Home Possibly Unwanted Program MergeDocsOnline Toolbar

MergeDocsOnline Toolbar

Posted: June 8, 2015

Threat Metric

Ranking: 753
Threat Level: 1/10
Infected PCs: 158,242
First Seen: June 8, 2015
Last Seen: October 17, 2023
OS(es) Affected: Windows

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{00e2c623-e999-4b80-8ae1-f64f299f564c}{0431C831-EB1B-4E49-9FE7-2DB98ADA7DEA}{17ee2918-3506-4491-8bc0-bbcded8aa08d}{1c2d91f9-972d-46ea-8496-4aaebe9819b7}{1E4BF1A1-68E0-48C7-BEA7-217F6C5A26FC}{2865183f-5cd9-4ae3-8cc5-93b699109726}{29090A5D-8EEE-4E24-8484-83934A5F536E}{2b088a90-aacb-4580-8efe-35e64d3c111c}{2BCF2793-1B23-4803-9500-7D36160F3B2D}{2C068747-C7F5-4E85-80D2-2E08813B9535}{318efb4b-716c-43c3-b74e-9ab8968eddc4}{31B5343A-5562-43C6-B963-3EC0EDBAD7E8}{363B5C90-D897-4BA7-B33E-DEEFD74625FC}{397A61C5-143E-4934-A573-2445DA081246}{3EDB76BC-AF67-4E46-8B89-9EC57E2B0CC9}{418cf89d-7ebc-492f-829c-4e7478fc3e07}{43B3795C-4F6E-4CA6-9BFD-7A55B893B078}{4E989F0D-A584-4771-ACDE-2B75BFBE9513}{4ff25fe5-0fdb-4ed4-8bd8-5ae65fff0ee4}{51068B9B-EE07-4B9F-A72B-A7ACE5D8A506}{524EAB3A-73E5-4DE9-8C4D-3F341D0A1891}{633D04E4-415E-428B-AD91-AD2BEE12EA92}{6C66E635-0943-4EDD-A044-D615F3229AB5}{6CE71972-8EBB-41FD-82BC-981BE9B6E636}{703DAB9D-8386-458D-B2D5-E092E314E2FE}{76711A5C-561D-4408-AC0E-C491D6F4D6BF}{768964CA-9780-4BF0-886A-43300F8939FF}{76AAB3EA-2470-4E08-A33E-616F470DC2DB}{7954f122-e29b-41f3-b5c0-3c40a553cc37}{801F3128-BAD5-47A7-B0A9-3ED20AADE916}{843EFC37-ADC5-4B78-B814-E7C2C7C33D67}{8654ea72-c1cf-40a0-91df-80363229a9b9}{8A0BD6B8-10FE-40A3-AFDF-FD8171F4829B}{8a52e7db-87b4-4a41-8bba-3d7459a92d3d}{908D321F-07D5-42E4-994C-6115822CD543}{9999574D-873E-4376-A5A1-BEDD609D5982}{9B67D0AF-551D-43A3-B4EA-FC3D2E42736E}{9f68d656-1b85-439b-b9e2-c7c57a92f137}{A2F33245-8DEE-4FDF-AE4B-7A9EF0B322C7}{A885C2B4-68B5-4247-967A-998B0670B654}{cf794b72-b3e6-4d11-85a5-c6ae838a695a}{D330743E-CC48-474B-87FD-F59808ECF805}{D6EB904A-FB81-4960-AF63-7B2DAE5AF8E5}{D9676808-EC36-4F68-8CFA-4F2C450E644C}{DAA11C14-B10B-4DB4-B237-43E5130D5DA7}{def96015-3613-4c5d-a7d3-7f689532dcb8}{E5BE0C0C-09C9-4D5F-83D2-EA24AA63278F}{EC60C9C9-1483-424F-A498-12F98E22CEBE}{ee38dfcd-3093-45f2-8200-cccd8ce0f0b8}{EFB5BE8F-9B08-498B-877D-1146271EF623}{F53E9A05-6F4E-481D-8E1B-37C32978DB50}{f66b4b08-fe06-4184-a3b1-4442737e481f}{F6E80842-C6FE-48C6-B4E1-64BA3F6C3BE5}{FB8526AD-BD0D-4395-95D4-2EE750799AB9}File name without pathhttp_mergedocsonline.dl.myway.com_0.localstoragehttp_mergedocsonline.dl.myway.com_0.localstorage-journalhttp_mergedocsonline.dl.tb.ask.com_0.localstoragehttp_mergedocsonline.dl.tb.ask.com_0.localstorage-journalHKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\mergedocsonline_ewSoftware\Microsoft\Internet Explorer\Approved Extensions\{00E2C623-E999-4B80-8AE1-F64F299F564C}Software\Microsoft\Internet Explorer\Approved Extensions\{7954F122-E29B-41F3-B5C0-3C40A553CC37}Software\Microsoft\Internet Explorer\Approved Extensions\{8A52E7DB-87B4-4A41-8BBA-3D7459A92D3D}Software\Microsoft\Internet Explorer\SearchScopes\{3923ed90-14c8-4377-8a52-ebf9a47a9573}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{8A52E7DB-87B4-4A41-8BBA-3D7459A92D3D}SOFTWARE\Microsoft\Tracing\mergedocsonline_RASAPI32SOFTWARE\Microsoft\Tracing\mergedocsonline_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{00E2C623-E999-4B80-8AE1-F64F299F564C}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{7954F122-E29B-41F3-B5C0-3C40A553CC37}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{00E2C623-E999-4B80-8AE1-F64F299F564C}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7954F122-E29B-41F3-B5C0-3C40A553CC37}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8A52E7DB-87B4-4A41-8BBA-3D7459A92D3D}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00E2C623-E999-4B80-8AE1-F64F299F564C}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7954F122-E29B-41F3-B5C0-3C40A553CC37}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8A52E7DB-87B4-4A41-8BBA-3D7459A92D3D}SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mergedocsonlineSOFTWARE\Microsoft\Windows\CurrentVersion\Run\mergedocsonline AppIntegrator 32-bitSOFTWARE\Microsoft\Windows\CurrentVersion\Run\mergedocsonline AppIntegrator 64-bitSOFTWARE\Microsoft\Windows\CurrentVersion\Run\mergedocsonline EPM SupportSOFTWARE\Microsoft\Windows\CurrentVersion\Run\mergedocsonline Search Scope MonitorSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{3923ed90-14c8-4377-8a52-ebf9a47a9573}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{8A52E7DB-87B4-4A41-8BBA-3D7459A92D3D}SOFTWARE\Wow6432Node\Microsoft\Tracing\mergedocsonline_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\mergedocsonline_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{00E2C623-E999-4B80-8AE1-F64F299F564C}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{7954F122-E29B-41F3-B5C0-3C40A553CC37}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\mergedocsonlineSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\mergedocsonline AppIntegrator 32-bitSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\mergedocsonline AppIntegrator 64-bitSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\mergedocsonline EPM SupportSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\mergedocsonline Search Scope MonitorHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}mergedocsonline_ewbar Uninstall Internet Explorer

Additional Information

The following URL's were detected:
ikfpkhpcdedcogbcdojogldmmoinfoak
Loading...