JawCubFeltLive is a browser hijacker and potentially unwanted program (PUP) that forcibly redirects your web searches and homepage to unfamiliar search engines while tracking your browsing activity. Like many browser hijackers, it enters systems bundled with free software downloads and immediately modifies browser settings without meaningful consent. Once installed, JawCubFeltLive proves difficult to remove through normal means because it reinstalls itself using hidden extensions, scheduled tasks, and registry modifications designed to survive typical uninstall attempts.
This hijacker primarily affects Windows systems running Chrome, Firefox, and Edge browsers. Users typically notice that their default search engine suddenly points to suspicious domains, their new tab page has changed, and they're seeing an unusual volume of advertisements during normal browsing. While JawCubFeltLive doesn't encrypt files or directly steal credentials like more aggressive malware, it compromises your privacy by logging search queries, visited URLs, and potentially sensitive information entered into web forms.
Threat Profile
| Attribute | Details |
|---|---|
| Threat Classification | Browser Hijacker / Potentially Unwanted Program (PUP) |
| Family | Generic bundleware hijacker (behavior consistent with adware-injector families) |
| Common Aliases | May be detected as PUP.Optional.JawCubFeltLive, BrowserModifier:Win32/JawCubFelt, Adware.Generic |
| Affected Platforms | Windows 7/8/10/11; targets Chrome, Firefox, Edge, and occasionally Opera |
| Primary Distribution | Software bundling, fake update prompts, deceptive download buttons on freeware sites |
| Persistence Mechanisms | Browser extensions (forced installation), scheduled tasks, Run/RunOnce registry keys, local AppData folders with randomized names |
| Primary Capabilities | Search redirection, homepage/new tab hijacking, ad injection, browsing data collection, affiliate link substitution |
| Data Collection | Search queries, browsing history, clicked links, IP address, browser type, approximate geolocation |
| Network Behavior | Frequent HTTP/HTTPS requests to advertising networks and tracking domains; may contact C2 servers for configuration updates |
| Typical Filesystem Artifacts | Random folders in %LOCALAPPDATA%, %APPDATA%\[RandomName], extension folders in browser profiles |
| Registry Modifications | HKCU\Software\Microsoft\Windows\CurrentVersion\Run, browser policy keys under HKLM and HKCU\Software\Policies |
| Removal Difficulty | Moderate — reinstalls itself if all components aren't removed; manual removal requires careful attention to browser profiles and scheduled tasks |
How It Spreads
JawCubFeltLive rarely travels alone. The most common infection vector is software bundling—legitimate-looking free programs (video converters, PDF tools, download managers) that include the hijacker as an "optional offer" buried in the installation wizard. These installers use deceptive interface patterns: the hijacker installation is often pre-checked, described with vague marketing language like "enhanced search experience," or hidden behind an "Advanced" or "Custom" installation option that most users skip past.
We've also seen this hijacker distributed through fake software update notifications, particularly counterfeit Flash Player or Java updates that appear while browsing suspicious websites. These fake prompts mimic legitimate update interfaces well enough to fool users who aren't paying close attention. Once you run the downloaded file, JawCubFeltLive installs alongside (or instead of) whatever you thought you were updating.
Additional distribution methods include:
- Deceptive download buttons: Freeware download sites often feature multiple "Download" buttons—only one is legitimate, while others download bundleware installers containing hijackers like JawCubFeltLive
- Malvertising: Compromised ad networks occasionally serve malicious advertisements that trigger drive-by downloads or redirect to pages hosting the hijacker installer
- Torrent bundles: Pirated software packages and key generators frequently include PUPs and hijackers as additional payloads
- Email attachments: Less common for this specific threat, but some variants arrive via spam campaigns disguised as invoices or shipping notifications
- Browser extension stores: Occasionally sneaks into official extension repositories by masquerading as productivity tools or coupon finders before being detected and removed
What It Does On Your Machine
Once JawCubFeltLive establishes itself, the first change you'll notice is your browser behavior. Your homepage suddenly points to an unfamiliar search engine, your new tab page displays a custom search portal you didn't choose, and your default search engine has changed—often to something that looks superficially like Google or Bing but uses a different domain. These search engines typically show legitimate results (often pulled from legitimate search providers) mixed with sponsored links and advertisements that generate revenue for the hijacker's operators through affiliate schemes.
The hijacker achieves this control through multiple mechanisms. It installs browser extensions without proper consent, modifies browser shortcut targets to include specific URLs as launch parameters, and on some systems writes browser policy registry keys that prevent users from changing settings back manually. Even if you manage to reset your homepage through browser settings, JawCubFeltLive's persistence mechanisms simply reapply the unwanted changes the next time the browser launches or a scheduled task executes.
Beyond visible browser changes, JawCubFeltLive runs surveillance on your browsing habits. It logs the search terms you enter, the websites you visit, which links you click, and how long you spend on various pages. This data gets transmitted back to remote servers—ostensibly for "improving search results" but more realistically for building advertising profiles and selling aggregated data to marketing companies. While this doesn't directly steal passwords or credit card numbers like banking trojans do, it's still a significant privacy violation, particularly if you're searching for medical information, shopping for specific products, or conducting research you'd prefer to keep private.
Typical filesystem and system artifacts you'll find with an active JawCubFeltLive infection look like this:
The hijacker may also modify your hosts file to redirect specific domains (typically security software update servers) to localhost, preventing your antivirus from receiving definition updates. Some variants inject additional adware or open backdoors for other PUPs to install, turning your initial infection into a gateway for more serious threats.
Manual Removal — Step by Step
Disconnect from the Internet
Unplug your ethernet cable or disable Wi-Fi before proceeding. This prevents the hijacker from downloading additional components or receiving configuration updates that might interfere with removal. It also stops data transmission to tracking servers while you work.
Boot Into Safe Mode with Networking
Restart your computer and press F8 repeatedly during boot (Windows 7) or hold Shift while clicking Restart from the login screen (Windows 10/11), then navigate to Troubleshoot → Advanced Options → Startup Settings → Restart → press 5 for Safe Mode with Networking. Safe mode prevents most hijacker components from loading automatically, making removal substantially easier.
Identify and Terminate Active Processes
Open Task Manager (Ctrl+Shift+Esc) and look for suspicious processes—anything with random names in your user profile's AppData folders, processes named "updater.exe" or similar generic names, or anything consuming network bandwidth despite being offline. Right-click these processes, select "Open file location" to note the path for later deletion, then end the process tree. Be cautious not to terminate legitimate Windows processes.
Remove Scheduled Tasks
Open Task Scheduler (type "Task Scheduler" in Start menu), expand Task Scheduler Library, and look for tasks created recently or with suspicious names. JawCubFeltLive typically creates tasks that run hourly or at logon. Right-click any related tasks and delete them. Pay special attention to tasks that reference executable files in %LOCALAPPDATA% or %APPDATA% with GUID-format folder names.
Clean Registry Persistence Keys
Press Win+R, type "regedit", and navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run. Look for entries pointing to random executables in your user folders—these are almost certainly hijacker persistence mechanisms. Delete these entries. Also check HKEY_CURRENT_USER\Software\Policies and HKEY_LOCAL_MACHINE\Software\Policies for browser policy keys that force extension installations. Delete any suspicious policy entries, particularly under Chrome, Firefox, or Edge subkeys.
Delete Hijacker File Folders
Navigate to the file locations you identified in Step 3. Common locations include folders in C:\Users\[YourName]\AppData\Local\ and \AppData\Roaming\ with GUID-format names or random character strings. Delete these entire folders. If Windows says files are in use, you may have missed terminating a process—return to Task Manager and ensure everything is stopped, then try again.
Remove Browser Extensions and Reset Settings
Open each affected browser and navigate to the extensions/add-ons management page. Remove any extensions you don't recognize or didn't intentionally install. Then reset browser settings: in Chrome, go to Settings → Reset settings → Restore settings to original defaults. In Firefox, type about:support in the address bar and click "Refresh Firefox." In Edge, go to Settings → Reset settings → Restore settings to their default values. This clears hijacked homepages, search engines, and startup pages.
Run a Reputable Anti-Malware Scanner
Download Malwarebytes (free version is sufficient) or another reputable anti-malware tool and run a full system scan. These tools catch remnants and related PUPs that manual removal might miss. Quarantine or delete everything the scanner identifies. Even if you've completed manual removal successfully, a scanner provides verification and often catches bundled threats that arrived with the hijacker.
Check and Clean the Hosts File
Navigate to C:\Windows\System32\drivers\etc\, right-click the "hosts" file, and open it with Notepad (you may need administrator privileges). Look for entries below the standard localhost entries—any domain redirections added by malware. Legitimate hosts files are nearly empty except for comments. Delete any suspicious entries, save the file, and close it.
Reboot and Verify Removal
Restart your computer normally (exit Safe Mode) and reconnect to the internet. Open your browsers and verify that your chosen homepage, search engine, and new tab page are properly set. Search for something and confirm you're not being redirected. Monitor Task Manager for a few minutes to ensure no suspicious processes restart. If everything looks clean and stays clean for a day of normal use, the removal was successful.
Prevention
- Always choose "Custom" or "Advanced" installation options when installing free software. Read every screen carefully and uncheck any pre-selected offers for toolbars, search engines, homepage changes, or "recommended" additional software. Legitimate programs don't need to bundle their installers with third-party offers.
- Download software only from official publisher websites rather than third-party download portals. Sites like Download.com, Softonic, and similar repositories often wrap legitimate software in bundleware installers. Go directly to the developer's website whenever possible.
- Keep a reputable ad-blocker installed on all browsers. Extensions like uBlock Origin prevent malicious advertisements and block many of the distribution sites that host hijacker installers. This single tool prevents a surprising percentage of browser-based infections.
- Maintain updated antivirus software with real-time protection enabled. While signature-based detection isn't perfect against brand-new threats, quality antivirus software catches the vast majority of PUPs and hijackers before they install. Windows Defender is adequate for most users if kept updated; Malwarebytes Premium or similar tools provide additional layers.
- Verify software updates are genuine before running them. If a website prompts you to update Flash (which is defunct anyway), Java, or any plugin, navigate directly to the official website rather than clicking the prompt. Legitimate software updates arrive through the application itself, not through browser pop-ups.
- Practice browser hygiene: Periodically review installed extensions and remove anything you don't actively use. Check your browser's homepage and search engine settings monthly to catch any unauthorized changes early, before tracking accumulates.
- Educate yourself about download button tricks. On freeware sites, the actual download link is often small and text-based, while large green "DOWNLOAD" buttons are advertisements. Hover over buttons to check their destination URLs before clicking—legitimate downloads point to the current domain, not random ad networks.
- Use a standard user account for daily activities rather than an administrator account. Many installers and hijackers require administrator privileges to write to system folders and registry locations. Running as a standard user forces a UAC prompt that gives you a chance to reconsider before approving suspicious installations.
Bring It In
Browser hijackers like JawCubFeltLive are deceptively stubborn. What looks like successful removal often turns out to be temporary relief because a hidden scheduled task or deep registry modification brings everything back hours later. We see this pattern regularly: someone spends an evening following removal guides, thinks they've succeeded, then discovers the hijacker has returned the next morning. Manual removal works when done thoroughly, but it requires patience and attention to detail that's easy to lose after the third or fourth attempt.
At Computer Repair Roswell, we handle infections like this daily. Our technicians clean the infection completely—browser profiles, scheduled tasks, registry persistence, filesystem artifacts, and any companion PUPs that came along for the ride. We verify removal with multiple scanning tools and test your browsers to confirm normal operation before returning your machine. Most hijacker removals are same-day service. Call us at (770) 856-1555 or stop by our Roswell location at 1601 Willeo Creek Dr, Roswell, GA 30075. We'll get your browser working properly again and show you what to watch for to avoid reinfection. Bring your machine in—we'll take care of it while you wait or grab lunch nearby.