Go.Com Toolbar

The Go.com toolbar provides instant access to Yahoo search and links to Disney Family of sites. The toolbar collects information about the user through various registration forms and it also collects information about the user’s browsing habits his ISP, IP address etc. The toolbar shows variety of popup ads related to games, movies, music etc.0

General information:

Malware Name: Go.Com Toolbar
Malware Type: Toolbar
Company Name: Walt Disney Internet Group
Company URL: http://www.go.com/
Threat Level: High
Operating System: WIN XP
Installation Type: Installed through ActiveX
Operation: Time of After Browser Restart.

Company Description:

Walt Disney Internet Group (WDIG) provides strategic leadership and operational management for The Walt Disney Company's Internet properties including category leaders Disney.com, ESPN.com and ABCNEWS.com. WDIG also directly operates Disney.com worldwide, FamilyFun.com, Movies.com, and the wireless businesses for all The Walt Disney Company properties.

Spyware Description:

The Go.com toolbar provides instant access to Yahoo search and links to Disney Family of sites. The toolbar collects information about the user through various registration forms and it also collects information about the user’s browsing habits his ISP, IP address etc. The toolbar shows variety of popup ads related to games, movies, music etc.0

Characteristics/Symptoms:

    -> Collects information about the pages visited -> Slows the browser -> Can change the default search settings -> Communicates with the host server -> Shows popup ads -> Creates Cookies0

Additional information might be found here:

google Search at Google for Go.Com Toolbar
bing Search at Bing for Go.Com Toolbar
yahoo Search at Yahoo for Go.Com Toolbar

Processes Running:

File information Created after Installation:

File Location Size (Bytes) Type
C:\Program Files\GO Toolbar\Cache\gologo.bmp 4368 Bitmap Image
C:\Program Files\GO Toolbar\Cache\gotb0200.cfg 5361 CFG File
C:\Program Files\GO Toolbar\Cache\search.bmp 824 Bitmap Image

Folder information Created after Installation:

Folder Location
C:\Program Files\GO Toolbar

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Code Store Database\Distribution Units\{4E7BD74F-2B8D-469E-DDF9-BF2CF4D5FA7D}
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Code Store Database\Distribution Units\{4E7BD74F-2B8D-469E-DDF9-BF2CF4D5FA7D}\DownloadInformation
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GO