HanutLive is a browser extension and potentially unwanted program (PUP) that infiltrates Windows and Mac systems under the guise of streaming or live-content functionality. Once installed, it hijacks browser settings to redirect search queries through modified search engines, injects unwanted advertisements into web pages you visit, and collects browsing data for advertising purposes. This software typically enters systems bundled with free software downloads or through deceptive pop-up advertisements promising enhanced streaming capabilities.

HanutLive — cybersecurity illustration
Photo by Tima Miroshnichenko on Pexels

While not classified as a virus in the traditional sense, HanutLive exhibits intrusive behavior that degrades system performance, compromises privacy, and creates security vulnerabilities by exposing users to potentially malicious advertising networks. Its persistence mechanisms make it difficult to remove through conventional uninstallation methods, requiring thorough cleanup of browser extensions, system files, and registry entries.

Think you're infected right now? Disconnect from the internet immediately if you're experiencing aggressive redirects or pop-ups. Close all browsers and do not enter passwords or financial information until the threat is removed. Skip to the removal section below, or call our Roswell shop at (770) 667-9995 for immediate assistance — we can often guide you through emergency containment over the phone.

Threat Profile

Attribute Details
Threat Family Browser Hijacker / Potentially Unwanted Program (PUP)
Common Aliases Hanut Live, HanutLive Extension, HanutStreamHelper
Platforms Affected Windows 7/8/8.1/10/11, macOS 10.12+, Chrome/Firefox/Edge/Safari browsers
First Observed Variants of this family circulating since 2021
Distribution Methods Software bundling, fake codec installers, deceptive advertisements, torrent packages
Persistence Mechanisms Browser extension with elevated permissions, scheduled tasks (Windows), LaunchAgents (macOS), registry modifications
Primary Capabilities Search redirection, advertisement injection, homepage/new-tab hijacking, browsing data collection, browser settings modification
Data at Risk Browsing history, search queries, IP addresses, cookies, potentially form data depending on extension permissions
Network Behavior Establishes persistent connections to advertising networks and data collection servers; redirects through intermediate domains before reaching legitimate search results
Secondary Payloads May download additional PUPs or adware components after initial installation
Typical File Locations Browser extension folders, %APPDATA%\Local\Temp subfolders, ~/Library/Application Support/ (Mac)
Removal Difficulty Moderate — requires manual browser cleanup, extension removal, and system file deletion; reinstalls itself if all components not removed

How It Spreads

HanutLive primarily spreads through software bundling, a deceptive distribution technique where the PUP is packaged with legitimate free software downloads. Users downloading video players, PDF converters, or system utilities from third-party download sites often encounter installation wizards that include HanutLive as an "optional" component — though the option to decline is frequently buried in custom/advanced installation settings or presented with confusing language designed to trick users into acceptance.

Fake update notifications represent another common infection vector. Users browsing streaming sites or file-sharing platforms may encounter pop-ups claiming that a "media codec update" or "Flash Player replacement" is required to view content. These fake alerts lead to installer packages that deploy HanutLive along with other unwanted software. The urgency of these messages combined with their professional appearance convinces many users to proceed with installation.

Social engineering tactics on torrent sites and warez forums also contribute to HanutLive distribution. Uploaders may package the PUP with cracked software or pirated media files, relying on users' willingness to accept risk when downloading unauthorized content. The infection becomes collateral damage in the pursuit of free software or entertainment.

  • Bundled installers from freeware download portals (Softonic, CNET Download.com clones, etc.)
  • Fake codec or player updates presented on streaming or adult content websites
  • Malicious advertisements on compromised legitimate sites (malvertising campaigns)
  • Torrent packages containing cracked software with PUP payloads
  • Email attachments disguised as document readers or utilities (less common for this specific family)
  • Browser notification clickjacking where permission requests are disguised as CAPTCHA verifications

What It Does On Your Machine

Upon installation, HanutLive immediately targets your web browsers, installing extensions without clear user consent or burying the disclosure in lengthy terms-of-service agreements. These extensions request broad permissions including the ability to "read and change all your data on websites you visit" — permissions that enable the complete hijacking of your browsing experience. The extension modifies your default search engine, homepage, and new tab page to redirect through advertising-revenue generating domains before eventually delivering search results from legitimate engines like Bing or Google.

The most visible symptom of HanutLive infection is the constant stream of injected advertisements. As you browse normally trusted websites, the extension inserts additional banner ads, pop-unders, and in-text advertising links that weren't part of the original page. These advertisements often promote questionable products, fake tech support services, or lead to further PUP downloads. The ads consume bandwidth, slow page loading times, and create a cluttered browsing experience that makes legitimate content difficult to access.

Behind the scenes, HanutLive collects browsing telemetry and transmits it to remote servers. This data collection includes your search queries, visited URLs, IP address, browser type, and operating system details. While the privacy policy (if one exists) may claim the data is "anonymized," the comprehensive nature of the tracking creates a detailed profile of your online behavior that can be monetized through advertising networks or potentially sold to third-party data brokers.

The software also establishes persistence mechanisms designed to survive casual removal attempts. On Windows systems, it may create scheduled tasks that reinstall the browser extension or modify the browser's shortcut target to include command-line parameters that force specific homepage settings. On macOS, LaunchAgents may be configured to monitor browser processes and re-inject the malicious extension if users attempt to disable it through normal browser settings.

Typical HanutLive Artifacts (Windows)
C:\Users\[Username]\AppData\Local\Google\Chrome\User Data\Default\Extensions\ jkbhlfegfmnaocmhpfnfpjkbhdbbdbmh\ # Extension folder (ID varies) C:\Users\[Username]\AppData\Local\Temp\ hanut_installer_[random].exe Registry Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Run Value: "HanutHelper" pointing to updater executable Scheduled Task: Task Scheduler Library\HanutUpdate # Runs hourly to check for "updates" Browser Shortcut Target Modified: "C:\Program Files\Google\Chrome\Application\chrome.exe" --homepage=http://[redirector-domain]

Manual Removal — Step by Step

01

Disconnect and Document

Disconnect your computer from the internet by unplugging the Ethernet cable or disabling Wi-Fi. Take note of any suspicious browser behavior, unusual programs in your installed software list, or unfamiliar extensions before you begin removal — this documentation helps verify complete cleanup later. If possible, take screenshots of the hijacked homepage or search engine settings as reference.

02

Boot to Safe Mode with Networking

Restart your computer in Safe Mode to prevent HanutLive's persistence mechanisms from reactivating during removal. On Windows 10/11, hold Shift while clicking Restart, then navigate to Troubleshoot > Advanced Options > Startup Settings > Restart > press F5 for Safe Mode with Networking. On macOS, restart and immediately hold Shift until you see the login screen. Safe Mode loads only essential system processes, making malware removal more effective.

03

Uninstall Suspicious Programs

Open Control Panel (Windows) or Applications folder (Mac) and carefully review your installed programs list for anything related to HanutLive, Hanut, or any programs you don't recognize that were installed around the time problems began. Uninstall these programs, but be aware that the uninstaller itself may be deceptive — decline any offers to "keep" features or install "replacement" software. Look for programs with generic names like "StreamHelper," "MediaCodec," or publisher names you don't recognize.

04

Remove Browser Extensions (All Browsers)

Open each browser you have installed and navigate to the extensions/add-ons manager (chrome://extensions/ for Chrome/Edge, about:addons for Firefox, Safari > Preferences > Extensions for Safari). Remove any extensions you don't recognize or didn't intentionally install, paying special attention to extensions with vague names, no reviews, or permissions to "read and change all your data." Don't just disable them — click Remove/Uninstall to delete completely. Repeat this process for every browser profile if you have multiple.

05

Reset Browser Settings

After removing extensions, reset each browser to default settings to eliminate lingering modifications. In Chrome/Edge, go to Settings > Reset settings > Restore settings to their original defaults. In Firefox, type about:support in the address bar and click "Refresh Firefox." In Safari, manually change your homepage and search engine back to preferred settings in Preferences. This step removes hijacked search engines, restores default new-tab pages, and clears out modified startup settings that the extension may have altered.

06

Delete Scheduled Tasks and Startup Items

On Windows, open Task Scheduler (search for it in Start menu) and look in Task Scheduler Library for any tasks related to HanutLive or with suspicious names containing random characters or references to "updater" processes in temporary folders. Delete these tasks. Also check msconfig (type it in Run dialog) > Startup tab and disable any unrecognized entries. On Mac, go to System Preferences > Users & Groups > Login Items and remove suspicious entries, then check ~/Library/LaunchAgents/ for .plist files related to Hanut and delete them.

07

Clean Registry Entries (Windows)

Press Win+R, type regedit, and carefully navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. Look for any entries referencing HanutLive, Hanut, or executables in suspicious locations like Temp folders or randomly-named subdirectories in AppData. Right-click and delete these entries. Exercise extreme caution in the registry — only delete entries you're confident are related to the infection. If uncertain, document the entry name and location for professional review.

08

Run Malwarebytes and AdwCleaner

Reconnect to the internet and download Malwarebytes (free version is sufficient) and Malwarebytes AdwCleaner from the official Malwarebytes website. Run AdwCleaner first — it specializes in PUPs and browser hijackers — and allow it to complete a full scan and removal. Restart when prompted. Then run a full Malwarebytes scan, which may take 45-90 minutes depending on your drive size. Quarantine and remove all detected items. These tools catch remnants and related PUPs that manual removal might miss.

09

Change Passwords

If you entered any passwords while HanutLive was active on your system, change them from a known-clean device or after completing all removal steps. Browser hijackers with data collection capabilities may have captured credentials through form monitoring or keylogging functionality. Prioritize email, banking, and primary social media accounts. Enable two-factor authentication wherever possible as an additional security layer.

10

Restart Normally and Verify

Restart your computer in normal mode and test your browsers thoroughly. Verify that your homepage, search engine, and new-tab page are as you expect them. Browse to several different websites and confirm that you're not seeing excessive advertisements or redirect behavior. Check Task Manager (Windows) or Activity Monitor (Mac) for any suspicious processes consuming resources. If problems persist, the infection may not be completely removed — at that point, professional assistance becomes advisable to avoid potential data compromise.

Prevention

  1. Download software only from official sources. Avoid third-party download sites that bundle additional software with installers. Go directly to the publisher's website or use the Microsoft Store (Windows) or Mac App Store when possible. Free software aggregator sites like Softonic or Download.com frequently repackage installers with PUPs included.
  2. Always choose Custom/Advanced installation. Never click through installation wizards using Express/Recommended settings. Custom installation reveals bundled software offers that would otherwise be installed silently. Read each screen carefully and uncheck any boxes offering toolbars, extensions, or "partner offers."
  3. Keep your system and browsers updated. Security vulnerabilities in outdated software create opportunities for drive-by downloads and automatic infection. Enable automatic updates for Windows/macOS and all browsers to ensure you receive security patches promptly.
  4. Install reputable ad-blocking and anti-tracking extensions. uBlock Origin (not uBlock — they're different) provides excellent protection against malicious advertisements and tracker-laden pages that distribute PUPs. Privacy Badger from the Electronic Frontier Foundation blocks trackers that attempt to profile your browsing behavior.
  5. Be skeptical of codec and player update prompts. Legitimate streaming services don't require random codec installations — modern browsers have everything needed for video playback built in. If you encounter a message claiming you need to install something to view content, close the tab and navigate away. Flash Player is officially discontinued and no longer receives updates; any Flash update prompt is definitely malicious.
  6. Review browser extensions quarterly. Set a calendar reminder to audit your installed extensions every three months. Remove anything you don't actively use or can't remember installing. PUPs sometimes install during moments of distraction, and periodic reviews catch these before they accumulate.
  7. Use a standard user account for daily computing. Don't operate as an administrator for routine tasks. Standard accounts can't install system-level persistence mechanisms without prompting for admin credentials, giving you an opportunity to block unwanted software before it takes hold.
  8. Maintain a real-time anti-malware tool. Windows Defender (built into Windows 10/11) provides adequate baseline protection if kept updated. For Mac users, Malwarebytes for Mac offers a free real-time scanner. Supplement with periodic scans using dedicated anti-PUP tools like AdwCleaner to catch items that slip past real-time protection.
Our 90-Day Warranty
When Computer Repair Roswell removes HanutLive or any malware from your system, we guarantee our work for 90 days. If the same threat returns within that period (not due to new user installation or high-risk behavior), we'll remove it again at no charge. We don't just clean your system — we explain what happened and how to avoid reinfection, giving you the knowledge to protect yourself going forward.

Bring It In

Manual removal of HanutLive and associated PUPs can be time-consuming and frustrating, particularly if the infection has established deep persistence mechanisms or bundled itself with additional unwanted software. If you've attempted the steps above without success, or if you're uncomfortable editing registry entries and system files, bring your computer to our Roswell shop at 1000 Alpharetta Street. We'll perform a comprehensive malware removal that includes not just eliminating the active infection, but also identifying and securing the vulnerabilities that allowed entry in the first place.

Our technicians see browser hijackers like HanutLive regularly, and we have specialized tools and techniques that go beyond consumer-grade solutions. We'll also check for secondary infections that often accompany PUPs — sometimes the visible hijacker is just the most obvious symptom of a broader compromise. Call us at (770) 667-9995 or stop by Monday through Friday, 10 AM to 6 PM. Most malware removals are completed same-day, and we'll have you back online with a clean, protected system before you know it.