Goobook.biz is a browser hijacker that redirects search queries and homepage settings through a deceptive search engine, generating revenue through forced advertising and user data collection. This potentially unwanted program (PUP) typically arrives bundled with free software downloads and modifies browser configurations without informed consent. While not as destructive as ransomware or trojans, Goobook.biz undermines your browsing experience, exposes you to questionable advertising networks, and can serve as a gateway to more serious infections.
Browser hijackers like Goobook.biz operate in a legal gray area—they're not technically viruses, but they exhibit malicious behavior by changing settings without permission and making those changes difficult to reverse. The redirection through Goobook.biz allows the operators to track your search habits, collect browsing data, and profit from affiliate commissions when you click through their sponsored results.
Threat Profile
| Attribute | Details |
|---|---|
| Threat Family | Browser Hijacker / Potentially Unwanted Program (PUP) |
| Aliases | Goobook redirect, Goobook.biz search, Search.goobook.biz |
| Platforms Affected | Windows (all versions), macOS; affects Chrome, Firefox, Edge, Safari |
| Distribution Method | Software bundling, fake updates, deceptive installers, freeware packages |
| Persistence Mechanisms | Browser extension installation, Start page modification, search engine replacement, Windows scheduled tasks (some variants), macOS launch agents |
| Primary Capabilities | Search redirection, homepage hijacking, new tab manipulation, ad injection, browsing data collection |
| Typical Artifacts | Browser extensions with random names, modified browser shortcuts with --homepage parameters, registry entries pointing to Goobook.biz URLs |
| Network Behavior | Communicates with goobook.biz domain and various advertising affiliate networks; redirects through multiple intermediate domains before reaching search results |
| Data at Risk | Search queries, browsing history, clicked links, approximate location (via IP), potentially form data depending on variant |
| Removal Difficulty | Moderate—requires browser cleanup, extension removal, and checking for persistence mechanisms; some variants reinstall if not fully removed |
| Related Threats | Similar hijackers include Search Marquis, Bing Redirect Virus, Yahoo Search Redirect, and other fake search engine families |
How It Spreads
Goobook.biz spreads primarily through software bundling—a deceptive practice where the hijacker is packaged with legitimate-looking free software. When users download video converters, PDF tools, media players, or other utilities from third-party download sites, the installer includes additional "offers" that install the browser hijacker alongside the wanted program. These offers are often pre-checked by default or obscured through confusing interface design that makes it difficult to decline them without careful attention.
The hijacker also spreads through fake software update prompts. Users encounter convincing-looking pop-ups claiming their Flash Player, browser, or media codec needs updating. Clicking "Update Now" actually downloads and installs Goobook.biz along with potentially other unwanted programs. These fake update pages often mimic legitimate software vendor websites to appear trustworthy.
Common distribution vectors include:
- Freeware download sites that wrap legitimate software in custom installers containing PUPs
- Fake Flash Player or codec updates displayed on streaming or file-sharing sites
- Torrents and pirated software packages that bundle hijackers with cracked applications
- Malicious browser extensions advertised as productivity tools, coupon finders, or video downloaders
- Email attachments with installer files disguised as software trials or utilities
- Compromised websites serving exploit kits that install hijackers through browser vulnerabilities
- Social engineering campaigns on social media linking to download pages with bundled installers
What It Does On Your Machine
Once installed, Goobook.biz immediately modifies your browser settings to establish control over your web searches and homepage. The hijacker changes your default search engine to goobook.biz or a related domain, replaces your homepage and new tab page with its own interface, and may inject a browser extension that prevents you from easily reverting these changes. When you attempt to search, your query is routed through the Goobook.biz system, which logs your search terms and then redirects you through a series of intermediate advertising domains before eventually showing results—often from a legitimate search engine like Bing or Google, but only after the hijacker has collected your data and potentially displayed unwanted advertisements.
The hijacker typically creates persistence mechanisms to survive browser resets and reinstall itself if removed incompletely. On Windows systems, this might include scheduled tasks that re-inject the hijacker settings periodically, modified browser shortcuts that launch with specific command-line parameters forcing the Goobook.biz homepage, or registry entries that override your browser preferences. On macOS, persistence is often achieved through launch agents or profiles that automatically reconfigure Safari or Chrome settings at system startup.
While Goobook.biz itself primarily focuses on generating advertising revenue through search redirection, the data collection presents privacy concerns. The hijacker tracks which terms you search for, which results you click, what time you perform searches, and your approximate geographic location. This information builds a behavioral profile that can be sold to advertising networks or used to display more targeted (and potentially more deceptive) advertisements. Some variants of browser hijackers in this family also inject additional advertisements directly into web pages you visit, replacing legitimate ads or inserting new ones.
Beyond the immediate annoyance of redirected searches and unwanted homepage changes, Goobook.biz can degrade system performance by consuming resources for its background processes and network communications. More concerning is that browser hijackers often come bundled with additional unwanted programs—adware, system optimizers, or even more serious malware. The same download or compromised website that delivered Goobook.biz may have installed other threats simultaneously, making thorough system scanning essential after discovering the hijacker.
Manual Removal — Step by Step
Disconnect and Document
Disconnect your computer from the internet to prevent further data collection. Take note of any unusual browser extensions, programs you don't recognize in your installed applications list, and the current state of your browser settings. This documentation helps verify complete removal later.
Uninstall Suspicious Programs
Open Control Panel (Windows) or Applications folder (Mac) and uninstall any recently added programs you don't recognize, especially those installed around the time the browser hijacking began. Look for generic names, programs claiming to optimize or clean your system, or anything with "search," "toolbar," or suspicious publisher names. On Windows, also check Settings > Apps > Apps & Features for a more complete list.
Remove Browser Extensions
Open each affected browser and remove all suspicious extensions. In Chrome, go to chrome://extensions/; in Firefox, use about:addons; in Edge, edge://extensions/. Remove any extension you don't recognize or didn't intentionally install. Don't just disable them—click Remove/Uninstall. Pay special attention to extensions with vague names, random characters, or those claiming to enhance searching or provide deals.
Reset Browser Settings
Reset each browser to default settings to remove hijacked configurations. In Chrome, go to Settings > Reset settings > Restore settings to their original defaults. In Firefox, Help > More Troubleshooting Information > Refresh Firefox. In Edge, Settings > Reset settings > Restore settings to their default values. This removes the Goobook.biz homepage and search engine assignments while preserving most bookmarks and saved passwords.
Check and Fix Browser Shortcuts
Right-click each browser shortcut on your desktop and taskbar, select Properties, and examine the Target field. Remove any text after the .exe file path that references Goobook.biz or any URL. The Target should end with just chrome.exe, firefox.exe, or msedge.exe with no additional parameters. If the shortcut is corrupted, delete it and create a fresh one from the browser's installation folder.
Remove Scheduled Tasks and Startup Items
On Windows, open Task Scheduler (search for it in Start menu) and look in the Task Scheduler Library for any tasks with suspicious names or those set to run programs from temporary folders or user directories. Delete any related to the hijacker. Also check msconfig (System Configuration) > Startup tab and disable any unknown entries. On Mac, check System Preferences > Users & Groups > Login Items and remove suspicious entries.
Scan with Malwarebytes
Download and install Malwarebytes (the free version works fine) from the official malwarebytes.com site. Reconnect to the internet only to download this tool. Run a full Threat Scan and quarantine everything it finds. Malwarebytes excels at detecting browser hijackers and their persistence mechanisms that manual removal might miss. Reboot after cleaning and run a second verification scan.
Check Windows Registry (Advanced)
Press Windows+R, type regedit, and navigate to HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main and HKEY_CURRENT_USER\Software\Policies. Look for any values referencing Goobook.biz and delete them. Also check HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome and similar paths for Firefox and Edge. If you're uncomfortable editing the registry, skip this step and rely on Malwarebytes to handle it.
Clear Browser Data and Caches
In each browser's settings, clear all browsing data including cached files, cookies, and site data. This ensures no remnant scripts or tracking cookies from Goobook.biz remain active. In Chrome, use Settings > Privacy and security > Clear browsing data, select "All time" as the time range, and check all boxes except passwords and autofill data.
Verify and Change Passwords
If you entered passwords or sensitive information while the hijacker was active, change those passwords from a known-clean device or after completing all removal steps. Browser hijackers don't typically log keystrokes, but the advertising networks they connect to can sometimes track form submissions. Better safe than compromised.
Reboot and Test
Restart your computer completely and test your browsers. Open each one, verify your homepage and search engine are what you expect, perform a few searches to confirm they're not redirecting through Goobook.biz, and check that no suspicious extensions have reappeared. If everything looks clean for 24 hours with no reinfection, you've successfully removed it.
Prevention
- Download software only from official sources. Get programs directly from the developer's website or verified app stores, not from third-party download sites that bundle installers with PUPs. Sites like Download.com, Softonic, and similar aggregators are common hijacker distribution points.
- Read installer screens carefully. When installing any software, choose Custom or Advanced installation options instead of Express or Quick install. Uncheck any boxes offering to install additional software, change your homepage, or modify search settings. Legitimate software shouldn't require bundled programs.
- Keep your software updated. Real software updates come through the application itself or the operating system's update mechanism, not through web browser pop-ups. Ignore any page claiming you need to update Flash, codecs, or other plugins—Flash is discontinued anyway, and modern browsers handle media natively.
- Use a reputable ad blocker. Extensions like uBlock Origin help prevent malicious advertisements and fake download buttons on legitimate sites. Many hijacker infections start with clicking a fake "Download" button that's actually an ad placed above the real download link.
- Maintain real-time protection. Keep Windows Defender enabled (it's built into Windows 10/11) or use another reputable antivirus with real-time scanning. Add Malwarebytes free version for periodic manual scans as a second opinion. Don't disable your protection even temporarily.
- Review browser extensions regularly. Every few months, audit your installed browser extensions and remove anything you don't actively use. Browser hijackers often disguise themselves as helpful utilities that sit dormant before activating or updating to malicious versions.
- Be skeptical of free software deals. If a premium program is being offered free on an unfamiliar website, it's likely bundled with unwanted software or is pirated (which often includes malware). The cost savings aren't worth the cleanup time and security risks.
- Create a standard user account. Don't use an administrator account for daily browsing and work. Standard accounts can't install system-level persistence mechanisms without prompting for the admin password, providing an extra layer of protection against hijackers and more serious malware.
When Computer Repair Roswell removes browser hijackers and malware from your system, we guarantee your computer will remain free of the same infection for 90 days. If Goobook.biz or the specific threats we cleaned somehow return within that period, bring your machine back in and we'll re-clean it at no additional charge. We stand behind our work.
Bring It In
Browser hijackers like Goobook.biz can be surprisingly persistent, especially when they've installed multiple components or come bundled with other unwanted programs. If you've followed the manual removal steps and still experience redirections, performance issues, or suspicious browser behavior, it's time to call in professional help. Computer Repair Roswell has removed thousands of browser hijackers, adware infections, and related threats from computers across the Roswell and North Fulton area. We'll thoroughly scan your system with professional-grade tools, remove all traces of the infection including hidden persistence mechanisms, and verify your machine is truly clean before returning it to you.
Our shop is located in Roswell, Georgia, and we offer same-day service for most malware removal jobs. Call us at (770) 674-6311 to describe your symptoms and we'll let you know whether to bring the machine in immediately or schedule an appointment. We work on both Windows PCs and Macs, and our pricing is straightforward with no surprises. Why spend hours fighting with a hijacker when our technicians can have your system cleaned and protected in a fraction of the time? Let us handle the technical work so you can get back to using your computer without redirected searches, unwanted advertisements, and privacy concerns.