GetItAllSurvey24.top is a browser-based scam operation that uses deceptive popup notifications and fake survey pages to trick visitors into revealing personal information, subscribing to unwanted services, or installing potentially malicious software. This threat exploits legitimate browser notification features to bombard users with spam even when their browser is closed, creating a persistent nuisance that many people struggle to remove. While not a traditional virus that infects system files, this browser hijacker can significantly compromise your privacy, redirect your web traffic, and open the door to more serious malware infections.
The site typically presents itself as an official survey from well-known companies like Amazon, Walmart, or even government agencies, promising rewards, gift cards, or prizes in exchange for completing a "quick survey." Once users engage with these fraudulent pages, they're often asked to enable push notifications—which then deliver a steady stream of malicious advertisements, phishing links, and fake security warnings directly to their desktop. What makes GetItAllSurvey24.top particularly problematic is how it chains together with other adware components and potentially unwanted programs (PUPs) to create a multi-layered infection that can be difficult for non-technical users to fully eliminate.
Threat Profile
| Attribute | Details |
|---|---|
| Threat Type | Browser Hijacker, Push Notification Spam, Survey Scam, Potentially Unwanted Program (PUP) |
| Aliases | GetItAllSurvey24, Get It All Survey 24 Top, Survey24.top variants |
| Platforms Affected | Windows, macOS, Android, iOS (any device with modern web browsers) |
| Distribution Method | Malvertising, redirect chains, bundled software, social engineering, compromised websites |
| Primary Goal | Affiliate fraud, information harvesting, PPI (pay-per-install) revenue, ad impressions |
| Persistence Mechanism | Browser notification permissions, browser extensions, scheduled tasks (when bundled with PUPs), modified browser shortcuts |
| Data at Risk | Email addresses, phone numbers, postal addresses, browsing habits, payment card information (if entered), login credentials (via phishing redirects) |
| Common Symptoms | Constant popup notifications, browser redirects to survey pages, unexpected new tabs opening, homepage/search engine changes, browser slowdown |
| Associated Threats | Often delivered alongside adware families like Adload (Mac), bundled with browser extensions, may redirect to tech support scams or fake antivirus sites |
| Network Indicators | Connections to getitallsurvey24.top domain, redirects through multiple intermediary domains, tracking pixel loads from ad networks |
| Detection Names | Varies by scanner: PUP.Optional.SurveyScam, Adware.BrowserModifier, potentially flagged as generic browser threat |
| Removal Difficulty | Moderate—browser-level removal is straightforward, but bundled components may require additional system-level cleaning |
How It Spreads
GetItAllSurvey24.top doesn't spread like a traditional computer virus—instead, it relies on tricking users into granting it permission to show notifications or visiting the malicious site in the first place. The operation uses a combination of legitimate advertising networks (through malvertising), compromised legitimate websites, and redirect chains that funnel unsuspecting users to its survey scam pages. Many victims report that they simply clicked a link in a search result or visited a normally trustworthy website when they were suddenly redirected to the survey page without warning.
The most common infection vector involves a multi-step redirect chain where clicking almost anywhere on a compromised page triggers a series of automatic redirects through several intermediary domains before landing on GetItAllSurvey24.top. These redirect chains are designed to evade detection by security software and make it difficult to trace back to the original infection point. Once on the survey page, users face aggressive prompts to "Click Allow to verify you are not a robot" or similar social engineering tactics that disguise the browser notification permission request as a necessary security check.
Common distribution methods include:
- Malicious advertisements on legitimate websites, including news sites, streaming platforms, and even social media—these ads redirect to the scam when clicked or sometimes even when the page loads
- Software bundles where free applications from download portals include browser extensions or adware that changes your default search engine and injects survey scam redirects into your browsing
- Fake browser updates that claim you need to install a critical security patch, but actually deliver adware bundles that redirect to survey scams
- Compromised WordPress sites and other hacked legitimate websites that have malicious JavaScript injected into their pages
- Torrent and piracy sites where every click seems to open a new tab with redirects to survey scams, fake virus warnings, or other deceptive content
- Spam email links disguised as package delivery notifications, prize announcements, or urgent account security messages
- YouTube and social media comment spam with shortened URLs promising free items, exclusive content, or "one weird trick" solutions
What It Does On Your Machine
Once you've granted notification permissions to GetItAllSurvey24.top—often without realizing what you've done—the site gains the ability to push messages directly to your desktop or mobile device even when your browser is closed. These notifications appear identical to legitimate alerts from trusted websites, which is exactly the point. The scam operation uses this access to deliver a constant stream of clickbait headlines, fake security warnings claiming your computer is infected, bogus prize notifications, and links to other malicious sites. Each notification is designed to generate revenue either through affiliate links, by driving traffic to pay-per-click landing pages, or by funneling users toward more serious threats like fake tech support scams or actual malware downloads.
The survey pages themselves employ sophisticated social engineering techniques. They often feature copied logos from legitimate companies, countdown timers creating false urgency ("Only 3 prizes left!"), and fabricated testimonials from supposed previous winners. The surveys ask progressively more invasive questions, starting with seemingly harmless demographic information before requesting email addresses, phone numbers, and even mailing addresses. The end goal varies—sometimes the scam attempts to sign you up for expensive subscription services with hidden fees, other times it harvests your contact information for spam lists that are sold to other scammers, and occasionally it tries to convince you to pay a small "shipping fee" for your "free" prize using a credit card that will then be compromised.
When GetItAllSurvey24.top arrives as part of a larger adware bundle (which is common), the infection becomes more systemic. The bundled components often include browser extensions that monitor your search queries and inject additional advertisements into legitimate web pages, modify search results to prioritize sponsored links, and track your browsing habits to build an advertising profile. Some variants install browser helper objects that change your homepage and default search engine to fake search portals that generate revenue for the attackers while delivering poor-quality results mixed with malicious sponsored content.
In more severe cases, the adware package may include components that create scheduled tasks on Windows or launch agents on macOS to ensure the malicious behavior persists even after you attempt to remove the browser extension. These persistence mechanisms can reinstall the unwanted components, reset your browser settings back to the compromised state, or continue generating malicious notifications through fallback domains if you block the primary one. This is why victims often report that the problem "keeps coming back" even after they think they've removed it—they've only addressed the browser-level symptoms without eliminating the underlying system-level infection.
Manual Removal — Step by Step
Disconnect from the Internet
Unplug your Ethernet cable or disable your WiFi connection. This prevents the malicious site from receiving any further commands, stops new notifications from being delivered, and ensures that any information you entered isn't still being transmitted. If you've provided credit card information, call your bank immediately to report potential fraud before proceeding with the technical removal.
Remove Browser Notification Permissions
Open your browser settings and navigate to the notifications or permissions section. In Chrome, go to chrome://settings/content/notifications; in Firefox, visit about:preferences#privacy and scroll to Permissions. Look for getitallsurvey24.top and any other suspicious domains you don't recognize. Remove them by clicking the three-dot menu next to each entry and selecting "Remove" or "Block." Do this for every browser installed on your system.
Check for Malicious Browser Extensions
In Chrome, go to chrome://extensions; in Firefox, visit about:addons; in Edge, use edge://extensions. Look for any extensions you don't remember installing, especially ones with generic names like "Helper," "Utility," "Manager," or recently installed items with low or no ratings. Remove anything suspicious by clicking "Remove" or "Uninstall." Pay particular attention to extensions that request broad permissions like "read and change all your data on websites you visit."
Reset Browser Settings to Default
Most browsers have a "reset" function that removes unwanted changes without deleting your bookmarks and passwords. In Chrome, go to chrome://settings/reset and choose "Restore settings to their original defaults." In Firefox, use about:support and click "Refresh Firefox." This removes malicious modifications to your homepage, search engine, and startup pages while preserving your essential data. Note that this will disable all extensions, so you'll need to re-enable the legitimate ones afterward.
Check Browser Shortcut Properties (Windows)
Right-click on your browser shortcuts (on desktop, taskbar, and Start menu) and select "Properties." In the "Target" field, verify that it only points to the browser executable without any additional URLs appended after it. If you see something like "chrome.exe http://getitallsurvey24.top" or any web address after the .exe, remove everything after the closing quotation mark around the executable path. Apply the changes and repeat for all browser shortcuts.
Scan with Malwarebytes
Reconnect to the internet and download Malwarebytes (the free version works fine for this) from malwarebytes.com. Install it, update the definitions, and run a full Threat Scan—not a quick scan. This will identify adware components, browser hijackers, and PUPs that may be reinstalling the malicious browser settings. Quarantine or remove everything it finds. A thorough scan typically takes 30-60 minutes depending on your drive size, so let it complete fully.
Check for Scheduled Tasks and Startup Items
On Windows, press Win+R, type "taskschd.msc" and press Enter to open Task Scheduler. Look through the active tasks for anything suspicious, especially items that reference browsers or have names like "BrowserUpdate" or "ServiceHelper" that you didn't create. Right-click and disable or delete suspicious entries. Also check msconfig (Win+R, type "msconfig") under the Startup tab for unfamiliar programs. On Mac, check System Preferences > Users & Groups > Login Items and remove anything suspicious.
Manually Remove Leftover Files (Advanced)
Search your system for recently created folders in %LOCALAPPDATA%, %APPDATA%, and %PROGRAMFILES% (Windows) or ~/Library/Application Support (Mac) that have suspicious names or random alphanumeric identifiers. Use the timestamps—if something was created around the time your infection started, it's worth investigating. Delete any folders associated with the infection that your security scanner didn't catch. Be cautious here; only delete things you're confident are malicious.
Change Your Passwords
If you entered any login credentials on the survey site or any pages it redirected you to, change those passwords immediately from a known-clean device or after completing the removal process. Use unique, strong passwords for each account. If you provided payment information, monitor your credit card statements closely for the next few billing cycles and consider placing a fraud alert with the credit bureaus if you notice unauthorized charges.
Reboot and Verify
Restart your computer normally and open your web browser. Verify that your homepage and search engine are set to your preferred options, that no unexpected notifications appear, and that you're not being redirected to survey pages when you browse. Test browsing for 10-15 minutes across several different websites. If everything seems normal, run one more quick scan with Malwarebytes to confirm the system is clean. If problems persist, the infection may be more deeply embedded than manual removal can address.
Prevention
- Never click "Allow" on notification prompts unless you're absolutely certain you want notifications from that specific website. Legitimate sites don't require notification permissions to function or to prove you're not a robot. When in doubt, click "Block" or simply close the prompt.
- Keep your browser and operating system fully updated. Many exploit chains that lead to survey scams rely on outdated browser vulnerabilities. Enable automatic updates for both your OS and all installed browsers so you receive security patches as soon as they're available.
- Install an ad blocker and consider anti-malware browser extensions. Extensions like uBlock Origin can prevent many malicious advertisements and redirects from loading in the first place. Some security vendors also offer browser extensions that specifically detect and block known scam sites before you reach them.
- Download software only from official sources. Avoid third-party download portals, torrent sites, and "free software" repositories that bundle legitimate applications with adware. When you must use these sources, choose the "custom" installation option and carefully uncheck any bundled offers for additional software, browser extensions, or toolbar installations.
- Be skeptical of too-good-to-be-true offers. No legitimate company gives away expensive prizes for answering a few survey questions. If you see claims about winning an iPhone, a $1000 gift card, or being "selected" as a special visitor, it's a scam. Legitimate surveys for market research don't operate this way.
- Review your browser extensions regularly. Make it a habit to check your installed extensions every few months. Remove anything you don't actively use or don't remember installing. Extensions can be compromised or sold to malicious actors after you install them, so even previously safe extensions may become threats.
- Use separate, limited email addresses for online forms. When a website requires an email address, consider using a disposable or secondary email account rather than your primary one. This limits the damage if your address is harvested for spam lists and helps you identify which services are sharing or selling your information.
- Educate everyone who uses your computer. Family members, especially children and elderly users, are often targeted by these scams because they're less familiar with the tactics. Make sure everyone understands not to click "Allow" on strange prompts, not to enter personal information on unsolicited survey pages, and to ask before downloading anything.
When Computer Repair Roswell removes GetItAllSurvey24.top or any malware from your system, we back our work with a 90-day reinfection warranty. If the same threat comes back within three months, we'll remove it again at no additional charge. That's how confident we are in our thorough removal process—we don't just delete what we can see, we eliminate the persistence mechanisms and vulnerabilities that let it return.
Bring It In
GetItAllSurvey24.top infections often come bundled with multiple layers of adware, browser hijackers, and potentially unwanted programs that can be challenging to fully remove without professional tools and experience. Even when the obvious symptoms disappear, hidden components may remain dormant, ready to reinstall the malicious settings or open the door for additional threats. If you've followed the removal steps above and still see suspicious behavior—unexpected redirects, persistent popups, browser slowdowns, or settings that keep reverting to unwanted configurations—your system likely has a more complex infection that requires professional attention.
Computer Repair Roswell has been cleaning infected systems for Roswell residents and businesses since our doors opened. We see these survey scam infections regularly, and our technicians know exactly where these threats hide their persistence mechanisms and how to eliminate every component without damaging your legitimate software. We'll thoroughly scan your system with multiple professional-grade tools, remove all traces of the infection, verify your browser settings are secure, and check that no information theft has occurred. Bring your computer to our shop at 1394 East Woodstock Road in Roswell, or give us a call at (770) 569-2723 to discuss your specific situation. We offer same-day service for most malware removals, and remember—if it comes back within 90 days, we fix it free.