GoforFiles

GoforFiles

Known Toolbar

by Righway Technologies, Inc

What is GoforFiles?

GoforFiles is software application developed by Righway Technologies, Inc. It is most commonly found on computers running Windows 7 with nearly 71.29% of installations running this operating system. GoforFiles's installer is typically 9.00 MB in size and installs around 7 files. The most common release is 1.9.1 with 18.11% of all installations currently using this version.

GoforFiles is most popular in the United States with 26.1% of installations residing in this country.

GoforFiles adds 2 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times. When using a computer that is connected to the internet, GoforFiles is known to create 2 firewall exceptions to allow inbound and outbound connectivity.

About GoforFiles?

GoforFiles is a software package that includes multiple browser toolbars, including the Delta Search Toolbar. The Delta Search Toolbar is an adware toolbar designed to alter the user's web browser settings, including the home page and search preferences.

Multiple virus scanners have detected malware in GoforFiles.

uninstall.exe (MD5: 9294a626096d00a0f230d51e43a76168) has been flagged by 20 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.ExpressFiles
Baidu-International Trojan.Win32.YourFileDownloader.apA
Bkav FE W32.Clod57e.Trojan.b489
Dr.Web Adware.Downware.825
ESET-NOD32 a variant of Win32/YourFileDownloader.B
K7 AntiVirus Unwanted-Program ( 00454f261 )
K7GW Unwanted-Program ( 00454f261 )
Malwarebytes PUP.Optional.GoForFiles.A
McAfee Artemis!9294A626096D
McAfee-GW-Edition Artemis!9294A626096D
Sophos Go For Files
VIPRE Antivirus ExpressFiles Installer (fs)
AVG Righway Technologies.55F
AVware SimpleFiles (fs)
G Data Win32.Adware.GoForFiles.A
Rising Antivirus PE:Malware.XPACK/RDM!5.1
Vba32 AntiVirus Signed-Downware.ExpressDownloader
avast! Win32:Adware-AHK [PUP]
eSafe Win32.Trojan
TrendMicro-HouseCall TROJ_GEN.F47V0115
goforfilesdl.exe (MD5: 3cf3383eae09bab72e73cb6e0cd8b813) has been flagged by 11 scanners:
Scanner Software Result
AVG Righway Technologies.55F
AVware SimpleFiles (fs)
Dr.Web Adware.Downware.1204
G Data Win32.Adware.GoForFiles.A
Rising Antivirus PE:Malware.XPACK/RDM!5.1
Vba32 AntiVirus Signed-Downware.ExpressDownloader
VIPRE Antivirus SimpleFiles (fs)
avast! Win32:Adware-AHK [PUP]
eSafe Win32.Trojan
ESET-NOD32 a variant of Win32/YourFileDownloader.B
TrendMicro-HouseCall TROJ_GEN.F47V0115
GFFUpdater.exe (MD5: 0429fca3ce38367c98b9eecfaa17b35a) has been flagged by 5 scanners:
Scanner Software Result
avast! Win32:Adware-AHK [PUP]
Dr.Web Tool.DownLoader.52
eSafe Win32.Trojan
ESET-NOD32 a variant of Win32/YourFileDownloader.B
TrendMicro-HouseCall TROJ_GEN.F47V0115

Software Behaviors

Firewall:
  • goforfilesdl.exe is added as a firewall exception for 'C:\Program Files\GoforFiles\goforfilesdl.exe'.
  • GoforFiles.exe is added as a firewall exception for 'C:\Program Files\GoforFiles\GoforFiles.exe'.
Scheduled tasks:
  • GoforFiles.exe is scheduled as a task with the class '{EC7E44AA-3E5D-4705-B7D8-5408B1ABE51F}' (runs on registration).
  • GFFUpdater.exe is scheduled as a task named 'C:\WINDOWS\Tasks\GoforFilesUpdate.job'.

Startup Entries

Startup tasks:
  • GFFUpdater.exe is automatically launched at startup through a scheduled task named GoforFilesUpdate.

Software Details

URL:
https://www.goforfiles.com
Support:
https://www.goforfiles.com/help
Installation path:
C:\Program Files\GoforFiles
Uninstaller:
"C:\Program Files\GoforFiles\uninstall.exe"
Size:
9.00 MB
Language:
English

GoforFiles Executable Details

Primary executable:
GoForFiles.exe
Name:
GoforFiles
Path:
C:\Program Files\GoforFiles\GoForFiles.exe
MD5:
4ce42d5cf5d556a4d429e95b474f413c
SHA-1:
SHA-256:
Files installed by GoforFiles
File Type Filename MD5
EXE
9294a626096d00a0f230d51e43a76168
DLL
109fe7e0c21589b4fbac129c26430ce4
EXE
4ce42d5cf5d556a4d429e95b474f413c
EXE
3cf3383eae09bab72e73cb6e0cd8b813
EXE
0429fca3ce38367c98b9eecfaa17b35a
EXE
5a89a5f6e498ebac94213d5c455496e7
EXE
5dfde75c2d08b5f7dcfb91e5f765927d