Home Malware Programs Bad Toolbars Quizulous Toolbar

Quizulous Toolbar

Posted: August 30, 2010

Threat Metric

Threat Level: 1/10
Infected PCs: 26,951
First Seen: August 30, 2010
Last Seen: October 28, 2022
OS(es) Affected: Windows


Quizulous Toolbar is an unwanted toolbar/potentially unwanted application that may be installed to the PC together with free software that are available for download for computer users on the Internet. Quizulous Toolbar may make modifications to the Web browser and strive to advertise irrelevant questionable websites. Quizulous Toolbar may be embedded into Internet Explorer, Mozilla Firefox and Google Chrome Web browsers. Quizulous Toolbar may use misleading techniques to install itself onto the Web browser without the computer user's approval. Quizulous Toolbar may interrupt with the PC user's surfing activity. Quizulous Toolbar may repeatedly show numerous pop-up ads that carry discount coupons, deals, offers and sponsored links. If the PC user clicks on them, the authors of these advertisements may generate advertising revenue by diverting the computer user to suspicious websites. Quizulous Toolbar may give PC users search results that are based on affiliated websites.

Aliases

probably a variant of Win32/Toolbar.MyWebSearch [NOD32]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\QuizulousBar\toolbar\1.bin\q2barsvc.exe File name: q2barsvc.exe
Size: 28.76 KB (28766 bytes)
MD5: c7894f75ed81631c159afe27f9d448ce
Detection count: 8,345
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\QuizulousBar\toolbar\1.bin
Group: Malware file
Last Updated: February 15, 2014
%PROGRAMFILES%\QuizulousBar\toolbar\1.bin\q2Plugin.dll File name: q2Plugin.dll
Size: 49.15 KB (49152 bytes)
MD5: f292d98b89b54e867124ccbecf32b144
Detection count: 6,333
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\QuizulousBar\toolbar\1.bin
Group: Malware file
Last Updated: February 15, 2014
%PROGRAMFILES%\QuizulousBar\toolbar\1.bin\q2SrcAs.dll File name: q2SrcAs.dll
Size: 65.53 KB (65536 bytes)
MD5: 31b2b50c6da03ed9e9925d07a8571048
Detection count: 6,200
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\QuizulousBar\toolbar\1.bin
Group: Malware file
Last Updated: February 15, 2014
%PROGRAMFILES%\QuizulousBar\toolbar\1.bin\q2bar.dll File name: q2bar.dll
Size: 323.58 KB (323584 bytes)
MD5: cb5bd4f1ef609be348542c1887ea58bc
Detection count: 5,872
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\QuizulousBar\toolbar\1.bin
Group: Malware file
Last Updated: February 15, 2014

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\QuizulousSoftware\Microsoft\Internet Explorer\Approved Extensions\{392d065e-4679-4d12-8342-2a2d505fd309}Software\Microsoft\Internet Explorer\Approved Extensions\{f675d3df-504c-4e3c-bea8-a45b3b9bbd1b}Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\tb_Quizulous.exeSoftware\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\tb_Quizulous2.exe

Additional Information

The following directories were created:
%APPDATA%\Quizulous%APPDATA%\Quizulous2%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\jhgmlalmdgjhpofpgikombehpflkeaha%LOCALAPPDATA%\Google\Chrome\User Data\Default\Local Extension Settings\jhgmlalmdgjhpofpgikombehpflkeaha%LOCALAPPDATA%\Google\Chrome\User Data\Default\Local Extension Settings\pnnhlhflllkencmebdgogcmgpkmhaegi%LOCALAPPDATA%\Google\Chrome\User Data\Default\databases\chrome-extension_jhgmlalmdgjhpofpgikombehpflkeaha_0%LOCALAPPDATA%\NativeMessaging\CT2617591%PROGRAMFILES%\Quizulous2%PROGRAMFILES(x86)%\Quizulous2%USERPROFILE%\AppData\LocalLow\Quizulous%USERPROFILE%\AppData\LocalLow\Quizulous2
Loading...