Home Malware Programs Browser Hijackers Search Module

Search Module

Posted: August 7, 2014

Threat Metric

Ranking: 7,923
Threat Level: 5/10
Infected PCs: 44,734
First Seen: August 7, 2014
Last Seen: February 18, 2025
OS(es) Affected: Windows


The Search Module browser extension by Goobzo Ltd. is promoted as a browser enhancer in freeware packages under the 'Custom' or 'Typical' option. The Search Module app is deemed by security analysts as a browser hijacker because it enters several registry keys in Windows to change your default search provider, new tab settings, and homepage. Additionally, the Search Module browser hijacker can run at Windows boot-up and delay the start of other applications. You might want to know that the Search Module browser hijacker might load advertisement content on banners, pop-up, and pop-under windows and place transparent layers over web pages you browse and redirect you to potentially harmful domains. Security analysts add that the Search Module browser hijacker can modify your DNS settings and generate web traffic towards sponsored services and websites. The Search Module app may use a background service to host its process use tracking cookies to create a personal advertising profile for you and allow advertisers to deploy tailor-suited commercials in your web browser. Moreover, the Search Module hijacker may install other software as updates to its binary that may include the YouTube Accelerator and ShopperPro. Computer users may want to seek the help of a reputable anti-spyware solution to purge the Search Module browser hijacker from their PC.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\Desktop\Old Desktop\Backup Drive E 12-23-16\USB DISK\downeloads 4 harold\deskbar.exe 2-4-09.exe File name: deskbar.exe 2-4-09.exe
Size: 253 KB (253008 bytes)
MD5: 6b792236360258eaa04328a16d97beba
Detection count: 3,204
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Desktop\Old Desktop\Backup Drive E 12-23-16\USB DISK\downeloads 4 harold\deskbar.exe 2-4-09.exe
Group: Malware file
Last Updated: September 2, 2023
%SYSTEMDRIVE%\AdwCleaner\FileQuarantine\C\Users\<username>\AppData\Local\DeskBar\2.7.5.1765\DeskBar.exe.vir File name: DeskBar.exe.vir
Size: 599.04 KB (599040 bytes)
MD5: 9252cc419c84f0ec639b4da6e21d6e61
Detection count: 162
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\AdwCleaner\FileQuarantine\C\Users\<username>\AppData\Local\DeskBar\2.7.5.1765\DeskBar.exe.vir
Group: Malware file
Last Updated: December 11, 2021
C:\Users\<username>\AppData\Local\SearchModule\trzC7A4.tmp File name: trzC7A4.tmp
Size: 391.16 KB (391168 bytes)
MD5: b13bccaa784f8ca6cb654b7aaab91352
Detection count: 59
File type: Temporary File
Mime Type: unknown/tmp
Path: C:\Users\<username>\AppData\Local\SearchModule\trzC7A4.tmp
Group: Malware file
Last Updated: March 21, 2021

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%WINDIR%\System32\Tasks\SMW_UpdateTask[RANDOM CHARACTERS]%WINDIR%\System32\Tasks\SMWUpd%WINDIR%\Tasks\SMW_UpdateTask[RANDOM CHARACTERS]HKEY..\..\..\..{RegistryKeys}Software\DeskBarSoftware\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\DeskBar.exeSOFTWARE\Microsoft\Tracing\DeskBar_RASAPI32SOFTWARE\Microsoft\Tracing\DeskBar_RASMANCSSOFTWARE\SearchModule\InfoSOFTWARE\SearchModule\SMUpdSOFTWARE\SearchModule\SuccessSOFTWARE\Wow6432Node\Microsoft\Tracing\DeskBar_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\DeskBar_RASMANCSSOFTWARE\Wow6432Node\SearchModuleHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Search moduleSearch Module_is1{D2E9FE6A-7003-42A0-96F6-5569DFC2A3A8}_is1{DE6791BD-7EAC-4822-B923-B8D6393C6110}_is1

Additional Information

The following directories were created:
%LOCALAPPDATA%\DeskBar%LOCALAPPDATA%\SearchModule%UserProfile%\Local Settings\Application Data\DeskBar%UserProfile%\Local Settings\Application Data\SearchModule

Related Posts

Loading...