MbMsgOnline is a browser hijacker and potentially unwanted program (PUP) that infiltrates systems to redirect web traffic and generate advertising revenue through forced search results. First documented in late 2019, this threat modifies browser settings without user consent, replacing the default search engine and new tab page with its own portal. While not as destructive as ransomware or data-stealing trojans, MbMsgOnline degrades system performance, exposes users to potentially malicious advertising networks, and creates persistent tracking mechanisms that compromise privacy.
The primary concern with MbMsgOnline extends beyond simple annoyance. By routing all search queries through third-party servers, the hijacker can log every search term, URL visited, and potentially sensitive information entered into web forms. This collected data becomes a commodity sold to advertising networks or, in worse scenarios, to more malicious actors. The redirected search results often prioritize sponsored links and advertisements over legitimate results, increasing the risk of exposure to phishing sites, fake software downloads, and additional PUP installations.
Threat Profile
| Attribute | Details |
|---|---|
| Threat Classification | Browser Hijacker / Potentially Unwanted Program (PUP) |
| Family | Generic search redirect family, similar to Conduit, MyWebSearch variants |
| Known Aliases | MbMsg Online, MB-MSG-Online, mbmsg.online (domain variant) |
| Platforms Affected | Windows 7/8/10/11 (Chrome, Firefox, Edge); limited Mac variants reported |
| First Documented | Late 2019, with peak activity 2020-2021 |
| Primary Distribution | Software bundling, fake update prompts, freeware installers |
| Persistence Mechanisms | Browser extension policies, scheduled tasks, registry Run keys, extension force-install policies (enterprise contexts) |
| Core Capabilities | Search redirection, homepage replacement, new tab hijacking, ad injection, user tracking, cookie manipulation |
| Network Behavior | Establishes C2 communication with advertising networks; redirects through multiple intermediate domains (mbmsg.online, various subdomains) before landing on search results pages |
| Data Collection | Browser history, search queries, IP address, geolocation data, device identifiers, installed extensions list |
| File System Artifacts | Extension folders in browser profile directories, randomly-named EXE files in AppData\Local, configuration JSON files |
| Removal Difficulty | Moderate—reinstalls via scheduled tasks if not thoroughly cleaned; some variants use Group Policy manipulation |
How It Spreads
MbMsgOnline rarely arrives alone. The most common infection vector involves software bundling, where legitimate-looking freeware installers contain hidden checkbox agreements that install the hijacker alongside the desired program. Users downloading video converters, PDF creators, system optimizers, or media players from third-party download sites face the highest risk. The installation wizard often uses deceptive patterns—pre-checked boxes buried in "Custom Installation" screens, accept buttons that actually consent to additional software, or deliberately confusing language that obscures what's being installed.
Fake browser update notifications represent another significant distribution channel. Users encounter professionally-designed pop-ups claiming their Chrome, Firefox, or Edge browser is outdated and requires an urgent security update. Clicking "Update Now" downloads an executable that installs MbMsgOnline instead of browser updates. These fake update pages often appear on compromised websites or through malicious advertising networks, making them difficult to avoid through careful browsing alone.
Additional distribution methods include:
- Cracked software packages: Pirated applications and games frequently bundle PUPs as a monetization strategy for the distribution group
- Email attachments disguised as documents: Macro-enabled Office files or ZIP archives containing launcher executables
- Malicious browser extensions: Fake ad-blockers, VPN tools, or "security" extensions that install the hijacker after gaining permissions
- Tech support scam follow-ups: After convincing victims they have infections, scammers install MbMsgOnline alongside fake "security" software
- USB drive propagation: Some variants copy themselves to removable media with autorun configurations (on older systems without autorun protections)
- Compromised software update mechanisms: Exploitation of outdated software with vulnerable update processes that can be hijacked for malware delivery
What It Does On Your Machine
Upon installation, MbMsgOnline immediately modifies browser configurations across all installed browsers. The hijacker sets itself as the default search engine, replacing Google, Bing, or DuckDuckGo with its own search portal. Every new tab opened displays the MbMsgOnline page instead of your chosen homepage. The browser's shortcut properties may be modified to append command-line arguments that force-load the hijacker's URL at startup. These changes persist even after manually resetting browser preferences because the underlying mechanisms reinstall the settings each time the browser launches.
The search redirection process follows a deliberate obfuscation pattern. When you enter a search query, the request first routes through MbMsgOnline's servers, where it's logged and analyzed. The query then bounces through several intermediate domains—sometimes five or six redirects—before finally delivering results from a legitimate search engine like Yahoo or Bing. This chain accomplishes multiple goals: it obscures the hijacker's infrastructure making takedowns difficult, it allows for real-time ad injection into results pages, and it complicates removal efforts by involving multiple domains that must be blocked.
System performance degradation becomes noticeable within days. Browser startup times increase significantly, sometimes taking 15-30 seconds longer than normal. Web pages load slowly due to the injection of additional advertising scripts and tracking pixels. CPU usage spikes during browsing sessions as the hijacker processes data collection tasks in the background. Memory consumption grows as multiple browser processes spawn to handle the injected content. Users with older hardware or limited RAM experience the most severe performance impacts, sometimes rendering web browsing nearly unusable.
Manual Removal — Step by Step
Disconnect Network and Document Current State
Disconnect your ethernet cable or disable WiFi before proceeding. Take screenshots of your browser's homepage, new tab page, and default search engine settings for reference. Open Task Manager (Ctrl+Shift+Esc) and screenshot any suspicious processes, particularly those with random names or high CPU usage while the browser is idle.
Boot to Safe Mode with Networking
Restart your computer and repeatedly press F8 during boot (or use Shift+Restart from Windows 10/11, then navigate to Troubleshoot > Advanced Options > Startup Settings > Restart > option 5). Safe Mode loads only essential drivers, preventing MbMsgOnline's persistence mechanisms from reactivating during removal. Select "Safe Mode with Networking" to allow scanner downloads later.
Uninstall Suspicious Programs
Open Control Panel > Programs and Features (or Settings > Apps on Windows 10/11). Sort by "Installed On" date and look for unfamiliar programs installed around when the hijacking began. Common names include MbMsg, various toolbars, "PC Optimizer" tools, or programs with no publisher information. Uninstall anything suspicious. Some variants install under generic names like "System Update Service" or use randomized alphanumeric names.
Terminate Processes and Delete Service Executables
Open Task Manager and end any processes named mbmsg_service.exe, MbMsg-related processes, or suspicious randomly-named executables running from AppData\Local folders. Navigate to C:\Users\[YourUsername]\AppData\Local\ and delete any folders named MbMsg, MbMsgOnline, or containing the executables you terminated. Also check AppData\Roaming for similar folders. If Windows prevents deletion claiming the file is in use, note the location and return after the next step.
Remove Persistence Mechanisms
Press Win+R, type "taskschd.msc" and press Enter to open Task Scheduler. Look for tasks with MbMsg references or generic names like "System Update Service" that run executables from AppData locations. Delete these tasks. Next, press Win+R, type "regedit" and navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. Delete any entries pointing to MbMsg executables or suspicious AppData paths. Also check HKEY_LOCAL_MACHINE\SOFTWARE\Policies\ for any Chrome, Firefox, or Edge subkeys containing ExtensionInstallForcelist entries.
Remove Browser Extensions and Reset Settings
For Chrome: Navigate to chrome://extensions/ and remove any unfamiliar extensions, particularly those lacking descriptions or from unknown developers. Then go to chrome://settings/searchEngines and delete MbMsgOnline entries. Reset homepage under chrome://settings/ to your preferred page. For Firefox: Navigate to about:addons, remove suspicious extensions, then go to about:preferences#search to remove unwanted search engines. For Edge: Go to edge://extensions/ and edge://settings/searchEngines and perform similar cleanup. Consider doing a full browser reset (Chrome: chrome://settings/reset, Firefox: about:support > Refresh Firefox) if changes persist.
Scan with Reputable Anti-Malware Tools
Reconnect to the internet and download Malwarebytes Free (from malwarebytes.com directly) and run a full system scan. This will catch residual components and related PUPs that manual removal missed. Follow with a scan using your primary antivirus if it includes PUP detection (enable PUP scanning in settings first—it's often disabled by default). Remove all detected threats before proceeding.
Clean Browser Profiles and Shortcuts
Right-click your browser shortcuts (desktop, taskbar, Start menu) and select Properties. In the "Target" field, remove anything after the .exe path—hijackers often append URLs here. Delete browser cache: Chrome: Ctrl+Shift+Del, select "All time" and check all boxes except passwords. Do the same for other browsers. This removes tracking cookies and cached hijacker scripts.
Change Passwords If Data Theft Is Suspected
If you entered passwords or financial information while the hijacker was active, change those credentials from a known-clean device or after completing all removal steps. Browser hijackers sometimes include keylogging components or can exfiltrate form data entered into phishing pages they redirect to. Prioritize email, banking, and primary account passwords.
Reboot Normally and Verify Clean Status
Restart your computer normally (not Safe Mode) and immediately open your browser before launching other programs. Verify that your chosen homepage loads, new tabs are correct, and searches use your preferred search engine without redirects. Open Task Manager and confirm no suspicious processes have returned. Monitor system behavior for 24-48 hours—some variants include delayed reinstallation mechanisms triggered by specific conditions. If redirects return, the scheduled task or registry entry likely wasn't fully removed, requiring another pass through steps 5-6.
Prevention
- Download software only from official publisher websites. Avoid third-party download aggregators like download.com, softonic.com, or similar portals that bundle PUPs with legitimate software. When searching for free software, go directly to the developer's official site.
- Always choose "Custom" or "Advanced" installation options. Default/Express installation automatically accepts all bundled software. Custom installation reveals hidden checkboxes that must be manually unchecked to decline unwanted programs. Read each screen carefully—some installers use confusing language where "Decline" is buried or "Accept" is the highlighted option.
- Keep browsers and operating systems updated. Enable automatic updates for Windows, Chrome, Firefox, and Edge. Legitimate browsers never require manual update downloads from pop-up prompts. If you see an "update required" message while browsing, close the tab and manually check for updates through the browser's internal settings menu.
- Use an ad-blocker and script-blocker extension. uBlock Origin (not uBlock—different projects) blocks many malicious advertising networks that distribute PUPs. NoScript or uMatrix provides more aggressive blocking but requires configuration. These tools prevent many fake update pages and malicious redirects from displaying.
- Enable your antivirus PUP detection features. Most commercial and free antivirus programs can detect potentially unwanted programs, but this feature is often disabled by default to reduce false positives. Access your antivirus settings and enable "PUP detection" or "Potentially Unwanted Application scanning."
- Review browser extension permissions before installation. Extensions requesting access to "read and change all your data on all websites" should be treated with extreme suspicion unless from verified, reputable developers. Check extension ratings, review counts, and developer information before installing.
- Implement DNS-level blocking. Configure your router or individual machines to use filtering DNS services like Cloudflare's Family DNS (1.1.1.3) or OpenDNS Family Shield. These block access to known malicious domains before your browser can load them, preventing many hijacker command-and-control connections.
- Create a standard user account for daily use. Windows administrator accounts allow programs to make system-wide changes without additional confirmation. Using a standard user account forces installation prompts that require administrator credentials, giving you a second chance to reject unwanted software during installation attempts.
Bring It In
Browser hijackers like MbMsgOnline sit in an awkward middle ground—serious enough to compromise your privacy and system performance, but often dismissed as "just adware" that doesn't warrant professional attention. That dismissal ignores the reality that today's hijackers increasingly include data-harvesting components, create security vulnerabilities that more dangerous malware exploits, and prove frustratingly persistent for users attempting self-removal. Incomplete removal attempts often leave registry remnants or scheduled tasks that reinstall the hijacker days or weeks later, creating a cycle of temporary relief followed by reinfection.
Computer Repair Roswell has developed systematic procedures for completely removing browser hijackers and the bundled PUPs they arrive with. We examine not just the obvious browser settings, but the deeper system modifications—Group Policy changes, proxy settings, certificate store manipulations, and host file redirects—that casual removal attempts miss. We typically complete hijacker removal service within 2-3 hours, including verification that your system boots and browses cleanly. Call (770) 679-9405 or visit us at 1750 Hembree Road, Suite 100, Roswell, GA 30076 (we're in the Parkaire Landing shopping center). Walk-ins welcome Monday through Friday, 10am to 6pm, and Saturday 10am to 4pm. Don't let MbMsgOnline continue degrading your online experience—bring it in and we'll sort it out properly.