84,488,480 programs installed

Should I remove Search Module Plus?

What percent of users and experts removed it?
79% remove it21% keep it
Overall Sentiment
What do people think about it?
(click star to rate)
How common is it?
Global Rank #17,174
United States Rank #10,487
Reach 0.0145%
Lifespan of installation (until removal)
< 1.05 days
30.91 days >
Average installed length: 16.24 days

Other programs by Goobzo LTD

Search Module Plus

What is Search Module Plus?

Goobzo's Search Module Plus is a web browser toolbar/extension that will insert itself into IE, Firefox or Chrome and will modify the search and home page providers of the targeted browser. Once installed Search Module Plus changes Windows host file and DNS settings. Also, this adware will show unwanted advertisements on a random web pages that the user visits and reports back to Goobzo's services details about the user's web browsing habits including pages and URLs visited and ads displayed and clicked on.


During setup, the program registers itself to launch on boot through a Windows Schedule Task in order to automatically start-up (this is typically done to avoid any UAC prompts). Upon being installed, the software adds a Windows Service which is designed to run continuously in the background. Manually stopping the service has been seen to cause the program to stop functing properly. It adds a background controller service that is set to automatically run. Delaying the start of this service is possible through the service manager. The primary executable is named sma.exe. A majority of users end up uninstalling this less than a week of it being installed. The setup package generally installs about 22 files and is usually about 6.82 MB (7,148,200 bytes). The installed file Updater.exe is the auto-update component of the program which is designed to check for software updates and notify and apply them when new versions are discovered.
  • Malware detected in the program
  • Starts automatically
  • Adds a background Windows Service
  • Displays unwanted advertisements
  • Hijacks the web browser's home page
  • Most users and experts agree, you should remove it!
Warning, multiple anti-virus scanners have detected possible malware in Search Module Plus.
sma.exe (987ed3058973c14fcd1f623dd87276bb) has been flagged by the following 26 scanners:
Anti-Virus softwareVersionDetection
Agnitum Outpost 7.1.1 Riskware.Agent
AhnLab-V3 2015.04.06 Win-PUP/CrossRider
avast! 2014.9-150413 Win32:Adware-CDO [PUP]
AVG 2016.0.3141 ShopperPro
AVware Goobzo (fs)
Baidu-International Adware.Win32.Shopper.BAI
Bkav FE W64.HfsAdware
CAT-QuickHeal AdWare.Shopper.r6 (Not a Virus)
Cyren W64/Goobzo.A
Dr.Web Adware.Searcher.2795
ESET-NOD32 9.11430 a variant of Win32/SBWatchman.D potentially unwanted
Fortinet FortiGate 4/13/2015 Adware/Shopper
F-Prot v6. W64/Goobzo.A
K7 AntiVirus 13.202.15489 Trojan
K7GW 13.202.15490 Trojan ( 004b02e01 )
Kaspersky not-a-virus:AdWare.Win32.Shopper
McAfee 5600.6797 Artemis!987ED3058973
NANO AntiVirus Riskware.Win64.Shopper.dlhkxi
Panda Antivirus Adware/Goobzo
Symantec 4/13/2015 rev. 2 WS.Reputation
Tencent Win32.Trojan.Falsesign.Hufu
Trend Micro 10.465.13 TROJ_GEN.R02EC0VBD15
TrendMicro-HouseCall 7.2.103 TROJ_GEN.R02EC0VBD15
Vba32 AntiVirus AdWare.Shopper
VIPRE Antivirus 39102 Goobzo (fs)
Zillya Adware.Shopper.Win64.9
smu.exe (413002a43da8635240a0d1e1f5e676c3) has been flagged by the following 33 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware Adware.Generic.1119786
AhnLab-V3 2015.08.08.00 Win-PUP/CrossRider
ALYac Adware.Generic.1119786
Antiy-AVL GrayWare[AdWare]/Win32.Shopper.adw
Arcabit Adware.Generic.D11162A
avast! 8.0.1489.320 Win32:Adware-CDO [PUP]
AVG ShopperPro.A8D
AVware Goobzo (fs)
Baidu-International Adware.Win32.Shopper.BAI
Bitdefender 7.2 Adware.Generic.1119786
CAT-QuickHeal 14.00 AdWare.Shopper.g6 (Not a Virus)
Cyren W64/Application.AFOF-6948
Dr.Web Adware.Searcher.2795
Emsisoft Anti-Malware Adware.Generic.1119786 (B)
ESET-NOD32 12061 a variant of Win64/SBWatchman.A potentially unwanted
Fortinet FortiGate Adware/Shopper
F-Secure 11.0.19100.45 Adware.Generic.1119786
G Data 25 Adware.Generic.1119786
Jiangmin 16.0.100 AdWare/Shopper.st
Kaspersky not-a-virus:AdWare.Win32.Shopper.adw
McAfee Artemis!413002A43DA8
McAfee-GW-Edition v2015 Artemis
MicroWorld-eScan Adware.Generic.1119786
NANO AntiVirus Riskware.Win64.Shopper.dlnwxc
Panda Antivirus Adware/Goobzo
Rising Antivirus PE:Trojan.Win32.Generic.18E56690!417687184
Sophos 4.98.0 Goobzo (PUA)
Symantec 20141.2.0.56 PUA.Goobzo
Tencent Win32.Trojan.Falsesign.Ozhw
Trend Micro 9.740.0.1012 TROJ_GEN.F0C2C00BI15
Vba32 AntiVirus AdWare.Shopper
VIPRE Antivirus 42696 Goobzo (fs)
Zillya Adware.Shopper.Win32.755
Updater.exe (9ad3ac159d9b3b758768c478b3d64f1c) has been flagged by the following 29 scanners:
Anti-Virus softwareSoftware versionDetection
AhnLab-V3 2015.04.02.00 Win-PUP/CrossRider
Antiy-AVL Trojan[Downloader:not-a-virus]/NSIS.Agent.ri
avast! 8.0.1489.320 Win32:Adware-CDO [PUP]
AVG ShopperPro.A8D
AVware Goobzo (fs)
Baidu-International Adware.Win32.Shopper.BAI
Bkav FE W32.HfsAdware.FF70
CAT-QuickHeal 14.00 Downloader.NSIS.r5 (Not a Virus)
Comodo Security 21617 ApplicUnwnt
Dr.Web Adware.Searcher.2795
ESET-NOD32 11413 a variant of Win32/ShopperPro.A potentially unwanted
Fortinet FortiGate 5.0.999.0 Riskware/Agent
G Data 25 Win32.Application.GoobZo.A
IKARUS anti.virus T3. PUA.ShopperPro
K7 AntiVirus 9.202.15452 Unwanted-Program ( 004a8e8b1 )
K7GW 9.202.15455 Unwanted-Program ( 004a8e8b1 )
Kaspersky not-a-virus:Downloader.NSIS.Agent.ri
McAfee Artemis!9AD3AC159D9B
NANO AntiVirus Trojan.Win32.Agent.dpphad
Panda Antivirus Adware/Goobzo
Qihoo-360 HEUR/QVM10.1.Malware.Gen
Sophos 4.98.0 Goobzo
Symantec 20141.2.0.56 WS.Reputation.1
Tencent Win32.Trojan.Falsesign.Hxgd
Trend Micro 9.740.0.1012 TROJ_GEN.F0C2C00AS15
TrendMicro-HouseCall 9.700.0.1001 TROJ_GEN.F0C2C00AS15
Vba32 AntiVirus Downloader.Agent
VIPRE Antivirus 38976 Goobzo (fs)
Zillya Downloader.Agent.Win32.234438
smp.exe (27074108c19dc3259dd1278b82c51072) has been flagged by the following 24 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware Trojan.Generic.12961913
ALYac Trojan.Generic.12961913
Arcabit Trojan.Generic.DC5C879
avast! 8.0.1489.320 Win32:PUP-gen [PUP]
AVG Generic12_c.VSU
AVware Trojan.Win32.Generic!BT
Baidu-International Hacktool.Win32.Packed.Themida
Bitdefender 7.2 Trojan.Generic.12961913
Bkav FE W32.HfsAutoB.DF2D
Comodo Security 23020 UnclassifiedMalware
Emsisoft Anti-Malware Trojan.Generic.12961913 (B)
ESET-NOD32 12102 a variant of Win32/Packed.Themida suspicious
F-Secure 11.0.19100.45 Trojan.Generic.12961913
G Data 25 Trojan.Generic.12961913
McAfee Artemis!27074108C19D
McAfee-GW-Edition v2015 BehavesLike.Win32.Trojan.tc
MicroWorld-eScan Trojan.Generic.12961913
nProtect 2015-08-13.01 Trojan.Generic.12961913
Panda Antivirus Trj/CI.A
Rising Antivirus PE:Trojan.Win32.Generic.1874E903!410315011
Sophos 4.98.0 Generic PUA EO (PUA)
Symantec 20141.2.0.56 Backdoor.Graybird
Trend Micro 9.800.0.1009 TROJ_GEN.R0C1C0OCM15
VIPRE Antivirus 42938 Trojan.Win32.Generic!BT
       View all 112 all detections

Program detailsProgram details

Displayed publisher: Goobzo
Installation folder: C:\Program Files\common files\gbupdateplus
Uninstaller: C:\Program Files\Common Files\GBUpdatePlus\smUninstall.exe
Estimated size: 6.82 MB

Program filesFiles installed by Search Module Plus

Program executable:sma.exe (Malware detected)
Path:C:\Program Files\common files\gbupdateplus\sma.exe
Additional files:
  • (Malware detected) Updater.exe - Update Helper
  • smu.exe - W (Search Module Plus Update Service)
  • smw.sys - sbw
  • SBIEBrowserHelperObject.dll - SBWatchman
  • smi32.exe - SBInject Application
  • SMUninstall.exe
  • smci32.dll
  • smci64.dll
  • smi64.exe
  • smp.exe
  • smei32.dll
  • smfi32.dll
  • smoi32.dll
  • smri32.dll
  • SCHelper.exe
  • smei64.dll
  • smfi64.dll
  • smoi64.dll
  • smri64.dll
  • rlz_id.dll
  • weedg.exe

Program behaviorsBehaviors exhibited

2 Scheduled Tasks (Boot/Login)
  • Updater.exe is automatically launched at startup through a scheduled task named SMWPUpd.
  • smp.exe is automatically launched at startup through a scheduled task named Smp.
  • smu.exe runs as a service named 'Search Module Plus Update' (SMUpdPlus).

How do I remove Search Module Plus?

You can uninstall Search Module Plus from your computer by using the Add/Remove Program feature in the Window's Control Panel.
  1. On the Start menu (for Windows 8, right-click the screen's bottom-left corner), click Control Panel, and then, under Programs, do one of the following:
    • Windows Vista/7/8/10: Click Uninstall a Program.
    • Windows XP: Click Add or Remove Programs.
  2. When you find the program Search Module Plus, click it, and then do one of the following:
    • Windows Vista/7/8/10: Click Uninstall.
    • Windows XP: Click the Remove or Change/Remove tab (to the right of the program).
  3. Follow the prompts. A progress bar shows you how long it will take to remove Search Module Plus.
  4. If for some reason uninstallation fails, please install Microsoft's uninstall fixer utility which will help fix problems with programs that can't be uninstalled at support.microsoft.com.

Win 7 (SP1) 52%
Win XP 0%
Windows Service? Yes
(Installs a service)
Uninstall it 79%
Keep it 21%

Windows OS versionsWindows

Which Windows OS versions does it run on?
Windows 7 53.66%
Windows 10 39.72%
Windows XP 3.48%
Windows Vista 3.14%
Which OS releases does it run on?
Windows 7 Home Premium 34.51%
Windows 8.1 28.87%
Windows 7 Professional 9.86%
Windows 7 Ultimate 7.39%
Microsoft Windows XP 3.52%
Windows Vista Home Premiu... 3.17%

Distribution by countryGeography

78.17% of installs come from the United States
Which countries install it?
  United States 78.17%
  Germany 11.50%
  Canada 6.10%
  United Kingdom 1.88%
  Australia 1.17%
  Belgium 0.23%
  Greece 0.23%
  PR 0.23%
  Saudi Arabia 0.23%
  South Africa 0.23%

OEM distributionPC manufacturers

What PC manufacturers (OEMs) have it installed?
Hewlett-Packard 30.65%
Dell 30.15%
Acer 11.56%
Toshiba 8.54%
ASUS 6.53%
Medion 3.02%
Lenovo 2.51%
Samsung 2.01%
Intel 1.51%
Sony 1.01%
Common models
HP 15 Notebook PC 8.09%
HP Pavilion g6 Notebook P... 3.68%
ASUS All Series 2.94%
Dell Inspiron 3521 2.21%
Dell Inspiron 530 2.21%
Acer Aspire 5740 1.47%


user comment
No one has commented yet. Help others learn more about this software, share your comments.