MilitantWitnessFelonCom is a browser hijacker that forcibly redirects users to dubious websites, manipulates search results, and injects unwanted advertisements into web browsing sessions. This potentially unwanted program typically enters systems bundled with freeware installations and immediately modifies browser settings without user consent. While not as destructive as ransomware or data-stealing trojans, MilitantWitnessFelonCom degrades system performance, compromises privacy by tracking browsing habits, and exposes users to potentially malicious sites through aggressive redirection schemes.

MilitantWitnessFelonCom — cybersecurity illustration
Photo by Ann H on Pexels
Think you're infected right now? Disconnect from the internet if you're seeing constant redirects or pop-ups. Do not enter passwords or financial information in your browser until the infection is removed. Call us at (770) 559-9587 or bring your machine to our Roswell shop—we can typically clean browser hijackers same-day and verify your system is truly clean.

Threat Profile

Attribute Details
Threat Family Browser Hijacker / Potentially Unwanted Program (PUP)
Aliases Militantwitnessfelon, Militant Witness Felon redirect, MilitantWitnessFelonCom adware
Platform Windows 7/8/10/11 (primarily affects Chrome, Firefox, Edge)
Distribution Method Software bundling, fake update prompts, deceptive download buttons
Persistence Mechanism Browser extension installation, shortcut modification, scheduled tasks, registry Run keys
Primary Capabilities Homepage/search engine hijacking, traffic redirection, ad injection, tracking cookie installation
Data Collection Browsing history, search queries, IP address, device identifiers, clicked links
Typical Artifacts Unknown browser extensions, modified browser shortcuts with appended URLs, new default search provider
Network Behavior Frequent connections to ad-serving domains, redirect chains through multiple intermediary sites
Associated Domains militantwitnessfelon[.]com and various rotating redirect endpoints
Payload Delivery May download additional PUPs or adware components after initial infection
Removal Difficulty Moderate—requires browser cleanup, extension removal, and registry/shortcut restoration

How It Spreads

MilitantWitnessFelonCom primarily spreads through software bundling, a deceptive distribution tactic where the hijacker is packaged with legitimate-looking freeware. Users downloading video converters, PDF tools, or download managers from third-party sites often encounter installation wizards that use pre-checked boxes or "Express Install" options to silently include unwanted programs. The hijacker's developers rely on users clicking through installation screens without reading the fine print or noticing the additional "offers" being accepted.

Fake update notifications represent another common infection vector. Users may encounter browser pop-ups claiming their Flash Player, video codec, or browser itself needs updating. These fraudulent prompts lead to downloads that bundle MilitantWitnessFelonCom with the supposed update. Similarly, deceptive download buttons on file-sharing sites and torrent platforms trick users into downloading the hijacker instead of their intended file.

The hijacker also spreads through malicious advertising (malvertising) on legitimate websites and through email attachments disguised as invoices or shipping notifications. Once a user opens the attachment or clicks the malicious ad, the installation process begins automatically.

  • Software bundles — Hidden in installers for free utilities, especially from download portals like Softonic, Download.com (when not carefully vetted), or torrent packages
  • Fake update prompts — Bogus Flash Player, Java, or browser update notifications appearing during web browsing
  • Deceptive download buttons — Misleading "Download" buttons on file-sharing sites that install the hijacker instead of the desired file
  • Malvertising campaigns — Compromised ad networks serving malicious advertisements that trigger drive-by downloads
  • Email attachments — Disguised as legitimate documents but containing installer scripts
  • Cracked software — Pirated applications bundled with browser hijackers as a monetization method

What It Does On Your Machine

Once installed, MilitantWitnessFelonCom immediately modifies your browser configuration to establish control over your web experience. The hijacker changes your homepage, default search engine, and new tab page to redirect through its controlled domains. These changes persist even after you manually revert them because the hijacker modifies browser shortcuts by appending command-line arguments that force the unwanted URLs to load on startup. If you right-click your browser shortcut and check Properties, you might see something like "C:\Program Files\Google\Chrome\Application\chrome.exe" http://militantwitnessfelon.com in the Target field—that trailing URL is the hijacker's work.

The primary function of MilitantWitnessFelonCom is traffic monetization. Every redirect generates revenue for its operators through pay-per-click advertising schemes and affiliate commissions. When you attempt to search using a legitimate search engine, the hijacker intercepts your query, routes it through its servers to collect data, then either displays modified search results filled with sponsored links or redirects you through a chain of intermediate sites before eventually landing on a search results page. This redirection chain serves multiple purposes: it obscures the hijacker's infrastructure, allows multiple parties in the affiliate chain to collect referral fees, and provides opportunities to track your behavior across sites.

Beyond search manipulation, MilitantWitnessFelonCom injects advertisements into websites you visit. You may see additional banner ads, pop-unders (ads that open in new windows behind your current browser), or in-text ads where random words become hyperlinks. The hijacker also tracks your browsing activity extensively—recording which sites you visit, what you search for, how long you spend on pages, and what you click. This data gets packaged and sold to advertising networks or used to serve you targeted ads. While browser hijackers typically don't steal passwords or banking credentials directly, the tracking they perform represents a significant privacy violation.

System performance suffers noticeably with MilitantWitnessFelonCom active. The constant redirection, ad injection, and background tracking consume memory and processor cycles, making your browser sluggish. Page load times increase because every request gets routed through the hijacker's infrastructure. Your machine may also download additional unwanted programs automatically as the hijacker attempts to install companion adware or search toolbars to maximize revenue generation.

Typical MilitantWitnessFelonCom Artifacts
# Browser extension (name varies, often installed without appearing in Extensions list) C:\Users\\AppData\Local\Google\Chrome\User Data\Default\Extensions\\ # Modified browser shortcuts with appended URLs Target: "C:\Program Files\Google\Chrome\Application\chrome.exe" http://militantwitnessfelon.com # Scheduled task for persistence \Task Scheduler Library\BrowserUpdateTask # Registry Run key for auto-start component HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ BrowserHelper = "%LOCALAPPDATA%\\bhelper.exe" # Modified search engine preferences (JSON file) C:\Users\\AppData\Local\Google\Chrome\User Data\Default\Preferences Contains modified default_search_provider settings

Manual Removal — Step by Step

01

Disconnect and Document Current State

Before making changes, take screenshots of your browser's homepage, new tab page, and default search engine settings. Note any unfamiliar extensions. Disconnect from the internet (unplug Ethernet or disable Wi-Fi) to prevent the hijacker from downloading additional components or communicating with command servers during the removal process.

02

Uninstall Suspicious Programs

Open Settings > Apps > Apps & features (Windows 10/11) or Control Panel > Programs and Features (Windows 7/8). Sort by install date and look for recently installed programs you don't recognize, especially those installed on the same date you first noticed the browser hijacking. Uninstall anything suspicious, particularly programs with generic names or those from unknown publishers. The hijacker may not appear here, but companion programs often do.

03

Remove Malicious Browser Extensions

Open each installed browser (Chrome, Firefox, Edge) and access the extensions/add-ons manager. In Chrome, navigate to chrome://extensions and enable Developer Mode to see all extensions. Remove any extensions you didn't intentionally install, especially those without proper names, with generic icons, or that request excessive permissions. MilitantWitnessFelonCom may install extensions that don't appear in the normal list, which is why enabling Developer Mode is important.

04

Fix Browser Shortcuts

Right-click each browser shortcut on your desktop, taskbar, and Start menu, then select Properties. In the Target field, verify it points only to the browser executable without any trailing URLs. The correct target for Chrome should end with chrome.exe" with nothing after the closing quote. Delete any appended web addresses. Repeat this for all browser shortcuts you use.

05

Reset Browser Settings

In each browser, access settings and perform a reset to defaults. In Chrome, go to Settings > Reset settings > Restore settings to their original defaults. In Firefox, use Help > More troubleshooting information > Refresh Firefox. In Edge, navigate to Settings > Reset settings > Restore settings to their default values. This removes unauthorized search engines, restores your homepage, and clears hijacked settings while preserving passwords and bookmarks.

06

Delete Scheduled Tasks

Press Win+R, type taskschd.msc, and press Enter to open Task Scheduler. Look through Task Scheduler Library for tasks with unfamiliar names, especially those set to run at login or hourly that point to executable files in AppData or Temp folders. Right-click suspicious tasks and select Delete. Common hijacker task names include variations of "BrowserUpdate," "ChromeHelper," or random alphanumeric strings.

07

Clean Registry Startup Entries

Press Win+R, type regedit, and press Enter. Navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and review all entries. Delete any that reference unfamiliar executables in AppData, Temp, or user profile folders. Repeat for HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run. Be cautious—only remove entries you can confirm are associated with the hijacker, not legitimate startup programs.

08

Delete Hijacker Files

Open File Explorer and enable viewing of hidden files (View tab > Hidden items checkbox). Navigate to %LOCALAPPDATA% and %APPDATA% and look for recently created folders with random or generic names. Delete folders containing executables that match the scheduled tasks or registry entries you removed. Also check %TEMP% for installer remnants and delete the entire contents of the Temp folder.

09

Run Reputable Anti-Malware Scanner

Reconnect to the internet and download Malwarebytes (the free version works fine for a single cleanup). Run a full system scan to catch any components manual removal might have missed. Browser hijackers often install multiple persistence mechanisms, and a thorough scanner will find registry entries, browser databases, and files that aren't obvious during manual inspection. Quarantine and remove everything it detects.

10

Verify and Monitor

Restart your computer and open your browsers to verify that homepages, search engines, and new tab pages are back to your preferences. Browse normally for a day while watching for any return of redirects or injected ads. Check Task Manager (Ctrl+Shift+Esc) periodically for unfamiliar processes. If symptoms return, the hijacker likely has a persistence mechanism you missed—that's when professional help becomes valuable.

Prevention

  1. Download software only from official sources. Avoid third-party download sites like Softonic, Download.com freeware sections, and file-sharing platforms. Get programs directly from the developer's website or Microsoft Store.
  2. Always choose Custom/Advanced installation. Never click "Express Install" or "Recommended Settings" when installing free software. Custom installation reveals bundled offers and pre-checked boxes that install unwanted programs. Uncheck everything except the program you actually want.
  3. Keep browsers and extensions minimal. Only install extensions from official stores (Chrome Web Store, Firefox Add-ons) and limit yourself to extensions you actively use. Review installed extensions monthly and remove any you don't recognize or no longer need.
  4. Maintain updated security software. A reputable antivirus with real-time protection (Windows Defender is adequate if kept updated) can block many PUP installers before they execute. Enable real-time protection and keep definitions current.
  5. Ignore update prompts in browser windows. Legitimate software updates come through the program itself (Help > Check for updates) or Windows Update, not through pop-up windows while browsing. If you see a Flash Player or codec update prompt in a browser window, close it and manually check for updates through official channels.
  6. Use a standard user account for daily work. Running Windows with administrator privileges allows software to install system-wide without prompting. A standard user account forces elevation prompts for installations, giving you a chance to catch unwanted programs before they install.
  7. Enable browser security features. Turn on Google Safe Browsing (or equivalent in other browsers), disable automatic downloads, and configure your browser to ask where to save each file instead of auto-saving to Downloads. These small friction points give you opportunities to catch malicious activity.
  8. Scan downloaded files before opening. Before running any installer, right-click it and select "Scan with [your antivirus]." Wait for the scan to complete. This catches many bundled PUPs that slip past real-time protection.
Our 90-Day Warranty: When Computer Repair Roswell removes malware from your system, that specific threat stays gone. If MilitantWitnessFelonCom or any other malware we've cleaned returns within 90 days, we'll remove it again at no charge. We stand behind our work because we do it right the first time—complete removal, not just symptom suppression.

Bring It In

Browser hijackers like MilitantWitnessFelonCom are frustrating precisely because they seem simple but often hide multiple persistence mechanisms that regenerate the infection after seemingly successful removal. If you've followed these manual steps and still see redirects, or if you're simply not comfortable editing the registry and task scheduler, bring your computer to our Roswell shop at 1785 Old Alabama Road. We'll thoroughly clean the infection, verify complete removal with multiple scanning tools, and check for the additional malware that browser hijackers sometimes download silently.

Most browser hijacker removals take 1-2 hours, and we can often complete them while you wait or within the same business day. Call us at (770) 559-9587 to describe your symptoms—we can usually tell you over the phone whether this is a straightforward cleaning or if your situation suggests a more serious infection that came bundled with the hijacker. Either way, we'll get your browser working properly again and show you exactly what we found so you know what to avoid in the future.