FourHub.Pop.Live is a browser hijacker and potentially unwanted program (PUP) that forcibly redirects users to dubious websites, manipulates search results, and generates intrusive advertising revenue for its operators. This threat typically infiltrates systems bundled with free software downloads, then modifies browser settings without permission to ensure persistent redirects to fourhub[.]pop[.]live and related advertising domains. While not technically a virus in the traditional sense, FourHub.Pop.Live exhibits malicious behavior by hijacking your browsing experience, exposing you to potentially harmful sites, and proving remarkably difficult to remove through standard uninstallation methods.

FourHub.Pop.Live — cybersecurity illustration
Photo by Lucas Andrade on Pexels

Users infected with FourHub.Pop.Live report constant redirects when attempting to search or browse, homepage and default search engine changes that revert even after manual correction, and a flood of pop-up advertisements that appear even on legitimate websites. The hijacker operates across all major browsers including Chrome, Firefox, Edge, and Safari, making it a cross-platform nuisance that affects both Windows and Mac users.

Think you're infected right now? Disconnect from the internet immediately if you're experiencing constant redirects or seeing unfamiliar browser extensions you didn't install. Do not enter passwords or financial information until the infection is removed. Call us at (770) 667-9487 or bring your computer to our Roswell shop — we can typically remove browser hijackers same-day and verify your system is clean.

Threat Profile

Attribute Details
Threat Classification Browser Hijacker / PUP (Potentially Unwanted Program)
Family Redirect malware, ad-injection family
Aliases FourHubPopLive, fourhub.pop.live redirect, FourHub hijacker
Affected Platforms Windows 7/8/10/11, macOS 10.12+, Linux (rare)
Targeted Browsers Google Chrome, Mozilla Firefox, Microsoft Edge, Safari, Opera
Distribution Method Software bundling, fake updates, deceptive advertising
Persistence Mechanism Browser extension/add-on, scheduled tasks, registry modifications (Windows), Launch Agents (Mac)
Primary Capabilities Search redirection, homepage hijacking, ad injection, tracking cookie installation, browser settings manipulation
Data Collection Browsing history, search queries, clicked links, IP address, approximate location
Network Behavior Connects to advertising networks, redirect chains through multiple domains, DNS query manipulation
Secondary Payloads May download additional PUPs or redirect to tech support scams
Removal Difficulty Moderate to High — uses multiple persistence methods and often reinstalls itself

How It Spreads

FourHub.Pop.Live primarily spreads through software bundling, a deceptive distribution tactic where the hijacker is packaged with legitimate-looking free software. When users download file converters, PDF tools, video players, or system optimization utilities from third-party download sites, the installer often includes FourHub.Pop.Live hidden in the "Custom" or "Advanced" installation options. Most users click through the installation wizard using default settings, unwittingly agreeing to install the hijacker alongside the desired program.

The threat also propagates through fake software update notifications that appear while browsing. These convincing pop-ups claim your Flash Player, Java, browser, or media codec is out of date and urgently needs updating. Clicking the update button downloads an installer that contains FourHub.Pop.Live rather than the legitimate update. These fake update pages are designed to mimic official software vendor sites, making them difficult for average users to distinguish from genuine update prompts.

Additional distribution vectors include:

  • Malicious advertising (malvertising) — Clicking infected ads on legitimate websites that trigger drive-by downloads or redirect to pages hosting the hijacker installer
  • Freeware download portals — Sites like Softonic, Download.com, and similar platforms that repackage software with bundled PUPs
  • Torrent and piracy sites — Cracked software and key generators frequently contain browser hijackers as additional payloads
  • Spam email attachments — Less common but occasionally seen in phishing campaigns disguised as document files or software installers
  • Compromised browser extensions — Legitimate extensions that get sold to malicious actors who then push hijacker updates to existing users
  • Social engineering tactics — Fake security warnings claiming your system is infected and offering a "solution" that installs the hijacker

What It Does On Your Machine

Once installed, FourHub.Pop.Live immediately targets your web browsers to establish control over your browsing experience. The hijacker modifies critical browser settings including your homepage, default search engine, and new tab page, redirecting all of these to fourhub[.]pop[.]live or intermediate redirect domains. When you attempt to perform a web search, your query gets intercepted and routed through the hijacker's servers before being forwarded to a search engine—during this process, the results are manipulated to include sponsored links and advertisements that generate revenue for the hijacker's operators.

The hijacker typically installs a browser extension or add-on that maintains its control even if you manually change your browser settings back. This extension operates with elevated permissions that allow it to read and modify all data on websites you visit, track your browsing history, and inject additional advertising content into legitimate web pages. Users commonly report seeing extra banner ads, pop-ups, in-text advertisements, and comparison shopping boxes on sites that normally don't display such content.

FourHub.Pop.Live also implements multiple persistence mechanisms to survive removal attempts. On Windows systems, it creates scheduled tasks that periodically check whether the hijacker is still active and reinstall components if they've been removed. The threat establishes registry entries that cause browsers to reload the malicious settings on startup. On Mac systems, it installs Launch Agents or Launch Daemons that perform similar watchdog functions. This multi-layered persistence is why many users find that simply removing the browser extension or resetting browser settings doesn't permanently eliminate the problem.

Beyond the immediate browsing disruption, FourHub.Pop.Live poses privacy concerns by collecting detailed browsing data. This includes your search queries, visited URLs, clicked links, and time spent on various sites—information that creates a comprehensive profile of your interests and online behavior. While the hijacker doesn't typically steal passwords or financial data directly, the redirect chains it creates can lead to phishing sites, fake tech support scams, or pages hosting more dangerous malware. The constant redirects also degrade system performance, as your browser continuously loads unwanted pages and processes injected advertisements.

Typical FourHub.Pop.Live Artifacts (Windows)
Browser Extension Locations:
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\[random-id]\
%APPDATA%\Mozilla\Firefox\Profiles\[profile]\extensions\[random-id].xpi
Registry Modifications:
HKCU\Software\Microsoft\Internet Explorer\Main\"Start Page" = fourhub.pop.live
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\[RandomName]
HKLM\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist
Scheduled Tasks:
\Task Scheduler Library\[RandomTaskName] → runs hourly to maintain hijacker
Files and Folders:
%LOCALAPPDATA%\[RandomFolderName]\updater.exe
%PROGRAMFILES(X86)%\[SuspiciousName]\service.exe
# Note: Specific names and GUIDs vary by variant

Manual Removal — Step by Step

01

Disconnect from the Internet

Unplug your ethernet cable or disable Wi-Fi before beginning removal. This prevents the hijacker from downloading additional components or communicating with command servers during the cleanup process. It also stops the constant redirects, making your system more responsive while you work on removing the infection.

02

Boot into Safe Mode with Networking

Restart your computer in Safe Mode to prevent the hijacker's background processes from running. On Windows 10/11, hold Shift while clicking Restart, then navigate to Troubleshoot > Advanced Options > Startup Settings > Restart, and select Safe Mode with Networking (option 5). On Mac, restart and hold Shift immediately after hearing the startup chime until the login screen appears.

03

Uninstall Suspicious Programs

Open Control Panel > Programs and Features (Windows) or Applications folder (Mac) and carefully review your installed programs. Look for anything installed around the time the redirects started, especially programs you don't recognize or that have suspicious names with random characters. Uninstall any questionable software, particularly items labeled as browser enhancers, search optimizers, or toolbars. Don't skip this step even if you don't see anything obvious—some variants disguise themselves with innocuous names.

04

Remove Malicious Browser Extensions

Open each installed browser and remove all unfamiliar extensions. In Chrome, go to chrome://extensions; in Firefox, go to about:addons; in Edge, go to edge://extensions. Remove anything you didn't intentionally install, paying special attention to extensions with vague names, those granted excessive permissions, or any installed recently without your knowledge. After removing extensions, also check your browser's search engine settings (Settings > Search Engine) and restore your preferred default, then verify your homepage and startup page settings.

05

Delete Scheduled Tasks and Startup Items

On Windows, open Task Scheduler (search for it in the Start menu) and carefully review the Task Scheduler Library for suspicious tasks, particularly those running frequently or triggering executable files from temporary folders or %LOCALAPPDATA%. Delete any tasks you don't recognize. Then run msconfig, go to the Startup tab, and disable suspicious startup items. On Mac, open System Preferences > Users & Groups > Login Items and remove unfamiliar entries, then check /Library/LaunchAgents/ and ~/Library/LaunchAgents/ for suspicious .plist files.

06

Clean Registry Entries (Windows Only)

Press Windows+R, type regedit, and navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. Look for entries pointing to suspicious executables and delete them. Also check HKEY_CURRENT_USER\Software for folders with random names or names matching suspicious programs you uninstalled. Be extremely careful when editing the registry—only delete entries you're confident are related to the hijacker. If you're uncomfortable with registry editing, skip this step and proceed to the scanner step.

07

Delete Hijacker Files and Folders

Navigate to %LOCALAPPDATA%, %APPDATA%, and %PROGRAMFILES% (Windows) or /Library and ~/Library (Mac) and look for folders with suspicious or random names, especially those created around the time of infection. Delete any folders associated with programs you removed in step 3. Also check your Downloads folder and delete any recently downloaded installers you don't recognize. Empty the Recycle Bin or Trash when finished.

08

Run Malwarebytes or Similar Scanner

Reconnect to the internet briefly to download Malwarebytes (free version is sufficient) if you don't have it already, then disconnect again. Run a full system scan—this can take 30-60 minutes but is essential for catching components you may have missed. Malwarebytes is particularly effective against browser hijackers and PUPs. Quarantine or remove all detected threats. Consider also running a second scan with AdwCleaner (also from Malwarebytes) which specifically targets adware and browser hijackers.

09

Reset Browser Settings Completely

After removing the hijacker components, reset each affected browser to default settings. In Chrome, go to Settings > Advanced > Reset and clean up > Restore settings to their original defaults. In Firefox, type about:support in the address bar and click "Refresh Firefox." In Edge, Settings > Reset settings > Restore settings to their default values. This clears any lingering configuration changes the hijacker made. After resetting, reconfigure your preferred homepage and search engine manually.

10

Restart and Verify Removal

Restart your computer normally (not in Safe Mode) and reconnect to the internet. Open your browser and test whether redirects still occur. Perform several searches, open new tabs, and visit various websites to confirm the hijacker is gone. Check your homepage, default search engine, and installed extensions one more time. If redirects persist or settings revert after a few minutes, the hijacker has a component you missed—in this case, professional removal is recommended to avoid wasting more time.

Prevention

  1. Download software only from official sources. Always obtain programs directly from the developer's website rather than third-party download sites. Avoid software aggregators like Softonic, Download.com, or CNET Downloads that frequently bundle PUPs with legitimate software.
  2. Choose Custom/Advanced installation every time. Never click through installers using Express or Recommended settings. Always select Custom or Advanced installation and carefully read each screen, unchecking any offers to install additional software, browser extensions, or change your homepage or search engine.
  3. Keep your system and software genuinely updated. Enable automatic updates for Windows, macOS, and all your applications so you receive patches directly rather than being vulnerable to fake update prompts. Legitimate software updates never come from pop-ups while browsing.
  4. Install a reputable ad blocker. Browser extensions like uBlock Origin (not just any ad blocker) prevent many malicious ads and redirects from appearing in the first place, significantly reducing your exposure to malvertising and drive-by downloads.
  5. Maintain active anti-malware protection. Run Windows Defender (which is quite good now) or install Malwarebytes Premium for real-time protection against PUPs and browser hijackers. Schedule regular scans even if you have real-time protection enabled.
  6. Be skeptical of urgent warnings. Any pop-up claiming your system is infected, your software is dangerously outdated, or you've won a prize is almost certainly fraudulent. Close these windows without clicking anything inside them (use Alt+F4 or force-quit the browser if necessary).
  7. Review browser extensions regularly. Once a month, check what extensions you have installed and remove any you don't actively use or don't remember installing. Extensions can be hijacked or sold to malicious actors who then push harmful updates to users.
  8. Avoid piracy sites and torrents. Cracked software, key generators, and pirated media are prime vectors for all types of malware. The "free" software you download this way almost always comes with unwanted extras that cost you far more time and money to remove.
Our Guarantee: When Computer Repair Roswell removes FourHub.Pop.Live or any browser hijacker from your system, the removal comes with a 90-day warranty. If the same threat returns within 90 days, we'll remove it again at no charge. We don't just delete files—we verify complete removal, patch the vulnerabilities that allowed infection, and ensure your system is genuinely clean before returning it to you.

Bring It In

Browser hijackers like FourHub.Pop.Live can be stubborn adversaries, often requiring multiple removal attempts and specialized tools to fully eliminate. If you've followed the manual steps above and still experience redirects, or if you're simply not comfortable performing technical troubleshooting on your own system, we're here to help. At Computer Repair Roswell, we remove browser hijackers and PUPs multiple times daily—it's one of our most common service calls. We have the specialized tools and experience to identify every component of the infection, including the persistent ones that standard scanners miss.

Bring your computer to our shop at 1685 Wallace Road in Roswell, or give us a call at (770) 667-9487 to discuss your issue. Most browser hijacker removals are completed same-day, and we'll take the time to show you how the infection happened and how to avoid similar threats in the future. We service both Windows PCs and Macs, and unlike remote tech support operations, you can meet us face-to-face and watch us work on your system if you prefer. Don't waste your entire weekend fighting a hijacker—let us handle it efficiently so you can get back to productive browsing.