Home Malware Programs Browser Hijackers Search Module Plus

Search Module Plus

Posted: March 6, 2015

Threat Metric

Ranking: 7,923
Threat Level: 5/10
Infected PCs: 44,734
First Seen: August 7, 2014
Last Seen: February 18, 2025
OS(es) Affected: Windows

Search Module Plus is a browser hijacker that is known for offering random services through your web browser. In most cases, the web browsers of Google Chrome, Firefox and Internet Explorer, are all prone to having reduced performance due to Search Module Plus being loaded. In such a case, Search Module Plus may load various web browser extensions or add-on components within those web browser programs later causing pop-up advertisements or unwanted site redirects. Eliminating all actions of Search Module Plus may require finding its components and removing each of them. Fortunately, through use of an updated antimalware application, Search Module Plus may be automatically removed along with its related components and files.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\Desktop\Old Desktop\Backup Drive E 12-23-16\USB DISK\downeloads 4 harold\deskbar.exe 2-4-09.exe File name: deskbar.exe 2-4-09.exe
Size: 253 KB (253008 bytes)
MD5: 6b792236360258eaa04328a16d97beba
Detection count: 3,204
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Desktop\Old Desktop\Backup Drive E 12-23-16\USB DISK\downeloads 4 harold\deskbar.exe 2-4-09.exe
Group: Malware file
Last Updated: September 2, 2023
%SYSTEMDRIVE%\AdwCleaner\FileQuarantine\C\Users\<username>\AppData\Local\DeskBar\2.7.5.1765\DeskBar.exe.vir File name: DeskBar.exe.vir
Size: 599.04 KB (599040 bytes)
MD5: 9252cc419c84f0ec639b4da6e21d6e61
Detection count: 162
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\AdwCleaner\FileQuarantine\C\Users\<username>\AppData\Local\DeskBar\2.7.5.1765\DeskBar.exe.vir
Group: Malware file
Last Updated: December 11, 2021
C:\Users\<username>\AppData\Local\SearchModule\trzC7A4.tmp File name: trzC7A4.tmp
Size: 391.16 KB (391168 bytes)
MD5: b13bccaa784f8ca6cb654b7aaab91352
Detection count: 59
File type: Temporary File
Mime Type: unknown/tmp
Path: C:\Users\<username>\AppData\Local\SearchModule\trzC7A4.tmp
Group: Malware file
Last Updated: March 21, 2021
C:\Program Files\common files\goobzo\gbupdateplus\smu.exe File name: C:\Program Files\common files\goobzo\gbupdateplus\smu.exe
MD5: 4235f0a1b73426f6d221e49b8da051ee
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%WINDIR%\System32\Tasks\SMW_UpdateTask[RANDOM CHARACTERS]%WINDIR%\System32\Tasks\SMWUpd%WINDIR%\Tasks\SMW_UpdateTask[RANDOM CHARACTERS]HKEY..\..\..\..{RegistryKeys}Software\DeskBarSoftware\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\DeskBar.exeSOFTWARE\Microsoft\Tracing\DeskBar_RASAPI32SOFTWARE\Microsoft\Tracing\DeskBar_RASMANCSSOFTWARE\SearchModule\InfoSOFTWARE\SearchModule\SMUpdSOFTWARE\SearchModule\SuccessSOFTWARE\Wow6432Node\Microsoft\Tracing\DeskBar_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\DeskBar_RASMANCSSOFTWARE\Wow6432Node\SearchModuleHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Search moduleSearch Module_is1{D2E9FE6A-7003-42A0-96F6-5569DFC2A3A8}_is1{DE6791BD-7EAC-4822-B923-B8D6393C6110}_is1

Additional Information

The following directories were created:
%LOCALAPPDATA%\DeskBar%LOCALAPPDATA%\SearchModule%UserProfile%\Local Settings\Application Data\DeskBar%UserProfile%\Local Settings\Application Data\SearchModule
Loading...