GogoTools.GoGoware
|
Description:
|
Adware
|
|
Risk Level:
|
High
|
|
Date of First Occurence:
|
Tuesday, July 10, 2007
|
|
Software Developer:
|
SpecificMEDIA, Inc.
|
|
Brief Info:
|
GogoTools/GoGoware is a Browser Helper Object that displays advertisements and downloads files. It also collects information on a user's browsing habits and may redirect default Internet Explorer search behaviour.
|
|
Removal:
|
This threat can be removed using "Spyware
Terminator"
|
SUPPRIMER SPYWARE »
Geographical Distribution of Threat "GogoTools.GoGoware"
Threat Info
View All
Detecting items list:
- Files by Name
%ProgramFiles%\GoGotools\GoGoware\GoGoDisplay.exe
%ProgramFiles%\GoGotools\GoGoware\GoGoLaunch.exe
%ProgramFiles%\GoGotools\GoGoware\GoGoTools.exe
%ProgramFiles%\GoGotools\GoGoware\HTMLEdit.dll
%ProgramFiles%\GoGotools\GoGoware\TrackInst.exe
%ProgramFiles%\GoGotools\GoGoware\Config.txt
%ProgramFiles%\GoGotools\unins000.exe
%ProgramFiles%\GoGotools\unins001.exe
%ProgramFiles%\GogoTools\Check.exe
%ProgramFiles%\GogoTools\GogoAddressBar\Address.dll
%ProgramFiles%\GogoTools\GogoAddressBar\samp.dll
%ProgramFiles%\GogoTools\Gogoware\GogoAdDisplay.exe
%ProgramFiles%\GogoTools\Gogoware\GogoTools.exe
%ProgramFiles%\GogoTools\Gogoware\HTMLEdit.dll
%ProgramFiles%\GogoTools\Gogoware\LaunchAdware.exe
%ProgramFiles%\GogoTools\Gogoware\Registration.exe
%ProgramFiles%\GogoTools\Gogoware\TrackInst.exe
%ProgramFiles%\GogoTools\Gogoware\uninsc.exe
%ProgramFiles%\GogoTools\Installer.exe
- Files by Directories
%ProgramFiles%\GoGotools\GoGoware
- Files by CLSID or Name
CLSID=3BEC9062-7625-4DE8-8ABE-B96AE461DC78
CLSID=1E1B2879-88FF-11D2-8D96-D7ACAC95951F
- Registry Keys
HKCU\Software\SpecificMEDIA\GoGoTools
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GoGo Tools_is1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Interactive Explorer Search Services_is1
HKLM\SOFTWARE\SpecificMEDIA\GoGoTools
- Registry Values
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ValueName=RUNFilePC
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ValueName=RUNGogoTools
«
Go to Software Database