GladFilmFellLive is a browser hijacker that redirects your searches through dubious ad networks and replaces your homepage and new-tab settings without permission. Typically bundled with free software installers or pushed through deceptive download buttons on file-sharing sites, this hijacker modifies browser configurations to generate pay-per-click revenue for its operators while degrading your browsing experience with intrusive ads and unwanted redirects. Though not as destructive as ransomware or data-stealing trojans, GladFilmFellLive creates persistent annoyance and potentially exposes you to more dangerous threats through the questionable sites it forces you to visit.
Threat Profile
| Attribute | Details |
|---|---|
| Threat Family | Browser Hijacker / Potentially Unwanted Program (PUP) |
| Common Aliases | Glad Film Fell Live, GladFilmFell redirect, Search.gladfilmfelllive.com |
| Platforms Affected | Windows (all versions), macOS (occasionally) |
| Browsers Targeted | Chrome, Firefox, Edge, Safari—all major browsers |
| Distribution Method | Software bundling, fake download buttons, misleading installers, compromised freeware |
| Persistence Mechanism | Browser extension policies, scheduled tasks, registry Run keys, browser shortcut target modification |
| Primary Behavior | Homepage/search engine replacement, search query redirection, intrusive advertising |
| Data Collection | Search queries, browsing history, clicked links—typical for ad-supported hijackers |
| Network Activity | Connections to various ad network domains, frequent HTTP redirects through intermediary pages |
| Typical Artifacts | Browser extensions with randomized names, modified browser shortcuts, scheduled tasks with obfuscated names |
| Removal Difficulty | Moderate—often reinstalls itself if all components aren't removed simultaneously |
| Estimated Prevalence | Medium—part of a broader family of search hijackers distributed through software bundling networks |
How It Spreads
GladFilmFellLive spreads almost exclusively through software bundling and deceptive distribution tactics. You won't find this hijacker on legitimate software download sites or official vendor pages. Instead, it piggybacks on free programs downloaded from third-party hosting sites—those "download managers" and "installer packages" that promise to deliver popular software but slip in half a dozen unwanted add-ons during the setup process.
The most common infection scenario starts when someone searches for free software—a PDF converter, a video player, a system optimization tool—and clicks a sponsored search result or visits a file-sharing site loaded with misleading "Download" buttons. The real download link might be a small text link buried at the bottom of the page, while three or four giant green buttons above it all lead to bundled installers. Click one of those, rush through the installation clicking "Next" without reading, and you've just agreed to install GladFilmFellLive along with whatever you actually wanted.
Common distribution vectors include:
- Software bundlers and download managers from freeware hosting sites that package hijackers with legitimate programs
- Fake download buttons on torrent sites, video converters, and file-sharing platforms designed to look like the real download link
- Misleading browser extension offers presented as required components for video playback or document viewing
- Compromised or rogue installers for popular free applications distributed through unofficial channels
- Social engineering popups claiming you need to install an "update" or "security tool" to continue browsing
- Malvertising campaigns on legitimate but poorly-moderated ad networks that redirect to pages pushing the hijacker
What It Does On Your Machine
Once installed, GladFilmFellLive immediately goes to work reconfiguring your browser settings. It replaces your default search engine with its own search page, changes your homepage to a branded portal, and often hijacks your new-tab page so every new tab you open reinforces the infection. These changes aren't presented as optional preferences—they're forced modifications that persist even after you try to change them back through normal browser settings.
The hijacker's core function is search redirection. When you type a query into the address bar or search box, instead of going to Google, Bing, or your chosen search engine, the query gets routed through the GladFilmFellLive infrastructure. Your search might pass through two or three intermediary domains before landing on a results page, and those results themselves are manipulated—legitimate organic results pushed down while sponsored links and dubious ads occupy the premium positions. Every click generates revenue for the hijacker's operators through affiliate networks and pay-per-click advertising schemes.
Beyond search manipulation, GladFilmFellLive typically injects additional advertisements into the pages you visit. You'll see extra banner ads in places where none existed before, pop-unders that open new browser windows behind your current one, and text-link ads where ordinary words on legitimate websites suddenly appear as hyperlinks. The hijacker monitors your browsing activity—which sites you visit, what you search for, how long you spend on different pages—and uses this data to target ads more effectively, though the quality of these ads is typically abysmal: weight-loss scams, fake tech support offers, dubious "system optimization" tools, and occasionally, links to more aggressive malware.
The persistence mechanisms make GladFilmFellLive particularly stubborn. It typically installs a browser extension or policy object that reapplies the hijacked settings whenever the browser starts. It may also create scheduled tasks that re-download missing components or modify browser shortcut targets to append command-line arguments that force specific homepage behavior. Some variants drop a small executable in your AppData folder that runs at startup to monitor and maintain the infection, reinstalling browser components if you delete them manually.
Manual Removal — Step by Step
Disconnect and document the behavior
Before making changes, disconnect from the internet to prevent the hijacker from downloading additional components or communicating with command servers. Take note of which browser is affected, what your homepage has been changed to, and whether you notice any suspicious browser extensions in your toolbar. This information helps ensure you find all components during removal.
Uninstall suspicious programs through Windows Settings
Open Settings → Apps → Apps & features (or Control Panel → Programs and Features on older Windows). Sort by install date and look for programs installed around the time the hijacking started. Uninstall anything with "GladFilm" or similar nonsense names, as well as any unfamiliar programs from the same timeframe—bundled installers often drop multiple PUPs simultaneously. Common suspicious names include generic phrases like "Web Companion," "Search Manager," or programs from unknown publishers.
Remove malicious browser extensions
Open each affected browser and navigate to its extensions page (chrome://extensions in Chrome, about:addons in Firefox, edge://extensions in Edge). Enable "Developer mode" in Chrome/Edge to see more details. Remove any extensions you don't recognize or didn't intentionally install, paying particular attention to extensions with generic names, no reviews, or permissions that request access to "all websites" or "browsing history." Don't worry about breaking functionality—legitimate extensions can always be reinstalled later from official sources.
Reset browser search and homepage settings
In each browser's settings, manually restore your preferred homepage and search engine. In Chrome, check Settings → Search engine → Manage search engines and remove any unfamiliar entries. In Firefox, check about:preferences#search. Also examine Settings → On startup (or equivalent) to ensure no hijacked URL is set to open automatically. Right-click your browser shortcut on the desktop or taskbar, select Properties, and examine the Target field—if there's anything after the .exe path (like "http://gladfilmfelllive.com"), delete everything after chrome.exe or firefox.exe.
Clear browser data and disable sync temporarily
Clear your browsing data including cookies, cached files, and site settings from the past month—this removes any tracking identifiers the hijacker planted. If you use browser sync (Chrome Sync, Firefox Sync), temporarily disable it before clearing data to prevent the hijacked settings from syncing back from the cloud. After you've confirmed the infection is gone, you can re-enable sync.
Remove persistence mechanisms from Windows
Press Win+R, type "taskschd.msc" to open Task Scheduler, and look through the Task Scheduler Library for any tasks with unfamiliar names or tasks that run executables from AppData or Temp folders. Delete suspicious tasks. Next, press Win+R and type "regedit" to open Registry Editor. Navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and look for any entries pointing to executables in your AppData\Local or AppData\Roaming folders with suspicious names. Delete these entries. Be cautious in the registry—only delete items you can confirm are related to the hijacker.
Delete the hijacker's installation folder
Navigate to C:\Users\[YourUsername]\AppData\Local\ and look for folders with names like "GladFilmFell," "GladFilm," or random GUID strings that were created around the infection date. Delete these entire folders. Also check AppData\Roaming and AppData\Local\Temp for similar folders. You may need to show hidden files (View → Hidden items in File Explorer) to see the AppData folder.
Scan with reputable anti-malware tools
Reconnect to the internet and run a full scan with Malwarebytes Free (download from malwarebytes.com—not from a search result that might be another trap). Let it complete the full scan, which typically takes 20–40 minutes. Quarantine everything it finds. Follow up with a Windows Defender full scan for a second opinion. These tools often catch remnants and registry entries that manual removal misses, and they can identify any additional PUPs that came bundled with the hijacker.
Verify browser behavior and check for policy locks
In Chrome, type "chrome://policy" in the address bar to see if any administrative policies are enforcing extensions or homepage settings—these would indicate deeper system-level hijacking. If you see policies you didn't create, you'll need to remove them from the registry under HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome or the equivalent Mozilla key for Firefox. In Firefox, type "about:policies" to check the same. If policies appear and you're not in a managed corporate environment, they're almost certainly malicious and need removal.
Restart and test thoroughly
Reboot your computer to ensure all changes take effect and that no startup processes reinstall the hijacker. After restarting, open your browser and verify that your chosen homepage loads, searches go to your preferred search engine, and no unexpected redirects occur. Open a few websites and confirm no unusual ads are injecting themselves into pages. Test for several hours—some hijackers have delayed reinstallation mechanisms that wait before reactivating.
Prevention
- Download software only from official vendor websites. If you need a free PDF reader, go to the Adobe website directly—don't search for "free PDF reader" and click whatever appears first. Searching for free software is the number-one infection vector for browser hijackers and bundled PUPs.
- Pay attention during software installation. Always choose "Custom" or "Advanced" installation rather than "Express" or "Recommended." Read each screen and uncheck any boxes offering to install additional toolbars, change your homepage, or install "partner software." Legitimate software doesn't require you to install browser extensions as a condition of use.
- Use an ad blocker and script blocker. Browser extensions like uBlock Origin block most malicious ads and pop-ups that lead to hijacker installations. Script blockers like uMatrix or NoScript provide even more protection by preventing unauthorized scripts from running when you visit questionable sites, though they require more technical knowledge to configure.
- Keep Windows Defender enabled with real-time protection. The built-in protection in Windows 10 and 11 is actually quite capable these days and will block many PUP installers before they execute. Don't disable it because some random website told you it slows down your computer—that's often advice pushed by sites that want you vulnerable.
- Maintain a reputable browser extension allow-list. Only install extensions from official browser stores (Chrome Web Store, Firefox Add-ons) and check reviews and ratings before installing. Remove extensions you no longer use—every installed extension is a potential vulnerability or performance drain.
- Be skeptical of download buttons and urgent prompts. If you're on a file-sharing site and see multiple "Download" buttons, assume they're all traps except for the smallest, least obvious link. If a website tells you that you "must install an update" or "require a codec" to view content, close the tab—legitimate sites don't operate that way.
- Create a Windows restore point before installing new software. If you do accidentally install something suspicious, you can roll back to the pre-infection state without spending hours on manual removal. Go to System Properties → System Protection → Create to make a restore point before installing anything from an unfamiliar source.
- Consider running a standard user account instead of an administrator account. Many hijackers and PUPs rely on administrative privileges for system-level persistence. A standard user account forces installation prompts to ask for credentials, giving you a chance to realize something unwanted is trying to install itself. This is more practical for single-user home systems than you might think.
Bring It In
Manual removal of browser hijackers works when you catch them early and follow every step precisely, but it's easy to miss registry keys, scheduled tasks, or policy objects that let the infection reinstall itself overnight. If GladFilmFellLive keeps coming back after you've tried removing it, or if you're seeing more serious symptoms like new user accounts appearing or antivirus software being disabled, you're likely dealing with additional infections that came bundled with the hijacker. At that point, professional removal becomes the sensible choice—you'll spend less time troubleshooting and get better results.
We're located in Roswell at 1395 South Marietta Parkway, and we handle browser hijacker removal daily. Bring your machine in or give us a call at (770) 695-6932. Most hijacker removals are same-day service—we'll clean the infection, verify all the persistence mechanisms are gone, update your security software, and show you exactly what we found so you know how to avoid it next time. No appointment necessary for drop-offs during business hours.