Home Malware Programs Browser Hijackers QuotationCafe Toolbar

QuotationCafe Toolbar

Posted: June 17, 2013

Threat Metric

Ranking: 16,968
Threat Level: 1/10
Infected PCs: 1,461
First Seen: June 17, 2013
Last Seen: July 17, 2023
OS(es) Affected: Windows

QuotationCafe is a toolbar that computer users can download from Quotationcafe.com. However, QuotationCafe has been noticed to be installed to random computer systems without a PC user's consent. QuotationCafe always comes bundled with other free applications that PC users can download from the Internet. QuatationCafe is not considered to be a malicious program, but it causes many inconveniences for the target computer user. QuotationCafe changes the default homepage and default search system to a suspicious website. QuotationCafe will also constantly redirect the victimized computer user to dubious websites while he/she is surfing the Internet. QuotationCafe attempts to create traffic to specific supported websites. QuotationCafe also gathers information about the attacked PC user's browsing activity and may permit third parties to use this data to display targeted pop-up advertisements on the screen of the targeted computer. Keeping QuotationCafe on the computer system poses a security risk to the affected computer's protection. QuotationCafe can also violate the victimized PC user's privacy.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{01A09E2C-AE36-4EEF-ADDF-82D7AF078108}{133BCF8B-D6D1-43A5-B6E2-9FA2CC203F8A}{13a18f5d-bad1-4971-908c-2cf62e86bcd7}{150F839C-4F8A-40DB-8ABC-094699A2C5DA}{1D63CC1B-2217-4EEB-B89C-0C3BB3C46D7A}{1d93a88a-e20d-4274-b788-4214a8004509}{256B2270-BFBD-4A03-931C-AFCD4C9FCD4B}{3453118d-ecae-4832-9026-cade4301f2c1}{3677B40B-7584-47E5-B2C3-DD605D4A9765}{36978F8D-689A-4E9A-9C77-62D7D407B4E0}{39818F1A-91C6-49FC-9A4B-65F0D4EF2F6B}{3b069953-cf59-4926-9d28-a4589c462859}{3FF0C41F-BFD8-463E-A392-4C53BAF98C73}{414770B6-4B86-487D-AB8A-C5B557A1623A}{42564B8D-89ED-44BC-BBEA-3C413EB856FC}{433D1691-34D0-47F5-B673-4153828669F3}{4B57B062-F035-4FA2-95A4-AFCD5C8A9FD9}{5646C32F-D0D5-43C6-98F0-B98C7A57B044}{56B3D182-D76A-4C48-911A-32F98E3CE84D}{56b9e219-0acb-41c2-a020-04588e35354a}{58C4DAE6-50EF-46E9-8249-4407EACCAA85}{614D2B09-9007-430C-B039-D341AFE9C313}{687272a0-645a-4d14-ae7d-9ae8a96aa532}{6ab96dd7-6e0c-4a7f-93e0-a8a47a685d81}{6E6EBD73-BA62-4837-A6C3-7B50D697264E}{76d2ba9a-db99-4328-a965-2547eb390a60}{76DC1A38-1192-4EC2-ABA6-587B055C772B}{7ABC0217-276F-4940-840E-2A0ACBEB4249}{7B5F6E6C-D5E6-4BD2-8316-C0BFF6812852}{855A1C2B-E11C-4518-A8B0-0D204A47C4D8}{8561f2a1-d885-4852-8289-81ae4ad0ad99}{8619595f-4eef-4164-b040-fb7436301a06}{8E29C446-AC83-49C9-800D-A8459A05900D}{908A219B-30DC-4CFB-A2C6-01639E712559}{9362fa55-5c21-4631-96ea-fc661f814423}{99bced2f-1db3-4ecd-8e35-8906428a6cfe}{9B6E2E90-E26C-43EF-8A0A-AD57EB5D0284}{9d4e4f05-7a77-45a1-befc-1fd6dbbc537d}{9FF234D5-7FC1-4851-B712-2F4D8C57B1C9}{A47108E7-824F-481E-844D-E4932E0B47B8}{A5401A15-B8E9-4F7C-8AA4-0E00BA27A189}{A675F307-5957-4405-9E96-607E6702FFA7}{A68C2498-7B5E-4FFE-8DF7-F38703FD378A}{A6ACF80B-12BE-4FDD-8F2E-0BE53CF1A5D4}{a751f365-575b-4d1a-931a-598a56e7b4d5}{aa2bce70-1c24-457d-8c63-4debc4185255}{B2C4F911-C085-451E-8924-26F437A196A5}{B4FCC21E-EEDE-419F-9ED9-7ECB7B77EADD}{b60142b7-b49c-4c7b-bdcb-edbadb895f5a}{ba9b0bb2-a1fe-4deb-ae64-bc0ccad70884}{BBDEA6E1-D3E3-4D50-B9F8-0DC879B6F1CE}{c30c26aa-9775-43ac-9877-b8f9ca1a81b4}{C505872D-F02A-4240-8649-1841AE5AD8BA}{CA98876E-BBEB-41BB-AD8A-972F1C7B4706}{CE02E6DB-B960-4668-996E-63D8C5543D5C}{D09439A5-A6C8-474E-B3F0-0260663A5260}{d4ebf666-812b-4412-91e1-680b5e4a3234}{D654CC32-E3AA-414D-BD3A-611BEA03FF73}{d869b2ca-ca35-4738-ae05-5668230c0a7f}{D90FAFF5-3534-4534-8760-871FADA933F1}{DD712088-9E33-4016-8A9B-DA8CBAA6F2CA}{e1e3eb24-ec60-42d4-a6cd-4c87bbecc6e2}{E78D7806-7B89-4746-A0F6-D27EEFE7B7B6}{E7F7D49B-46E8-497E-A0F9-507DE0516981}{EA620275-04DA-4864-9BC2-82E466E72F1D}{EDA17A58-0135-411F-9D78-7E98DD801BDD}File name without pathhttp_quotationcafe.dl.mywebsearch.com_0.localstorageHKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\QuotationCafe_45SOFTWARE\Classes\QuotationCafe_45.DynamicBarButtonSOFTWARE\Classes\QuotationCafe_45.DynamicBarButton.1SOFTWARE\Classes\QuotationCafe_45.FeedManagerSOFTWARE\Classes\QuotationCafe_45.FeedManager.1SOFTWARE\Classes\QuotationCafe_45.HTMLMenuSOFTWARE\Classes\QuotationCafe_45.HTMLMenu.1SOFTWARE\Classes\QuotationCafe_45.HTMLPanelSOFTWARE\Classes\QuotationCafe_45.HTMLPanel.1SOFTWARE\Classes\QuotationCafe_45.MultipleButtonSOFTWARE\Classes\QuotationCafe_45.MultipleButton.1SOFTWARE\Classes\QuotationCafe_45.PseudoTransparentPluginSOFTWARE\Classes\QuotationCafe_45.PseudoTransparentPlugin.1SOFTWARE\Classes\QuotationCafe_45.RadioSOFTWARE\Classes\QuotationCafe_45.Radio.1SOFTWARE\Classes\QuotationCafe_45.RadioSettingsSOFTWARE\Classes\QuotationCafe_45.RadioSettings.1SOFTWARE\Classes\QuotationCafe_45.ScriptButtonSOFTWARE\Classes\QuotationCafe_45.ScriptButton.1SOFTWARE\Classes\QuotationCafe_45.SettingsPluginSOFTWARE\Classes\QuotationCafe_45.SettingsPlugin.1SOFTWARE\Classes\QuotationCafe_45.SkinLauncherSOFTWARE\Classes\QuotationCafe_45.SkinLauncher.1SOFTWARE\Classes\QuotationCafe_45.SkinLauncherSettingsSOFTWARE\Classes\QuotationCafe_45.SkinLauncherSettings.1SOFTWARE\Classes\QuotationCafe_45.ThirdPartyInstallerSOFTWARE\Classes\QuotationCafe_45.ThirdPartyInstaller.1SOFTWARE\Classes\QuotationCafe_45.ToolbarProtectorSOFTWARE\Classes\QuotationCafe_45.ToolbarProtector.1SOFTWARE\Classes\QuotationCafe_45.UrlAlertButtonSOFTWARE\Classes\QuotationCafe_45.UrlAlertButton.1SOFTWARE\Classes\QuotationCafe_45.XMLSessionPluginSOFTWARE\Classes\QuotationCafe_45.XMLSessionPlugin.1Software\Microsoft\Internet Explorer\Approved Extensions\{8561F2A1-D885-4852-8289-81AE4AD0AD99}Software\Microsoft\Internet Explorer\Approved Extensions\{8619595F-4EEF-4164-B040-FB7436301A06}Software\Microsoft\Internet Explorer\Approved Extensions\{99BCED2F-1DB3-4ECD-8E35-8906428A6CFE}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5ade1a85-0387-4d69-a819-4e59b83187f9}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{783a4d51-67c4-42b3-9781-910246867646}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a47108e7-824f-481e-844d-e4932e0b47b8}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d869b2ca-ca35-4738-ae05-5668230c0a7f}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ea620275-04da-4864-9bc2-82e466e72f1d}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{eda17a58-0135-411f-9d78-7e98dd801bdd}Software\Microsoft\Internet Explorer\SearchScopes\{5941bc46-57ca-4649-8c07-aef5f99313f2}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{99bced2f-1db3-4ecd-8e35-8906428a6cfe}Software\Microsoft\Internet Explorer\URLSearchHooks\{6ab96dd7-6e0c-4a7f-93e0-a8a47a685d81}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{8561f2a1-d885-4852-8289-81ae4ad0ad99}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{8619595f-4eef-4164-b040-fb7436301a06}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{13a18f5d-bad1-4971-908c-2cf62e86bcd7}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3453118d-ecae-4832-9026-cade4301f2c1}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3b069953-cf59-4926-9d28-a4589c462859}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9362fa55-5c21-4631-96ea-fc661f814423}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{ba9b0bb2-a1fe-4deb-ae64-bc0ccad70884}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CA98876E-BBEB-41BB-AD8A-972F1C7B4706}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e1368b44-60a8-470f-9537-c1bc2390c8e3}SOFTWARE\Microsoft\Windows\CurrentVersion\Run\QuotationCafe Search Scope MonitorSOFTWARE\Mozilla\Firefox\Extensions\45ffxtbr@QuotationCafe_45.comSOFTWARE\QuotationCafe_45SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5ade1a85-0387-4d69-a819-4e59b83187f9}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{783a4d51-67c4-42b3-9781-910246867646}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a47108e7-824f-481e-844d-e4932e0b47b8}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d869b2ca-ca35-4738-ae05-5668230c0a7f}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ea620275-04da-4864-9bc2-82e466e72f1d}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{eda17a58-0135-411f-9d78-7e98dd801bdd}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{5941bc46-57ca-4649-8c07-aef5f99313f2}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{99bced2f-1db3-4ecd-8e35-8906428a6cfe}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{8561f2a1-d885-4852-8289-81ae4ad0ad99}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{8619595f-4eef-4164-b040-fb7436301a06}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{13a18f5d-bad1-4971-908c-2cf62e86bcd7}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3453118d-ecae-4832-9026-cade4301f2c1}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3b069953-cf59-4926-9d28-a4589c462859}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9362fa55-5c21-4631-96ea-fc661f814423}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{ba9b0bb2-a1fe-4deb-ae64-bc0ccad70884}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CA98876E-BBEB-41BB-AD8A-972F1C7B4706}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e1368b44-60a8-470f-9537-c1bc2390c8e3}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\QuotationCafe Search Scope MonitorSOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions\45ffxtbr@QuotationCafe_45.comSOFTWARE\Wow6432Node\QuotationCafe_45SYSTEM\ControlSet001\services\QuotationCafe_45ServiceSYSTEM\ControlSet002\services\QuotationCafe_45ServiceSYSTEM\CurrentControlSet\services\QuotationCafe_45ServiceHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}QuotationCafe_45bar Uninstall

Additional Information

The following directories were created:
%LOCALAPPDATA%\QuotationCafe_45%PROGRAMFILES%\QuotationCafe_45%PROGRAMFILES(x86)%\QuotationCafe_45%USERPROFILE%\AppData\LocalLow\QuotationCafe_45
The following URL's were detected:
QuotationCafe
Loading...