Home Malware Programs Bad Toolbars Search-Gol Toolbar

Search-Gol Toolbar

Posted: October 22, 2013

Threat Metric

Ranking: 4,311
Threat Level: 5/10
Infected PCs: 108,524
First Seen: October 22, 2013
Last Seen: October 16, 2023
OS(es) Affected: Windows

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\is420858837\957456_stp\SearchGol.exe File name: SearchGol.exe
Size: 734.57 KB (734576 bytes)
MD5: 4b5b56bbc4d472d52c03c7dc6c33026d
Detection count: 492
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\is420858837\957456_stp\SearchGol.exe
Group: Malware file
Last Updated: September 14, 2023
C:\Program Files (x86)\searchgol\searchgol\1.8.16.19\uninstall.exe File name: uninstall.exe
Size: 203.51 KB (203510 bytes)
MD5: af0149dfa8135b9b7fa5a228d03e3837
Detection count: 307
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\searchgol\searchgol\1.8.16.19\uninstall.exe
Group: Malware file
Last Updated: September 4, 2023
%PROGRAMFILES%\searchgol\searchgol\1.8.16.19\bh\searchgol.dll File name: searchgol.dll
Size: 255.38 KB (255384 bytes)
MD5: cc267b30895692147b6672490150b596
Detection count: 9
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\searchgol\searchgol\1.8.16.19\bh
Group: Malware file
Last Updated: October 22, 2013
%PROGRAMFILES%\searchgol\searchgol\1.8.16.19\bh\searchgol.dll File name: searchgol.dll
Size: 255.38 KB (255384 bytes)
MD5: 7d8ab7a7feb956661b033b58ad6e5af6
Detection count: 7
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\searchgol\searchgol\1.8.16.19\bh
Group: Malware file
Last Updated: October 22, 2013
%APPDATA%\searchgol\searchgolctrl.exe File name: searchgolctrl.exe
Size: 268.29 KB (268290 bytes)
MD5: 5ad49e2e0dc6e664bf28864ef5f1d3bf
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\searchgol
Group: Malware file
Last Updated: October 22, 2013

Registry Modifications

The following newly produced Registry Values are:

CLSID{00078E95-3A4A-4137-8DE7-2824908D1C17}{105F25A9-C42F-48A6-998D-0494E8AE336A}{4277F7CF-0000-46CF-BA49-D624465C4BAB}{539F74BF-7E5C-46BD-9D45-35B1A91C9CBD}{840A13FF-B464-4782-9C96-AAF3092E55DD}{88AF4F6A-C6B7-4229-9275-824E98BF97F9}{8F547BDD-FCD4-48F8-A06F-573D6F404A3C}{9448AC19-EB62-46D5-B7DA-B059A7DB466A}{D8E43B96-EB46-4820-92B7-232AEB735685}HKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\esrv.searchgolESrvcSOFTWARE\Classes\esrv.searchgolESrvc.1SOFTWARE\Classes\searchgol.searchgolappCoreSOFTWARE\Classes\searchgol.searchgolappCore.1SOFTWARE\Classes\searchgol.searchgoldskBndSOFTWARE\Classes\searchgol.searchgoldskBnd.1SOFTWARE\Classes\searchgol.searchgolHlprSOFTWARE\Classes\searchgol.searchgolHlpr.1Software\Microsoft\Internet Explorer\Approved Extensions\{00078E95-3A4A-4137-8DE7-2824908D1C17}Software\Microsoft\Internet Explorer\Approved Extensions\{8F547BDD-FCD4-48F8-A06F-573D6F404A3C}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8C5CBB76-7379-4490-AA5B-B037C0A36381}Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\searchgol.comSOFTWARE\Microsoft\Internet Explorer\Toolbar\{00078E95-3A4A-4137-8DE7-2824908D1C17}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{8F547BDD-FCD4-48F8-A06F-573D6F404A3C}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{00078E95-3A4A-4137-8DE7-2824908D1C17}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8F547BDD-FCD4-48F8-A06F-573D6F404A3C}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00078E95-3A4A-4137-8DE7-2824908D1C17}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8F547BDD-FCD4-48F8-A06F-573D6F404A3C}Software\searchgolSoftware\searchgol LTDSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8C5CBB76-7379-4490-AA5B-B037C0A36381}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{00078E95-3A4A-4137-8DE7-2824908D1C17}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{8F547BDD-FCD4-48F8-A06F-573D6F404A3C}SOFTWARE\Wow6432Node\searchgolHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}searchgol

Additional Information

The following directories were created:
%AppData%\golsearch%AppData%\searchgol%LOCALAPPDATA%\tcbackup%ProgramFiles%\golsearch%ProgramFiles%\searchgol%ProgramFiles(x86)%\golsearch%ProgramFiles(x86)%\searchgol%TEMP%\mt_ffx\searchgol%UserProfile%\AppData\LocalLow\searchgol
The following URL's were detected:
golsearchhttps://www.searchgol.com/
Loading...