GetProtecteds.com is a browser hijacker that forcibly redirects your web searches and homepage to its own search portal, which then feeds you through a chain of questionable advertising networks. While not as destructive as ransomware or banking trojans, this hijacker can seriously disrupt your browsing experience, expose you to scam advertisements, and track your search queries for marketing purposes. Most users discover they have it when their browser suddenly starts opening to an unfamiliar search page despite repeatedly changing their settings back.

GetProtecteds.com — cybersecurity illustration
Photo by John (Giannis) Tekeridis on Pexels

This hijacker typically arrives bundled with free software downloads—particularly media converters, PDF tools, and download managers from third-party hosting sites. Once installed, it modifies browser shortcuts, changes default search engines, and can reinstall itself even after you think you've removed it. The persistence mechanisms make manual removal tricky for the average user, which is exactly what we'll walk you through in this guide.

Think you're infected right now? Disconnect from the internet if you're in the middle of entering passwords or payment information. GetProtecteds.com primarily hijacks browsers rather than stealing credentials directly, but the redirected search results can lead to phishing sites. If you've already entered sensitive information on an unfamiliar site after being redirected, consider changing those passwords from a known-clean device. For immediate professional help, call Computer Repair Roswell at (770) 954-1480.

Threat Profile

Attribute Details
Threat Family Browser Hijacker / Potentially Unwanted Program (PUP)
Aliases GetProtecteds, Get-Protecteds.com redirect, GetProtecteds Search
Target Platform Windows (7, 8, 10, 11); affects Chrome, Firefox, Edge, and other Chromium-based browsers
First Observed Variants of this hijacker family have circulated since approximately 2018-2019
Distribution Method Software bundling, fake update prompts, deceptive advertisements, freeware installers
Persistence Mechanism Modified browser shortcuts (target field injection), browser extension installation, search engine/homepage policy changes, scheduled tasks (in some variants)
Primary Capabilities Search query redirection, homepage replacement, new tab hijacking, tracking cookie installation, ad injection
Typical Artifacts Browser extensions with random names, modified Chrome/Firefox profiles, altered desktop shortcuts with appended URLs, registry keys controlling browser policies
Network Behavior Redirects through multiple domains (getprotecteds.com → intermediate ad networks → final search page), communicates with tracking servers to report search queries
Data Collection Search terms, browsing history, clicked links, IP address, browser type, general geographic location
Payload Severity Low to Moderate (does not encrypt files or steal banking credentials, but creates security risks through exposure to malicious advertisements)
Removal Difficulty Moderate (reinstalls itself if all components aren't removed; requires cleaning browser settings, shortcuts, and extensions)

How It Spreads

GetProtecteds.com spreads almost exclusively through software bundling, a practice where legitimate-looking free programs include "optional" software in their installers that's actually selected by default. When users rush through installation screens clicking "Next" without reading, they inadvertently agree to install the hijacker alongside the program they actually wanted. The bundling is often disguised in the "Custom" or "Advanced" installation options that most people skip.

Third-party download sites are the primary culprits here. Even if you're downloading a well-known program like a PDF reader or video converter, sites like Softonic, Download.com (in some cases), and various "free software" portals wrap the original installer in their own bundle-loader that includes GetProtecteds.com and similar unwanted programs. The original software developer often has no involvement in this bundling—it's added by the distribution platform to monetize the download.

Common distribution vectors include:

  • Freeware installers from third-party sites — Download managers, media converters, codec packs, and PC optimization tools frequently carry hijacker bundles
  • Fake software update notices — Pop-ups claiming your Flash Player, Java, or browser needs updating, leading to installer downloads that include the hijacker
  • Malicious advertisements on torrent sites and streaming platforms — "Download" or "Play" buttons that aren't actually for the content you want
  • Email attachments disguised as document viewers — Emails claiming you need to install a viewer to see an attached document or invoice
  • Browser extension stores (unofficial or compromised) — Extensions that promise features like weather updates or quick converters but actually install the hijacker
  • Peer-to-peer file sharing networks — Executables downloaded through torrents or file-sharing programs that include the hijacker bundled with cracked software

What It Does On Your Machine

Once installed, GetProtecteds.com immediately goes to work changing your browser's behavior. The first thing you'll notice is that your homepage—the page that opens when you launch your browser—has been changed to getprotecteds.com or a similar domain. Your default search engine gets replaced too, so when you type queries into the address bar, they're sent through the hijacker's search portal instead of Google, Bing, or whatever you had configured. Even your new tab page can be affected, opening to the hijacker's page instead of a blank tab or your preferred start page.

The hijacker achieves this persistence through multiple mechanisms working together. It often installs a browser extension with a generic name like "Helpful Search" or "Quick Search Tool" that enforces the settings changes. More insidiously, it modifies your browser shortcuts—the icons on your desktop and taskbar—by appending the hijacker URL to the target field. This means even if you manually change your homepage back in browser settings, the shortcut will still launch with the hijacker page forced open. Some variants also modify Chrome or Firefox policy files to prevent you from changing certain settings through the normal preferences interface.

Beyond the obvious redirects, GetProtecteds.com tracks your search behavior. Every query you type, every result you click, gets logged and sent back to tracking servers. This data builds a profile of your interests, demographics, and browsing habits that gets sold to advertising networks. The search results page itself is designed to look somewhat legitimate—it may even display actual search results pulled from a real search engine—but it inserts sponsored links and advertisements at the top, often without clear labeling. These sponsored results can lead to scam sites, fake tech support pages, or additional PUP downloads.

The real danger isn't the hijacker itself, but where it leads you. Users have reported being redirected to fake virus warnings ("Your PC has 5 viruses! Call this number!"), phishing pages that mimic banking sites, and download pages for fake software that contains actual malware. The hijacker creates a gateway that exposes you to a much broader range of threats than the simple search redirection would suggest.

Typical GetProtecteds.com Artifacts
Browser Extension: C:\Users\[Username]\AppData\Local\Google\Chrome\User Data\Default\Extensions\[random-ID]\ # Extension folder with random identifier, contains manifest.json with search override Modified Shortcut Target: "C:\Program Files\Google\Chrome\Application\chrome.exe" http://getprotecteds.com # Desktop and taskbar shortcuts have URL appended to legitimate program path Registry Keys (Varies): HKCU\Software\Policies\Google\Chrome\HomepageLocation HKCU\Software\Policies\Google\Chrome\DefaultSearchProviderSearchURL # Policy keys that override user preferences Scheduled Task (Some Variants): Task Name: "Browser Update Check" or similar generic name Action: Runs script to re-apply hijacker settings periodically

Manual Removal — Step by Step

01

Disconnect and Document

Disconnect your computer from the internet to prevent the hijacker from communicating with its control servers during removal. Take screenshots of your current homepage and default search engine settings so you know what to restore later. Make a note of any unfamiliar browser extensions you see installed.

02

Uninstall Suspicious Programs

Open Windows Settings (or Control Panel on older systems) and go to Apps & Features. Sort by install date and look for programs installed around the time the hijacking started. Remove anything you don't recognize, particularly items with generic names like "Search Manager," "Web Helper," or anything containing "Protected" or "Safe." Uninstall these completely—don't just disable them.

03

Remove Browser Extensions

Open your browser's extension management page (chrome://extensions/ for Chrome, about:addons for Firefox, edge://extensions/ for Edge). Enable "Developer mode" to see all details. Remove any extensions you didn't intentionally install, paying special attention to those with names related to search, toolbars, or helpers. Even if an extension seems legitimate, remove it if you don't remember installing it yourself.

04

Reset Browser Settings

In Chrome, go to Settings → Reset settings → Restore settings to their original defaults. In Firefox, go to Help → More Troubleshooting Information → Refresh Firefox. In Edge, Settings → Reset settings → Restore settings to their default values. This removes the search engine changes and homepage modifications while preserving your bookmarks and passwords. You'll need to reconfigure any custom settings you had.

05

Fix Your Browser Shortcuts

Right-click each browser shortcut on your desktop and taskbar, select Properties, and examine the Target field. It should contain ONLY the path to the browser executable—nothing more. If you see any URLs appended after the .exe, delete everything after the closing quotation mark. Click Apply and OK. Do this for every browser shortcut you have, including ones pinned to the Start menu.

06

Check Scheduled Tasks

Open Task Scheduler (type "task scheduler" in the Windows search box). Look through the Task Scheduler Library for any tasks with generic names or tasks that run browser-related commands you don't recognize. Right-click and delete any suspicious scheduled tasks, particularly those created around the same date as your infection. Legitimate Windows and software update tasks usually have clear, professional names from recognized publishers.

07

Clean Registry Policies (Advanced)

Press Windows+R, type "regedit" and press Enter to open Registry Editor. Navigate to HKEY_CURRENT_USER\Software\Policies and look for keys related to your browsers (Chrome, Firefox, Edge). If you see keys setting homepage, search provider, or other browser behaviors that you didn't configure through enterprise management, delete those keys. Be careful—only remove keys you're certain are hijacker-related. If you're not comfortable with registry editing, skip this step and use the scanner in the next step instead.

08

Run Malwarebytes or Similar Scanner

Reconnect to the internet and download Malwarebytes Free (from malwarebytes.com directly—nowhere else). Install and run a full system scan. Malwarebytes specifically targets PUPs and hijackers like GetProtecteds.com and will catch components you might have missed manually. Let it quarantine everything it finds. Restart when prompted. Consider running a second scan with AdwCleaner (also from Malwarebytes) for additional coverage.

09

Verify and Test

Open your browser and confirm your homepage is back to what you want. Type a search query in the address bar and verify it goes to your intended search engine. Open a new tab and confirm it behaves normally. Check your browser's search engine settings (usually under Settings → Search engine) and verify only your chosen search engine is listed—remove any entries for getprotecteds or unfamiliar search providers.

10

Change Passwords (If Necessary)

If you entered any passwords or sensitive information while the hijacker was active—especially if you were redirected to unfamiliar login pages—change those passwords from a known-clean device or after you've confirmed your system is clean. While GetProtecteds.com doesn't typically include keylogging functionality, the redirects it creates can lead to phishing sites that do capture credentials.

Prevention

  1. Download software only from official sources. Get programs directly from the developer's website, not from third-party download portals. If you must use a site like CNET Download or Softonic, choose the "Direct Download" option when available and always select Custom installation to see what's bundled.
  2. Read every installer screen carefully. Don't rapid-fire click "Next" through installation wizards. Look for pre-checked boxes offering "recommended" software, browser toolbars, or homepage changes. Choose "Custom" or "Advanced" installation instead of "Express" or "Recommended" to see all optional components.
  3. Keep a reputable ad-blocker installed. Browser extensions like uBlock Origin block malicious advertisements that lead to hijacker downloads. They also prevent fake update notices and deceptive "Download" buttons on shady sites. This single step prevents a significant percentage of PUP infections.
  4. Ignore unsolicited update prompts. If a website tells you that you need to update Flash, Java, your video player, or anything else to view content, close the tab. Go directly to the official website for that software if you genuinely need an update. Flash is dead anyway and should be uninstalled entirely.
  5. Use Windows built-in security. Windows Defender (now called Microsoft Defender) on Windows 10 and 11 is quite capable and includes real-time protection that can block many PUP installers. Keep Windows Update enabled so you receive the latest threat definitions.
  6. Be skeptical of browser extensions. Only install extensions from the official Chrome Web Store, Firefox Add-ons site, or Edge Add-ons store—never from third-party sites. Even then, read reviews and check the number of users. A brand-new extension with zero reviews offering amazing features is probably malicious.
  7. Maintain regular backups. While browser hijackers don't typically damage files, having backups means you can restore to a known-clean state if something more serious sneaks in alongside the PUP. Use Windows File History or a third-party backup solution to protect your important documents.
  8. Educate other users on your computer. If family members or employees use the same machine, make sure they understand not to install random programs. Many infections happen because one person on a shared computer fell for a "free PC cleaner" advertisement or installed a game with bundled malware.
Our 90-Day Warranty: When Computer Repair Roswell removes malware from your system, we back our work with a 90-day warranty. If the same threat returns within 90 days, we'll remove it again at no charge. We don't just delete files—we identify how the infection got in, close that door, and make sure your system is truly clean. Most DIY removal attempts miss something, which is why hijackers like GetProtecteds.com keep coming back.

Bring It In

If you've followed these steps and GetProtecteds.com keeps reappearing, or if you're seeing other suspicious behavior like pop-ups, slowness, or unfamiliar programs running, you're dealing with a more complex infection that needs professional attention. Browser hijackers often travel in packs—where there's one PUP, there are usually several more hiding in startup folders, services, and obscure registry locations. Computer Repair Roswell has removed thousands of these infections from Roswell-area computers, and we have the tools and experience to find every component.

Bring your computer to our shop at 535 South Atlanta Street in Roswell, or give us a call at (770) 954-1480 to discuss your situation. We offer free diagnostics, so there's no charge just to find out what you're dealing with. Most hijacker removals are completed same-day, and we'll explain exactly what was on your system and how to avoid it in the future. We also service both PCs and Macs, handle everything from viruses to hardware failures, and provide honest assessments—if your issue is something you can handle yourself, we'll tell you. We're here to help Roswell stay secure, one computer at a time.