How to remove

What is

If you launched your browser and discovered as your homepage, then it means that your computer is infected with a browser hijacker that is also called Search Module Plus. Besides altering the homepage it is capable of changing search engine to one of these:,, or Manual changing of settings by user won’t have an effect, as Search Module Plus adds a scheduled process SMWPUpd, which is responsible for restoration of the adjustments. The main nuisance of the hijacker is that it shows corrupted search results that lead people on the pages they didn’t intend to visit. Beyond all doubt, Search Module Plus shouldn’t be kept on your browser, and in this guide we suggest several ways for you to remove page

How got installed on your computer?

Knowing the methods of malware spreading may help you to avoid infections in future. The highest chances to get the hijacker are while headily installing freeware from dubious site. Such programs have only a few words said about there being additional components and not a word at all about their true nature. Still, you need to be attentive with installation screens and EULAs – if there is a choice between installation types, select Advanced.

Symptoms of infection

  • First and the most striking proof of having a browser hijacker is change of the main page. Usually it is a search engine page that is designed so that user would believe in its legitimacy.
  • Generally, hijackers cause redirections when user makes a search query on its page or tries to reach a blocked site (usually another search engine or anti-malware sites)
  • Another indicator of hijacker infection is appearance of new programs, toolbars and browser extensions that you don’t remember installing and processes in start-up queue.
  • Also, you may notice the significant slowdown in the system operating, since running of the applications required for malware activity may consume a lot of CPU.
  • Besides, hijacker infection may as well negatively affect the speed of Internet connection.

How to remove

To make sure that the hijacker won’t appear again, you need to delete completely. For this you need to remove the application from the Control Panel and then check the drives for such leftovers as files and registry entries.
We should warn you that performing some of the steps may require above-average skills, so if you don’t feel experienced enough, you may apply to automatic removal tool.

Download SpyHunter

Performing an antimalware scan with Norton would automatically search out and delete all elements related to It is not only the easiest way to eliminate, but also the safest and most assuring one.

Steps of manual removal

Uninstall from Control Panel

As it was stated before, more likely that the hijacker appeared on your system brought by other software. So, to get rid of you need to call to memory what you have installed recently.

How to remove from Windows XP

  1. Click the Start button and open Control Panel
  2. Go to Add or Remove Programs
  3. Find the application related to and click Uninstall

How to remove from Windows 7/Vista

  1. Click the Start button and open Control Panel
  2. Go to Uninstall Program
  3. Find the application related to and click Uninstall

How to remove from Windows 8/8.1

  1. Right-click the menu icon in left bottom corner
  2. Choose Control Panel
  3. Select the Uninstall Program line
  4. Uninstall the application related to

How to remove from Windows 10

  1. Press Win+X to open Windows Power menu
  2. Click Control Panel
  3. Choose Uninstall a Program
  4. Select the application related to and remove it

noteIf you experience problems with removing from Control Panel: there is no such title on the list, or you receive an error preventing you from deleting the application, see the article dedicated to this issue.
Read what to do if program won’t uninstall from Control Panel

Remove from browsers

Since some of hijacker threats use a disguise of a browser add-on, you will need to check the list of extensions/add-ons in your browser.

How to remove from Google Chrome

  1. Start Google Chrome
  2. Click on Tools, then go to the Extensions
  3. Delete or other extensions that look suspicious and you don’t remember installing them

How to remove from Internet Explorer

  1. Launch Internet Explorer
  2. Click on the Tools/Gear icon, then select Manage Add-ons
  3. Delete or other extensions that look suspicious and you don’t remember installing them

How to remove from Mozilla Firefox

  1. Start Mozilla Firefox
  2. Click on the right-upper corner button
  3. Click Add-ons, then go to Extensions
  4. Delete or other extensions that look suspicious and you don’t remember installing them

Reset your browsers

How to reset settings in Google Chrome

  1. Click on the icon in the right-upper corner
  2. Choose Settings
  3. Click Show advanced settings
  4. Click the Reset Settings button

How to reset settings in Mozilla Firefox

  1. Click the icon in the upper right corner
  2. Choose Help
  3. Select Troubleshooting Information
  4. Click the Reset Firefox… button

How to reset settings in Internet Explorer

  1. Click on the Tools button
  2. Go to Internet options
  3. Go to the Advanced tab
  4. Click Reset

Delete files and registry entries added by

Sometimes removal via Control Panel is not enough since the built-in application can leave some files that shortly will restore the hijacker. So, you need to find all of the following items and delete them

Remove files and folders:

%ProgramFiles%\Common Files\Goobzo\
%ProgramFiles%\Common Files\Goobzo\GBUpdatePlus\
%ProgramFiles%\Common Files\Goobzo\GBUpdatePlus\SBIEBrowserHelperObject.dll
%ProgramFiles%\Common Files\Goobzo\GBUpdatePlus\Search.lnk
%ProgramFiles%\Common Files\Goobzo\GBUpdatePlus\sma.exe
%ProgramFiles%\Common Files\Goobzo\GBUpdatePlus\smci32.dll
%ProgramFiles%\Common Files\Goobzo\GBUpdatePlus\smci64.dll
%ProgramFiles%\Common Files\Goobzo\GBUpdatePlus\smei32.dll
%ProgramFiles%\Common Files\Goobzo\GBUpdatePlus\smei64.dll
%ProgramFiles%\Common Files\Goobzo\GBUpdatePlus\smfi32.dll
%ProgramFiles%\Common Files\Goobzo\GBUpdatePlus\smfi64.dll
%ProgramFiles%\Common Files\Goobzo\GBUpdatePlus\smi32.exe
%ProgramFiles%\Common Files\Goobzo\GBUpdatePlus\smi64.exe
%ProgramFiles%\Common Files\Goobzo\GBUpdatePlus\smoi32.dll
%ProgramFiles%\Common Files\Goobzo\GBUpdatePlus\smoi64.dll
%ProgramFiles%\Common Files\Goobzo\GBUpdatePlus\smp.exe
%ProgramFiles%\Common Files\Goobzo\GBUpdatePlus\smri32.dll
%ProgramFiles%\Common Files\Goobzo\GBUpdatePlus\smri64.dll
%ProgramFiles%\Common Files\Goobzo\GBUpdatePlus\smu.exe
%ProgramFiles%\Common Files\Goobzo\GBUpdatePlus\SMUninstall.exe
%ProgramFiles%\Common Files\Goobzo\GBUpdatePlus\smw.sys
%ProgramFiles%\Common Files\Goobzo\GBUpdatePlus\Updater.exe

Remove registry entries:

HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{5DA58806-B50C-4DF2-B16C-43FFD66AB632}
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F219737D-CE3B-4851-98F2-CF3110F6471D}
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Search Module Plus
HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\SuggestionsURLFallback "{searchTerms}" (old value="{searchTerms}&maxwidth={ie:maxWidth}&rowheight={ie:rowHeight}§ionHeight={ie:sectionHeight}&FORM=IESS02&market={language}")
HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\FaviconURLFallback "" (old value="")
HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\DisplayName "Search" (old value="Bing")
HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\URL ",fa7aa36a-0e54-4de1-8250-50df0d51be8e,&q={searchTerms}" (old value="{searchTerms}&src=IE-SearchBox&FORM=IESR02")
HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\TopResultURLFallback ",fa7aa36a-0e54-4de1-8250-50df0d51be8e,&q={searchTerms}" (old value="{searchTerms}&src=IE-TopResult&FORM=IETR02")
HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\FaviconURL "" (old value="")
HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\TopResultURL ",fa7aa36a-0e54-4de1-8250-50df0d51be8e,&q={searchTerms}" (old value="{searchTerms}&src=IE-TopResult&FORM=IETR02")
HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\SuggestionsURL "{searchTerms}" (old value="{searchTerms}&maxwidth={ie:maxWidth}&rowheight={ie:rowHeight}§ionHeight={ie:sectionHeight}&FORM=IESS02&market={language}")

Leave a Reply

Your email address will not be published. Required fields are marked *