Searchya! Toolbar

Searchya! Toolbar Description

Searchya Toolbar Image 1Classified as adware, the Searchya! Toolbar is used to deliver advertisements to computer users, often in the form of pop-up windows and browser redirects. Carrying out a search on Searchya! Toolbar's associated search engine will usually result in low-quality search results replete with advertisements and links to websites containing unsafe content. Even though Searchya! Toolbar's website supposedly contains uninstall instructions, this adware infection may not be easy to remove and will usually require the help of a reliable anti-malware program.

Although the main symptoms of a browser hijacker infection associated with the Searchya.com website is the presence of the Searchya! Toolbar itself, there are several symptoms that point to the fact that Searchya! Toolbar is not a reliable web browser add-on:

  • The presence of the Searchya! Toolbar on your computer may usually result in poor computer performance.
  • Attempting to remove Searchya! Toolbar manually may usually result in error messages, crashes, or in the Searchya! Toolbar being reinstalled automatically when the infected web browser starts up again.
  • Your web browser's homepage may have been changed to Searchya.com without your authorization. Your default search engine and favorite websites may also have been altered as well.
  • The Searchya! Toolbar may usually cause the infected web browser to display fake error messages and pop-up alerts from the Windows Task Bar.
  • Unfortunately, the Searchya! Toolbar will rarely attack alone. If the Searchya! Toolbar is installed on your computer, then it is probable that your machine has become infected with other kinds of malware threats.

Removing the Searchya! Toolbar from your computer will usually require an updated anti-malware program. Since Searchya! Toolbar will often be associated with other malware threats, ESG security researchers advise scanning your hard drives to make sure that other malware infections have not entered your computer. The Searchya! Toolbar makes modifications to the Windows Registry and to your computer's settings. Because of this, simply reinstalling you web browser or changing from one web browser to another will do nothing to stop symptoms associated with the Searchya! Toolbar.

Technical Information

File System Details

Searchya! Toolbar creates the following file(s):
# File Name Size MD5 Detection Count
1 %PROGRAMFILES%\Ironsource\searchya\1.5.13.0\searchyasrv.exe 352,768 78301801b3ac5cd6cefed6621ebc9509 24
2 %PROGRAMFILES%\Ironsource\searchya\1.5.13.0\bh\searchya.dll 261,632 8a7ef1ada6cd5f3ff17ce651e45acdc9 1
3 %TEMP%\nsr7659.tmp\34\SearchYaSetup_2.2.1.503.1.exe 2,157,568 2ded70f1dc6a6dae4bbb4443c4a95fbf 1
4 %TEMP%\is1852162411\SearchYaLatest.exe 2,249,261 33f3b03bca3e1e3e0e8ae21b5c002d53 1
5 C:\Program Files\SearchYa!\1.5.20.0\searchyaApp.dll N/A
6 C:\Program Files\SearchYa!\1.5.20.0\escortShld.dll N/A
7 C:\Program Files\SearchYa!\1.5.20.0\searchyaTlbr.dll N/A
8 C:\Program Files\SearchYa!\1.5.20.0\bh\searchya.dll N/A
9 C:\Program Files\SearchYa!\1.5.20.0\searchyaEng.dll N/A
10 C:\Program Files\SearchYa!\1.5.20.0\FavIcon N/A
11 C:\Program Files\SearchYa!\1.5.20.0\searchyasrv N/A
12 C:\Program Files\SearchYa!\1.5.20.0\uninstall N/A
More files

Registry Details

Searchya! Toolbar creates the following registry entry or registry entries:
Registry key
SOFTWARE\Classes\esrv.searchyaESrvc
SOFTWARE\Classes\esrv.searchyaESrvc.1
SOFTWARE\Classes\ironsource.searchyaappCore
SOFTWARE\Classes\ironsource.searchyaappCore.1
SOFTWARE\Classes\ironsource.searchyadskBnd
SOFTWARE\Classes\ironsource.searchyadskBnd.1
SOFTWARE\Classes\ironsource.searchyaHlpr
SOFTWARE\Classes\ironsource.searchyaHlpr.1
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{819DC4CA-4FFF-4C2E-800D-F346471D99BC}
SOFTWARE\Microsoft\Internet Explorer\Toolbar\{33AA308B-B565-4376-AC66-59EE9B6AD13E}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Searchya
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{25927741-5E5B-4D27-8D8B-9188FE64373F}
Software\Searchya
Software\searchya!
Software\searchya.com
SOFTWARE\Wow6432Node\FoxTab\searchya
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{819DC4CA-4FFF-4C2E-800D-F346471D99BC}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{33AA308B-B565-4376-AC66-59EE9B6AD13E}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{25927741-5E5B-4D27-8D8B-9188FE64373F}
Directory
%PROGRAMFILES%\Ironsource\searchya
%PROGRAMFILES%\SearchYa!
%PROGRAMFILES(x86)%\Ironsource\searchya
%PROGRAMFILES(x86)%\SearchYa!
Uninstaller
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\searchya
searchya
CLSID
{15F6BCB7-BB0F-4A66-8762-4765B05597EB}
{1973277F-87B0-4EA3-9ED2-470A91D284CF}
{25927741-5E5B-4D27-8D8B-9188FE64373F}
{33AA308B-B565-4376-AC66-59EE9B6AD13E}
{54B24FA9-87E8-47FC-8589-F9D382D8B299}
{5B45AC88-523C-431E-86D7-F339B2EE262E}
{6801410E-CC88-42D6-A93B-909E95645407}
{69332529-EEC8-4D0D-9FD3-202C4AE8E589}
{8B0C188C-F6F3-484D-8225-E40262DDE633}
RegistryKeyValue
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Start Page"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar "SearchYa Toolbar"
RegistryKeysandSubkeys
HKEY_CLASSES_ROOT\esrv.searchyaESrvc
HKEY_CLASSES_ROOT\esrv.searchyaESrvc\CurVer
HKEY_CLASSES_ROOT\ironsource.searchyaHlpr
HKEY_CLASSES_ROOT\ironsource.searchyaappCore
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.searchyaESrvc

Site Disclaimer

Enigmasoftware.com is not associated, affiliated, sponsored or owned by the malware creators or distributors mentioned on this article. This article should NOT be mistaken or confused in being associated in any way with the promotion or endorsement of malware. Our intent is to provide information that will educate computer users on how to detect, and ultimately remove, malware from their computer with the help of SpyHunter and/or manual removal instructions provided on this article.

This article is provided "as is" and to be used for educational information purposes only. By following any instructions on this article, you agree to be bound by the disclaimer. We make no guarantees that this article will help you completely remove the malware threats on your computer. Spyware changes regularly; therefore, it is difficult to fully clean an infected machine through manual means.

Leave a Reply

Please DO NOT use this comment system for support or billing questions. For SpyHunter technical support requests, please contact our technical support team directly by opening a customer support ticket via your SpyHunter. For billing issues, please refer to our "Billing Questions or Problems?" page. For general inquiries (complaints, legal, press, marketing, copyright), visit our "Inquiries and Feedback" page.


HTML is not allowed.