HpUI.exe virus. How to remove Search Protect malware

Start spreading the news!

Many browser hijackers today use a special service called Search Protect, with its main process called HpUI.exe. For example, if your system is infected by iStartSurf, or iStart123 browser hijackers, your PC may be additionally burdened by HpUI.exe running process, which is in charge of Search Protect PUP (potentially unwanted program). This program doesn’t really represent any value for you or your computer. You might think that it protects your browser from being amended without your consent or permission, but in reality this is the software that has in mind to prevent you from removing browser hijackers that have already affected your system, without your intention for such amendments to take place on your system.

HpUI.exe virus

Because of HpUI.exe and Search Protect you can’t actually remove browser hijackers like iStart123 and iStartSurf. Unless you delete HpUI.exe and get rid of Search Protect PUP, all your attempts to remove the above-said browser hijackers will be vain. They will appear again and again, even if you try changing the settings of your browsers manually.

So, obviously, the key to removal of browser hijackers like iStartSurf or iStart123, and all similar hijackers, is to remove Search Protect and its core process called HpUI.exe. We recommend you to remove this infection by scanning your system with a powerful anti-malware tool called GridinSoft Trojan Killer. It will help you to detect all other files and registry entries related to these browser hijackers, and remove them effectively from your system (with the full registered version of GridinSoft Trojan Killer).

On the other hand, you might try to remove HpUI.exe and Search Protect malware manually. This is only possible for just a few of the versions of these browsers hijackers. This manual removal method is explained in the video below, however, our strong recommendation is that you choose the manual method of removing these browser hijackers, HpUI.exe, Search Protect program and all sorts of other useless applications from your computer. Please follow the guidelines below to fix the problem with your browser that has been hijacked. If you need any additional help on our part, please do not hesitate to get in touch with us at any time of your preference.


Instructions to remove HpUI.exe, iStartSurf and iStart123 hijackers manually (for free):

  • Shut down all your open affected browsers.
  • Right-click on Task Bar with the PC mouse and click on Task Manager.
  • Find the active (running) processes like HpUI.exe, IePlugin Service, Loader32.exe, Loader64.exe and all running processes of your browsers (if active). Right-click on them and select “End task“.
  • Go to the Program Files folder on your system drive.
  • Find “Sup Tab” folder there, delete it.
  • Remove Sup Tab folder from the Recycle Bin.
  • Repair the Desktop shortcuts and Start menu objects related to your browser infected by such browser hijackers:
  • These browser hijackers also sets up its attribute to the Desktop icons and possibly some Start menu items of your browsers attacked by it. In order to fix this issue you need to right-click the Desktop icons and Start menu items related to your browsers attacked by this browser hijacker. Click “Properties” and check their destination path in the “Target” section of the shortcut tab. Make sure there’s nothing related to istart123.com or istartsurf.com in this destination path. If you see the website of this hijacker set there by default, remove it completely and leave only the clear destination path that leads to the executable of your browser.

  • Right-click the Desktop icons, Quick Launch or Start Menu items or your infected browser, click “Properties“.
  • How to fix Desktop shortcut of hijacked browser
    How to fix Quick Launch shortcut of hijacked browser

  • In the window that comes up click the “Shortcut” tab. Make sure that the target to your browser doesn’t have any “tails” that could lead to istart123.com or istartsurf.com hijackers. If you see such a “tail”, remove it. These are most common targets to all major browsers (if their installation path was initially set by default):
  • “C:\Program Files\Internet Explorer\iexplore.exe”for Internet Explorer
    “C:\Program Files\Mozilla Firefox\firefox.exe”for Mozilla Firefox
    “C:\Program Files\Google\Chrome\Application\chrome.exe”for Google Chrome
    “C:\Program Files\Opera\launcher.exe”for Opera

  • After you remove all junk data from the Desktop shortcuts, Quick Launch and Start menu items of your browser affected by iStart123 hijacker, click “Apply” and “OK” to apply all introduced amendments made by you in an attempt to fix your browser:
  • How to fix the shortcut of hijacked browser

    Download Combo Cleaner

    Example of fixing the Desktop shortcuts and Start menu items related to your browser infected by this hijacker (YouTube video guide that is applicable for fixing all infected browsers):

  • Perform additional removal manipulations for Mozilla Firefox browser (if the above-said steps proved to be unsuccessful):
  • Open Mozilla Firefox browser.
  • Type “about:config” in the address bar and press “Enter” on your keyboard.
  • Click “I’ll be careful, I promise!” button.
  • about:config command in Mozilla Firefox

  • This will open the Settings page of your Mozilla Firefox browser.
  • Type “Keyword.url” in the search box, then right-click and reset it.
  • Type “browser.search.defaultengine” in the search box, then right-click and reset it.
  • browser.search.defaultengine

  • Type “browser.search.selectedengine” in the search box, then right-click and reset it.
  • Search for “browser.newtab.url“. Right-click and reset it. This is a very important step that will prevent the search page of this hijacker from opening in each new tab of your Firefox browser.
  • browser.newtab.url

Video that explains free HpUI.exe and iStart123 (iStartSurf) removal (manual method):


HpUI.exe, iStart123 and iStartSurf automatic removal guide:

Anti-malware tool necessary for HpUI.exe, iStartSurf, iStart123 and related malware automatic removal

Download GridinSoft Trojan Killer

Note that GridinSoft Trojan Killer is a shareware application. Its free 15-day trial is limited only to removal of 2 infections detected by it during scan. However, Trojan Killer has a free built-in module that helps you reset your browser after the attack of browser hijackers like iStart123 and iStartSurf. This free module helps you reset browsers like Internet Explorer, Google Chrome, Mozilla Firefox and Opera. If Trojan Killer has detected more than 2 threats on your computer and you would like to remove them for free, please let us know.

Introductory steps (recommended). Uninstalling programs related to iStart123 and iStartSurf hijackers from the Control Panel of your computer (from the list above).

Instructions for Windows XP, Vista and 7 operating systems:

  • Make sure that all your browsers infected with Istart123 hijack are shut down (closed).
  • Click “Start” and go to the “Control Panel“:
  • Start Control Panel in Windows

  • In Windows XP click “Add or remove programs“:
  • Add or remove programs in Windows XP

  • In Windows Vista and 7 click “Uninstall a program“:
  • Uninstall a program in Windows Vista and 7

  • Uninstall programs related to iStartSurf trojan from your PC (see the list above). To do it, in Windows XP click “Remove” button related to it. In Windows Vista and 7 right-click any suspicious adware program with the PC mouse and click “Uninstall / Change“. Note that these can be the programs like WindowsMangerProtect20.0.0.502, wpm_v20.0.0.502.exe, SupTab, or similar junkware.

Instructions for Windows 8 operating system:

  • Move the PC mouse towards the top right hot corner of Windows 8 screen, click “Search“:
  • Windows 8 search

  • Type “Uninstall a program“, then click “Settings“:
  • Uninstall a program in Windows 8

  • In the left menu that has come up select “Uninstall a program“:
  • Uninstall a program in Win 8

  • Uninstall related unwanted programs. To do it, in Windows 8 right-click the unwanted program with the PC mouse and click “Uninstall / Change“.

Mandatory steps for automatic removal. Scanning your computer with a powerful anti-malware tool and resetting your browsers with its help.

  • Download GridinSoft Trojan Killer through the download button below.
  • Download GridinSoft Trojan Killer
  • Install the program and scan your computer with it.
  • At the end of scan click “Apply” to remove all infections associated with this browser hijacker.
  • Important! It is also necessary that you reset your browsers with GridinSoft Trojan Killer after iStartSurf virus removal. Shut down all your available browsers now.
  • In GridinSoft Trojan Killer click “Tools” tab and select “Reset browser settings“:
  • tools_reset_browser_settings

  • Select which particular browsers you want to be reset and choose the reset options:
  • browser_reset_options

  • Click on “Reset” button.
  • You will receive the confirmation windows about browser settings reset successfully.
  • Reboot your PC now.