Severity scale:  

Remove virus (Removal Instructions) - Dec 2020 update

removal by Ugnius Kiguolis - -   Also known as searching virus | Type: Browser Hijackers is a threat that causes redirects and gets offered via other software through advertisements or unknowingly is the browser hijacker that loads into the web browser via another extension or an add-on like Search Module Plus. This potentially unwanted intruder affects search results because it injects them with commercial content pop-ups, banners, hyperlinks, and shows not useful material. It keeps the user from accessing needed information with these altered results It is designed to show sponsored content, expose the user to third-party commercial pages, so those sites receive views and can monetize al the views.

Questions about virus virus belongs to a browser hijacker[1] category of cyber threats because it pretends to be legitimate and safe to use the search engine. This potentially unwanted program is compatible with Windows and Mac OS X operating system, so the intruder can easily infect any device. It typically spreads bundled with free programs and can hijack any web browser including Chrome, Firefox, or Safari. Immediately after the infiltration, it replaces browser's settings, sets its domain as a default search engine, and starts controlling user's browsing sessions.

Summary of the infection
Type Browser hijacker
Relation with other PUPs Plus! Network, YTDownloader, Youtube Accelerator, Search Module, and BrowserAir that is the version of the Chromium virus
Affected OS Mac OS X, Windows
Targeted browsers Google Chrome, Mozilla Firefox, Internet Explorer, Safari, etc.
Symptoms Changed homepage and default search engine, installation of unknown add-ons, delivery of an increased amount of ads
Distribution Software bundling and freeware installation methods often get used for spreading such intruders, so the machine gets affected and all the sponsored content gets delivered to you
Elimination To remove from the machine properly, you should run a scan with the security tool designed to find and eliminate possibly dangerous or malicious components on the system
Recovery Since the program can affect more than your browsing online functions, you should check for the affected parts and possible damage, repair those issues using particular system optimizers like ReimageIntego

At first glance, seems like an ordinary search engine. However, if you found it unexpectedly after opening your browser, it's a clear sign that something is shady about this tool. Indeed, this browser hijacker is capable of hijacking web browsers and performing various tasks without user's permission, for instance:

  • the appearance of an unknown search engine on each of your web browsers;
  • changes in the start page and the default search engine;
  • redirects to unknown/unsafe websites;
  • slowdowns and browser crashes;
  • problems with hijacker's removal procedure;
  • suspicious data monitoring activities.

The virus usually hijacks the system after downloading YTDownloaderYoutube Accelerator, Search Module, and BrowserAir that are also considered as “potentially unwanted.” After the hijack, it might alter the registry and browser’s settings, install BHOs, and cause other changes in order to strengthen its presence. Therefore, you might not be able to set your preferred search engine as the default one.

However, using this search engine is not recommended. First of all, it redirects to Plus! Network results page is known as a shady and unreliable search provider. Secondly, it might alter search results and include sponsored links to them. Hence, you might be tricked into clicking on links that lead to potentially dangerous websites. is a suspicious search engine that might deliver suspicious search results and redirect to dangerous websites. After hijack, it might be hard to find useful information quickly. However, browsing through suspicious commercial websites might end up with infected computers or data loss. At the top of the results page, you can always find ads that look like ordinary search results. Thus, you might be easily tricked especially if you are in a rush.

The hijacker might also display unwanted pop-up ads or initiate disturbing browser redirects. There is no guarantee that such sites are virus-free – they can be used to spread ransomware or redirect you to a domain that seeks to swindle your personal information.

After a deep analysis, it has been revealed that some of the unwanted ads on legitimate sites can be closely related to malware [2]. Thus, you should not delay removal in order to protect your PC from cyber threats. However, it’s not the reason why you should get rid of it ASAP. 

Security researchers have concerns about another suspicious hijacker’s feature. As soon as it gets inside, it starts monitoring users’ browsing habits. Developers of reliable software always include Privacy Policy, EULA, or other important documents. However, authors of Searching do not inform how they treat sensitive information. search is the PUP that affects online browsing because it shows altered results filled with commercial content.

However, search queries are redirected to Plus! Network's website which includes the privacy policy, and it reveals about shady data tracking activities. The program is capable of tracking personal information which may lead to serious privacy-related issues because it might be shared with third-parties:

Our database of personal details (however we collect these details) is used by us, and third parties acting on our behalf, for administration and marketing related purposes.

There's no doubt that you should remove to protect your privacy. We highly recommend using an anti-malware program like ReimageIntego to clean this cyber threat from the machine. However, if you want to try to eliminate the hijacker without additional help, please follow the manual removal guide at the end of this article. Privacy is the PUP that tracks and collects information about its users and shares those details with third-party advertisers.

Software bundling helps to install unwanted search engine silently

Most of the time, users learn about the hijacked browser after finding new search engines once they launch their browsers. Indeed, these PUPs seek to get inside computers and start being used as default search engines [3] without the user’s permission.

www-searching and other suspicious search engines are widely spread with the help of bundling. This distribution method allows spreading the hijacker with software bundles as an optional component. The program has been noticed spreading with:

  • YTDownloader;
  • Youtube Accelerator;
  • Search Module;
  • BrowserAir.

We highly recommend avoiding each of these programs to prevent system hijack. However, it might be distributed with other programs as well. To avoid infiltration of such and similar potentially unwanted programs (PUPs) in the future, you should bear in mind that they usually travel along with freeware and shareware as optional suggestions. Thus, you have to:

  1. select “Advanced” or “Custom” installation option;
  2. monitor the entire installation process;
  3. opt-out of suggestions to change your system settings.

Researchers from[4] remind to stay away from “Quick” or “Recommended” installation modes. In the removal instructions given below, you can find a list of recommended malware prevention and elimination programs. browser is the potentially unwanted program that shows tons of pop-ups to collect data about the user.

Modification of registry entries helps browser hijacker to get back after the removal

One of the main negative features of the Searching virus is that it might keep coming back. It might happen because of browser helper objects [5] that are typically spread in a bundle with this suspicious search engine. They can be detected with the help of anti-spyware, so there is no doubt that you need to consider the automatic removal of this hijacker. Besides, can insert the following registry keys to your operating system:

HKLM\SOFTWARE\Wow6432Node\Policies\Google\Chrome\HomepageLocation and HKLM\SOFTWARE\Wow6432Node\Policies\Google\Chrome\RestoreOnStartupURLs\1

Such registry entries [6] and their modifications cannot be noticed easily, but you can delete them from your computer if you are attentive enough. After eliminating these registry keys, you should change your default search provider or a start page and reset your browser.

That's what you need to fix your computer after www-searching infiltration. For a deeper understanding, we recommend taking a look at manual elimination guidelines that ensure complete elimination. By carefully implementing each step, you will be able to restore the browser settings and return to a previously used browsing tool. fake search engine is not a thing that can be trusted.

Two options for Searching virus removal

The majority of hijackers are not hard to get rid of, removal might be a challenge. Users note that hijacker tends to come back no matter what they do. Therefore, you should prepare yourself for a serious task.

At the end of the article, you can find manual elimination instructions. If you are interested in this option, you should follow each of the steps carefully. Make sure that any hijacker-related entries were not left on the system or web browsers.

If the hijacker still shows up on your browser, you should opt for the automatic removal option. In order to remove automatically, you have to scan the device with reputable anti-malware.

Detailed removal instructions for Windows 10 users

The latest version of Windows might seem more resistant to cyber threats, inattentive, and careless actions on the web might cause the hijack. Actually, the virus is supposed to attack mostly Windows 8 and Windows 10 users.

However, users might find difficulties with hijacker’s removal from the latest version of Windows. These problems are usually related to browser helper objects, registry, or settings modifications. Therefore, we want to pay your attention to a few aspects. If you still couldn’t find the way how to get rid of this search engine, you should:

  1. Access affected browsers from the desktop or find it with the help of Cortana. Then check the settings and lookup for entries related to the searching virus.
  2. Check Advanced settings and make sure that any hijacker-related entries were not left there.
  3. Right-click on the browser’s desktop icon and select Properties. If you see the hijacker’s domain at the end of the destination or target location text field, delete it.

You may remove virus damage with a help of ReimageIntego. SpyHunter 5Combo Cleaner and Malwarebytes are recommended to detect potentially unwanted programs and viruses with all their files and registry entries that are related to them.

do it now!
Reimage Happiness
Intego Happiness
Compatible with Microsoft Windows Supported versions Compatible with OS X Supported versions
What to do if failed?
If you failed to remove virus damage using Reimage Intego, submit a question to our support team and provide as much details as possible.
Reimage Intego has a free limited scanner. Reimage Intego offers more through scan when you purchase its full version. When free scanner detects issues, you can fix them using free manual repairs or you can decide to purchase the full version in order to fix them automatically.
Alternative Software
Different software has a different purpose. If you didn’t succeed in fixing corrupted files with Reimage, try running SpyHunter 5.
Alternative Software
Different software has a different purpose. If you didn’t succeed in fixing corrupted files with Intego, try running Combo Cleaner.

To remove virus, follow these steps:

Erase from Windows systems

IMPORTANT. Browser hijackers, as well as adware and other PUPs, have mostly been spreading around in a bundle with charge-free software. Bear in mind that uninstalling only programs that brought these parasites into your system does not solve the problem. You need to uninstall each of these spyware variants individually to remove this search tool from your browser and prevent its appearance in the future.

The easiest way to do that is to use anti-malware tools or you can try to find these components both on your system and in each of your web browsers: BrowserAir, Search Module, Search Module Plus, YTDownloader, Shopper Pro, Youtube Accelerator, or any other program developed by Goobzo, Ltd. 

  1. Click Start Control Panel Programs and Features (if you are Windows XP user, click on Add/Remove Programs). Click 'Start -> Control Panel -> Programs and Features' (if you are 'Windows XP' user, click on 'Add/Remove Programs').
  2. If you are Windows 10 / Windows 8 user, then right-click in the lower left corner of the screen. Once Quick Access Menu shows up, select Control Panel and Uninstall a Program. If you are 'Windows 10 / Windows 8' user, then right-click in the lower left corner of the screen. Once 'Quick Access Menu' shows up, select 'Control Panel' and 'Uninstall a Program'.
  3. Uninstall and related programs
    Here, look for or any other recently installed suspicious programs.
  4. Uninstall them and click OK to save these changes. Right click on each of suspicious entries and select 'Uninstall'
  5. Remove from Windows shortcuts
    Right click on the shortcut of Mozilla Firefox and select Properties. Right click on browsers' icon and select 'Properties'
  6. Go to Shortcut tab and look at the Target field. Delete malicious URL that is related to your virus. Select 'Shortcut' tab and delete '' or other suspicious URL

Repeat steps that are given above with all browsers' shortcuts, including Internet Explorer and Google Chrome. Make sure you check all locations of these shortcuts, including Desktop, Start Menu and taskbar.

Get rid of from Mac OS X system

Review and delete apps developed by Goobzo. It is advisable to eliminate applications developed by Goobzo, examples of such programs are YTDownloader, Search Module, BrowserAir, Search Module Plus, Youtube Accelerator, Shopper Pro.

If your macOS is displaying some infection symptoms, proceed with the following guide:

Remove virus from Applications folder:

  1. From the menu bar, select Go > Applications.
  2. In the Applications folder, look for virus-related entries.
  3. Click on the app and drag it to Trash (or right-click and pick Move to Trash)Uninstall from Mac 1

To fully remove virus, you need to access Application Support, LaunchAgents, and LaunchDaemons folders and delete relevant files:

  1. Select Go > Go to Folder.
  2. Enter /Library/Application Support and click Go or press Enter.
  3. In the Application Support folder, look for any dubious entries related to virus and then delete them.
  4. Now enter /Library/LaunchAgents and /Library/LaunchDaemons folders the same way and terminate all the virus-related entries.Uninstall from Mac 2

Remove from Mozilla Firefox (FF)

It seems that Mozilla Firefox is the most vulnerable to the PUP. If this browser hijacker has affected your Mozilla, you should follow steps that are given down below and remove malicious Add-ons and Extensions. Also, perform these steps:

  • Close the affected web browser and open File Explorer
  • Now enter %AppData% and search for user.js
  • You have to rename this file if it exists on your computer
  • Now open Mozilla Firefox and type about:config in the address bar. Press Enter
  • When settings page shows up, enter Keyword.url to the Search field, and right-click it to Reset.
  • Do the same with, and browser.newtab.url.

    1. Remove dangerous extensions
      Open Mozilla Firefox, click on the menu icon (top right corner) and select Add-ons Extensions. Click on menu icon and select 'Add-ons'
    2. Here, select and other questionable plugins. Click Remove to delete these entries. Select 'Extensions' and look for malicious entries. Click 'Remove' to get rid of each of them
    3. Change your homepage if it was altered by virus:
      Click on the menu (top right corner), choose Options General.
    4. Here, delete malicious URL and enter preferable website or click Restore to default.
    5. Click OK to save these changes. When in 'General' tab, delete malicious URL from 'Home Page' section or click on 'Restore to Default' button. Click 'OK' to save changes
    6. Reset Mozilla Firefox
      Click on the Firefox menu on the top left and click on the question mark. Here, choose Troubleshooting Information. Click on menu icon and then on '?'. Select 'Troubleshooting Information'
    7. Now you will see Reset Firefox to its default state message with Reset Firefox button. Click this button for several times and complete removal. Click on 'Reset Firefox' button for a couple of times

    Delete from Google Chrome

    1. Delete malicious plugins
      Open Google Chrome, click on the menu icon (top right corner) and select Tools Extensions. Click on menu icon. Select 'Tools' and 'Extensions'
    2. Here, select and other malicious plugins and select trash icon to delete these entries. Look for malicious entries and delete each of them by clicking on the Trash bin icon
    3. Change your homepage and default search engine if it was altered by your virus
      Click on menu icon and choose Settings.
    4. Here, look for the Open a specific page or set of pages under On startup option and click on Set pages. After clicking on menu and 'Settings', select 'Set pages'
    5. Now you should see another window. Here, delete malicious search sites and enter the one that you want to use as your homepage. Click 'X' to remove malicious URLs
    6. Click on menu icon again and choose Settings Manage Search engines under the Search section. When in 'Settings', select 'Manage search engines...'
    7. When in Search Engines..., remove malicious search sites. You should leave only Google or your preferred domain name. Click 'X' to remove malicious URLs
    8. Reset Google Chrome
      Click on menu icon on the top right of your Google Chrome and select Settings.
    9. Scroll down to the end of the page and click on Reset browser settings. When in 'Settings', scroll down to 'Reset browser settings' button and click on it
    10. Click Reset to confirm this action and complete removal. Click on 'Reset' button to complete your removal

    Uninstall from Internet Explorer (IE)

    Remove dangerous add-ons:

    1. Open Internet Explorer, click on the Gear icon (IE menu) on the top-right corner of the browser
    2. Pick Manage Add-ons.
    3. You will see a Manage Add-ons window. Here, look for virus and other suspicious plugins. Click on these entries and select Disable.Remove add-ons from Internet Explorer

    Change your homepage if it was altered:

    1. Open IE and click on the Gear icon.
    2. Select Internet Options.
    3. In the General tab, delete the Home page address and replace it by your preferred one (for example,
    4. Click Apply and then select OK.Reset IE homepage

    Delete temporary files:

    1. Press on the Gear icon and select Internet Options.
    2. Under Browsing history, click Delete…
    3. Select relevant fields and press Delete.Clear temporary files from Internet Explorer

    Reset Internet Explorer:

    1. Click on Gear icon > Internet options and select Advanced tab.
    2. Select Reset.
    3. In the new window, check Delete personal settings and select Reset again to complete virus removal.Reset Internet Explorer

    Eliminate virus from Microsoft Edge

    If you have been suffering from redirect, you can either reset this browser or eliminate suspicious add-ons and change the homepage/the default search engine on it. Add-ons that are considered related to this hijacker are BrowserAir, Search Module, Search Module Plus, YTDownloader, Shopper Pro, etc. 

    Delete unwanted extensions from MS Edge:

    1. Select Menu (three horizontal dots at the top-right of the browser window) and pick Extensions.
    2. From the list, pick the virus-related extension and click on the Gear icon.
    3. Click on Uninstall at the bottom.Remove extensions from Edge

    Clear cookies and other browser data:

    1. Click on the Menu (three horizontal dots at the top-right of the browser window) and select Privacy & security.
    2. Under Clear browsing data, pick Choose what to clear.
    3. Select everything (apart from passwords, although you might want to include Media licenses as well, if applicable) and click on Clear.Clear Edge browsing data

    Reset MS Edge if that above steps did not work:

    1. Press on Ctrl + Shift + Esc to open Task Manager.
    2. Click on More details arrow at the bottom of the window.
    3. Select Details tab.
    4. Now scroll down and locate every entry with Microsoft Edge name in it. Right-click on each of them and select End Task to stop MS Edge from running.Reset MS Edge

    If this solution failed to help you, you need to use an advanced Edge reset method. Note that you need to backup your data before proceeding.

    1. Find the following folder on your computer: C:\\Users\\%username%\\AppData\\Local\\Packages\\Microsoft.MicrosoftEdge_8wekyb3d8bbwe.
    2. Press Ctrl + A on your keyboard to select all folders.
    3. Right-click on them and pick DeleteAdvanced MS Edge reset 1
    4. Now right-click on the Start button and pick Windows PowerShell (Admin).
    5. When the new window opens, copy and paste the following command, and then press Enter:

      Get-AppXPackage -AllUsers -Name Microsoft.MicrosoftEdge | Foreach {Add-AppxPackage -DisableDevelopmentMode -Register “$($_.InstallLocation)\\AppXManifest.xml” -VerboseAdvanced MS Edge reset 2

    Instructions for Chromium-based Edge

    Delete extensions from MS Edge (Chromium):

    1. Open Edge and click select Settings > Extensions.
    2. Delete unwanted extensions by clicking Remove.Remove extensions from Chromium Edge

    Clear cache and site data:

    1. Click on Menu and go to Settings.
    2. Select Privacy and services.
    3. Under Clear browsing data, pick Choose what to clear.
    4. Under Time range, pick All time.
    5. Select Clear now.Clear browser data from Chroum Edge

    Reset Chromium-based MS Edge:

    1. Click on Menu and select Settings.
    2. On the left side, pick Reset settings.
    3. Select Restore settings to their default values.
    4. Confirm with Reset.Reset Chromium Edge

    Erase from Safari

    If you can't remove from Firefox, you need to eliminate all suspicious add-ons from this browser at first. We highly recommend removing these entries: BrowserAir, Search Module, Search Module Plus, YTDownloader, Shopper Pro, Youtube Accelerator, or any other program developed by Goobzo, Ltd. In addition, don't forget to reset your web browser. 

    1. Remove dangerous extensions
      Open Safari web browser and click on Safari in menu at the top left of the screen. Once you do this, select Preferences. Click on 'Safari' and select 'Preferences'
    2. Here, select Extensions and look for or other suspicious entries. Click on the Uninstall button to get rid each of them. Go to 'Extensions' and uninstall malicious add-ons
    3. Change your homepage if it was altered by virus:
      Open your Safari web browser and click on Safari in menu section. Here, select Preferences as it was displayed previously and select General.
    4. Here, look at the Homepage field. If it was altered by, remove unwanted link and enter the one that you want to use for your searches. Remember to include the "http://" before typing in the address of the page. When in 'General', delete malicious URL and enter your desired domain name
    5. Reset Safari
      Open Safari browser and click on Safari in menu section at the top left of the screen. Here, select Reset Safari.... Click on 'Safari' and select 'Reset Safari...'
    6. Now you will see a detailed dialog window filled with reset options. All of those options are usually checked, but you can specify which of them you want to reset. Click the Reset button to complete removal process. Select all options and click on 'Reset' button

Choose a proper web browser and improve your safety with a VPN tool

Online spying has got momentum in recent years and people are getting more and more interested in how to protect their privacy online. One of the basic means to add a layer of security – choose the most private and secure web browser. Although web browsers can't grant full privacy protection and security, some of them are much better at sandboxing, HTTPS upgrading, active content blocking, tracking blocking, phishing protection, and similar privacy-oriented features. However, if you want true anonymity, we suggest you employ a powerful Private Internet Access VPN – it can encrypt all the traffic that comes and goes out of your computer, preventing tracking completely.


Lost your files? Use data recovery software

While some files located on any computer are replaceable or useless, others can be extremely valuable. Family photos, work documents, school projects – these are types of files that we don't want to lose. Unfortunately, there are many ways how unexpected data loss can occur: power cuts, Blue Screen of Death errors, hardware failures, crypto-malware attack, or even accidental deletion.

To ensure that all the files remain intact, you should prepare regular data backups. You can choose cloud-based or physical copies you could restore from later in case of a disaster. If your backups were lost as well or you never bothered to prepare any, Data Recovery Pro can be your only hope to retrieve your invaluable files.

About the author
Ugnius Kiguolis
Ugnius Kiguolis - The mastermind

If this free removal guide helped you and you are satisfied with our service, please consider making a donation to keep this service alive. Even a smallest amount will be appreciated.

Contact Ugnius Kiguolis
About the company Esolutions

Removal guides in other languages