SearchMe Toolbar

SearchMe Toolbar Description

ScreenshotThe SearchMe Toolbar is a PUP (Potentially Unwanted Program). These kinds of programs make unwanted changes to your Web browser. There are dozens of variants of the SearchMe Toolbar, all associated with the Conduit search engine. This search engine has been linked to a number of PUPs and is known for its unreliable search results and its association with browser redirects and pay-per-click marketing schemes. The SearchMe Toolbar may cause a number of other symptoms, including pop-ups and problems with your computer's performance. It is important to note that, despite the fact that the SearchMe Toolbar is considered as a PUP, its effects may be similarly disruptive to more risky forms of threats. Because of this, the SearchMe Toolbar should be removed immediately from the affected Web browser with the aid of a strong anti-malware tool.

What PUPs Such as the SearchMe Toolbar are Used For

The main purpose of the SearchMe Toolbar and similar PUPs is to generate revenue from advertising and affiliate marketing. Apart from browser redirects, the SearchMe Toolbar also makes changes to the affected computer's settings, changing the affected Web browser's homepage and default search engine to Conduit. Other issues surrounding the SearchMe Toolbar include changes to the infected Web browser's security settings and significant effects on the affected computer's performance. For example, the SearchMe Toolbar may cause the affected computer to freeze frequently or decrease its Internet connectivity. All of these symptoms may be extremely disruptive, despite the fact that the SearchMe Toolbar is considered as a PUP rather than a more sophisticated form of threat.

How to Remove the SearchMe Toolbar from Your Computer

The SearchMe Toolbar and similar PUPs can be removed using the 'Add and Remove Programs' option in the Windows Control Panel. Once the SearchMe Toolbar has been removed, it is often necessary to undo changes that this PUP makes to your Web browser settings. Adjustments that need to be undo manually include changes to your Web browser's homepage and default search engine. Since the SearchMe Toolbar may indirectly expose your Web browser to hazardous content and known online scams, ESG malware analysts strongly advise following up uninstalling of this program with a full scan carried out with a reliable anti-malware program.

Technical Information

File System Details

SearchMe Toolbar creates the following file(s):
# File Name Size MD5 Detection Count
1 %SYSTEMDRIVE%\Backup\Program Files\IObit Apps Toolbar\IE\9.3\iobitappsToolbarIE64.dll\iobitappsToolbarIE64.dll 1,997,120 6f280abb7a2341e6f6f7c19dd64cafa5 680
2 searchmeToolbar.exe 5,283,080 91c80441fb9dd3beef05a99d753b5d58 0

Registry Details

SearchMe Toolbar creates the following registry entry or registry entries:
Regexp file mask
%TEMP%\searchmeToolbar.exe
Registry key
Software\AppDataLow\Software\SearchMe
SOFTWARE\Classes\Installer\Features\FEE772BFF22B1F141A963FD212C7C551
SOFTWARE\Classes\Installer\Products\FEE772BFF22B1F141A963FD212C7C551
SOFTWARE\Classes\Installer\UpgradeCodes\ADC68DBC02C280344858E3F362E555E3
Software\Microsoft\Internet Explorer\Approved Extensions\{841300b2-82bb-4cbe-b037-a2ad9faf2917}
Software\Microsoft\Internet Explorer\Approved Extensions\{B9C767DD-F66A-40B4-8F12-4199A9A4393C}
Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B9C767DD-F66A-40B4-8F12-4199A9A4393C}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B9C767DD-F66A-40B4-8F12-4199A9A4393C}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B9C767DD-F66A-40B4-8F12-4199A9A4393C}
SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\ADC68DBC02C280344858E3F362E555E3
SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\FEE772BFF22B1F141A963FD212C7C551
Software\SearchMe
Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B9C767DD-F66A-40B4-8F12-4199A9A4393C}
SOFTWARE\Wow6432Node\SearchMe
Directory
%APPDATA%\SearchMe
%APPDATA%\TB\ChromeExtData\beoaheobdgcfjnpkhibepdogohpdhbkl
%LOCALAPPDATA%\Google\Chrome\User Data\Default\databases\chrome-extension_beoaheobdgcfjnpkhibepdogohpdhbkl_0
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\beoaheobdgcfjnpkhibepdogohpdhbkl
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Local Extension Settings\beoaheobdgcfjnpkhibepdogohpdhbkl
%PROGRAMFILES%\SearchMe Toolbar
%PROGRAMFILES(x86)%\SearchMe Toolbar
%USERPROFILE%\AppData\LocalLow\SearchMe
%USERPROFILE%\AppData\LocalLow\TB\ChromeExtData\beoaheobdgcfjnpkhibepdogohpdhbkl
%WINDIR%\Installer\{FB277EEF-B22F-41F1-A169-F32D217C5C15}
Uninstaller
{FB277EEF-B22F-41F1-A169-F32D217C5C15}
CLSID
{B9C767DD-F66A-40B4-8F12-4199A9A4393C}

Related Posts

Site Disclaimer

Enigmasoftware.com is not associated, affiliated, sponsored or owned by the malware creators or distributors mentioned on this article. This article should NOT be mistaken or confused in being associated in any way with the promotion or endorsement of malware. Our intent is to provide information that will educate computer users on how to detect, and ultimately remove, malware from their computer with the help of SpyHunter and/or manual removal instructions provided on this article.

This article is provided "as is" and to be used for educational information purposes only. By following any instructions on this article, you agree to be bound by the disclaimer. We make no guarantees that this article will help you completely remove the malware threats on your computer. Spyware changes regularly; therefore, it is difficult to fully clean an infected machine through manual means.

Leave a Reply

Please DO NOT use this comment system for support or billing questions. For SpyHunter technical support requests, please contact our technical support team directly by opening a customer support ticket via your SpyHunter. For billing issues, please refer to our "Billing Questions or Problems?" page. For general inquiries (complaints, legal, press, marketing, copyright), visit our "Inquiries and Feedback" page.


HTML is not allowed.