Home Malware Programs Bad Toolbars Searchya! Toolbar

Searchya! Toolbar

Posted: August 24, 2012

Threat Metric

Ranking: 3,952
Threat Level: 5/10
Infected PCs: 24,074
First Seen: August 24, 2012
Last Seen: October 17, 2023
OS(es) Affected: Windows

Searchya Toolbar Screenshot 1Searchya! Toolbar is a search engine toolbar that's used to promote the searchya.com website. Although Searchya! Toolbar and its associated site do possess search features, most PC users have expressed dissatisfaction with the quality of these functions, and malware researchers have found clear indications of Searchya! Toolbar including characteristics of a PUP or browser hijacker. To remove Searchya! Toolbar's unwanted browser changes, you should delete Searchya! Toolbar with a trustworthy anti-malware application; other removal methods may fail to remove all of Searchya! Toolbar's components, which are compatible with multiple types of web browsers. However, temporary contact with searchya.com and other symptoms of Searchya! Toolbar infections can be considered low-level risks that are unlikely to damage your PC if resolved in a timely fashion.

When Searchya! Toolbar Takes Your Searches to Its Own Places of Interest

Like many low-level browser hijackers and PUPs, Searchya! Toolbar's sole purpose is to redirect traffic to an associated website: the searchya.com domain. Searchya.com, in turn, provides search features similar to Google or Yahoo Search, although with substantially less accurate results that often include irrelevant links. SpywareRemove.com malware analysts have found that the most common browser modifications linked to Searchya! Toolbar attacks include changes to your homepage and redirects that trigger when you try to use unrelated search sites (Google, etc.).

Searchya! Toolbar attacks have expressed a wide degree of compatibility with various brands of web browsers, including Internet Explorer, Chrome and Firefox. Given that the Searchya! Toolbar is likely to include non-browser-specific components, SpywareRemove.com malware experts encourage you to use anti-malware products to detect and delete Searchya! Toolbar in its entirety, rather than attempting to disable Searchya! Toolbar in a specific browser.

Keeping Your PC Out of the Reach of the Searchya! Toolbar's Fishing Net

The Searchya! Toolbar is often installed unintentionally through bundled installers with games, media utilities and other programs that are distributed through unsafe sources. SpywareRemove.com malware researchers recommend keeping close tabs on any toolbars or other add-ons that are installed by programs from risky sources, since many such installers will allow you to opt out of an installation of Searchya! Toolbar or similar PUPs.

At this time, Searchya! Toolbar has been in distribution for at least half a year, with new Searchya! Toolbar attacks still being reported recently. As a low-level PC threat that resists deletion and hinders your ability to use reputable websites, Searchya! Toolbar should be considered an active, if minor danger to your computer. However, searchya.com has not been found to host overtly malicious content, although Searchya! Toolbar-related sites may expose you to PC threats unintentionally due to a lack of the appropriate safety protocols that are used by reputable search engines.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\Searchya\UpdateProc\UpdateTask.exe File name: UpdateTask.exe
Size: 194.51 KB (194512 bytes)
MD5: b352141bc9ca645f7c72b00fad5dea27
Detection count: 2,401
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Searchya\UpdateProc
Group: Malware file
Last Updated: January 17, 2020
%APPDATA%\searchya\UpdateProc\UpdateTask.exe File name: UpdateTask.exe
Size: 231.93 KB (231936 bytes)
MD5: 6c842266b98f7296a611f263eaba4c49
Detection count: 90
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\searchya\UpdateProc
Group: Malware file
Last Updated: March 23, 2016
%APPDATA%\Searchya\UpdateProc\UpdateTask.exe File name: UpdateTask.exe
Size: 194.51 KB (194512 bytes)
MD5: 43c2ac7f29703112be161f0433e0009d
Detection count: 82
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Searchya\UpdateProc
Group: Malware file
Last Updated: March 23, 2016
%APPDATA%\searchya\UpdateProc\UpdateTask.exe File name: UpdateTask.exe
Size: 207.87 KB (207872 bytes)
MD5: 8c11e6e7189a2afd533c77c0f77486bc
Detection count: 63
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\searchya\UpdateProc
Group: Malware file
Last Updated: March 23, 2016
%APPDATA%\Searchya\UpdateProc\UpdateTask.exe File name: UpdateTask.exe
Size: 207.87 KB (207872 bytes)
MD5: f8eb65acd84dc9210a2bb20e31c971d0
Detection count: 54
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Searchya\UpdateProc
Group: Malware file
Last Updated: March 23, 2016
%APPDATA%\Searchya\UpdateProc\UpdateTask.exe File name: UpdateTask.exe
Size: 86.01 KB (86016 bytes)
MD5: 089e824c45d0916890f9d26271ed3704
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Searchya\UpdateProc
Group: Malware file
Last Updated: March 23, 2016
%APPDATA%\searchya\UpdateProc\UpdateTask.exe File name: UpdateTask.exe
Size: 273.92 KB (273920 bytes)
MD5: 8abc1d44d33a771b4bfc266506695968
Detection count: 22
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\searchya\UpdateProc
Group: Malware file
Last Updated: March 23, 2016
%APPDATA%\searchya\UpdateProc\UpdateTask.exe File name: UpdateTask.exe
Size: 244.22 KB (244224 bytes)
MD5: 5d97db0e6f5b00ebde63fafb589ac02a
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\searchya\UpdateProc
Group: Malware file
Last Updated: March 23, 2016
%APPDATA%\Searchya\UpdateProc\UpdateTask.exe File name: UpdateTask.exe
Size: 207.87 KB (207872 bytes)
MD5: dbbbbe301d965a4fd0e7a21dd9ea2014
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Searchya\UpdateProc
Group: Malware file
Last Updated: March 23, 2016
%SystemDrive%\Documents and Settings\NetworkService\Application Data\Searchya\UpdateProc\UpdateTask.exe File name: UpdateTask.exe
Size: 207.87 KB (207872 bytes)
MD5: c3c2c4a2024663825dbaabd849931d09
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Documents and Settings\NetworkService\Application Data\Searchya\UpdateProc
Group: Malware file
Last Updated: March 23, 2016
%APPDATA%\searchya\UpdateProc\UpdateTask.exe File name: UpdateTask.exe
Size: 207.87 KB (207872 bytes)
MD5: 0c900c60528ded5dd99e33c394d822d7
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\searchya\UpdateProc
Group: Malware file
Last Updated: March 23, 2016
%SystemDrive%\Documents and Settings\NetworkService\Application Data\Searchya\UpdateProc\UpdateTask.exe File name: UpdateTask.exe
Size: 281.6 KB (281600 bytes)
MD5: 44150f02341e188df4819bb50cda605b
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Documents and Settings\NetworkService\Application Data\Searchya\UpdateProc
Group: Malware file
Last Updated: March 23, 2016
%APPDATA%\Searchya\UpdateProc\UpdateTask.exe File name: UpdateTask.exe
Size: 124.41 KB (124416 bytes)
MD5: ba2262e410ceac160c52b28d467c1c2e
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Searchya\UpdateProc
Group: Malware file
Last Updated: March 23, 2016
%SystemDrive%\Documents and Settings\deve\Application Data\Searchya\UpdateProc\UpdateTask.exe File name: UpdateTask.exe
Size: 230.86 KB (230864 bytes)
MD5: 100c9668acef56401b09903b883bf1f4
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Documents and Settings\deve\Application Data\Searchya\UpdateProc
Group: Malware file
Last Updated: March 23, 2016
%SystemDrive%\Documents and Settings\NetworkService\Application Data\Searchya\UpdateProc\UPDATETASK.EXE File name: UPDATETASK.EXE
Size: 241.94 KB (241949 bytes)
MD5: 27333544d92bd0117c6b1105fa1c0a46
Detection count: 5
File type: Executable File
Mime Type: unknown/EXE
Path: %SystemDrive%\Documents and Settings\NetworkService\Application Data\Searchya\UpdateProc
Group: Malware file
Last Updated: March 23, 2016
%SystemDrive%\Documents and Settings\NetworkService\Dane aplikacji\Searchya\UpdateProc\UpdateTask.exe File name: UpdateTask.exe
Size: 228.35 KB (228352 bytes)
MD5: ddeb4d0323df8f4b23d92df92a06ceb4
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Documents and Settings\NetworkService\Dane aplikacji\Searchya\UpdateProc
Group: Malware file
Last Updated: March 23, 2016
%APPDATA%\searchya\UpdateProc\UpdateTask.exe File name: UpdateTask.exe
Size: 210.94 KB (210940 bytes)
MD5: 1f854f6803b195cb1cf057e8e88de969
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\searchya\UpdateProc
Group: Malware file
Last Updated: March 23, 2016
C:\Program Files\SearchYa!\1.5.20.0\bh\searchya.dll File name: C:\Program Files\SearchYa!\1.5.20.0\bh\searchya.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\Program Files\SearchYa!\1.5.20.0\escortShld.dll File name: C:\Program Files\SearchYa!\1.5.20.0\escortShld.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\Program Files\SearchYa!\1.5.20.0\FavIcon File name: C:\Program Files\SearchYa!\1.5.20.0\FavIcon
Mime Type: unknown/0\FavIcon
Group: Malware file
C:\Program Files\SearchYa!\1.5.20.0\searchyaApp.dll File name: C:\Program Files\SearchYa!\1.5.20.0\searchyaApp.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\Program Files\SearchYa!\1.5.20.0\searchyaEng.dll File name: C:\Program Files\SearchYa!\1.5.20.0\searchyaEng.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\Program Files\SearchYa!\1.5.20.0\searchyasrv File name: C:\Program Files\SearchYa!\1.5.20.0\searchyasrv
Mime Type: unknown/0\searchyasrv
Group: Malware file
C:\Program Files\SearchYa!\1.5.20.0\searchyaTlbr.dll File name: C:\Program Files\SearchYa!\1.5.20.0\searchyaTlbr.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\Program Files\SearchYa!\1.5.20.0\uninstall File name: C:\Program Files\SearchYa!\1.5.20.0\uninstall
Mime Type: unknown/0\uninstall
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%WINDIR%\System32\Tasks\Searchya%WINDIR%\Tasks\Searchya.jobHKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Start Page"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar "SearchYa Toolbar"HKEY..\..\..\..{Subkeys}HKEY_CLASSES_ROOT\esrv.searchyaESrvcHKEY_CLASSES_ROOT\esrv.searchyaESrvc\CurVerHKEY_CLASSES_ROOT\ironsource.searchyaappCoreHKEY_CLASSES_ROOT\ironsource.searchyaHlprHKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.searchyaESrvcHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\searchya

Additional Information

The following directories were created:
%APPDATA%\Searchya
The following URL's were detected:
.search-ya.com
Loading...