GidensLive is a browser hijacker and potentially unwanted program (PUP) that modifies your web browser settings without permission, redirecting searches through unfamiliar search engines and bombarding you with intrusive advertising. Once installed, it commandeers your homepage, default search provider, and new tab page — typically forcing searches through low-quality intermediary sites that generate revenue for its operators through pay-per-click schemes. While not destructive malware in the traditional sense, GidensLive degrades your browsing experience, slows system performance, and exposes you to dubious advertising networks that may lead to more serious infections.

GidensLive — cybersecurity illustration
Photo by Ann H on Pexels

This hijacker commonly arrives bundled with free software installers, masquerading as a helpful browser extension or system utility. Users rarely install it intentionally; instead, it slips onto machines when people rush through setup wizards without reading the fine print or unchecking pre-selected offers. Once active, GidensLive proves stubborn to remove through normal means, reinstalling itself or leaving remnants that trigger the same redirects even after you think you've uninstalled it.

Infected right now? If you're experiencing constant redirects, unfamiliar toolbars, or can't change your browser settings back, disconnect from the internet immediately to prevent further data collection. Do not enter passwords or financial information until you've cleaned the infection. Skip ahead to the Manual Removal section below, or call us at (770) 741-0041 for immediate assistance — we can often walk you through emergency containment over the phone.

Threat Profile

AttributeDetails
Threat TypeBrowser Hijacker, Potentially Unwanted Program (PUP)
FamilyAdware / Search Hijacker cluster
AliasesGidensLive Extension, Gidens Live Search, PUP.Optional.GidensLive
Platforms AffectedWindows 7, 8, 8.1, 10, 11; targets Chrome, Firefox, Edge
Distribution MethodsSoftware bundling, fake download buttons, deceptive installers
Primary GoalSearch redirect revenue, advertising impressions, affiliate commissions
Persistence MechanismsBrowser extension, scheduled tasks, Registry run keys, policy overrides
Data CollectionSearch queries, browsing history, clicked links, approximate location (via IP)
Typical Artifacts%LOCALAPPDATA%\GidensLive, browser extension folders, Registry policies
Network BehaviorRedirects through intermediary domains; contacts ad-serving infrastructure
Removal DifficultyModerate — uses multiple persistence layers, reinstalls from hidden components
Destructive PayloadNone directly, but ads may link to exploit kits or scareware

How It Spreads

GidensLive spreads almost exclusively through software bundling, a distribution tactic where free or pirated programs carry additional "offers" that install alongside the main application. Download sites that aggregate freeware — particularly those offering video converters, PDF tools, or system utilities — frequently repackage legitimate software with bundlers that include GidensLive and similar PUPs. When you download what you think is a straightforward installer for a harmless utility, you're actually getting a wrapper program that presents a series of rapid-fire installation screens, many with pre-checked boxes agreeing to install "recommended" components.

The deception works because most users click "Next" repeatedly without reading each screen. The hijacker's installation is often buried in a "Custom" or "Advanced" settings panel that users skip entirely, or it's worded in confusing legalese that obscures what's actually being installed. Some bundlers use dark patterns — placing the decline option in small gray text while the accept button is large and colorful, or using double-negative phrasing like "Do not uncheck this box if you do not want to decline the offer."

Common infection vectors include:

  • Freeware bundlers: Download managers, video converters, codec packs, and PC "optimizers" from third-party download sites
  • Fake download buttons: Misleading ads on file-sharing or streaming sites that look like legitimate download links
  • Pirated software installers: Cracked programs and keygens that bundle malware to monetize illegal downloads
  • Malicious browser extensions: Browser add-ons promising features like weather updates or coupon finders that actually hijack search settings
  • Phishing emails with attachments: Occasionally bundled with fake software updates delivered via email
  • Compromised websites: Drive-by downloads triggered by visiting sites with malicious advertising or exploit kits

What It Does On Your Machine

Once installed, GidensLive immediately modifies your browser configuration to intercept web searches and homepage loads. It typically installs as a browser extension with elevated permissions, giving it control over your search queries, navigation, and the ability to inject content into web pages you visit. Your default search engine gets replaced with an unfamiliar provider — often a generic search portal that mimics legitimate engines — and all queries get routed through this intermediary before eventually displaying results (sometimes genuine Google or Bing results, sometimes lower-quality alternatives). Each redirect generates advertising revenue for the hijacker's operators.

The hijacker doesn't stop at search redirection. It commonly injects additional advertisements into legitimate websites, displaying banners or pop-ups that the site owner never placed there. You might see coupon offers overlaid on shopping sites, video ads interrupting content, or "related links" sections that are actually sponsored placements. These injected ads slow page loading, clutter your screen, and frequently link to questionable destinations — tech support scams, fake security warnings, survey scams, or sites pushing additional PUPs.

GidensLive employs multiple persistence mechanisms to survive casual removal attempts. Installing it as a browser extension is just the visible component; the program also drops files in hidden system folders, creates scheduled tasks that reinstall the extension if you remove it, and may set Group Policy overrides that prevent you from changing certain browser settings. When you try to reset your homepage or default search engine through browser settings, the changes either don't stick or revert within minutes. Some variants modify the browser's preferences files directly and set them to read-only, blocking legitimate configuration changes.

Behind the scenes, the hijacker collects data about your browsing activity. While the operators claim this is "anonymous usage statistics," the reality is that search queries, visited URLs, clicked links, and your IP address (revealing approximate location) all flow back to remote servers. This information builds an advertising profile used for targeted ads, but it may also be sold to third-party data brokers. The privacy policy for these PUPs — if one exists at all — typically grants broad permission to share your information with unnamed "partners."

Typical GidensLive Filesystem Artifacts
C:\Users\<username>\AppData\Local\GidensLive\ ├── updater.exe ├── config.dat └── resources\ C:\Users\<username>\AppData\Roaming\GidensLiveExt\ └── manifest.json ; Browser extension folders (Chrome example): C:\Users\<username>\AppData\Local\Google\Chrome\User Data\Default\Extensions\[random-ID]\ ; Registry persistence keys: HKCU\Software\Microsoft\Windows\CurrentVersion\Run "GidensLive Updater" = "%LOCALAPPDATA%\GidensLive\updater.exe" HKLM\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist (Forces extension reinstallation even after manual removal) ; Scheduled task (runs hourly or at logon): Task: \GidensLive Update Task

Manual Removal — Step by Step

01

Disconnect from the Network

Unplug your Ethernet cable or disable Wi-Fi to prevent the hijacker from receiving commands, downloading additional components, or uploading more of your browsing data. This also stops any background update processes that might interfere with removal.

02

Boot Into Safe Mode with Networking

Restart your computer and press F8 (or Shift+F8 on newer systems) during boot to access Advanced Boot Options. Select "Safe Mode with Networking." This loads Windows with minimal drivers and prevents most startup items — including GidensLive's persistence mechanisms — from running, making removal much cleaner.

03

Uninstall Suspicious Programs

Open Control Panel → Programs and Features (or Settings → Apps on Windows 10/11). Sort by install date and look for programs installed around the time redirects started. Uninstall anything named GidensLive, plus any unfamiliar entries installed the same day — bundlers often drop multiple PUPs simultaneously. Watch for vague names like "Web Companion," "Search Manager," or random company names you don't recognize.

04

Remove Browser Extensions

Open each browser you use and access the extensions/add-ons manager (chrome://extensions/ in Chrome, about:addons in Firefox, edge://extensions/ in Edge). Remove any extension you didn't intentionally install, especially anything related to search, coupons, or toolbars. Check "Hidden" or "Managed" extensions — these require admin removal and indicate policy-based installation.

05

Delete GidensLive Folders Manually

Open File Explorer and navigate to %LOCALAPPDATA% (paste that into the address bar). Look for any folder named GidensLive or containing "gidens" in the name. Delete the entire folder. Also check %APPDATA% and %PROGRAMFILES% for similar folders. If you get "access denied" errors, take ownership of the folder first: right-click → Properties → Security → Advanced → Change owner to your user account.

06

Clean the Registry and Scheduled Tasks

Press Win+R, type "regedit," and navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. Delete any entry referencing GidensLive or the paths you removed in the previous step. Then open Task Scheduler (taskschd.msc), look for any task with GidensLive in the name or that runs executables from the paths you deleted, and delete those tasks.

07

Remove Browser Policy Overrides

Some hijackers install via Group Policy to force extension installation. In Registry Editor, check HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome and HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Mozilla\Firefox. Delete any keys related to ExtensionInstallForcelist or similar forced-installation policies. This prevents the extension from auto-reinstalling.

08

Reset Browser Settings

In each affected browser, reset settings to defaults. Chrome: Settings → Reset settings → Restore settings to their original defaults. Firefox: Help → More Troubleshooting Information → Refresh Firefox. Edge: Settings → Reset settings → Restore settings to their default values. This clears hijacked homepage/search settings and removes lingering configuration changes.

09

Scan with Reputable Anti-Malware Tools

Download and run Malwarebytes (free version works fine) and perform a full system scan. This catches leftover components manual removal might have missed and identifies any additional PUPs that came bundled with GidensLive. Quarantine and remove everything it finds. Consider also running a scan with AdwCleaner, which specializes in browser hijacker removal.

10

Reboot and Verify Complete Removal

Restart your computer normally (not Safe Mode) and reconnect to the network. Open your browsers and verify that homepage and search settings stay where you set them. Perform a few test searches and navigate to familiar websites — if you see no redirects, injected ads, or unwanted search portals, the removal was successful. If problems persist, repeat the registry and folder checks, or bring the machine to our shop for professional cleaning.

Prevention

  1. Download software only from official sources. Get programs directly from the developer's website, not from third-party download portals. Aggregator sites repackage installers with bundled PUPs to monetize free downloads.
  2. Always choose "Custom" or "Advanced" installation. Never click through installers using Express/Recommended options. Read every screen carefully and uncheck any offers for additional software, browser toolbars, or "helpful" utilities.
  3. Keep Windows and browsers fully updated. Enable automatic updates for your operating system and all installed browsers. Security patches close vulnerabilities that drive-by downloads and exploit kits use to install malware without interaction.
  4. Install a reputable ad blocker. Browser extensions like uBlock Origin block malicious advertising networks that distribute PUPs through fake download buttons and deceptive ads on legitimate sites.
  5. Run standard-user accounts for daily use. Don't use an administrator account for routine browsing and email. PUPs have much harder time installing persistence mechanisms when running under a limited user account.
  6. Be skeptical of browser extension requests. Only install extensions from official browser stores, and even then, check the developer, reviews, and requested permissions. Extensions requesting broad access to "read and change all your data on websites" should raise red flags unless from well-known developers.
  7. Perform monthly scans with anti-malware tools. Even with good habits, occasional scans with Malwarebytes or similar tools catch PUPs before they become entrenched. Schedule these during off-hours so they don't interfere with work.
  8. Learn to recognize fake download buttons. On file-sharing or software sites, the real download link is often small and text-based, while large colorful "DOWNLOAD" buttons are typically ads. When in doubt, look for the developer's official link or hover over buttons to see where they actually lead before clicking.
Our 90-Day Warranty: When you bring an infected computer to Computer Repair Roswell for malware removal, we don't just clean the immediate infection — we fortify your system against reinfection and verify every component is functioning properly. Our removal service includes a 90-day warranty: if the same infection returns within three months, we'll re-clean your system at no additional charge. That's our commitment to doing the job right the first time.

Bring It In

Browser hijackers like GidensLive exploit the gap between what manual removal requires and what most users have time or expertise to accomplish. Even following detailed steps, you can miss a scheduled task, overlook a policy override, or inadvertently leave components that reinstall everything you just removed. The hijacker's developers know most people will give up after one or two failed attempts and simply tolerate the redirects. Don't let that be you. Professional removal takes us about 30-45 minutes because we know exactly where these programs hide and have tools that automate finding every artifact.

Computer Repair Roswell is located right here in Roswell, Georgia, and we've cleaned hundreds of hijacker infections from local residents' and small businesses' machines. Bring your computer by our shop or give us a call at (770) 741-0041 — we can often provide phone guidance for simple cases, or schedule a same-day appointment if you'd rather have us handle it completely. We'll remove GidensLive and any companion PUPs, verify your system is clean, and show you exactly what was installing it so you can avoid the same trap in the future. No jargon, no upselling, just straight answers and effective repairs from people who've been doing this work in this community for years.