Home Malware Programs Potentially Unwanted Programs (PUPs) GetFormsOnline Toolbar

GetFormsOnline Toolbar

Posted: August 30, 2016

Threat Metric

Ranking: 621
Threat Level: 2/10
Infected PCs: 357,597
First Seen: November 14, 2015
Last Seen: October 17, 2023
OS(es) Affected: Windows

The GetFormsOnline Toolbar is a Potentially Unwanted Program (PUP) by Mindspark Interactive Network. The software products of this company are well-known for bringing unwanted changes to the user's Web browser settings as soon as they are installed. For example, anyone who installs the GetFormsOnline Toolbar may accept to have their Web browser's default new tab page changed to http://int.search.myway.com/search/Ggmain.jhtm. This search engine is less popular than Yahoo and Bing, and you can rest assured there is a good explanation for this. Low-quality search engines like the one linked to the GetFormsOnline Toolbar may often be used to deliver sponsored search results, and this case isn't any different. Using the search features offered by the GetFormsOnline Toolbar may put sponsored ads on top of the search results, therefore misleading the user into believing that they are getting the most relevant content.

Apart from changing the Web browser's new tab page, the GetFormsOnline Toolbar is meant to be a tool that allows users to find templates for documents linked to taxes, employment, etc. quickly. Keep in mind that the templates and the information linked to them are available for free and can be found by simply searching the Web. The GetFormsOnline Toolbar doesn't offer anything unique – it just adds several quick links that lead users to Web destinations that can be found via Google, Bing, Yahoo, or other popular search engines.

Due to the GetFormsOnline Toolbar lack of valuable features, as well as the fact that it is listed as a PUP by reputable anti-malware products, it is safe to say that this isn't a utility that you need to keep on your computer. The removal of the GetFormsOnline Toolbar can be carried out by uninstalling the 'the GetFormsOnline Toolbar' entry from the list of installed Web browser extensions or by running an anti-malware scanner.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{034D0D48-05C2-4284-9F8E-53F748BD74ED}{1BDD3DB7-744B-4526-AA0F-4E61A7DE26CF}{1d66b1b3-acec-4f39-90ea-93d3bd964ffb}{2620990E-E2F1-4FDF-A4DC-7DE3B161A11C}{287F97AD-BF0E-4F14-B25E-5FFED795C6E1}{3C5C86AA-6F8B-4C74-ACF0-521AC87F31A4}{3E6902D7-C46A-4327-A37A-B09BC391B60B}{3FBFBFCF-54A5-4E50-801C-39165BDF39FF}{43591ed2-2a1f-4b62-8ae7-33be6c02d155}{43802896-242F-429F-B53D-C6F5EDEDFCCD}{44d5f146-e57a-44c1-911b-47a705f5a649}{45059655-A44D-440B-8CD0-CA779B725FF3}{47B95FD1-D537-487A-B057-4DEFB039DD29}{531614D5-8CC6-4C0B-86FF-0BAA4BE06D51}{53BBBF72-A1FE-48D7-A333-D6EBC42650AE}{53C93E7F-9AAB-4427-ADD6-71BB91BAC834}{5B810830-40A7-4B8B-AC57-E9F37240B232}{64BFDFCD-9FFC-4F8F-8176-2C056CA31340}{6b69261e-55eb-47dc-b75e-f53c06de3d3a}{71a7ae03-84b0-4471-8b3c-067bca74597e}{77CF0AFB-3090-4B81-863B-9167E79CB8E5}{84B3DD96-63F1-482E-B297-3CDAAC049F42}{853d9ae6-7ba1-4094-bb4a-cb6a51bcbe5b}{8a04fa5f-0a1a-4996-abe4-b607dad3840b}{8e2d73ab-1af7-451a-a958-fec6340fc83c}{9284C161-84F4-4A61-9812-43BFC9165D0E}{98078EAF-1F65-4846-8F10-3BEE56BF4D36}{9DF5A0DD-1B89-4515-BB0B-417E76410457}{9E6C46D6-B4D3-4E37-BCC8-D20232E363D6}{AA53EECC-A814-4FED-B33C-A3305691832A}{abd60aa7-0a4f-4b0b-b05c-cac4ffc79b18}{B48C4EC9-5E67-44B8-9F96-C88C473D68BF}{b8e5f7d1-cfcd-494f-9603-cf1158cdf51b}{CC3C0DFB-E534-47A6-8881-1477CB8572B1}{D91A242C-3212-4F1B-A9A4-C92C6CFE1597}{DB868FEA-713E-44E2-920E-BFEF80EAD333}{F0EF51FC-30D7-401D-8A92-D5DCC966D16A}{f18926ce-ba1d-4467-8ebd-5ba4c0d0d4ae}{F3DF4B20-7E30-43BE-898B-EB59EA9FDF69}{ff57b31a-0257-40cb-9c5e-6aec88bcf9de}File name without pathgetformsonline.dl.myway[1].xmlhttp_getformsonline.dl.myway.com_0.localstoragehttp_getformsonline.dl.myway.com_0.localstorage-journalhttp_getformsonline.dl.tb.ask.com_0.localstoragehttp_getformsonline.dl.tb.ask.com_0.localstorage-journalHKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\GetFormsOnline_dbSoftware\GetFormsOnlineSoftware\Microsoft\Internet Explorer\Approved Extensions\{6B69261E-55EB-47DC-B75E-F53C06DE3D3A}Software\Microsoft\Internet Explorer\Approved Extensions\{F18926CE-BA1D-4467-8EBD-5BA4C0D0D4AE}Software\Microsoft\Internet Explorer\Approved Extensions\{FF57B31A-0257-40CB-9C5E-6AEC88BCF9DE}Software\Microsoft\Internet Explorer\DOMStorage\getformsonline.dl.myway.comSoftware\Microsoft\Internet Explorer\DOMStorage\getformsonline.dl.tb.ask.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\getformsonline.dl.myway.comSoftware\Microsoft\Internet Explorer\SearchScopes\{d4c69a1b-c048-4976-bf25-48a4675a4b46}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{ff57b31a-0257-40cb-9c5e-6aec88bcf9de}SOFTWARE\Wow6432Node\GetFormsOnline_dbSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{d4c69a1b-c048-4976-bf25-48a4675a4b46}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{ff57b31a-0257-40cb-9c5e-6aec88bcf9de}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}GetFormsOnline_dbbar Uninstall Internet ExplorerGetFormsOnlineTooltab Uninstall Internet Explorer

Additional Information

The following directories were created:
%LOCALAPPDATA%\GetFormsOnlineTooltab%LOCALAPPDATA%\GetFormsOnline_db%PROGRAMFILES%\GetFormsOnline_db%PROGRAMFILES(x86)%\GetFormsOnline_db%USERPROFILE%\AppData\LocalLow\GetFormsOnline_db%USERPROFILE%\Local Settings\Application Data\GetFormsOnlineTooltab
Loading...