Home Safe Programs Good Toolbars Rosqxvmn Toolbar

Rosqxvmn Toolbar

Posted: November 6, 2008

Rosqxvmn Toolbar, a clone of Wxdbpfvo Toolbar and Olnmraew Toolbar, is a malignant "tool" of the nefarious Trojan Zlob which attempts to defraud you of your money by frightening you into purchasing worthless anti-spyware applications. Rosqxvmn Toolbar tries to accomplish this scam by producing false pop-up warnings informing you that your computer is infected and needs their bogus anti-spyware software to remove these infections. Other deceitful tactics Rosqxvmn Toolbar may use include hijacking your home page, displaying links and slowing down your computer in order to entice you to buy their frivolous anti-spyware programs.

Rosqxvmn Toolbar may also place icons onto your desktop to con you into buying their products. Rosqxvmn Toolbar usually displays four icons – "Popup Remover", "Antispyware", "Security Scanner" and "NoMoreSpam". Do NOT click on the icons as they are all decoys to purchase rogue security products. The Rosqxvmn Toolbar may display a thin yellow bar that attaches itself to the top of the search results page to once again deceptively lure you into losing your money by purchasing useless anti-spyware programs. Rosqxvmn Toolbar is typically bundled together with the miscreant application Smart Antivirus 2009. If you believe you are infected with the Rosqxvmn Toolbar, remove it immediately with a reliable anti-spyware or anti-virus program.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 browsew.dll
    2 byxww.dll
    3 ctl3d3.dll
    4 Fqbewlna.dll
    5 Fqbewlna.exe
    6 hggdbab.dll
    7 oggview32.dll
    8 Rosqxvmn Toolbar.exe
    9 Rosqxvmn Toolbar.lnk
    10 Rosqxvmn.dll
    11 sprt_ads.dll
    12 ssqpp.dll
    13 toprates.dll
    14 turbosearchsite.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6439B80C-3784-4DEB-BB22-7802A6F5E014}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6439B80C-3784-4DEB-BB22-7802A6F5E014}\InprocServer32HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6439B80C-3784-4DEB-BB22-7802A6F5E014}\ProgIDHKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6439B80C-3784-4DEB-BB22-7802A6F5E014}\VersionIndependentProgIDHKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4D22068D-44DA-44E8-AFA3-B430CB14B733}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4D22068D-44DA-44E8-AFA3-B430CB14B733}\ProxyStubClsidHKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4D22068D-44DA-44E8-AFA3-B430CB14B733}\ProxyStubClsid32HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4D22068D-44DA-44E8-AFA3-B430CB14B733}\TypeLibHKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0D290043-3B99-482A-BB5B-EB6B3643437F}\1.0HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0D290043-3B99-482A-BB5B-EB6B3643437F}\1.0\0\win32HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0D290043-3B99-482A-BB5B-EB6B3643437F}\1.0\FLAGSHKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0D290043-3B99-482A-BB5B-EB6B3643437F}\1.0\HELPDIRHKEY_LOCAL_MACHINE\SOFTWARE\Classes\rosqxvmn.ToolBar.1HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rosqxvmn.ToolBar.1\CLSIDHKEY_LOCAL_MACHINE\SOFTWARE\Classes\rosqxvmn.bpetHKEY_LOCAL_MACHINE\SOFTWARE\Classes\rosqxvmn.bpet\CLSIDHKEY_LOCAL_MACHINE\SOFTWARE\Classes\rosqxvmn.bpet\CurVer
Loading...