Googlesearch.me

By GoldSparrow in Browser Hijackers

The Googlesearch.me site is not a domain under the control of Google Inc. The Googlesearch.me Web portal is operated by a third-party entity that did not add contact info on Googlesearch.me apart from the 'bestaddon@gmail.com' email account, which does not appear to relate to any company. The Googlesearch.me site is presented to visitors as a search services provider that includes a social feed from a Google's account at Plus.google.com/+google. The site owner appears to be trying to confuse users that Googlesearch.me is an official domain that offers content related to technologies by Google. Browser tabs loaded with Googlesearch.me feature the title 'Google search' and the official Google logo.

However, search operations performed on Googlesearch.me trigger a series of browser redirects via yhseach.club/812.html?q=[keyword] to goto.maxdealz.com/v1/hostedsearch?keyword=[keyword] and you arrive at us.search.yahoo.com. The site is closely associated with a browser hijacker that might be installed on computers thanks to free software bundles. The Googlesearch.me browser hijacker is observed to affect browsers like Google Chrome, Internet Explorer and Mozilla Firefox. Web surfers who are compromised and click on content at Googlesearch.me may be shown pop-up and pop-under windows with promotional materials like banners, video commercials, discounts and recommended software. We have found that the Googlesearch.me site exchanges data with servers on the following addresses:

  • ad.crwdcntrl[.]net
  • assets.juicer[.]io
  • go.onclasrv[.]com
  • goto.maxdealz[.]com
  • mt.rmark[.]net
  • onclkds[.]com
  • yhseach[.]club

Evidently, the manager of Googlesearch.me is using the services of legitimate companies like Propeller Ads Media (Propellerads.com), Juicer (Juicer.io) and Lotame (Lotame.com) to improve the ad revenue generated from pop-ups, pop-unders, and banners on the site. In this case, Juicer pulls new posts from a Google's social media account at Plus.google.com/+google; Lotame analyzes the visitor's browser and approximate location to load custom ads; Propeller Ads Media handles the advertisement content delivery. PC users infected with the Googlesearch.me browser hijacker may be unable to set a new start page and new tab page until their systems are cleaned. The Googlesearch.me browser hijacker may allow its creator to claim a decent ad revenue from Web traffic on affected computers. You can eliminate the Googlesearch.me browser hijacker safely by running a complete system scan with a trusted anti-malware tool.

Trending

Most Viewed

Loading...