Mevarabon.com is a browser hijacker that forcibly redirects users through unwanted search engines and advertising pages, degrading the browsing experience while harvesting search queries and browsing data. Unlike simple adware, this threat modifies browser settings at multiple layers—default search provider, new tab page, homepage—and actively resists manual removal attempts by reinstalling itself from hidden persistence mechanisms. Computer Repair Roswell has removed dozens of these hijackers from customer machines in the past year, often finding them bundled with freeware downloads or installed through deceptive software update prompts.
Threat Profile
| Attribute | Details |
|---|---|
| Family | Browser Hijacker / Potentially Unwanted Program (PUP) |
| Aliases | Mevarabon redirect, Mevarabon.com search hijacker, Mevarabon browser modifier |
| Platform | Windows (7, 8.1, 10, 11); affects Chrome, Firefox, Edge, and Internet Explorer |
| Discovered | Variants circulating since 2018; updated distribution methods observed through 2023 |
| Distribution | Software bundlers (InstallCore, Amonetize), fake Flash updates, torrent bundles, malicious browser extensions |
| Persistence | Browser extensions, scheduled tasks, registry run keys, policy settings (Group Policy, Chrome Policies), helper services |
| Capabilities | Homepage/search engine replacement, new tab hijacking, search query redirection, tracking cookie deployment, advertisement injection |
| Data Collection | Search queries, browsing history, clicked links, IP address, browser fingerprint, approximate geolocation |
| Typical Artifacts | Browser extension folders in user profiles, scheduled tasks with random names, registry keys in HKCU\Software\Policies |
| Network Behavior | Redirects through multiple intermediary domains before landing on ad pages or affiliate search engines; beacons to tracking servers |
| Payload Risk | Low direct damage potential; primary risks are privacy exposure and secondary infection through redirected advertising networks |
| Removal Difficulty | Moderate to high—multiple persistence points require thorough cleanup; incomplete removal causes immediate reinfection |
How It Spreads
Mevarabon.com spreads almost exclusively through deceptive software bundling, where legitimate-seeming free programs carry hidden "optional offers" that install the hijacker alongside the wanted application. These bundlers present misleading installation screens where the hijacker is pre-checked in "custom" or "advanced" settings that most users skip. We've traced infections back to video converters, PDF utilities, download managers, and system optimization tools downloaded from third-party software repositories rather than official developer sites.
The second major vector involves fake update notifications—pop-ups claiming your Flash Player, Java, or browser needs an urgent security update. Clicking "Update Now" downloads an installer package that deploys Mevarabon.com instead of or alongside any legitimate update. These fake prompts appear on compromised websites, torrent sites, and streaming portals. The notifications are designed to mimic legitimate system dialogs, complete with official-looking logos and security warning language.
Common distribution channels include:
- Bundled freeware installers from download sites like Softonic, Download.com (when users don't verify the download button), and CNET mirrors
- Fake Flash Player updates on streaming sites and file-sharing platforms—Adobe discontinued Flash in 2020, so any Flash update prompt is malicious
- Browser extension stores where the hijacker disguises itself as a "search enhancer," coupon finder, or weather toolbar
- Torrent bundles where cracked software or media files include "cracks" or "keygens" that are actually hijacker installers
- Email attachments in phishing campaigns, though less common for this particular threat
- Compromised legitimate software where attackers inject the hijacker into otherwise-clean downloads through supply chain attacks on smaller software vendors
What It Does On Your Machine
Once installed, Mevarabon.com immediately reconfigures your browser settings to route all search activity through its redirection infrastructure. Your homepage changes to an unfamiliar search page, your default search engine switches to a Mevarabon-controlled provider, and every new tab opens to the hijacker's landing page. These changes persist even after you manually reset them because the hijacker uses multiple enforcement mechanisms—browser policies managed through Windows registry keys, hidden extensions that reapply settings on browser startup, and scheduled tasks that check configuration every few minutes.
The hijacker's core function is search redirection monetization. When you perform a web search, your query passes through several intermediary servers before reaching a legitimate search engine (often a white-labeled Yahoo or Bing). This chain allows the operators to inject sponsored results at the top of your search page and collect referral fees when you click those links. More concerning, every search query, every clicked result, and your browsing patterns are logged and transmitted to the hijacker's tracking servers. This data feeds into advertising profiles sold to third parties or used to deliver targeted advertising through other channels.
Beyond search hijacking, affected users often report performance degradation—browsers launch slowly, pages load with delays while waiting for tracking scripts, and CPU usage spikes from background data collection processes. The hijacker may inject additional advertisements into web pages you visit, display pop-under windows when you click anywhere on a page, and replace legitimate affiliate links on shopping sites with the hijacker's own affiliate IDs to steal commissions from content creators.
The most insidious aspect of Mevarabon.com is its self-repair capability. If you remove the browser extension but leave the scheduled task or registry policies intact, the helper process reinstalls the extension within minutes. If you delete the program folder but don't remove the scheduled task, the task attempts to re-download components from the hijacker's distribution servers. Complete removal requires identifying and eliminating every persistence mechanism simultaneously.
Manual Removal — Step by Step
Disconnect From the Network
Before starting removal, disable your internet connection—unplug the Ethernet cable or turn off WiFi from the system tray. This prevents the hijacker from downloading additional components, communicating with tracking servers, or receiving updated configuration that might interfere with cleanup. Work offline throughout the entire removal process.
Boot Into Safe Mode With Networking
Restart your computer and press F8 repeatedly during boot (or Shift+Restart from Windows 10/11, then Troubleshoot → Advanced → Startup Settings → Restart → press 5). Select "Safe Mode with Networking." This loads Windows with minimal drivers and services, preventing the hijacker's background processes from launching and interfering with removal. The "with Networking" option allows you to download removal tools if needed later.
Uninstall Suspicious Programs
Open Settings → Apps → Apps & features (or Control Panel → Programs and Features on older Windows). Sort by installation date and look for unfamiliar programs installed around the time the hijacking started. Common disguise names include "Browser Helper," "Search Manager," "PC Optimizer," or random company names you don't recognize. Uninstall anything suspicious—if you're uncertain about a program, search its name online before removing. The hijacker's main uninstaller may appear here, though it often leaves components behind intentionally.
Remove Browser Extensions
Open each browser and check extensions. In Chrome: three-dot menu → Extensions → Manage Extensions. In Firefox: three-bar menu → Add-ons and themes → Extensions. In Edge: three-dot menu → Extensions. Remove any extensions you didn't intentionally install, especially those with vague names like "Search Helper," "Quick Search," or extensions from unknown developers. Mevarabon.com often uses generic names designed to blend in with legitimate extensions.
Delete Scheduled Tasks
Press Win+R, type taskschd.msc, and press Enter to open Task Scheduler. Click "Task Scheduler Library" in the left pane and review the task list. Look for tasks with suspicious names, tasks that run from %LOCALAPPDATA% or %APPDATA% folders, or tasks created by unknown publishers. Right-click suspicious tasks and select "End" (if running) then "Delete." Pay special attention to tasks that run at logon or repeat every few minutes—these are hijacker persistence mechanisms.
Clean Registry Policies and Run Keys
Press Win+R, type regedit, and press Enter. Navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and look for entries pointing to unfamiliar executables in user folders. Delete suspicious entries. Then check HKEY_CURRENT_USER\Software\Policies\Google\Chrome, ...\Policies\Microsoft\Edge, and ...\Policies\Mozilla\Firefox—delete these entire "Policies" keys if present (they shouldn't exist on consumer machines unless set by corporate IT). These registry locations enforce browser settings that override user preferences.
Delete Hijacker Program Folders
Open File Explorer and navigate to C:\Users\[YourUsername]\AppData\Local and ...\AppData\Roaming. Show hidden files (View → Hidden items checkbox). Look for folders with random GUID names (like {A1B2C3D4-...}) or suspicious folder names created around infection time. Open them to verify they contain hijacker executables (names like browser_assistant, updater, service_host). Delete the entire folder. Also check your browser profile folders for suspicious extension directories and remove them manually.
Reset Browser Settings
After removing extensions and files, reset each browser to defaults. In Chrome: Settings → Reset settings → Restore settings to their original defaults. In Firefox: Help → More troubleshooting information → Refresh Firefox. In Edge: Settings → Reset settings → Restore settings to their default values. This clears homepage, search engine, and startup page settings enforced by the hijacker. You'll need to reconfigure bookmarks and saved passwords afterward, so export those first if possible.
Scan With Reputable Anti-Malware Tools
Reconnect to the internet and download Malwarebytes (free version works fine) from malwarebytes.com. Run a full system scan to catch any remaining components manual removal might have missed. Follow this with a scan from your existing antivirus if you have one. These tools maintain databases of known hijacker signatures and can identify variants you might not recognize. Restart the computer after cleaning is complete, then run one more scan to verify nothing reinstalled.
Change Important Passwords
Since the hijacker logged your browsing activity and search queries, assume your account credentials may have been exposed if you entered them while infected. Change passwords for email, banking, shopping sites, and social media accounts—do this from a known-clean device if possible. Enable two-factor authentication where available. Monitor your accounts for unusual activity over the next few weeks, especially financial accounts.
Prevention
- Download software only from official sources. Go directly to the developer's website rather than using third-party download repositories. Verify the URL is correct—typosquatting sites often mimic legitimate download pages. For open-source software, use the official GitHub repository or the project's designated download page.
- Always choose "Custom" or "Advanced" installation. Never click through an installer using "Express" or "Recommended" settings. Read every screen carefully, uncheck pre-selected offers for toolbars or "helpful" programs, and decline additional software even if the installer claims it's required. If an installer won't let you refuse bundled offers, cancel the installation entirely.
- Keep browsers and extensions minimal. Only install extensions from official browser stores (Chrome Web Store, Firefox Add-ons), and limit yourself to extensions from known developers with thousands of positive reviews. Review your extension list monthly and remove anything you no longer actively use. Extensions have broad permissions to modify web content and can become attack vectors.
- Ignore fake update prompts. Legitimate software updates come through the application's built-in update mechanism (like Chrome's automatic updates) or directly from Windows Update. If a website pop-up claims you need to update Flash, Java, or your browser, it's a scam—close the tab immediately. Adobe discontinued Flash Player in December 2020; any Flash update prompt is malicious.
- Use an ad blocker and anti-tracking extension. Install uBlock Origin (not uBlock, different projects) to block advertisement networks that host malicious redirects. Add Privacy Badger or similar to block tracking scripts. These tools prevent many hijacker distribution methods and reduce exposure to compromised advertising networks.
- Run automatic Windows updates. Keep Windows, your browser, and all software current with security patches. Enable automatic updates for Windows and browsers. Unpatched software vulnerabilities allow hijackers to install themselves without user interaction through "drive-by downloads" when you visit compromised websites.
- Maintain active antivirus protection. Windows Defender is adequate for most users if kept updated, but consider Malwarebytes Premium or Bitdefender for enhanced real-time protection. Configure your antivirus to scan downloaded files automatically before execution. Schedule weekly full system scans to catch infections early.
- Create standard user accounts for daily use. Don't use an administrator account for web browsing, email, and general computing. Run your daily account as a Standard User and only elevate privileges when installing software you specifically chose to install. This containment prevents hijackers from installing system-wide persistence mechanisms without your explicit approval via a UAC prompt.
Bring It In
Browser hijackers like Mevarabon.com are frustrating for home users but routine for us—we see several every week and can typically clean them in 45 minutes to an hour, depending on how many persistence mechanisms the particular variant deployed. We use professional-grade tools that go beyond consumer antivirus, checking BIOS settings, Windows services, network configuration, and hidden scheduled tasks that typical users wouldn't know to examine. More importantly, we verify the removal: after cleaning, we monitor the system through several restart cycles to confirm nothing reinstalls itself, then document every change we made so you understand what was wrong and how we fixed it.
If you've tried the manual removal steps above and still see redirects, or if you simply want the confidence of professional cleaning, bring your machine to Computer Repair Roswell at 1000 Alpharetta Street (corner of Alpharetta and Woodstock, across from the Roswell Cultural Arts Center). We're open Monday through Saturday, and we can usually start work immediately for walk-ins. Call ahead at (770) 534-5320 if you'd like to confirm we have a tech available or if you'd prefer to drop the machine off for service while you run errands. We'll call you with findings before proceeding with any work beyond the initial diagnostic, and we can often have you back up and running the same day. Let's get your browser back under your control.