Home Malware Programs Browser Hijackers ConservativeTalkNow Toolbar

ConservativeTalkNow Toolbar

Posted: April 29, 2014

Threat Metric

Ranking: 17,049
Threat Level: 1/10
Infected PCs: 2,593
First Seen: April 29, 2014
Last Seen: October 14, 2023
OS(es) Affected: Windows


The ConservativeTalkNow Toolbar is a homepage and search engine hijacker that malware researchers have listed as a Potentially Unwanted Program. Although the ConservativeTalkNow Toolbar does include some minor interface changes that you might find advantageous, the ConservativeTalkNow Toolbar also makes modifications to your Web browser with the intent of promoting affiliated sites that have been found to have poor reputations. Because there are few serious advantages to the ConservativeTalkNow Toolbar and some not insignificant disadvantages, malware researchers recommend removing the ConservativeTalkNow Toolbar from your computer by any means necessary.

The Talk About the ConservativeTalkNow Toolbar that It doesn't Want You Hearing

The ConservativeTalkNow Toolbar brands itself as a useful add-on for accessing online radio shows, particularly talk shows associated with US conservative punditry. This heavily politicized marketing plan may be semi-creative, but malware researchers needed a minimum of time to identify the ConservativeTalkNow Toolbar as a clone of previous browser hijackers for Windows Web browsers. PC users who use the ConservativeTalkNow Toolbar to 'tune in' to their favorite speakers may find that their Web browsers have their homepages and search engines frozen to MyWebSearch.com.

MyWebSearch.com, of course, has its own reasons for notoriety, including being promoted by enormous quantities of other browser hijackers similar to the ConservativeTalkNow Toolbar. This site is not listed as a threat infection vector but does not provide original search results. Visiting reputable search engines should provide equivalent results and does not require the non-consensual modification of any Web browser under your control. Malware experts also note that the inclusion of advertisements by the ConservativeTalkNow Toolbar's search engine may endanger your computer, particularly with any prolonged, unprotected exposure. Potential advertisement-based attacks, such as attempts to install other PUPs onto your computer, should be watched for with alacrity after any ConservativeTalkNow Toolbar's hijack.

Getting Conservative About the Toolbars on Your Web Browser

As a Web-browsing add-on, the ConservativeTalkNow Toolbar is not a complete hoax and does provide minor features related to its marketing thrust. However, malware analysts find that search engine hijackers rarely provide the security of search results that would be expected of a real search site, and often create a range of safety and performance issues for any browser that they modify. Uninstalling the ConservativeTalkNow Toolbar and other MyWebSearch.com hijackers always should be strongly considered.

Since the ConservativeTalkNow Toolbar's incomplete removal may continue to cause performance issues for your browsers, removing the ConservativeTalkNow Toolbar with PC security solutions will give your future Web-surfing experiences the best chances of success. Most anti-malware and anti-adware products worthy of the name also should be competent for detecting the bundles that install the ConservativeTalkNow Toolbar, although malware experts would strongly suggest avoiding any download sources that could install the ConservativeTalkNow Toolbar at all.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\ConservativeTalkNow_4n\bar\2.bin\4nbrmon.exe File name: 4nbrmon.exe
Size: 27.64 KB (27648 bytes)
MD5: d4bab65a9ca379cfc12105cb99dc1e62
Detection count: 595
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\ConservativeTalkNow_4n\bar\2.bin
Group: Malware file
Last Updated: December 16, 2014
%PROGRAMFILES%\ConservativeTalkNow_4n\bar\2.bin\4nSrcAs.dll File name: 4nSrcAs.dll
Size: 60.41 KB (60416 bytes)
MD5: 23922763b4fe51664623a7e2796912c3
Detection count: 436
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\ConservativeTalkNow_4n\bar\2.bin
Group: Malware file
Last Updated: December 16, 2014
%LOCALAPPDATA%\ConservativeTalkNowAuto.exe File name: ConservativeTalkNowAuto.exe
Size: 960.59 KB (960592 bytes)
MD5: 90ed4b4d2a48e02d994611a633e43104
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%
Group: Malware file
Last Updated: December 16, 2014
%LOCALAPPDATA%\ConservativeTalkNowAuto.exe File name: ConservativeTalkNowAuto.exe
Size: 90.23 KB (90230 bytes)
MD5: fd63e08c6dcdafcc8438edb5c7fc0592
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%
Group: Malware file
Last Updated: December 16, 2014
%USERPROFILE%\My Documents\ConservativeTalkNowSetup2.5.5.6.YTman000.exe File name: ConservativeTalkNowSetup2.5.5.6.YTman000.exe
Size: 3.29 MB (3297704 bytes)
MD5: 34659e2812264a9bbefa5ea930ff3998
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\My Documents
Group: Malware file
Last Updated: December 16, 2014
%PROGRAMFILES%\ConservativeTalkNow_4n\bar\1.bin\4nSrchMn.exe File name: 4nSrchMn.exe
Size: 38.44 KB (38440 bytes)
MD5: 0bdba24779a4b5c522eab49cf71a3808
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\ConservativeTalkNow_4n\bar\1.bin
Group: Malware file
Last Updated: December 16, 2014

Registry Modifications

The following newly produced Registry Values are:

CLSID{02585BF8-B543-4193-B8F4-F1D98124CA88}{28e21c4d-0fca-4313-8767-ca92f8bcb222}{330832C2-2E2F-4443-86B5-BFC09DD73FB1}{330b9ed3-3f52-4364-9e80-821baa40d1ea}{33A49F40-81BA-4378-87E3-801B4123961E}{41569195-F4B7-4837-B83A-ED80ADD8672A}{42CE1C53-100A-4937-8C9C-5533BCE20D57}{440470BB-305D-4A6B-B4A1-587277AAAD20}{4BD9052A-0E9F-4220-9217-9F9E87B532ED}{4CE1A103-E631-4633-9FB7-BBB8EBCE5467}{4D9CEBA5-C8B7-4610-8708-CED9DB9B3C8D}{4FA20E57-0DBA-4743-8613-117BBE161146}{533329c9-ca91-42a2-8792-7f91c7b4172a}{54871808-ba7d-4061-b5a3-bc9362d4d183}{54b4973f-0421-4c50-ba88-1d02274b03eb}{55598F12-5900-4520-B576-7CA2D0F89C26}{5644F1EB-CE4F-4954-B67C-47A9D8E8FC12}{599627ba-5630-430f-aa7b-a1dd622e6192}{5DC0360A-B2C9-4F2C-8A41-A5F566E0C979}{5E57D9EF-9E76-4B70-A2DE-386B6514B8DC}{5fc11356-4449-4a31-a786-139a4bfda0eb}{5FD1100F-4C64-4BFF-87F0-8E4839348D38}{62A09DC3-7073-41B9-B553-F4EA6F511A23}{62DF7A52-5F9F-4318-AD6D-AB23C0E11289}{646C705C-80B8-45F2-9489-330A333E2C9E}{6BA04F30-FA8F-44F7-B3B6-7B96A7B178BD}{6DA2F139-5A5A-4E45-8CAD-2F2ED56C1F14}{7176577E-3F02-4915-97BA-A18BC8B33D48}{752929fc-c897-4620-9fa8-0303247277e2}{7DF72004-1FF5-4BF6-9D46-EF81C3A9F4BA}{8a309664-9ce3-447c-b714-e9c4aba2cb11}{9198B111-3AA0-43C7-9112-79ED6E76DF0B}{975e5be7-19e5-4bc6-ae96-d21f4d3b11ef}{a443e1c8-1107-40f5-be40-08af57b76d28}{a4d55b4c-707b-4725-bd68-07c78166f33a}{af706b7e-f57d-4f08-98d7-e9d9087c8ce4}{af77c74d-a46e-4671-afa0-1a09b1d4be39}{B42A16AE-ED06-4BC9-A2B4-AB7BE1C76DAC}{B7D0B105-CD66-43C1-AE72-6D9F993E67BD}{BB2F50B1-3AE6-43E0-92E7-872E2FC3E30B}{c03e6bbb-91c4-4dc2-b1e7-efbb6f6e60ec}{c2aba2ca-0f9b-48d9-a4e1-ec0e4c1b500f}{C7CCA6A2-6BD7-4C50-BFD0-14CBBC312BDE}{C7D38DBF-0C38-4A5D-8D74-77F003F0BD95}{C8C86036-8F45-44C6-AEE9-D897F387904E}{CBA60110-74A5-4245-9A69-2D1B53D42007}{D44373FA-3761-483A-AC85-764897FE58A8}{D58FF743-3096-4BA9-AE08-6E7B42A37B18}{D5D4C534-A95B-44A7-BFE1-7E5898C07AAE}{D6CAA194-242B-4EC1-853D-885AF2776659}{DD1B69E7-D07F-4D34-8182-720AE4EF0FAC}{DF2029BC-524A-4C26-997B-5C1BAFEF4D55}{e5280609-bf3f-4b1c-aa62-d3f6e69d00b3}{e5af9d32-01d7-47b8-9eb6-87d9afce744f}{E687A06E-6E4F-4052-A48D-104F1B876A55}{eb3cdcf7-d1d6-4cd8-817b-f4de2cbcda34}{F24CE9B7-7F63-4BA7-B81F-2BCCCD881403}{F9C34B05-DAA6-45EC-93C7-29CE19AAC87B}{FC4BAA59-3B9B-4A8C-B43E-552AFC40134B}File name without pathhttp_conservativetalknow.dl.tb.ask.com_0.localstoragehttp_conservativetalknow.dl.tb.ask.com_0.localstorage-journalHKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{533329C9-CA91-42A2-8792-7F91C7B4172A}Software\Microsoft\Internet Explorer\Approved Extensions\{AF77C74D-A46E-4671-AFA0-1A09B1D4BE39}Software\Microsoft\Internet Explorer\Approved Extensions\{E5AF9D32-01D7-47B8-9EB6-87D9AFCE744F}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{330832c2-2e2f-4443-86b5-bfc09dd73fb1}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{54b4973f-0421-4c50-ba88-1d02274b03eb}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{55598f12-5900-4520-b576-7ca2d0f89c26}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6866e1ba-3ed6-4a50-ba15-d0dc5154ea3f}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6c13170c-d64b-4910-9c2f-eba2b9261c42}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{b05788f6-da1c-4f39-a2f0-fe42760fa60c}SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{461fc775-35b6-4d0b-9ff3-af280bfaba83}Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{533329C9-CA91-42A2-8792-7F91C7B4172A}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{533329c9-ca91-42a2-8792-7f91c7b4172a}Software\Microsoft\Internet Explorer\URLSearchHooks\{752929fc-c897-4620-9fa8-0303247277e2}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{af77c74d-a46e-4671-afa0-1a09b1d4be39}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{e5af9d32-01d7-47b8-9eb6-87d9afce744f}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{330b9ed3-3f52-4364-9e80-821baa40d1ea}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{599627ba-5630-430f-aa7b-a1dd622e6192}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{af706b7e-f57d-4f08-98d7-e9d9087c8ce4}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e5280609-bf3f-4b1c-aa62-d3f6e69d00b3}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F24CE9B7-7F63-4BA7-B81F-2BCCCD881403}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{533329C9-CA91-42A2-8792-7F91C7B4172A}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AF77C74D-A46E-4671-AFA0-1A09B1D4BE39}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E5AF9D32-01D7-47B8-9EB6-87D9AFCE744F}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{533329C9-CA91-42A2-8792-7F91C7B4172A}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AF77C74D-A46E-4671-AFA0-1A09B1D4BE39}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E5280609-BF3F-4B1C-AA62-D3F6E69D00B3}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E5AF9D32-01D7-47B8-9EB6-87D9AFCE744F}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{330832c2-2e2f-4443-86b5-bfc09dd73fb1}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{54b4973f-0421-4c50-ba88-1d02274b03eb}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{55598f12-5900-4520-b576-7ca2d0f89c26}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6866e1ba-3ed6-4a50-ba15-d0dc5154ea3f}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6c13170c-d64b-4910-9c2f-eba2b9261c42}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{b05788f6-da1c-4f39-a2f0-fe42760fa60c}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{461fc775-35b6-4d0b-9ff3-af280bfaba83}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{533329c9-ca91-42a2-8792-7f91c7b4172a}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{af77c74d-a46e-4671-afa0-1a09b1d4be39}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{e5af9d32-01d7-47b8-9eb6-87d9afce744f}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{330b9ed3-3f52-4364-9e80-821baa40d1ea}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{599627ba-5630-430f-aa7b-a1dd622e6192}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{af706b7e-f57d-4f08-98d7-e9d9087c8ce4}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e5280609-bf3f-4b1c-aa62-d3f6e69d00b3}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F24CE9B7-7F63-4BA7-B81F-2BCCCD881403}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}ConservativeTalkNow_4nbar Uninstall Internet Explorer

Additional Information

The following directories were created:
%PROGRAMFILES%\ConservativeTalkNow_4n%PROGRAMFILES(x86)%\ConservativeTalkNow_4n
The following URL's were detected:
ConservativeTalkNow
Loading...