Search-Gol Chrome Toolbar

Search-Gol Chrome Toolbar

Known Toolbar

by Search-Gol

What is Search-Gol Chrome Toolbar?

Search-Gol Chrome Toolbar is software application developed by Search-Gol. It is most commonly found on computers running Windows 7 with nearly 62.54% of installations running this operating system. Search-Gol Chrome Toolbar's installer is typically 1.00 MB in size and installs around 4 files.

Search-Gol Chrome Toolbar is most popular in Germany with 20.79% of installations residing in this country.

Search-Gol Chrome Toolbar adds 1 scheduled task to the Windows Task Scheduler launching the program at randomly scheduled times.

About Search-Gol Chrome Toolbar?

The SearchGol Toolbar Platform is a cross web browser plugin designed with ad-supported features, allowing users to view additional banner, search, pop-up, pop-under, interstitial, and in-text link advertisements. This plugin is compatible with Internet Explorer (BHO) and Firefox/Chrome (plugin), and is distributed through various monetization platforms during installation. The browser extension is equipped with various functionalities that can alter the browser's default or customized settings including the home page, search settings, and in some cases, Internet Explorer's load time threshold. Additionally, the plugin may place a lock file within Firefox to prevent competing software from modifying its settings, and disable the browser's Content Security Policy to enable cross site scripting.

Multiple virus scanners have detected malware in Search-Gol Chrome Toolbar.

BUSolution.dll (MD5: 857125f003b7cec720f2103ba1bae6bb) has been flagged by 11 scanners:
Scanner Software Result
Comodo Security ApplicUnsaf.Win32.AdWare.cinmus.194
Dr.Web Adware.BGuard.19
TrendMicro-HouseCall TROJ_GEN.F47V0411
Agnitum Outpost PUA.Toolbar.Babylon!
Antiy-AVL Trojan/Win32.Tgenic
Baidu-International Adware.Win32.Bbylon.E
ESET-NOD32 Win32/Toolbar.Babylon.I
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.Babylon.A
NANO AntiVirus Trojan.Win32.Babylon.csmnej
Bkav FE HW32.Laneul.pmuo
enhancedNT.dll (MD5: dd326484dcef1fee39e5ef283d220f0b) has been flagged by 4 scanners:
Scanner Software Result
Bkav FE HW32.Laneul.pmuo
Dr.Web DLOADER.Trojan
ESET-NOD32 a variant of Win32/Toolbar.Babylon.W
TrendMicro-HouseCall TROJ_GEN.F47V0918
BabMaint.exe (MD5: ba53e73d56387ca1905561ba02a0b22d) has been flagged by 10 scanners:
Scanner Software Result
Agnitum Outpost PUA.Toolbar.Babylon!
Antiy-AVL Trojan/Win32.Tgenic
Baidu-International Adware.Win32.Bbylon.E
Dr.Web Adware.Babylon.12
ESET-NOD32 Win32/Toolbar.Babylon.I
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.Babylon.A
NANO AntiVirus Trojan.Win32.Babylon.csmnej
Bkav FE HW32.Laneul.pmuo
TrendMicro-HouseCall TROJ_GEN.F47V0918

Software Behaviors

Scheduled tasks:
  • BabMaint.exe is scheduled as a task named 'Scheduled scanning task' (runs weekly on Fridays at 00:00).

Startup Entries

Startup tasks:
  • BabMaint.exe is automatically launched at startup through a scheduled task named SBWUpdateTask_Logon_f61fb1a7-001E101FC20F.
Registry entries:
  • enhancedNT.dll is loaded in the current user (HKCU) registry as an auto-starting executable named 'NTRedirect' and executes as C:\Windows\SysWOW64\rundll32.exe "C:\users\user\appdata\Roaming\BabSolution\Shared\enhancedNT.dll",Run.

Software Details

URL:
https://info.searchgol.com
Support:
Installation path:
C:\users\user\appdata\roaming\babsolution\shared
Uninstaller:
"C:\users\user\appdata\Roaming\BabSolution\Shared\GUninstaller.exe" -key "Search-Gol Chrome Toolbar" -rmkey -ask
Size:
1.00 MB
Language:
English

Search-Gol Chrome Toolbar Executable Details

Primary executable:
BUSolution.dll
Name:
Search-Gol Chrome Toolbar
Path:
C:\users\user\appdata\roaming\babsolution\shared\BUSolution.dll
MD5:
857125f003b7cec720f2103ba1bae6bb
SHA-1:
SHA-256:
Files installed by Search-Gol Chrome Toolbar
File Type Filename MD5
EXE
25e5512a65b55d216c58769e29c016ba
DLL
857125f003b7cec720f2103ba1bae6bb
DLL
dd326484dcef1fee39e5ef283d220f0b
EXE
ba53e73d56387ca1905561ba02a0b22d