GoGoTools

Description: Adware
Risk Level: Low
Date of First Occurence: Tuesday, April 15, 2008
Software Developer: (unknown)
Brief Info: Adware Software that is displaying pop-up/pop-under windows containing advertisements when the primary user interface is not visible or displayed advertisements are not related to the product.
Removal: This threat can be removed using "Spyware Terminator"

SCAN & REMOVE NOW »

Geographical Distribution of Threat "GoGoTools"

Threat Info

View All

Detected Items

  1. Detected Files: %PROGRAMFILES%\GoGotools\unins000.exe MD5: BF15CE70E055955FAFD81A18EC1C0771 Size:77257 %PROGRAMFILES%\GogoTools\Gogoware\LaunchAdware.exe MD5: 6495340EA489547542556A9147BF6C0B Size:200826 %PROGRAMFILES%\GogoTools\Gogoware\HTMLEdit.dll MD5: BD2CABA492A28D2D3B8DB4652772386A Size:57344 %PROGRAMFILES%\GogoTools\Gogoware\GogoTools.exe MD5: 901101657D75AB402BA514FF97F9B34E Size:61440 %PROGRAMFILES%\GogoTools\Gogoware\GogoLaunch.exe MD5: C0A1B0062CB8EC66BB803DA4F44A5DC3 Size:24576
  2. Detected Files with variable Filenames:

Detecting items list:

  1. Files by Name %ProgramFiles%\GoGotools\GoGoware\GoGoDisplay.exe %ProgramFiles%\GoGotools\GoGoware\GoGoLaunch.exe %ProgramFiles%\GoGotools\GoGoware\GoGoTools.exe %ProgramFiles%\GoGotools\GoGoware\HTMLEdit.dll %ProgramFiles%\GoGotools\GoGoware\TrackInst.exe %ProgramFiles%\GoGotools\GoGoware\Config.txt %ProgramFiles%\GoGotools\unins000.exe %ProgramFiles%\GoGotools\unins000.dat %ProgramFiles%\GoGotools\unins001.exe %ProgramFiles%\GoGotools\unins001.dat %ProgramFiles%\GogoTools\Check.exe %ProgramFiles%\GogoTools\Gogo.ico %ProgramFiles%\GogoTools\GogoAddressBar\Address.dll %ProgramFiles%\GogoTools\GogoAddressBar\samp.dll %ProgramFiles%\GogoTools\Gogoware\Config.bin %ProgramFiles%\GogoTools\Gogoware\GogoAdDisplay.exe %ProgramFiles%\GogoTools\Gogoware\GogoTools.exe %ProgramFiles%\GogoTools\Gogoware\HTMLEdit.dll %ProgramFiles%\GogoTools\Gogoware\LaunchAdware.exe %ProgramFiles%\GogoTools\Gogoware\Registration.exe %ProgramFiles%\GogoTools\Gogoware\TrackInst.exe %ProgramFiles%\GogoTools\Gogoware\uninsc.dat %ProgramFiles%\GogoTools\Gogoware\uninsc.exe %ProgramFiles%\GogoTools\Installer.exe %ProgramFiles%\GogoTools\SearchGogo\AtlCustom.exe %ProgramFiles%\GogoTools\SearchGogo\FilePC Uploads\FilePCData.dat %ProgramFiles%\GogoTools\SearchGogo\GogoAddressBar.exe %ProgramFiles%\GogoTools\SearchGogo\GogoToolbar.exe %ProgramFiles%\GogoTools\SearchGogo\gogotools0.exe %ProgramFiles%\GogoTools\SearchGogo\Menu.exe %ProgramFiles%\GogoTools\SearchGogo\MFC42.dll %ProgramFiles%\GogoTools\SearchGogo\MSVCRT.DLL %ProgramFiles%\GogoTools\SearchGogo\PgTemplate.htm %ProgramFiles%\GogoTools\SearchGogo\PictureShare.exe %ProgramFiles%\GogoTools\SearchGogo\Print.dll %ProgramFiles%\GogoTools\SearchGogo\ReadGenPara.dll
  2. Files by Directories %ProgramFiles%\GogoTools
  3. Files by CLSID or Name CLSID=1E1B2879-88FF-11D2-8D96-D7ACAC95951F CLSID=1E1B2879-88FF-11D2-8D96-D7ACAC95951F CLSID=3BEC9062-7625-4DE8-8ABE-B96AE461DC78 CLSID=8066D3A1-D93D-4A0E-978C-C192FBE7BCE7 CLSID=AD6865DE-43AE-42C7-89A6-F6F834A5DCE2
  4. Registry Keys HKCR\Adware.IETrackerIF HKCR\Adware.IETrackerIF.1 HKCR\AppID\Adware.EXE HKCR\HTMLEdit.IETracker HKCR\HTMLEdit.IETracker.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GogoTools_is1 HKLM\SOFTWAREe\SpecificMEDIA\GoGoTools HKLM\SOFTWARE\Classes\Adware.IETrackerIF HKLM\SOFTWARE\Classes\Adware.IETrackerIF.1 HKLM\SOFTWARE\Classes\Print.StockBar HKLM\SOFTWARE\Classes\Print.StockBar.1 HKLM\SOFTWARE\Classes\Samp.initsearchgogo HKLM\SOFTWARE\Classes\Samp.initsearchgogo.1 HKLM\SOFTWARE\Classes\SpecificSearch.SpecificSearchBar HKLM\SOFTWARE\Classes\SpecificSearch.SpecificSearchBar.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GoGo Tools_is1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Interactive Explorer Search Services_is1 HKCU\Software\SpecificMEDIA HKCU\Software\SpecificMEDIA\GoGoTools
  5. Registry Values HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ValueName=RUNGogoTools HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ValueName=RUNFilePC

« Go to Software Database