Home Malware Programs Browser Hijackers QuotationCafe Toolbar

QuotationCafe Toolbar

Posted: June 17, 2013

Threat Metric

Ranking: 19,448
Threat Level: 1/10
Infected PCs: 1,480
First Seen: June 17, 2013
Last Seen: December 11, 2024
OS(es) Affected: Windows

QuotationCafe is a toolbar that computer users can download from Quotationcafe.com. However, QuotationCafe has been noticed to be installed to random computer systems without a PC user's consent. QuotationCafe always comes bundled with other free applications that PC users can download from the Internet. QuatationCafe is not considered to be a malicious program, but it causes many inconveniences for the target computer user. QuotationCafe changes the default homepage and default search system to a suspicious website. QuotationCafe will also constantly redirect the victimized computer user to dubious websites while he/she is surfing the Internet. QuotationCafe attempts to create traffic to specific supported websites. QuotationCafe also gathers information about the attacked PC user's browsing activity and may permit third parties to use this data to display targeted pop-up advertisements on the screen of the targeted computer. Keeping QuotationCafe on the computer system poses a security risk to the affected computer's protection. QuotationCafe can also violate the victimized PC user's privacy.

Use SpyHunter to Detect and Remove PC Threats

If you are concerned that malware or PC threats similar to QuotationCafe Toolbar may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.

* See Free Trial offer below. EULA and Privacy/Cookie Policy.

Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{01A09E2C-AE36-4EEF-ADDF-82D7AF078108}{133BCF8B-D6D1-43A5-B6E2-9FA2CC203F8A}{13a18f5d-bad1-4971-908c-2cf62e86bcd7}{150F839C-4F8A-40DB-8ABC-094699A2C5DA}{1D63CC1B-2217-4EEB-B89C-0C3BB3C46D7A}{1d93a88a-e20d-4274-b788-4214a8004509}{256B2270-BFBD-4A03-931C-AFCD4C9FCD4B}{3453118d-ecae-4832-9026-cade4301f2c1}{3677B40B-7584-47E5-B2C3-DD605D4A9765}{36978F8D-689A-4E9A-9C77-62D7D407B4E0}{39818F1A-91C6-49FC-9A4B-65F0D4EF2F6B}{3b069953-cf59-4926-9d28-a4589c462859}{3FF0C41F-BFD8-463E-A392-4C53BAF98C73}{414770B6-4B86-487D-AB8A-C5B557A1623A}{42564B8D-89ED-44BC-BBEA-3C413EB856FC}{433D1691-34D0-47F5-B673-4153828669F3}{4B57B062-F035-4FA2-95A4-AFCD5C8A9FD9}{5646C32F-D0D5-43C6-98F0-B98C7A57B044}{56B3D182-D76A-4C48-911A-32F98E3CE84D}{56b9e219-0acb-41c2-a020-04588e35354a}{58C4DAE6-50EF-46E9-8249-4407EACCAA85}{614D2B09-9007-430C-B039-D341AFE9C313}{687272a0-645a-4d14-ae7d-9ae8a96aa532}{6ab96dd7-6e0c-4a7f-93e0-a8a47a685d81}{6E6EBD73-BA62-4837-A6C3-7B50D697264E}{76d2ba9a-db99-4328-a965-2547eb390a60}{76DC1A38-1192-4EC2-ABA6-587B055C772B}{7ABC0217-276F-4940-840E-2A0ACBEB4249}{7B5F6E6C-D5E6-4BD2-8316-C0BFF6812852}{855A1C2B-E11C-4518-A8B0-0D204A47C4D8}{8561f2a1-d885-4852-8289-81ae4ad0ad99}{8619595f-4eef-4164-b040-fb7436301a06}{8E29C446-AC83-49C9-800D-A8459A05900D}{908A219B-30DC-4CFB-A2C6-01639E712559}{9362fa55-5c21-4631-96ea-fc661f814423}{99bced2f-1db3-4ecd-8e35-8906428a6cfe}{9B6E2E90-E26C-43EF-8A0A-AD57EB5D0284}{9d4e4f05-7a77-45a1-befc-1fd6dbbc537d}{9FF234D5-7FC1-4851-B712-2F4D8C57B1C9}{A47108E7-824F-481E-844D-E4932E0B47B8}{A5401A15-B8E9-4F7C-8AA4-0E00BA27A189}{A675F307-5957-4405-9E96-607E6702FFA7}{A68C2498-7B5E-4FFE-8DF7-F38703FD378A}{A6ACF80B-12BE-4FDD-8F2E-0BE53CF1A5D4}{a751f365-575b-4d1a-931a-598a56e7b4d5}{aa2bce70-1c24-457d-8c63-4debc4185255}{B2C4F911-C085-451E-8924-26F437A196A5}{B4FCC21E-EEDE-419F-9ED9-7ECB7B77EADD}{b60142b7-b49c-4c7b-bdcb-edbadb895f5a}{ba9b0bb2-a1fe-4deb-ae64-bc0ccad70884}{BBDEA6E1-D3E3-4D50-B9F8-0DC879B6F1CE}{c30c26aa-9775-43ac-9877-b8f9ca1a81b4}{C505872D-F02A-4240-8649-1841AE5AD8BA}{CA98876E-BBEB-41BB-AD8A-972F1C7B4706}{CE02E6DB-B960-4668-996E-63D8C5543D5C}{D09439A5-A6C8-474E-B3F0-0260663A5260}{d4ebf666-812b-4412-91e1-680b5e4a3234}{D654CC32-E3AA-414D-BD3A-611BEA03FF73}{d869b2ca-ca35-4738-ae05-5668230c0a7f}{D90FAFF5-3534-4534-8760-871FADA933F1}{DD712088-9E33-4016-8A9B-DA8CBAA6F2CA}{e1e3eb24-ec60-42d4-a6cd-4c87bbecc6e2}{E78D7806-7B89-4746-A0F6-D27EEFE7B7B6}{E7F7D49B-46E8-497E-A0F9-507DE0516981}{EA620275-04DA-4864-9BC2-82E466E72F1D}{EDA17A58-0135-411F-9D78-7E98DD801BDD}File name without pathhttp_quotationcafe.dl.mywebsearch.com_0.localstorageHKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\QuotationCafe_45SOFTWARE\Classes\QuotationCafe_45.DynamicBarButtonSOFTWARE\Classes\QuotationCafe_45.DynamicBarButton.1SOFTWARE\Classes\QuotationCafe_45.FeedManagerSOFTWARE\Classes\QuotationCafe_45.FeedManager.1SOFTWARE\Classes\QuotationCafe_45.HTMLMenuSOFTWARE\Classes\QuotationCafe_45.HTMLMenu.1SOFTWARE\Classes\QuotationCafe_45.HTMLPanelSOFTWARE\Classes\QuotationCafe_45.HTMLPanel.1SOFTWARE\Classes\QuotationCafe_45.MultipleButtonSOFTWARE\Classes\QuotationCafe_45.MultipleButton.1SOFTWARE\Classes\QuotationCafe_45.PseudoTransparentPluginSOFTWARE\Classes\QuotationCafe_45.PseudoTransparentPlugin.1SOFTWARE\Classes\QuotationCafe_45.RadioSOFTWARE\Classes\QuotationCafe_45.Radio.1SOFTWARE\Classes\QuotationCafe_45.RadioSettingsSOFTWARE\Classes\QuotationCafe_45.RadioSettings.1SOFTWARE\Classes\QuotationCafe_45.ScriptButtonSOFTWARE\Classes\QuotationCafe_45.ScriptButton.1SOFTWARE\Classes\QuotationCafe_45.SettingsPluginSOFTWARE\Classes\QuotationCafe_45.SettingsPlugin.1SOFTWARE\Classes\QuotationCafe_45.SkinLauncherSOFTWARE\Classes\QuotationCafe_45.SkinLauncher.1SOFTWARE\Classes\QuotationCafe_45.SkinLauncherSettingsSOFTWARE\Classes\QuotationCafe_45.SkinLauncherSettings.1SOFTWARE\Classes\QuotationCafe_45.ThirdPartyInstallerSOFTWARE\Classes\QuotationCafe_45.ThirdPartyInstaller.1SOFTWARE\Classes\QuotationCafe_45.ToolbarProtectorSOFTWARE\Classes\QuotationCafe_45.ToolbarProtector.1SOFTWARE\Classes\QuotationCafe_45.UrlAlertButtonSOFTWARE\Classes\QuotationCafe_45.UrlAlertButton.1SOFTWARE\Classes\QuotationCafe_45.XMLSessionPluginSOFTWARE\Classes\QuotationCafe_45.XMLSessionPlugin.1Software\Microsoft\Internet Explorer\Approved Extensions\{8561F2A1-D885-4852-8289-81AE4AD0AD99}Software\Microsoft\Internet Explorer\Approved Extensions\{8619595F-4EEF-4164-B040-FB7436301A06}Software\Microsoft\Internet Explorer\Approved Extensions\{99BCED2F-1DB3-4ECD-8E35-8906428A6CFE}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5ade1a85-0387-4d69-a819-4e59b83187f9}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{783a4d51-67c4-42b3-9781-910246867646}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a47108e7-824f-481e-844d-e4932e0b47b8}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d869b2ca-ca35-4738-ae05-5668230c0a7f}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ea620275-04da-4864-9bc2-82e466e72f1d}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{eda17a58-0135-411f-9d78-7e98dd801bdd}Software\Microsoft\Internet Explorer\SearchScopes\{5941bc46-57ca-4649-8c07-aef5f99313f2}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{99bced2f-1db3-4ecd-8e35-8906428a6cfe}Software\Microsoft\Internet Explorer\URLSearchHooks\{6ab96dd7-6e0c-4a7f-93e0-a8a47a685d81}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{8561f2a1-d885-4852-8289-81ae4ad0ad99}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{8619595f-4eef-4164-b040-fb7436301a06}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{13a18f5d-bad1-4971-908c-2cf62e86bcd7}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3453118d-ecae-4832-9026-cade4301f2c1}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3b069953-cf59-4926-9d28-a4589c462859}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9362fa55-5c21-4631-96ea-fc661f814423}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{ba9b0bb2-a1fe-4deb-ae64-bc0ccad70884}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CA98876E-BBEB-41BB-AD8A-972F1C7B4706}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e1368b44-60a8-470f-9537-c1bc2390c8e3}SOFTWARE\Microsoft\Windows\CurrentVersion\Run\QuotationCafe Search Scope MonitorSOFTWARE\Mozilla\Firefox\Extensions\45ffxtbr@QuotationCafe_45.comSOFTWARE\QuotationCafe_45SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5ade1a85-0387-4d69-a819-4e59b83187f9}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{783a4d51-67c4-42b3-9781-910246867646}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a47108e7-824f-481e-844d-e4932e0b47b8}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d869b2ca-ca35-4738-ae05-5668230c0a7f}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ea620275-04da-4864-9bc2-82e466e72f1d}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{eda17a58-0135-411f-9d78-7e98dd801bdd}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{5941bc46-57ca-4649-8c07-aef5f99313f2}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{99bced2f-1db3-4ecd-8e35-8906428a6cfe}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{8561f2a1-d885-4852-8289-81ae4ad0ad99}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{8619595f-4eef-4164-b040-fb7436301a06}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{13a18f5d-bad1-4971-908c-2cf62e86bcd7}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3453118d-ecae-4832-9026-cade4301f2c1}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3b069953-cf59-4926-9d28-a4589c462859}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9362fa55-5c21-4631-96ea-fc661f814423}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{ba9b0bb2-a1fe-4deb-ae64-bc0ccad70884}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CA98876E-BBEB-41BB-AD8A-972F1C7B4706}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e1368b44-60a8-470f-9537-c1bc2390c8e3}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\QuotationCafe Search Scope MonitorSOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions\45ffxtbr@QuotationCafe_45.comSOFTWARE\Wow6432Node\QuotationCafe_45SYSTEM\ControlSet001\services\QuotationCafe_45ServiceSYSTEM\ControlSet002\services\QuotationCafe_45ServiceSYSTEM\CurrentControlSet\services\QuotationCafe_45ServiceHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}QuotationCafe_45bar Uninstall

Additional Information

The following directories were created:
%LOCALAPPDATA%\QuotationCafe_45%PROGRAMFILES%\QuotationCafe_45%PROGRAMFILES(x86)%\QuotationCafe_45%USERPROFILE%\AppData\LocalLow\QuotationCafe_45
The following URL's were detected:
QuotationCafe
Loading...
Spywareremove.com uses cookies to provide you with a better browsing experience and analyze how users navigate and utilize the Site. By using this Site or clicking on "OK", you consent to the use of cookies. Learn more.