MyBeeSearch.com

By CagedTech in Browser Hijackers

Threat Scorecard

Threat Level: 50 % (Medium)
Infected Computers: 79
First Seen: January 3, 2016
Last Seen: January 25, 2023
OS(es) Affected: Windows

The Mybeesearch.com site is associated with cases of browser hijacking. Users reported that their browser might load Mybeesearch.com as the default start page, new tab page and search aggregator. The Mybeesearch.com site appears to offer Web surfers access to a customized version of Search.yahoo.com, which comes with links to resources on Yahoo.com like news, weather forecast, instant messaging and email. Mybeesearch.com acts as a redirect-gateway that may appear like a legitimate search provider. However, Mybeesearch.com offers a single text box and no options to specify parameters for your search. Your search input is sent to Search.yahoo.com, and your traffic is monetized by whoever owns Mybeesearch.com.

The browser hijacker associated with Mybeesearch.com may be listed in the 'Programs and Features' module of the 'Control Panel' as MyBeeSearch Toolbar. We have found that the MyBeeSearch Toolbar may be distributed to users via free software bundles. There is a standalone client that is uploaded to beedownloadserver.com/downloads, but you need a direct link to the installer to download it. The client for the MyBeeSearch Toolbar may kill the processes of Google Chrome, Internet Explorer and Mozilla Firefox before it proceeds to install its files and alter your Internet-related settings. We have found that the Mybeesearch.com browser hijacker writes the following files to the system drive:

C:\DOCUME~1\~1\LOCALS~1\Temp\is-NFFV1.tmp\8e216e73182f6c32f93fa254d4594bd1e2f22c88565dc9dd3c29d1bd6fb33528.tmp
C:\DOCUME~1\~1\LOCALS~1\Temp\is-RSPO5.tmp\_isetup\_shfoldr.dll
C:\DOCUME~1\~1\LOCALS~1\Temp\is-RSPO5.tmp\EasyBundling.dll

The MyBeeSearch Toolbar appears to resemble the code we have seen in the Widgi Toolbar, which is classified as a suspicious toolbar. Additionally, the MyBeeSearch Toolbar is reported to exchange data with servers on mybrowserbar.com and ultimatumz.com. The Mybeesearch.com browser hijacker may send information like your software configuration, browser type, IP address, OS version, and Internet history via a GET request to the following addresses:

http://www.ultimatumz[.]com/install/reportinstall_mybeesearch.php?tparam=MyBeeSearch_InstallMonetizer
http://www.mybrowserbar[.]com/kits/EasyBundlingDLL/611642/so.xml?kt=eipcamc&wv=5.1&rsv=4

Computer security researchers do not recommend users to tolerate the MyBeeSearch Toolbar and use the Mybeesearch.com site for their Internet activities. The Mybeesearch.com site shares the 205.186.187.146 IP address with phishing pages and links to riskware like the RelevantKnowledge adware. It is best to remove the files connected to Mybeesearch.com with the help of a reputable anti-malware utility. AV vendors may flag objects linked to the MyBeeSearch Toolbar as:

  • Adware ( 004d8ee81 )
  • PUA.Toolbar.Widgi
  • PUP.MyBeeSearch/Variant
  • Trojan.DownLoader19.21340
  • Trojan.Generic-ilVC2TkmQPR (cloud)
  • Widgi Toolbar
  • Widgi Toolbar (not malicious)
  • Win32:Adware-gen [Adw]

SpyHunter Detects & Remove MyBeeSearch.com

Registry Details

MyBeeSearch.com may create the following registry entry or registry entries:
SOFTWARE\mbs_install
SOFTWARE\mybeesearch
SOFTWARE\Wow6432Node\mybeesearch

Trending

Most Viewed

Loading...