliar browser extensions by name—these details help ensure you don't miss anything during cleanup.

02

Boot to Safe Mode with Networking

Restart your computer into Safe Mode to prevent FifensLive's persistence mechanisms from running. On Windows 10/11, hold Shift while clicking Restart, then navigate to Troubleshoot → Advanced Options → Startup Settings → Restart, and select option 5 (Safe Mode with Networking). This loads Windows with minimal drivers and prevents most malware from executing its protection routines.

03

Uninstall via Control Panel / Settings

Open Settings → Apps → Apps & features (or Control Panel → Programs and Features on older Windows). Look for entries named "FifensLive," "Fifens," or anything installed on the same date your browser issues started. Also check for unfamiliar programs with generic names like "Browser Assistant," "Search Manager," or publishers you don't recognize. Uninstall all suspicious entries, paying attention to any that try to convince you to keep them with misleading messages.

04

Remove Browser Extensions and Reset Settings

Open each installed browser and navigate to the extensions/add-ons manager (chrome://extensions in Chrome, about:addons in Firefox, edge://extensions in Edge). Remove any unfamiliar extensions, particularly those you didn't intentionally install. Then reset browser settings: in Chrome/Edge go to Settings → Reset settings → Restore settings to their original defaults; in Firefox use Help → More troubleshooting information → Refresh Firefox. This clears hijacked homepage and search settings while preserving bookmarks and passwords.

05

Clean Browser Policy Registry Keys

Press Win+R, type regedit, and press Enter to open Registry Editor. Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome and HKEY_CURRENT_USER\Software\Policies and look for Chrome, Edge, or Mozilla keys. Delete any policy entries related to ExtensionInstallForcelist, DefaultSearchProviderEnabled, or HomepageLocation. Also check HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and delete any FifensLive or suspicious entries. Export a backup of each key before deletion in case you need to restore it.

06

Remove Scheduled Tasks

Open Task Scheduler by typing taskschd.msc in the Run dialog. Expand Task Scheduler Library and look through the folders for tasks with names like "FifensUpdate," "Browser Update," or tasks created by unknown publishers on the infection date. Right-click suspicious tasks and select Delete. Pay particular attention to tasks scheduled to run at logon or every few minutes—these are common persistence mechanisms for browser hijackers.

07

Delete Program Folders and Leftover Files

Navigate to %APPDATA%, %LOCALAPPDATA%, and %PROGRAMFILES% and look for folders named FifensLive or containing the infection date in their properties. Delete these folders entirely. Also check your browser profile directories (like %LOCALAPPDATA%\Google\Chrome\User Data\Default) for unfamiliar extension folders—the folder names will be long random strings, but you can identify hijacker extensions by opening the manifest.json file inside and reading the name/description fields.

08

Scan with Reputable Anti-Malware Tools

Download and run Malwarebytes Free (from malwarebytes.com on a clean device if possible, transferring via USB) to catch anything you missed. Perform a full Threat Scan, which typically takes 30-60 minutes. Quarantine all detected items. Follow up with a scan using Windows Defender (Settings → Update & Security → Windows Security → Virus & threat protection → Scan options → Full scan) for a second opinion. Some persistent hijackers leave registry artifacts that dedicated anti-malware tools catch more reliably than manual removal.

09

Change Important Passwords

Since FifensLive collects browsing data and may have logged credentials entered on spoofed pages, change passwords for critical accounts—email, banking, social media—from a known-clean device. Enable two-factor authentication on all accounts that support it. This precaution addresses the possibility that your credentials were exposed through phishing pages delivered via the hijacker's redirect infrastructure.

10

Reboot Normally and Verify Removal

Restart your computer in normal mode and reconnect to the internet. Open your browsers and verify that your chosen homepage loads, searches go to your preferred engine, and new tabs open without redirects. Check Task Manager (Ctrl+Shift+Esc) for unfamiliar processes and verify that no suspicious scheduled tasks have regenerated. Test browsing several websites to ensure you're not seeing injected advertisements. If any hijacker behavior returns, repeat the registry and scheduled task checks—some variants use multiple persistence mechanisms that all must be addressed.

Prevention

  1. Download software only from official sources. Avoid third-party download sites like Download.com, Softonic, or similar aggregators. Go directly to the developer's website or use the Microsoft Store. If you must use a download portal, scrutinize the actual download button—many such sites have fake "Download" buttons that are actually ads leading to bundled installers.
  2. Always choose Custom/Advanced installation. Never click "Express Install" or "Recommended Settings" when installing free software. The Custom option reveals bundled PUPs as pre-checked offers that you can deselect. Read each screen carefully—look for language about "additional software," "search providers," or "browser enhancements" and decline all such offers.
  3. Keep browsers and operating systems updated. Enable automatic updates for Windows and all browsers. Many hijackers exploit outdated browser vulnerabilities to install themselves without user interaction. Current software patches these vulnerabilities and often includes improved protection against malicious extensions.
  4. Use a reputable ad-blocker. Browser extensions like uBlock Origin (for Chrome/Firefox/Edge) prevent most malvertising attacks by blocking the ad networks that deliver compromised advertisements. This single measure stops a significant percentage of hijacker distribution vectors before they reach your screen.
  5. Be skeptical of browser update prompts. Legitimate browsers update themselves silently or through built-in update mechanisms. If a website tells you that your "video player needs an update" or your "browser is out of date," ignore it. Check for updates manually through the browser's built-in help menu instead of clicking suspicious prompts.
  6. Review browser extensions regularly. Once a month, audit your installed extensions. Remove anything you don't actively use or don't remember installing. Be especially suspicious of extensions with vague names like "Shopping Helper," "Search Protect," or "Browser Security" that you can't recall adding deliberately.
  7. Maintain current antivirus protection. Windows Defender (built into Windows 10/11) provides solid baseline protection if you keep it updated. Consider supplementing it with Malwarebytes Premium, which specifically targets PUPs and browser hijackers that traditional antivirus sometimes misses. Run full system scans weekly.
  8. Create a standard user account for daily use. Set up a non-administrator account for regular computing and only elevate privileges when installing known-legitimate software. Browser hijackers often can't install system-level persistence mechanisms without administrator rights, limiting their ability to survive removal attempts.
Our 90-Day Warranty: When Computer Repair Roswell removes malware from your system, we guarantee our work for 90 days. If the same infection returns within that window, we'll clean it again at no additional charge. We also provide post-cleaning guidance on security settings and safe browsing practices so you stay protected long after you leave our shop.

Bring It In

Browser hijackers like FifensLive frustrate even technically confident users because of their persistence mechanisms and the way they bury themselves across multiple system locations. If you've followed the removal steps above and still see redirects, injected ads, or suspicious browser behavior, you're dealing with a particularly stubborn variant that may require specialized tools or techniques. That's where we come in. At Computer Repair Roswell, we've cleaned hundreds of hijacked systems and know exactly where these programs hide their hooks—registry policies that regenerate settings, scheduled tasks with misleading names, and browser configuration files that resist manual editing.

Bring your computer to our shop at 870 Holcomb Bridge Road in Roswell, or give us a call at (770) 695-6860 to discuss your symptoms. We offer same-day service for most malware removals, and our flat-rate pricing means you'll know the cost upfront—no hourly surprises. We'll clean the infection thoroughly, verify that all persistence mechanisms are gone, update your security software, and walk you through the specific prevention steps that apply to your computing habits. Your browser should work for you, not against you—let's get it back to normal.