Home Safe Programs Good Toolbars Qalkfxor Toolbar

Qalkfxor Toolbar

Posted: September 3, 2008

Qalkfxor Toolbar is a Trojan toolbar from the Zlob family. Qalkfxor Toolbar is a clone of other popular malicious toolbars like Nmwegbsf Toolbar, Atfxqogp Toolbar, Gktxaspm Toolbar, Mkrndofl Toolbar, Pvnsmfor Toolbar and Sgoblxtm Toolbar.

Qalkfxor Toolbar infects your system through corrupt video codecs, such as Video Access Codec, which are found on rogue and porn websites.

Qalkfxor Toolbar has four icons named "Remove Popups", "Scan Spyware", "Security Test" and "Spam Protection", all of which lead to malicious websites that promote rogue anti-spyware programs.

Also, the Qalkfxor Toolbar displays a yellow bar that attaches itself to the top of the search results webpage and says the following message: "Warning: possible spyware or adware infection! Click here to scan your computer for spyware...".

None of the products and services Qalkfxor Toolbar distributes are legitimate or trustworthy. It is recommended the immediate removal of Qalkfxor Toolbar.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 browsew.dll
    2 byxww.dll
    3 hggdbab.dll
    4 oggview32.dll
    5 Qalkfxor Toolbar.exe
    6 Qalkfxor.dll
    7 Qalkfxor.exe
    8 sprt_ads.dll ctl3d3.dll
    9 ssqpp.dll
    10 toprates.dll
    11 turbosearchsite.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Qalkfxor ToolbarF10587E9-0E47-4CBE-84AE-7DD20B8684BB
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}A74F3FC3-CC9A-4D4C-AFB5-B56F0CAA445D17D2F953-B2D1-4D1B-BCD3-20432E09ECF1BCBC8B3C-397C-4D98-B6BA-FF337B9671E13DAF1739-AB9E-493E-8DD7-F65CDF363BCB14B65C62-1F53-4B15-9476-5D697608536F82C8422E-86A3-41C1-9F2E-094F7BF849E24911E55D-9240-49DB-B878-337DE4F53E7080DFDD57-D8B8-4991-82B9-9E9D426668B047EFD4AD-CB46-4549-B24B-CEE415394C564090F502-6B2D-41B4-8409-B08905A3A0E6
Loading...