JellyMatchSite is a browser hijacker and potentially unwanted program (PUP) that forces changes to your web browser's homepage, default search engine, and new tab page without consent. Once installed, it redirects search queries through suspicious intermediary sites, bombards you with intrusive advertising, and tracks your browsing activity to build marketing profiles. While not as destructive as ransomware or banking trojans, JellyMatchSite degrades system performance, compromises your privacy, and creates security vulnerabilities by exposing you to malicious advertising networks and phishing sites.
This hijacker typically bundles itself with free software downloads, pirated media files, or fake software updaters. Many users discover it only after noticing their browser homepage has changed to an unfamiliar search portal or their searches consistently redirect through unfamiliar domains. The software resists simple removal by reinstalling itself through scheduled tasks, browser extensions, and registry persistence mechanisms.
Threat Profile
| Attribute | Details |
|---|---|
| Threat Type | Browser Hijacker, PUP (Potentially Unwanted Program) |
| Family | Search-redirect hijacker cluster |
| Common Aliases | Jelly Match Site, JellyMatch redirect, JellyMatchSite.com hijacker |
| Platform | Windows (7, 8, 10, 11); targets Chrome, Firefox, Edge, Safari on macOS |
| First Observed | Variants circulating since approximately 2020 |
| Distribution Method | Software bundling, fake installers, malvertising, compromised download sites |
| Persistence Mechanisms | Browser extensions, scheduled tasks, registry Run keys, modified browser shortcuts |
| Primary Capabilities | Homepage/search hijacking, query redirection, advertising injection, browsing tracking |
| Data Collection | Search queries, visited URLs, IP address, browser fingerprint, click patterns |
| Network Behavior | Communicates with ad-serving domains, monetization platforms, tracking networks |
| Payload Risk | May download additional PUPs or expose users to malicious advertising |
| Removal Difficulty | Moderate — requires browser cleanup, extension removal, and persistence elimination |
How It Spreads
JellyMatchSite employs deceptive distribution tactics that exploit user trust and inattention during software installation. The most common infection vector is software bundling, where the hijacker hides inside the installation package of legitimate-looking free programs. Users who rush through installation wizards using "Express" or "Recommended" settings unknowingly authorize the installation of JellyMatchSite alongside their intended software. The bundling partners often obscure the hijacker's presence in dense legal text or pre-checked opt-in boxes buried in advanced installation screens.
Fake software updaters and codec packs represent another significant distribution channel. Users seeking to watch video content or download media players encounter convincing prompts claiming their Flash Player, video codec, or media player is outdated. These fraudulent update notifications lead to installers that deliver JellyMatchSite instead of or alongside the promised update. Torrent sites, free download portals, and sites offering cracked software frequently host these compromised installers.
Additional distribution methods include:
- Malvertising campaigns — Advertisements on legitimate websites that redirect to fake download pages or execute drive-by downloads when clicked
- Fake browser extensions — Extensions in unofficial stores or promoted through social media that promise productivity features but install the hijacker
- Email attachments — Spam emails with executable attachments disguised as invoices, shipping notifications, or software cracks
- Compromised freeware sites — Once-legitimate download portals that have been compromised to inject bundlers into previously clean installers
- Social engineering — Fake security warnings claiming your system is infected and urging you to download a "cleanup tool" that contains the hijacker
- YouTube comment scams — Links in video comments promising free downloads, game hacks, or "working" serial numbers that lead to infected installers
What It Does On Your Machine
Once executed, JellyMatchSite immediately begins modifying browser configurations across all installed browsers. It changes your homepage, default search engine, and new tab page to redirect through domains controlled by the hijacker operators. These domains vary by infection variant but typically route queries through multiple intermediary sites before delivering search results from legitimate engines like Bing or Yahoo — a process that allows the operators to inject advertisements and affiliate links while collecting data about every search you perform.
The hijacker establishes persistence through multiple mechanisms to survive standard removal attempts. It creates scheduled tasks that reinstall the hijacker components if deleted, modifies browser shortcuts to include command-line parameters that force the hijacked homepage, and installs browser extensions that enforce the configuration changes. Some variants modify the Windows registry to set default browser associations and disable browser reset functionality. The combination of these techniques means simply uninstalling the visible program or removing the browser extension typically fails to eliminate the threat.
Beyond search redirection, JellyMatchSite actively monitors your browsing behavior to support its advertising operation. It tracks the websites you visit, the search terms you enter, your geographic location derived from IP address, and your click patterns. This data feeds into advertising networks that build detailed behavioral profiles for targeted advertising. While the hijacker itself doesn't typically steal passwords or banking credentials, the advertising networks it connects to may deliver malicious advertisements that lead to phishing sites, tech support scams, or genuine malware.
System performance degradation is a common side effect. The constant background communication with advertising servers consumes bandwidth and processing resources. Users report slower browser startup times, increased memory usage, sluggish page loading, and frequent browser crashes. The injected advertisements and redirects add multiple network round-trips to every search operation, creating noticeable delays even on fast internet connections.
Manual Removal — Step by Step
Disconnect from the Internet
Unplug your Ethernet cable or disable Wi-Fi to prevent the hijacker from downloading additional components or communicating with command servers during the removal process. This isolation stops the threat from reinforcing its persistence mechanisms while you work.
Boot Into Safe Mode with Networking
Restart your computer and press F8 (or Shift+F8 on newer systems) during boot to access the Advanced Boot Options menu. Select "Safe Mode with Networking" to start Windows with minimal drivers and services, which prevents most hijacker components from loading automatically and makes them easier to remove.
Uninstall Suspicious Programs
Open Control Panel → Programs and Features (or Settings → Apps on Windows 10/11) and sort the list by installation date. Look for unfamiliar programs installed around the time your browser behavior changed, particularly anything containing "Jelly," "Match," or other game-related terms. Uninstall all suspicious entries, but note that the uninstaller may be fake or incomplete.
Remove Browser Extensions and Reset Settings
Open each installed browser (Chrome, Firefox, Edge) and navigate to the extensions/add-ons page. Remove any unfamiliar extensions, especially those installed recently without your knowledge. Then reset browser settings: in Chrome, go to Settings → Advanced → Reset and clean up → Restore settings to their original defaults. In Firefox, use Help → More Troubleshooting Information → Refresh Firefox. This removes custom search engines and homepage overrides.
Check and Repair Browser Shortcuts
Right-click your browser shortcuts on the desktop and taskbar, select Properties, and examine the Target field. Hijackers often append URLs to the end of the legitimate browser path. The Target should end with the browser executable (chrome.exe, firefox.exe, msedge.exe) with no additional URLs or parameters. If you find extra text, delete everything after the .exe and click OK.
Delete Scheduled Tasks
Press Win+R, type "taskschd.msc" and press Enter to open Task Scheduler. Examine the Task Scheduler Library for tasks with suspicious names (anything containing "Jelly," "Match," or random alphanumeric strings). Check the Actions tab of suspicious tasks to see what they execute — if the path points to a folder you identified earlier, delete the task. Hijackers use these tasks to reinstall themselves after reboot.
Clean Registry Entries
Press Win+R, type "regedit" and press Enter to open Registry Editor. Navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. Look for entries pointing to the JellyMatch folders you identified. Delete those entries. Also search the registry (Ctrl+F) for "JellyMatch" and remove any found keys or values, being careful not to delete unrelated entries.
Delete Installation Folders
Navigate to the AppData folders where JellyMatchSite stores its files (typically %LOCALAPPDATA% and %APPDATA%). Delete any folders named "JellyMatch," "JellyMatchSite," or similar variants. Also check C:\Program Files and C:\Program Files (x86) for installation directories. You may need to take ownership of stubborn folders or delete them from Safe Mode if they're locked.
Run Reputable Anti-Malware Software
Reconnect to the internet and download Malwarebytes Free (from malwarebytes.com — verify the URL carefully) or another reputable scanner. Run a full system scan to catch any components you missed and to detect additional threats that may have been installed alongside JellyMatchSite. Quarantine and remove all detected items. Consider running a second scan with a different tool like HitmanPro or AdwCleaner for thoroughness.
Change Passwords and Monitor Accounts
If you entered any passwords or personal information while the hijacker was active, change those passwords immediately from a known-clean device or after verifying your system is clean. Browser hijackers can potentially log keystrokes or capture form data through injected scripts. Monitor your financial accounts and credit reports for suspicious activity over the following weeks.
Reboot and Verify Cleanup
Restart your computer normally (not in Safe Mode) and verify that your browser homepage and search engine are correct. Perform several searches and browse to different websites, watching for redirects or suspicious behavior. Check Task Manager (Ctrl+Shift+Esc) for unfamiliar processes consuming resources. If problems persist, the hijacker may have additional components that require professional removal.
Prevention
- Download software only from official sources. Avoid third-party download sites, torrent repositories, and "free software" portals that bundle legitimate programs with adware. Go directly to the software publisher's website and verify you're on the correct domain before downloading.
- Always choose Custom or Advanced installation. Never click through installers using Express or Recommended settings. Custom installation reveals bundled offers and allows you to decline additional software. Read every screen carefully and uncheck pre-selected options for toolbars, browser changes, or "recommended" programs.
- Keep your operating system and software updated. Enable automatic updates for Windows, your browsers, and common applications like Adobe Reader and Java. Many exploits that deliver PUPs target outdated software vulnerabilities. Remove software you don't use to reduce your attack surface.
- Use a reputable ad blocker. Install uBlock Origin or similar content blockers to prevent malicious advertisements from loading. Many infections begin with malvertising on otherwise legitimate websites. Ad blockers also improve performance and reduce tracking.
- Maintain real-time antivirus protection. While antivirus software isn't perfect, a good security suite provides real-time protection against known PUPs and can block suspicious downloads before they execute. Windows Defender is adequate for most users if kept updated, but consider adding Malwarebytes Premium for anti-exploit protection.
- Be skeptical of update notifications. Legitimate software updates through the application itself or Windows Update, not through pop-up browser notifications or emails. If you see an update prompt while browsing, close it and check for updates through the software's official menu or website.
- Create a standard user account for daily use. Running Windows as an administrator gives malware elevated privileges during installation. Create a standard user account for everyday computing and only use an administrator account when installing vetted software or making system changes.
- Review browser extensions regularly. Audit your installed extensions monthly and remove anything you don't actively use or don't remember installing. Extensions have extensive permissions and can modify website content, inject ads, and track browsing behavior.
Bring It In
Manual removal of browser hijackers can be time-consuming and frustrating, especially when the threat uses multiple persistence mechanisms or installed additional payloads you haven't discovered. If you've attempted removal and still experience redirects, or if you're uncomfortable editing the registry and modifying system files, professional help is your fastest path to a clean system. Computer Repair Roswell has specialized tools and experience that make thorough removal significantly faster than DIY approaches.
We're located at 1735 Woodstock Road in Roswell, just minutes from the historic downtown square. Call us at (770) 679-9001 to describe your symptoms and get an estimate, or stop by during business hours — we can often begin work immediately. Our typical turnaround for hijacker removal is same-day, and we'll verify your system is completely clean before returning it. We'll also identify how the infection occurred and give you specific recommendations to prevent reinfection on your particular system.