Home Safe Programs Good Toolbars Rafbsvnx Toolbar

Rafbsvnx Toolbar

Posted: August 26, 2008

Rafbsvnx Toolbar is a rogue toolbar designed to spread fake anti-spyware programs on the web. Rafbsvnx Toolbar may be installed in your browser with the help of Trojan Zlob or a Video ActiveX Object Error. Once installed, Zlob may generate annoying ads and hijack your browser home page. Rafbsvnx Toolbar has rogue buttons that read: "Remove Popups, Scan Spyware, Security Test, and Spam Protection." If you click on any of these buttons you will probably be redirected to a rogue website that promotes rogue anti-spyware programs as legitimate softwares.

Also, if you try to make a search, your search results may be topped with a rogue alert that may read:

"Warning: possible spyware or adware infection! Click here to scan your computer for spyware and adware..."

Rafbsvnx Toolbar is just another scam to scare users into thinking they are infected with spyware infections when they're not. Do not be tricked by Rafbsvnx Toolbar's malicious tactics. All of Rafbsvnx Toolbar's attempts will try to redirect you to a rogue website to waste your money on a product that doesn't give what it alleges to deliver.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 browsew.dll
    2 byxww.dll
    3 ctl3d3.dll
    4 hggdbab.dll
    5 oggview32.dll
    6 Rafbsvnx Toolbar.exe
    7 sprt_ads.dll
    8 ssqpp.dll
    9 toprates.dll
    10 turbosearchsite.dll
    11 Vrmdtneg.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Rafbsvnx ToolbarF10587E9-0E47-4CBE-84AE-7DD20B8684BB
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}14B65C62-1F53-4B15-9476-5D697608536F80DFDD57-D8B8-4991-82B9-9E9D426668B0A74F3FC3-CC9A-4D4C-AFB5-B56F0CAA445D17D2F953-B2D1-4D1B-BCD3-20432E09ECF13DAF1739-AB9E-493E-8DD7-F65CDF363BCB47EFD4AD-CB46-4549-B24B-CEE415394C56BCBC8B3C-397C-4D98-B6BA-FF337B9671E14090F502-6B2D-41B4-8409-B08905A3A0E64911E55D-9240-49DB-B878-337DE4F53E7082C8422E-86A3-41C1-9F2E-094F7BF849E2
Loading...