GetSuperPrizesHereLife is a browser hijacker and potentially unwanted program (PUP) that infiltrates Windows and Mac systems to manipulate web browser settings, redirect searches, and deliver intrusive advertising. This threat typically arrives bundled with freeware installers or disguised as a legitimate browser extension promising rewards, deals, or enhanced shopping experiences. Once active, it modifies your homepage, default search engine, and new tab page to redirect traffic through affiliate networks that generate revenue for its operators while degrading your browsing experience and potentially exposing you to malicious sites.
While not classified as a traditional virus or trojan, GetSuperPrizesHereLife exhibits aggressive persistence mechanisms that make it difficult for average users to remove manually. The hijacker creates multiple registry entries, scheduled tasks, and hidden browser policies that restore its settings even after you think you've cleaned it. Beyond the annoyance factor, this PUP can slow system performance, track your browsing habits for advertising purposes, and create security vulnerabilities by disabling browser protections or redirecting you to phishing pages.
Threat Profile
| Attribute | Details |
|---|---|
| Family | Browser Hijacker / PUP (Potentially Unwanted Program) |
| Aliases | GetSuperPrizesHere.life, Get Super Prizes Here Life, SuperPrizesHere redirect |
| Platform | Windows (7/8/10/11), macOS; affects Chrome, Firefox, Edge, Safari |
| Discovered | Variants circulating since approximately 2019–2020 |
| Distribution | Software bundling, fake updates, malicious ads, torrent files |
| Persistence | Registry Run keys, scheduled tasks, browser extension policies, helper applications |
| Primary Behavior | Homepage/search engine hijacking, forced redirects, ad injection, tracking cookie deployment |
| Data Collection | Browsing history, search queries, IP address, geolocation, device identifiers |
| Typical Artifacts | Browser extensions with random names, scheduled tasks named after legitimate services, registry policies blocking settings changes |
| Network Behavior | Redirects through multiple affiliate domains before final destination; contacts ad-serving infrastructure |
| Removal Difficulty | Moderate to High—reinstalls itself if all components not removed simultaneously |
| Payload Risk | Low direct damage; moderate risk as gateway to more serious infections via malicious redirects |
How It Spreads
GetSuperPrizesHereLife employs classic PUP distribution tactics that exploit user trust and inattention during software installation. The most common infection vector is software bundling, where the hijacker piggybacks on legitimate freeware installers downloaded from third-party sites. Users racing through installation wizards using "Express" or "Recommended" settings unknowingly agree to install additional components. The bundlers deliberately obscure the hijacker's presence using pre-checked boxes, misleading language about "enhanced browsing features," or placement in collapsed sections that require deliberate expansion to discover.
Fake browser update prompts represent another major distribution channel. You visit a compromised website or one displaying malicious advertising, and a convincing overlay appears claiming your Chrome, Firefox, or Flash Player is out of date. The download button delivers GetSuperPrizesHereLife instead of the promised update. These fake prompts mimic legitimate update interfaces closely enough that even cautious users sometimes fall victim, especially when the warning appears on otherwise-trustworthy sites that have been compromised through advertising networks.
Additional distribution methods include:
- Torrent and peer-to-peer files: Cracked software, key generators, and pirated media files frequently contain bundled PUPs as monetization for the distributors
- Malicious browser extensions: Promoted through social media ads or search engine results with promises of coupons, PDF converters, or video downloaders
- Email attachments: Less common for this specific threat, but some variants arrive as "install this to claim your prize" executables
- Compromised websites: Drive-by downloads that exploit browser vulnerabilities to silently install components (more typical on unpatched systems)
- Tech support scams: Fake support sites that convince victims to install "diagnostic tools" that are actually hijackers
What It Does On Your Machine
Once installed, GetSuperPrizesHereLife immediately targets your web browsers to establish control over your online experience. It modifies browser configuration files and system registry entries to change your homepage to getsuperprizesherelife[.]com or related domains, replaces your default search engine with a custom one that routes queries through affiliate networks, and hijacks the new tab page to display advertisements or redirect to partner sites. These changes persist even when you manually reset them through browser settings because the hijacker has implemented policy-level restrictions that override user preferences.
The search redirection mechanism is particularly insidious. When you perform a search, the hijacker intercepts your query and routes it through several intermediate domains—collecting data at each hop—before eventually delivering results from a legitimate search engine like Bing or Yahoo. This multi-step redirection serves several purposes: it obscures the hijacker's infrastructure from analysis, allows multiple parties in the affiliate chain to track your activity, and makes it harder for security researchers to map the complete operation. During this process, the hijacker injects additional advertisements into the search results and may reorder organic results to prioritize paid placements.
Beyond browser manipulation, GetSuperPrizesHereLife establishes multiple persistence mechanisms throughout your system. It creates scheduled tasks that check for the hijacker's presence every few hours and reinstall components if they're detected missing. On Windows systems, it commonly adds Run registry keys that launch helper processes at startup. These helper processes run silently in the background, monitoring your browsers and restoring hijacked settings if you manage to change them manually. Some variants also install a browser extension with administrative privileges that cannot be removed through normal browser interfaces—you'll see it listed in your extensions but the Remove button is grayed out.
The data collection aspect poses privacy concerns even though the hijacker doesn't steal passwords or financial data directly. It deploys tracking cookies and browser fingerprinting techniques to build a profile of your browsing habits, search history, frequently visited sites, and shopping behavior. This information gets transmitted to advertising networks and data brokers who aggregate it with information from other sources to create detailed consumer profiles. While the immediate operators of GetSuperPrizesHereLife are primarily motivated by advertising revenue, the data they collect can end up in databases that later get breached or sold to more malicious actors.
Manual Removal — Step by Step
Disconnect and Document
Unplug your Ethernet cable or disconnect from WiFi before beginning removal. This prevents the hijacker from downloading additional components or updating its configuration during the cleaning process. Take screenshots of your hijacked browser settings (homepage, search engine, extensions list) for reference—this helps verify complete removal later.
Boot Into Safe Mode with Networking
On Windows, hold Shift while clicking Restart, then navigate to Troubleshoot > Advanced Options > Startup Settings and select Safe Mode with Networking. On Mac, restart while holding Shift. Safe mode prevents most startup items and scheduled tasks from launching, which stops the hijacker's persistence mechanisms from interfering with removal.
Uninstall Suspicious Programs
Open Control Panel > Programs and Features (Windows) or Applications folder (Mac). Sort by installation date and look for programs installed around the time your browser hijacking started. Uninstall anything named GetSuperPrizesHere, SuperPrizes, or unfamiliar applications with generic names like "System Utilities," "Browser Helper," or "PC Optimizer." The hijacker often disguises itself with names that sound legitimate.
Remove Browser Extensions and Reset Settings
In Chrome, type chrome://extensions/ in the address bar and remove any suspicious extensions, especially those you didn't intentionally install. Then go to chrome://settings/reset and choose "Restore settings to their original defaults." Repeat this process for Firefox (about:addons and about:support), Edge, and any other installed browsers. Some policy-enforced extensions won't remove yet—we'll address those in the registry cleaning step.
Delete Scheduled Tasks
Open Task Scheduler (search for it in the Start menu) and examine the Task Scheduler Library. Delete any tasks with suspicious names, especially those that run frequently and launch executables from AppData or ProgramData folders. Common GetSuperPrizesHereLife task names include variations of "Update," "Maintenance," "SystemCheck," or random alphanumeric strings. Right-click and delete each suspicious task.
Clean Registry Entries
Press Win+R, type "regedit" and hit Enter. Navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run. Delete any entries pointing to the hijacker. Also check HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome (or Mozilla\Firefox) for forcelist policies that reinstall extensions. Delete the entire GetSuperPrizesHere key if present under HKEY_CURRENT_USER\Software. Back up the registry before making changes (File > Export).
Delete Hijacker Files
Open File Explorer and navigate to C:\Users\[YourUsername]\AppData\Local and \AppData\Roaming. Delete any folders named GetSuperPrizesHere, SuperPrizes, or with random GUID-style names that contain executables and appeared around your infection date. Also check C:\Program Files and C:\Program Files (x86) for related folders. Show hidden files (View tab > Hidden items checkbox) to see everything.
Run Reputable Anti-Malware Scanners
Download and run Malwarebytes (free version is sufficient) and perform a full system scan. Follow up with a scan using AdwCleaner, which specializes in PUPs and browser hijackers. Let both tools remove everything they detect. Restart between scans. Even if you've manually removed visible components, these scanners often find hidden persistence mechanisms or additional bundled PUPs that came along for the ride.
Reset Browser Profiles and Clear Data
For stubborn cases, create a new browser profile. In Chrome, go to Settings > Manage other people > Add person. Set up the new profile with your bookmarks and passwords (from your password manager—never from the compromised browser's storage). Completely remove the old profile. Clear all browsing data including cached images, cookies, and site data for at least the past month.
Change Passwords and Verify Removal
After confirming the hijacker is gone (test by setting a custom homepage and restarting—it should stay), change passwords for important accounts using a clean device or the now-clean system. Check your browser's homepage, search engine, and extensions list one final time. Monitor system performance and browser behavior for the next few days—any return of redirects or unwanted ads means a component was missed and professional removal is recommended.
Prevention
- Download software only from official sources. Get applications directly from the developer's website or verified app stores. Third-party download sites (Softonic, Download.com, CNET Downloads) frequently bundle PUPs with legitimate installers. When you must use a third-party source, choose "Custom" or "Advanced" installation and carefully uncheck any additional offers.
- Keep your system and browsers updated. Enable automatic updates for Windows/macOS and all installed software. Browser hijackers sometimes exploit known vulnerabilities in outdated software to gain deeper system access or bypass user prompts. Updated browsers also have better built-in protections against malicious extensions.
- Use a reputable ad blocker. Extensions like uBlock Origin block the malicious advertising networks that distribute fake update prompts and drive-by downloads. Configure it to block third-party frames and scripts on unfamiliar sites. Ad blockers reduce exposure to the compromised advertising infrastructure that hijackers use for distribution.
- Never trust "urgent update" pop-ups. Legitimate software updates don't come through random website pop-ups. If a site claims your browser or Flash Player needs updating, close the pop-up and manually check for updates through the application's own menu. Firefox prompts come through Firefox's menu; Chrome updates through Chrome's settings. Anywhere else is suspect.
- Review browser extensions quarterly. Open your extensions list and remove anything you don't actively use or don't remember installing. Extensions can get compromised after installation when developers sell them to advertising networks. Even if you installed something legitimately six months ago, it may have turned malicious through an update.
- Implement DNS-level filtering. Configure your router or individual devices to use DNS services like Cloudflare's 1.1.1.1 for Families or OpenDNS Home, which block known malicious domains. This creates a network-level barrier that prevents connections to hijacker infrastructure even if the software gets installed.
- Enable browser security features. In Chrome, Edge, and Firefox, ensure "Enhanced Protection" or "Strict" security settings are enabled. These features check downloads against malware databases and warn about deceptive sites. Disable automatic extension installations and require explicit approval for any extension that requests installation.
- Educate everyone who uses your computers. Browser hijackers disproportionately affect households where less tech-savvy family members click through installers without reading or fall for fake support scams. Brief conversation about not clicking "Next" repeatedly and verifying update prompts can prevent most infections.
When Computer Repair Roswell removes malware from your system, it stays removed. We provide a 90-day warranty against the same infection returning—if it comes back within three months, we'll clean it again at no charge. That's because we remove every component, every persistence mechanism, and every trace of the infection, then verify your system is genuinely clean before returning it to you.
Bring It In
GetSuperPrizesHereLife removal requires thoroughness that's difficult to achieve without diagnostic tools and experience with hijacker persistence tactics. If you've attempted manual removal and the redirects keep returning, or if you're simply not comfortable editing the registry and hunting through system folders, professional removal is the faster and safer option. We see dozens of browser hijacker infections monthly at our Roswell shop, and we've developed systematic approaches that ensure complete removal on the first attempt. Most hijacker removals take 2–4 hours, and we typically complete same-day service for drop-offs before noon.
Call us at (770) 856-1578 to describe your symptoms and get an upfront price quote, or bring your machine directly to 1394 Canton Road, Roswell, GA 30075. We're open Monday through Friday, 10 AM to 6 PM, and Saturday by appointment. While you're here, we'll also check for other bundled threats that often accompany browser hijackers, verify your antivirus is functioning properly, and ensure your system is fully updated against current threats. You'll leave with a clean machine and clear guidance on avoiding reinfection—no ongoing subscriptions required, no pressure to buy unnecessary services, just honest repair work from technicians who've been serving Roswell for years.