Home Malware Programs Bad Toolbars Nvstech Toolbar

Nvstech Toolbar

Posted: January 7, 2014

Threat Metric

Ranking: 10,410
Threat Level: 5/10
Infected PCs: 2,630
First Seen: January 7, 2014
Last Seen: September 22, 2023
OS(es) Affected: Windows

Nvstech Toolbar Screenshot 1Nvstech Toolbar is a potentially unwanted browser extension, which may be installed on the Web browsers such as Internet Explorer, Mozilla Firefox, and Google Chrome without a PC user's permission. Nvstech Toolbar may advertise itself as an app being able to help computer users save money while shopping online. Nvstech Toolbar may appear as a useful tool but, in truth, it may use tricky tactics to enter a PC. Nvstech Toolbar may usually be installed on the computer system through bundled freeware without a PC user's approval. Once Nvstech Toolbar is installed on the computer, it may replace the default home page and default search engine with an unreliable website. MySavings Toolbar may also show random pop-up ads including sponsored links within search results in any genuine search engine.

Nvstech Toolbar Screenshot 2

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



hktbNvST.dll File name: hktbNvST.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
hk64tbNvST.dll File name: hk64tbNvST.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
tbNvST.dll File name: tbNvST.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
prxtbNvST.dll File name: prxtbNvST.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
ldrtbNvST.dll File name: ldrtbNvST.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

CLSID{b7ed701d-d643-4631-9c82-e40cd3d7746e}{D432F2F5-1D8B-482B-8A49-9FADFABD8CD7}HKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\NvSTECHSoftware\AppDataLow\Toolbar\RegisteredSources\CT3254645SOFTWARE\Classes\Toolbar.CT3254645Software\Microsoft\Internet Explorer\Approved Extensions\{d432f2f5-1d8b-482b-8a49-9fadfabd8cd7}Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\tb_NvSTECH.exeSoftware\Microsoft\Internet Explorer\Toolbar\WebBrowser\{D432F2F5-1D8B-482B-8A49-9FADFABD8CD7}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{d432f2f5-1d8b-482b-8a49-9fadfabd8cd7}Software\Microsoft\Internet Explorer\URLSearchHooks\{d432f2f5-1d8b-482b-8a49-9fadfabd8cd7}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{d432f2f5-1d8b-482b-8a49-9fadfabd8cd7}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{d432f2f5-1d8b-482b-8a49-9fadfabd8cd7}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D432F2F5-1D8B-482B-8A49-9FADFABD8CD7}SOFTWARE\NvSTECHSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{d432f2f5-1d8b-482b-8a49-9fadfabd8cd7}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\{d432f2f5-1d8b-482b-8a49-9fadfabd8cd7}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{d432f2f5-1d8b-482b-8a49-9fadfabd8cd7}SOFTWARE\Wow6432Node\NvSTECH

Additional Information

The following directories were created:
%APPDATA%\NvSTECH%LOCALAPPDATA%\NativeMessaging\CT3254645%PROGRAMFILES%\NvSTECH%PROGRAMFILES(x86)%\NvSTECH%TEMP%\ct3254645%USERPROFILE%\AppData\LocalLow\NvSTECH
The following URL's were detected:
NvSTECH.OurToolbar.com
Loading...