GetSecures.com is a browser hijacker that forcibly redirects your web searches and homepage to its own search engine, often bundled with free software downloads or disguised as a legitimate security tool. Unlike more destructive malware like ransomware or trojans, GetSecures.com primarily aims to generate advertising revenue by controlling your browsing experience and collecting data on your search habits. While not inherently dangerous in the traditional sense, this hijacker degrades system performance, compromises your privacy, and exposes you to potentially malicious advertising networks that could lead to more serious infections.
Threat Profile
| Attribute | Details |
|---|---|
| Threat Classification | Browser Hijacker / Potentially Unwanted Program (PUP) |
| Family | Search redirect hijacker family |
| Affected Platforms | Windows (all versions), macOS; targets Chrome, Firefox, Edge, Safari |
| Distribution Method | Software bundling, fake software updates, malicious browser extensions |
| Primary Capability | Search and homepage redirection, advertising injection, data collection |
| Persistence Mechanism | Browser extension installation, Windows registry modifications, scheduled tasks, browser policy enforcement |
| Data at Risk | Browsing history, search queries, IP address, system information, potentially credentials via phishing redirects |
| Network Behavior | Connects to advertising networks, tracking domains, and sponsored search partners; generates revenue through click fraud |
| Common Aliases | Get Secures, GetSecures Search, Secures Browser Helper |
| Typical Artifacts | Browser extensions with randomized names, modified browser shortcuts, registry keys enforcing homepage settings |
| Removal Difficulty | Moderate — uses multiple persistence mechanisms and may reinstall itself if not completely removed |
| Payload Severity | Low to moderate — primarily nuisance and privacy concern, but can facilitate secondary infections |
How It Spreads
GetSecures.com rarely arrives on your system through an honest installation process. The most common infection vector is software bundling, where the hijacker piggybacks on legitimate free software installers. When you download a video converter, PDF reader, or system utility from a third-party download site, the installer may include GetSecures.com as an "optional offer" that's pre-checked or hidden in a custom installation screen. Users who quickly click through the installation using the Express or Recommended options inadvertently authorize the hijacker's installation.
Fake software update notifications represent another major distribution channel. You might see a convincing pop-up claiming your Flash Player, browser, or video codec needs updating. Clicking the update button downloads not a legitimate patch but an installer package containing GetSecures.com along with other potentially unwanted programs. These fake updates often appear on sketchy streaming sites, torrent pages, or compromised legitimate websites.
Additional distribution methods include:
- Malicious browser extensions: Extensions advertised as security tools, ad blockers, or productivity helpers that actually install the hijacker
- Email attachments: Executable files disguised as invoices, shipping notifications, or document files
- Compromised download mirrors: Popular software repackaged with the hijacker and distributed through unofficial download sites
- Social engineering tactics: Tech support scam sites that claim your system is infected and offer a "security tool" that's actually the hijacker
- Malvertising campaigns: Legitimate advertising networks compromised to serve malicious ads that trigger drive-by downloads
- Software cracks and keygens: Pirated software installers deliberately bundled with hijackers and other malware
What It Does On Your Machine
Once installed, GetSecures.com immediately modifies your browser settings to redirect all searches through its own search engine. Your homepage, new tab page, and default search engine all point to GetSecures.com or one of its associated domains. When you attempt to search for anything, your query passes through the hijacker's servers before eventually displaying results—often Bing or Yahoo results wrapped in the hijacker's interface, complete with injected advertisements and sponsored links.
The hijacker establishes multiple persistence mechanisms to prevent easy removal. It creates browser extensions that may not appear in your normal extensions list, modifies browser policy settings that override your preferences, and adds registry keys that automatically restore the hijacked settings if you manually change them. On some systems, GetSecures.com installs a scheduled task that periodically checks whether its components are still active and reinstalls them if they've been removed.
Throughout its operation, GetSecures.com collects extensive data about your browsing habits. Every search query, every website you visit, your IP address, your system configuration, and your browser fingerprint all get transmitted to remote servers. This data serves both to customize the advertisements you see and to be sold to third-party marketing companies. More concerning is that the hijacker often redirects users to sketchy advertising networks and affiliate sites that themselves may host more dangerous threats.
Performance degradation becomes noticeable as the hijacker runs. Your browser loads pages more slowly because each request must route through the hijacker's redirection chain. The injected advertising scripts consume system resources and memory. Your startup time increases because the hijacker's components load during boot. Users frequently report that their browsers become unstable, crashing more often or freezing when loading certain pages.
Manual Removal — Step by Step
Disconnect and Document
Disconnect your computer from the internet by unplugging the Ethernet cable or disabling Wi-Fi. Take screenshots of any unfamiliar programs in your Control Panel (Windows) or Applications folder (Mac) and note any suspicious browser extensions before you begin removal. This documentation helps identify what changed and ensures you remove all components.
Boot Into Safe Mode
Restart your computer in Safe Mode with Networking (Windows: hold Shift while clicking Restart, then navigate to Troubleshoot > Advanced Options > Startup Settings > Restart > press F5; Mac: restart and hold Shift immediately). Safe Mode prevents most of the hijacker's components from loading automatically, making removal easier and reducing the chance that it will reinstall itself while you're working.
Uninstall Suspicious Programs
Open your Control Panel (Windows) or Applications folder (Mac) and uninstall any programs installed around the time the hijacking started. Look for anything named "GetSecures," "Secures Helper," "Browser Protection," or similar. Also remove any unfamiliar toolbars, system optimizers, or security programs you didn't deliberately install. Some hijackers install under generic names like "Utility Manager" or use random character strings.
Remove Browser Extensions
Open each of your browsers and completely remove all extensions—especially any you don't recognize or didn't install yourself. In Chrome, go to chrome://extensions/; in Firefox, click Menu > Add-ons; in Edge, go to edge://extensions/. Remove anything suspicious, then restart the browser. GetSecures.com often installs extensions with legitimate-sounding names like "Safe Search" or "Privacy Guard" to avoid detection.
Reset Browser Settings
Reset each browser to its default settings to remove hijacker modifications. In Chrome: Settings > Reset Settings > Restore settings to their original defaults. In Firefox: Help > More Troubleshooting Information > Refresh Firefox. In Edge: Settings > Reset Settings > Restore settings to their default values. This removes the hijacked homepage, search engine, and startup page settings while preserving your bookmarks and passwords.
Check Browser Shortcuts
Right-click each browser shortcut (on your desktop, taskbar, and Start menu), select Properties, and examine the Target field. If you see anything after the .exe file path—especially URLs or additional parameters—delete everything after the closing quotation mark that follows the .exe. Hijackers often append their redirect URLs to browser shortcuts so they load even after you've cleaned the browser settings.
Clean Registry and Scheduled Tasks
Press Windows+R, type "taskschd.msc," and delete any scheduled tasks with suspicious names (anything related to "Secures," "Update," or random character strings that run at login). Then press Windows+R, type "regedit," and navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. Delete any entries you don't recognize. Be cautious—only remove entries you're confident are malicious.
Delete Hijacker Folders
Navigate to C:\Users\[YourUsername]\AppData\Local\ and C:\Users\[YourUsername]\AppData\Roaming\ and delete any folders related to GetSecures or with names matching the suspicious programs you uninstalled earlier. You may need to show hidden files (View menu > Hidden items checkbox). Also check C:\Program Files\ and C:\Program Files (x86)\ for related folders.
Run Reputable Anti-Malware Scanners
Download and run Malwarebytes (the free version works fine) and perform a full system scan. Also run a scan with your existing antivirus if you have one. Malwarebytes specifically excels at detecting browser hijackers and PUPs that traditional antivirus might miss. Remove everything the scanners identify, then run a second scan to confirm your system is clean.
Change Passwords and Verify
After confirming the removal, change passwords for any accounts you accessed while infected, particularly email, banking, and social media accounts. Reconnect to the internet and monitor your browser behavior for several days. If search redirects return or your homepage changes again, the hijacker wasn't completely removed—in that case, bring the machine to us for a professional cleaning.
Prevention
- Download software only from official sources: Avoid third-party download sites like Download.com, Softonic, or Tucows. Always download directly from the developer's official website or from verified sources like the Microsoft Store or Apple App Store.
- Read installation screens carefully: Always choose Custom or Advanced installation options instead of Express or Recommended. Uncheck any boxes offering additional software, toolbars, or homepage changes. If an installer won't let you decline bundled software, cancel the installation entirely.
- Keep your software updated legitimately: Enable automatic updates for your operating system and browsers. Never click on pop-up update notifications while browsing—these are almost always fake. Real updates come through your system's built-in update mechanism or the application's own update checker.
- Use an ad blocker: Install a reputable ad-blocking extension like uBlock Origin to prevent malicious advertisements from displaying. This blocks many of the fake download buttons and update notifications that lead to hijacker infections.
- Maintain active antivirus protection: Keep a reputable antivirus or anti-malware program running with real-time protection enabled. Windows Defender (built into Windows 10 and 11) provides solid baseline protection if kept updated. Consider adding Malwarebytes Premium for enhanced PUP detection.
- Be skeptical of security warnings: Legitimate security alerts come from your installed security software, not from websites. If a website claims your system is infected or your software is outdated, close the browser tab immediately—don't click anything on the page.
- Review installed programs monthly: Set a calendar reminder to review your installed programs list once a month. Remove anything you don't use or don't recognize. Hijackers often sit dormant for weeks before activating.
- Create a separate user account for risky activities: If you must visit potentially risky sites or download software from uncertain sources, do so from a limited user account rather than an administrator account. This restricts what malware can install system-wide.
Bring It In
Browser hijackers like GetSecures.com can be frustrating to remove completely because they establish multiple persistence mechanisms designed to survive amateur removal attempts. If you've followed these steps and still see redirects, or if you're not comfortable working with the Windows registry and system files, bring your computer to Computer Repair Roswell. We remove hijackers, PUPs, and more serious malware every day. Most cleanings are completed same-day, and we'll optimize your system performance while we're at it.
We're located in Roswell, Georgia, and we work on both Windows PCs and Macs. Call us at (770) 629-7750 to describe your symptoms, or just stop by with your machine during business hours. No appointment necessary. We'll give you an honest assessment of what's going on and a flat-rate quote before we start work. Our technicians will also help you understand what allowed the hijacker to install in the first place and set up better defenses so you don't have the same problem again next month.