GetSharedStore.com is a browser hijacker that forcibly redirects your web searches and homepage settings through a suspicious search portal, monetizing your clicks while exposing you to potentially malicious advertising networks. This unwanted modification typically arrives bundled with free software installers and alters browser settings across Chrome, Firefox, Edge, and Safari without meaningful user consent. While not classified as a virus in the traditional sense, GetSharedStore.com exhibits intrusive behavior that degrades browsing performance, compromises privacy, and opens pathways for additional unwanted software installations.

GetSharedStore.com — cybersecurity illustration
Photo by John (Giannis) Tekeridis on Pexels

Victims commonly notice that their default search engine has changed to GetSharedStore.com or related domains, their homepage loads unfamiliar pages, and new tabs open to advertising content. The hijacker operates by modifying browser shortcuts, extension settings, and system policies to maintain persistence even after manual removal attempts. Beyond the immediate annoyance, GetSharedStore.com collects browsing data including search queries, visited URLs, and potentially sensitive information entered into web forms, transmitting this data to remote servers for profiling and ad targeting.

Think You're Infected Right Now? If GetSharedStore.com has taken over your browser, disconnect from the internet immediately to prevent further data collection. Don't enter passwords or sensitive information until the hijacker is removed. Skip to the Manual Removal section below for step-by-step instructions, or call Computer Repair Roswell at (770) 726-4637 for same-day cleanup service. We're located at 1273 Hembree Road and can typically eliminate browser hijackers within an hour.

Threat Profile

Threat Type Browser Hijacker, Potentially Unwanted Program (PUP), Search Redirect
Threat Family Search-redirect hijacker group (operates similarly to MyWay, SearchMine, SafeFinder)
Aliases Get Shared Store, SharedStore redirect, PUP.Optional.GetSharedStore
Affected Platforms Windows (7/8/10/11), macOS, browser-agnostic (Chrome, Firefox, Edge, Safari)
Distribution Method Software bundling, fake installers, deceptive download buttons, update notifications
Persistence Mechanisms Browser extension installation, shortcut modification, managed browser policies, scheduled tasks, startup registry entries
Primary Capabilities Search redirection, homepage hijacking, new-tab manipulation, ad injection, browsing data collection
Data at Risk Search queries, browsing history, clicked URLs, IP address, geolocation, system configuration, potentially form data
Network Behavior Redirects through multiple intermediary domains before landing on search results; communicates with ad networks and tracking servers; typical for revenue-generating redirect chains
Common Artifacts Browser extensions with generic names, modified browser shortcuts with appended URLs, policies in browser preference files, scheduled tasks with random alphanumeric names
Removal Difficulty Moderate — employs multiple persistence layers requiring browser reset and system-level cleanup
Reinfection Risk High if distribution source (bundled software habits) isn't addressed

How It Spreads

GetSharedStore.com primarily distributes through software bundling, a deceptive practice where legitimate-seeming applications include additional "offers" pre-selected in their installation wizards. Users downloading free utilities, PDF converters, video downloaders, or codec packs from third-party download sites frequently encounter installers that quietly add GetSharedStore.com modifications unless they specifically opt out during installation. These bundled installers often use confusing language, placing the hijacker installation in "Custom" settings that most users skip, or presenting it as a recommended security update.

The hijacker also spreads through fake software updates and misleading browser notifications. Compromised websites and malicious advertising networks display pop-ups claiming your Flash Player, browser, or video codec is out of date, leading to installer downloads that deploy GetSharedStore.com alongside or instead of the advertised software. Some distribution campaigns use typosquatting domains that mimic legitimate software publishers, tricking users who mistype popular download URLs.

Common distribution vectors include:

  • Bundled freeware installers from download aggregation sites like Softonic, download.com, or similar platforms that repackage software
  • Fake update notifications appearing on streaming sites, torrent portals, or compromised legitimate websites
  • Deceptive download buttons on file-hosting services where the actual download link is obscured among advertisement buttons
  • Pirated software installers and key generators that include PUPs as additional payload
  • Email attachments disguised as invoices, shipping notifications, or document converters
  • Malicious browser extensions promoted through social media or search ads claiming to offer useful features
  • Drive-by downloads from compromised websites exploiting outdated browser or plugin vulnerabilities

What It Does On Your Machine

Once installed, GetSharedStore.com immediately modifies your browser configuration to control your web searching and homepage behavior. The hijacker changes your default search engine to GetSharedStore.com or an intermediary redirect domain, ensuring all search queries pass through its monetization infrastructure before reaching actual search results. Your homepage and new-tab page settings are similarly altered, forcing you to view controlled content each time you open your browser or create a new tab. These modifications persist even after manually changing settings back, as the hijacker reapplies them through extensions, system policies, or shortcut manipulation.

The search redirection chain typically routes your query through multiple domains before eventually delivering results from legitimate search engines like Bing or Yahoo. This multi-hop process accomplishes several objectives: it obscures the ultimate destination to complicate blocking efforts, it allows the operators to inject sponsored results and advertisements at various stages, and it creates multiple data collection points where your search terms and click behavior are logged. Users report noticeably slower search response times and frustration with irrelevant sponsored results appearing prominently in their search outcomes.

GetSharedStore.com also functions as a data collection engine, harvesting information about your browsing habits for advertising profiles and potentially selling aggregated data to third parties. The hijacker typically collects search queries, visited URLs, clicked links, time spent on pages, and technical information about your system and browser. While the privacy policies associated with these hijackers often claim they don't collect "personally identifiable information," the browsing data itself can be highly revealing and valuable to data brokers and advertising networks.

Beyond the primary redirection behavior, many installations include additional unwanted modifications. Users frequently report new browser extensions appearing without permission, modified browser shortcuts that launch with specific URLs appended, aggressive advertising injection on previously ad-free websites, and occasional pop-ups promoting fake tech support or additional software installations. The hijacker may also modify security settings to prevent easy removal, disable certain browser features, or install companion programs that monitor for and re-enable the hijacker after removal attempts.

Typical GetSharedStore.com Artifacts
Browser Shortcuts Modified: "C:\Program Files\Google\Chrome\Application\chrome.exe" --homepage=http://getsharedstore.com Browser Extensions: Random alphanumeric ID or generic names like "Helper," "Extension," "Search Manager" Registry Persistence (Windows): HKCU\Software\Microsoft\Windows\CurrentVersion\Run\[Random Name] HKLM\Software\Policies\Google\Chrome\ExtensionInstallForcelist Scheduled Tasks: Task Scheduler Library\[Random GUID or Name] — triggers on login/hourly File Locations (Varies): %LOCALAPPDATA%\[Random Folder]\[Random].exe %APPDATA%\[Extension Name]\ %PROGRAMFILES(X86)%\[Software Bundle Name]\ # File/folder names are typically randomized or generic to evade detection

Manual Removal — Step by Step

01

Disconnect from the Internet

Unplug your ethernet cable or disable Wi-Fi to prevent the hijacker from downloading additional components, communicating with control servers, or transmitting collected data during the removal process. This also prevents any browser-based re-infection attempts that might trigger during cleanup.

02

Uninstall Suspicious Programs

Open Control Panel (Windows) or Applications folder (Mac) and look for recently installed programs you don't recognize, especially those installed around the time the hijacking started. Common names include generic utilities, toolbars, or "helper" applications. Uninstall anything suspicious, paying attention to programs with no publisher information or those from unfamiliar companies.

03

Remove Browser Extensions

Open each affected browser's extension/add-on manager (usually found in Settings or Tools menu). Remove any extensions you didn't intentionally install, especially those with vague names, no description, or lacking a reputable publisher. In Chrome, visit chrome://extensions/; in Firefox, go to about:addons; in Edge, use edge://extensions/. Disable or remove anything suspicious.

04

Check and Repair Browser Shortcuts

Right-click your browser shortcuts (desktop, taskbar, Start menu) and select Properties. In the Target field, verify it points only to the browser executable without any URLs or parameters after it. If you see anything appended after chrome.exe, firefox.exe, or similar, delete everything after the .exe portion. Apply the changes and repeat for all browser shortcuts.

05

Reset Browser Settings

In each browser, navigate to Settings and find the reset/restore option. In Chrome, search settings for "reset" and choose "Restore settings to their original defaults." In Firefox, use "Refresh Firefox." In Edge, choose "Restore settings to their default values." This removes unwanted search engines, resets your homepage, and clears malicious policies while preserving bookmarks and passwords in most cases.

06

Scan with Malwarebytes or Similar Tool

Download and install Malwarebytes Free (from malwarebytes.com only) on a clean device, transfer it via USB if your infected machine is still offline, or reconnect briefly to download it directly. Run a full Threat Scan to detect hijacker remnants, associated PUPs, and any persistence mechanisms the manual steps may have missed. Quarantine and remove all detected items.

07

Check Scheduled Tasks and Startup Items

On Windows, open Task Scheduler (search for it in Start menu) and review the Task Scheduler Library for tasks with random names or those pointing to suspicious executables in temporary folders. Delete any that look unfamiliar. Also open Task Manager (Ctrl+Shift+Esc), go to the Startup tab, and disable any unknown entries. On Mac, check System Preferences > Users & Groups > Login Items.

08

Clear Browser Data and Cookies

Clear your browsing history, cached files, and cookies from the time period covering the infection. This removes tracking cookies and cached redirect pages. In most browsers, use Ctrl+Shift+Delete (Cmd+Shift+Delete on Mac) to open the clearing dialog. Select "All time" as the time range and check all data categories except passwords.

09

Change Important Passwords

If you entered passwords or accessed financial accounts while infected, change those passwords from a known-clean device or after completing removal and verification. While GetSharedStore.com is primarily a redirect hijacker rather than a password stealer, some variants include keylogging or form-grabbing capabilities, and the bundled software it arrives with may include more dangerous components.

10

Reboot and Verify Clean Operation

Restart your computer and open your browsers to verify they're functioning normally. Check that your homepage, search engine, and new-tab page are set to your preferences and remain that way after closing and reopening the browser. Perform a few test searches to ensure you're not being redirected through unfamiliar domains. If problems persist, the hijacker may have additional persistence mechanisms requiring professional removal.

Prevention

  1. Download software only from official sources. Avoid third-party download sites and aggregators that repackage installers with bundled PUPs. Get software directly from the developer's website or from verified stores like the Microsoft Store or Mac App Store.
  2. Always choose Custom/Advanced installation options. Never click through installers using Express or Recommended settings. Custom installation reveals bundled offers, allowing you to uncheck unwanted additions before they install. Read each screen carefully before clicking Next.
  3. Keep your software and operating system updated. Enable automatic updates for your OS, browsers, and essential software to patch vulnerabilities that drive-by downloads exploit. Outdated software is the primary entry point for many infection vectors.
  4. Use a reputable ad-blocker and anti-malware extension. Browser extensions like uBlock Origin block malicious advertising networks that distribute hijackers, while tools like Malwarebytes Browser Guard can warn about and block PUP downloads before they execute.
  5. Be skeptical of update notifications. Legitimate software updates occur through the application itself or through your operating system's update mechanism, not through random website pop-ups. Never download "required" updates from unfamiliar websites.
  6. Avoid pirated software and key generators. Cracked software and activation tools are consistently bundled with malware, hijackers, and worse threats. The "free" software comes at the cost of your system security and privacy.
  7. Review browser extensions regularly. Once per month, audit your installed browser extensions and remove any you're not actively using or don't remember installing. Browser extension ecosystems are common targets for hijacker developers.
  8. Create a standard user account for daily use. Operating as an administrator makes it easier for hijackers to install system-level persistence mechanisms. A standard user account requires elevation for system changes, providing an additional approval checkpoint for unwanted installations.
Our 90-Day Warranty on Malware Removal
When Computer Repair Roswell removes GetSharedStore.com or any other malware from your computer, we back our work with a 90-day reinfection warranty. If the same threat returns within 90 days, we'll remove it again at no charge. We also provide guidance on safe browsing habits and recommend appropriate security software to keep your system clean long-term. Our technicians don't just clean the infection — we explain what happened and how to prevent it from happening again.

Bring It In

While the manual removal steps above work for many GetSharedStore.com infections, some variants employ sophisticated persistence mechanisms that resist DIY removal, and you may inadvertently miss components that enable reinfection. If you've attempted manual removal but continue experiencing redirects, or if you're simply not comfortable working through system-level changes, Computer Repair Roswell can thoroughly eliminate the hijacker and any bundled threats in typically under an hour. We use professional-grade tools and techniques to ensure complete removal, verify your browser security settings, and scan for additional threats that may have arrived alongside the hijacker.

Our shop is located at 1273 Hembree Road in Roswell, just minutes from the historic downtown area. We offer same-day service for malware removal — no appointment necessary, though calling ahead at (770) 726-4637 ensures we have a technician ready when you arrive. We service both Windows PCs and Macs, and our transparent pricing means you'll know the cost before we begin work. Beyond just removing GetSharedStore.com, we'll help you understand how it got there and set up appropriate defenses to prevent future infections, giving you genuine peace of mind rather than just a temporary fix.