Security Stronghold security made easy

Remove Toolbar888 from Chrome, Firefox, IE



Threat's profile Threat indicator: HIGH

Name of the threat:Toolbar888

Command or file name:matcash.exe

Threat type:Toolbars

Affected OS:Win32/Win64 (Windows XP, Vista/7, 8/8.1, Windows 10)

Affected browsers:Google Chrome, Mozilla Firefox, Internet Explorer, Safari

Nearly all commercial anti spyware currently find spyware-adware and spyware, but dominantly it's needed to have specially - orientated spyware-adware removal tools as regular spyware-adware removal can not be completely performed by anti rootkit. The Eudora computer mail client is a notorious example of an spyware-adware "mode" in a application when you let penetrate while not having a worthy spyware-adware removal tool. You should remove spyware-adware as badly infected systems may serve very slowly, break constantly and betweenwhiles may not start at all, so, it is reasonable to execute spyware-adware removal operation. You can encounter the question with concealed PC files being used by spyware-adware. Being troublous of spyware-adware and abnegate global Internet browsing is not the better way out - better have a worthy spyware-adware removal tool which is Security Stronghold spyware-adware removal tool. Searching results from spyware-adware hijacked toolbars may be restricted to only WWW sites that pay for position controlling.


Toolbar888 intrusion method

Usually Toolbar888 comes bundled with freeware downloads. During installation you can be offered to change default homepage and search engine to Toolbar888. Toolbar888 copies its file(s) to your hard disk. Its typical file name is matcash.exe. Then it creates new startup key with name Toolbar888 and value matcash.exe. You can also find it in your processes list with name matcash.exe or Toolbar888. Also, it can create folder with name Toolbar888 under C:\Program Files\ or C:\ProgramData. If you have further questions about Toolbar888, please ask below. You can use programs to remove Toolbar888 from your browsers below.


Download Removal Tool

Download this advanced removal tool and solve problems with Toolbar888 and matcash.exe (download of fix will start immediately):

Download WiperSoft Antispyware to remove Toolbar888

* WiperSoft Antispyware was developed to remove threats like Toolbar888 in automatic mode. Remover has active module to protect PC from hijackers, trojans, ransomware and other viruses. Trial version of Wipersoft provides detection of computer viruses for FREE. To remove malware, you have to purchase the full version of Wipersoft.


Features of WiperSoft Antispyware Malware Remediation Tool

  • Removes all files created by viruses.
  • Removes all registry entries created by viruses.
  • You can activate System and Network Guards and forget about malware.
  • Can fix browser problems and protect browser settings.
  • Removal is guaranteed - if Removal Tool fails ask for FREE support.
  • 24/7 Spyware Helpdesk Support included into the package.

  • Download Spyhunter Remediation Tool by Enigma Software

    Download antimalware designed specifically to remove threats like Toolbar888 and matcash.exe (download of fix will start immediately):

    Download AntiMalware to remove Toolbar888

    Features of Spyhunter Remediation Tool

    • Removes all files created by Toolbar888.
    • Removes all registry entries created by Toolbar888.
    • Fixes browser redirection and hijack if needed.
    • "Toolbar Remover" tool will help you get rid of unwanted browser extensions.
    • Removal is guaranteed - if Spyhunter Remediation Tool fails ask for FREE support.
    • 24/7 Helpdesk Support and 5 hours of Remote Support via GoToAssist included into the package.


We noticed that you are on smartphone or tablet now, but you need this solution on your PC. Enter your email below and we’ll automatically send you an email with the downloading link for Toolbar888 Removal Tool, so you can use it when you are back to your PC.

Privacy Policy


Let our support team solve your problem with Toolbar888 and remove Toolbar888 right now!

Submit support ticket below and describe your problem with Toolbar888. Support team will offer you solution in several minutes and give a step-by-step instruction on how to remove Toolbar888. Trouble-free tech support with over 10 years experience removing malware.
Submit support ticket

Software Industry Professionals Member Threat's description and solution are developed by Security Stronghold security team.

Here you can also learn:


How to remove Toolbar888 manually

This problem can be solved manually by deleting all registry keys and files connected with Toolbar888, removing it from startup list and unregistering all corresponding DLLs. Additionally missing DLL's should be restored from distribution in case they are corrupted by Toolbar888.

To get rid of Toolbar888, you should:

1. Kill the following processes and delete the appropriate files:

  • nsprocess.dll
  • csrrs.exe
  • cproc.exe
  • winbjv32.dll
  • oerjyzh.dll
  • fxtavkl.dll
  • anti4[1].exe
  • mljjghg.dll
  • winemx32.dll
  • mstf.bat
  • 13.exe
  • winzzc32.dll
  • winqca32.dll
  • efcdbcc.dll
  • 35[1].exe
  • winbfi32.dll
  • tuvwtrs.dll
  • mst8b.bat
  • winnhz32.dll
  • tuvspmj.dll
  • 888.dll
  • bar888.dll
  • mst14.tmp
  • mst14.bat
  • mst18.tmp
  • mst18.bat
  • mst10.tmp
  • viyjhai.dll
  • win6.tmp.exe
  • 888bar.dll
  • zgame5.exe
  • 1270.exe
  • xyz.txt
  • xyz.exe
  • aaa1.exe
  • matcash.exe

Warning: you should delete only those files which checksums are listed as malicious. There may be valid files with the same names in your system. We recommend you to use WiperSoft Antispyware Malware Remediation Tool for safe problem solution.

**Trial version of Wipersoft provides detection of computer viruses for FREE. To remove malware, you have to purchase the full version of Wipersoft.

2. Delete the following malicious folders:

  • %temp%\nsx4.tmp\
  • %system%\crunner\
  • %commonprogramfiles%\{34306db1-0898-1033-0729-050002}\
  • %commonprogramfiles%\{34306db1-08a2-1033-1203-0503050002}\
  • %commonprogramfiles%\{34306db1-0d53-1033-1203-0503050002}\

3. Delete the following malicious registry entries and\or values:

  • Key: Interface\{95B92D92-8B7D-4A19-A3F1-43113B4DBCAF}\TypeLib
    Value: Version
  • Key: MyToolBar.MyToolBarObj.1
  • Key: MyToolBar.MyToolBarObj.1\CLSID
  • Key: MyToolBar.MyToolBarObj
  • Key: MyToolBar.MyToolBarObj\CLSID
  • Key: MyToolBar.MyToolBarObj\CurVer
  • Key: CLSID\{CBCC61FA-0221-4ccc-B409-CEE865CACA3A}
  • Key: CLSID\{CBCC61FA-0221-4ccc-B409-CEE865CACA3A}\ProgID
  • Key: CLSID\{CBCC61FA-0221-4ccc-B409-CEE865CACA3A}\VersionIndependentProgID
  • Key: CLSID\{CBCC61FA-0221-4ccc-B409-CEE865CACA3A}\InprocServer32
    Value: ThreadingModel
  • Key: TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0
  • Key: TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\FLAGS
  • Key: TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\0\win32
  • Key: TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\HELPDIR
  • Key: Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}
  • Key: Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\TypeLib
    Value: Version
  • Key: Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\ProxyStubClsid32
  • Key: Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\ProxyStubClsid
  • Key: CLSID\{CBCC61FA-0221-4ccc-B409-CEE865CACA3A}\TypeLib
  • Key: CLSID\{D3B3C51E-8D11-4667-85B9-0930F519BED7}\InprocServer32
    Value: ThreadingModel
  • Key: SOFTWARE\Classes\MezziaCodec.Chl\CLSID
  • Key: MezziaCodec.Chl\CLSID
  • Key: CLSID\{C004DEC2-2623-438e-9CA2-C9043AB28508}
  • Key: CLSID\{C004DEC2-2623-438e-9CA2-C9043AB28508}\ProgID
  • Key: CLSID\{C004DEC2-2623-438e-9CA2-C9043AB28508}\VersionIndependentProgID
  • Key: CLSID\{C004DEC2-2623-438e-9CA2-C9043AB28508}\InprocServer32
    Value: ThreadingModel
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\ToolBar888
    Value: DisplayName
  • Key: CLSID\{C004DEC2-2623-438e-9CA2-C9043AB28508}\TypeLib
  • Key: Software\MyToolBar\all\History
  • Key: Software\MyToolBar\all
  • Key: Software\MyToolBar
  • Key: CLSID\{234872CE-5649-4C54-994E-09DB662C1CA9}\InprocServer32
    Value: ThreadingModel
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    \{C004DEC2-2623-438e-9CA2-C9043AB28508}
  • Key: LuckyToolBar.LuckyToolBarObj.1
  • Key: LuckyToolBar.LuckyToolBarObj.1\CLSID
  • Key: LuckyToolBar.LuckyToolBarObj
  • Key: LuckyToolBar.LuckyToolBarObj\CLSID
  • Key: LuckyToolBar.LuckyToolBarObj\CurVer
  • Key: ToolBar.ToolBarObj.1\CLSID
  • Key: ToolBar.ToolBarObj.1
  • Key: ToolBar.ToolBarObj\CLSID
  • Key: ToolBar.ToolBarObj
  • Key: ToolBar.ToolBarObj\CurVer
  • Key: CLSID\{C1B4DEC2-2623-438e-9CA2-C9043AB28508}
  • Key: CLSID\{C1B4DEC2-2623-438e-9CA2-C9043AB28508}\ProgID
  • Key: CLSID\{C1B4DEC2-2623-438e-9CA2-C9043AB28508}\VersionIndependentProgID
  • Key: CLSID\{C1B4DEC2-2623-438e-9CA2-C9043AB28508}\InprocServer32
    Value: ThreadingModel
  • Key: CLSID\{C1B4DEC2-2623-438e-9CA2-C9043AB28508}\TypeLib
  • Key: Software\Classes\CLSID\{14306DB1-0897-1033-1203-0503050002}\Request
  • Key: Software\Classes\CLSID\{14306DB1-0D54-1033-1203-0503050002}\Request
  • Key: Software\Classes\CLSID\{14306DB1-0898-1033-1203-0503050002}\Request
  • Key: Software\Classes\CLSID\{14306DB1-08A3-1033-1203-0503050002}\Request
  • Key: Software\Classes\CLSID\{14306DB1-08A6-1033-1203-0500002}
  • Key: SOFTWARE\Classes\MyToolBar.MyToolBarObj.1
  • Key: SOFTWARE\Classes\MyToolBar.MyToolBarObj.1\CLSID
  • Key: SOFTWARE\Classes\MyToolBar.MyToolBarObj
  • Key: SOFTWARE\Classes\MyToolBar.MyToolBarObj\CLSID
  • Key: SOFTWARE\Classes\MyToolBar.MyToolBarObj\CurVer
  • Key: SOFTWARE\Classes\CLSID\{C004DEC2-2623-438e-9CA2-C9043AB28508}
  • Key: SOFTWARE\Classes\CLSID\{C004DEC2-2623-438e-9CA2-C9043AB28508}\ProgID
  • Key:
    SOFTWARE\Classes\CLSID\{C004DEC2-2623-438e-9CA2-C9043AB28508}\VersionIndependentProgID
  • Key:
    SOFTWARE\Classes\CLSID\{C004DEC2-2623-438e-9CA2-C9043AB28508}\Programmable
  • Key:
    SOFTWARE\Classes\CLSID\{C004DEC2-2623-438e-9CA2-C9043AB28508}\InprocServer32

    Value: ThreadingModel
  • Key: SOFTWARE\Classes\CLSID\{C004DEC2-2623-438e-9CA2-C9043AB28508}\TypeLib
  • Key: SOFTWARE\Classes\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}
  • Key: SOFTWARE\Classes\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0
  • Key:
    SOFTWARE\Classes\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\FLAGS
  • Key: SOFTWARE\Classes\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\0
  • Key:
    SOFTWARE\Classes\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\0\win32
  • Key:
    SOFTWARE\Classes\TypeLib\{569304BA-83ED-4CFF-AC26-BE3E482F7208}\1.0\HELPDIR
  • Key: SOFTWARE\Classes\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}
  • Key:
    SOFTWARE\Classes\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\ProxyStubClsid
  • Key:
    SOFTWARE\Classes\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\ProxyStubClsid32
  • Key:
    SOFTWARE\Classes\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\TypeLib

    Value: Version
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\888Bar
    Value: DisplayName
  • Key: SOFTWARE\Classes\ToolBar.ToolBarObj.1
  • Key: SOFTWARE\Classes\ToolBar.ToolBarObj.1\CLSID
  • Key: SOFTWARE\Classes\ToolBar.ToolBarObj
  • Key: SOFTWARE\Classes\ToolBar.ToolBarObj\CLSID
  • Key: SOFTWARE\Classes\ToolBar.ToolBarObj\CurVer
  • Key: SOFTWARE\Classes\CLSID\{C1B4DEC2-2623-438e-9CA2-C9043AB28508}
  • Key: SOFTWARE\Classes\CLSID\{C1B4DEC2-2623-438e-9CA2-C9043AB28508}\ProgID
  • Key:
    SOFTWARE\Classes\CLSID\{C1B4DEC2-2623-438e-9CA2-C9043AB28508}\VersionIndependentProgID
  • Key:
    SOFTWARE\Classes\CLSID\{C1B4DEC2-2623-438e-9CA2-C9043AB28508}\Programmable
  • Key:
    SOFTWARE\Classes\CLSID\{C1B4DEC2-2623-438e-9CA2-C9043AB28508}\InprocServer32

    Value: ThreadingModel
  • Key: SOFTWARE\Classes\CLSID\{C1B4DEC2-2623-438e-9CA2-C9043AB28508}\TypeLib
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\Bar888
    Value: DisplayName
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\ToolBar888
    Value: UninstallString
  • Key: Software\Microsoft\Internet Explorer\Toolbar
    Value: {C49DD894-C6DE-4910-8C41-BA20F852D8BC}
  • Key: Software\Microsoft\Internet Explorer\URLSearchHooks
    Value: {C49DD894-C6DE-4910-8C41-BA20F852D8BC}
  • Key: Software\Microsoft\Internet Explorer\Toolbar
    Value: {CBCC61FA-0221-4ccc-B409-CEE865CACA3A}
  • Key: Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    \{CBCC61FA-0221-4ccc-B409-CEE865CACA3A}

    Value: _{02EE5B04-F144-47BB-83FB-A60BD91B74A9}
  • Key: Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
    Value: {CBCC61FA-0221-4CCC-B409-CEE865CACA3A}
  • Key: Software\Classes\CLSID\{14306DB1-0897-1033-0729-0529050002}
    Value: Request
  • Key: Software\Microsoft\Windows\CurrentVersion\Run
    Value: csr
  • Key: Software\Microsoft\Windows\CurrentVersion\Run
    Value: cprocsvc
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
    Value: {D3B3C51E-8D11-4667-85B9-0930F519BED7}
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wvusrpo
    Value: Asynchronous
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wvusrpo
    Value: DllName
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wvusrpo
    Value: Impersonate
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wvusrpo
    Value: Logon
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wvusrpo
    Value: Logoff
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mljjghg
    Value: Asynchronous
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mljjghg
    Value: DllName
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mljjghg
    Value: Impersonate
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mljjghg
    Value: Logon
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mljjghg
    Value: Logoff
  • Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winemx32
    Value: Asynchronous
  • Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winemx32
    Value: DllName
  • Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winemx32
    Value: Impersonate
  • Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winemx32
    Value: Startup
  • Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winemx32
    Value: Shutdown
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}
    \iexplore

    Value: Type
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}
    \iexplore

    Value: Count
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CBCC61FA-0221-4CCC-B409-CEE865CACA3A}
    \iexplore

    Value: Time
  • Key: Software\Microsoft\Internet Explorer\Toolbar
    Value: {C004DEC2-2623-438e-9CA2-C9043AB28508}
  • Key: Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
    Value: {C004DEC2-2623-438E-9CA2-C9043AB28508}
  • Key: Software\Classes\CLSID\{14306DB1-0898-1033-0729-0520002}
    Value: Request
  • Key: Software\Classes\CLSID\{14306DB1-0898-1033-0729-0520002}
    Value: Register
  • Key: Software\Classes\CLSID\{14306DB1-0898-1033-0729-0520002}
    Value: Installation
  • Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winbfi32
    Value: Asynchronous
  • Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winbfi32
    Value: DllName
  • Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winbfi32
    Value: Impersonate
  • Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winbfi32
    Value: Startup
  • Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winbfi32
    Value: Shutdown
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
    Value: {234872CE-5649-4C54-994E-09DB662C1CA9}
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvwtrs
    Value: Asynchronous
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvwtrs
    Value: DllName
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvwtrs
    Value: Impersonate
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvwtrs
    Value: Logon
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvwtrs
    Value: Logoff
  • Key: Software\Classes\CLSID\{14306DB1-0898-1033-0729-0520002}
    Value: Request
  • Key: Software\Classes\CLSID\{14306DB1-0898-1033-0729-0520002}
    Value: Installation
  • Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winnhz32
    Value: Asynchronous
  • Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winnhz32
    Value: DllName
  • Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winnhz32
    Value: Impersonate
  • Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winnhz32
    Value: Startup
  • Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winnhz32
    Value: Shutdown
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvspmj
    Value: Asynchronous
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvspmj
    Value: DllName
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvspmj
    Value: Impersonate
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvspmj
    Value: Logon
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvspmj
    Value: Logoff
  • Key: Software\Classes\CLSID\{14306DB1-08A3-1033-0729-0520002}
    Value: Request
  • Key: Software\Classes\CLSID\{14306DB1-08A3-1033-0729-0520002}
    Value: Register
  • Key: Software\Classes\CLSID\{14306DB1-08A3-1033-0729-0520002}
    Value: Installation
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C004DEC2-2623-438E-9CA2-C9043AB28508}
    \iexplore

    Value: Type
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C004DEC2-2623-438E-9CA2-C9043AB28508}
    \iexplore

    Value: Count
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C004DEC2-2623-438E-9CA2-C9043AB28508}
    \iexplore

    Value: Time
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C004DEC2-2623-438E-9CA2-C9043AB28508}
    \iexplore

    Value: Count
  • Key: software\LuckyToolBar\\all\History
    Value: buy a car
  • Key: Software\Classes\CLSID\{14306DB1-0898-1033-0729-0529050002}
    Value: Request
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
    Value: {9B0C7A02-A17A-4C81-BD7D-30A622701C36}
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\opnkhfe
    Value: Asynchronous
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\opnkhfe
    Value: DllName
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\opnkhfe
    Value: Impersonate
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\opnkhfe
    Value: Logon
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\opnkhfe
    Value: Logoff
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1B4DEC2-2623-438E-9CA2-C9043AB28508}
    \iexplore

    Value: Type
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1B4DEC2-2623-438E-9CA2-C9043AB28508}
    \iexplore

    Value: Count
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1B4DEC2-2623-438E-9CA2-C9043AB28508}
    \iexplore

    Value: Time
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1B4DEC2-2623-438E-9CA2-C9043AB28508}
    \iexplore

    Value: Type
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1B4DEC2-2623-438E-9CA2-C9043AB28508}
    \iexplore

    Value: Count
  • Key: Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
    Value: {C1B4DEC2-2623-438E-9CA2-C9043AB28508}
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\Bar888
    Value: UninstallString
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{630B5231-3A4A-73A1-B4B1-0B811CAE84F7}
    \iexplore

    Value: Type
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{630B5231-3A4A-73A1-B4B1-0B811CAE84F7}
    \iexplore

    Value: Count
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{630B5231-3A4A-73A1-B4B1-0B811CAE84F7}
    \iexplore

    Value: Time
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{630B5231-3A4A-73A1-B4B1-0B811CAE84F7}
    \iexplore

    Value: Count
  • Key: Software\Microsoft\Internet Explorer\Toolbar
    Value: {C1B4DEC2-2623-438e-9CA2-C9043AB28508}
  • Key: Software\Classes\CLSID\{14306DB1-0897-1033-0729-0520002}
    Value: Request
  • Key: Software\Classes\CLSID\{14306DB1-0897-1033-0729-0520002}
    Value: Register
  • Key: Software\Classes\CLSID\{14306DB1-0897-1033-0729-0520002}
    Value: Installation
  • Key: Software\Microsoft\Windows\CurrentVersion\Explorer\Run
    Value: {74306DB1-0897-1033-1203-0503050002}
  • Key: Software\Classes\CLSID\{14306DB1-0897-1033-1203-0503050002}
    Value: Request
  • Key: Software\Classes\CLSID\{14306DB1-0897-1033-1203-0503050002}
    Value: Register
  • Key: Software\Classes\CLSID\{14306DB1-0897-1033-1203-0503050002}
    Value: Installation
  • Key: Software\Microsoft\Windows\CurrentVersion\Explorer\Run
    Value: {74306DB1-0D54-1033-1203-0503050002}
  • Key: Software\Classes\CLSID\{14306DB1-0D54-1033-1203-0503050002}
    Value: Request
  • Key: Software\Classes\CLSID\{14306DB1-0D54-1033-1203-0503050002}
    Value: Register
  • Key: Software\Classes\CLSID\{14306DB1-0D54-1033-1203-0503050002}
    Value: Installation
  • Key: System\CurrentControlSet\Services\Client IP-IPX
    Value: Type
  • Key: System\CurrentControlSet\Services\Client IP-IPX
    Value: Start
  • Key: System\CurrentControlSet\Services\Client IP-IPX
    Value: ErrorControl
  • Key: System\CurrentControlSet\Services\Client IP-IPX
    Value: DisplayName
  • Key: System\CurrentControlSet\Services\Client IP-IPX\Security
    Value: Security
  • Key: System\CurrentControlSet\Services\Client IP-IPX
    Value: ObjectName
  • Key: Software\Classes\CLSID\{14306DB1-0898-1033-1203-0503050002}
    Value: Request
  • Key: Software\Classes\CLSID\{14306DB1-0898-1033-1203-0503050002}
    Value: Register
  • Key: Software\Classes\CLSID\{14306DB1-0898-1033-1203-0503050002}
    Value: Installation
  • Key: System\CurrentControlSet\Services\Client IP-IPX
    Value: ImagePath
  • Key: Software\Classes\CLSID\{14306DB1-08A3-1033-1203-0503050002}
    Value: Request
  • Key: Software\Classes\CLSID\{14306DB1-08A3-1033-1203-0503050002}
    Value: Register
  • Key: Software\Classes\CLSID\{14306DB1-08A3-1033-1203-0503050002}
    Value: Installation
  • Key: CLSID\{14306DB1-08A6-1033-1203-0500002}
    Value: Request
  • Key: CLSID\{14306DB1-08A6-1033-1203-0500002}
    Value: Register
  • Key: CLSID\{14306DB1-08A6-1033-1203-0500002}
    Value: Installation
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\888Bar
    Value: UninstallString
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon
    Value: Userinit
    Data: %system%\userinit.exe,wgqcepg.exe
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon
    Value: Shell
    Data: Explorer.exe, %system%\mlkxt.exe

Warning: if value is listed for some registry entries, you should only clear these values and leave keys with such values untouched. We recommend you to use WiperSoft Antispyware Malware Remediation Tool for safe problem solution.


Uninstall Toolbar888 related programs from Control Panel

We recommend you to check list of installed programs and search for Toolbar888 entry or other unknown and suspicious programs. Below are instructions for different version if Windows. In some cases adware programs are protected by malicious service or process and it will not allow you to uninstall it. If Toolbar888 won't uninstall or gives you error message that you do not have sufficient rights to do this perform below instructions in Safe Mode or Safe Mode with Networking or use WiperSoft Antispyware Malware Remediation Tool.


Windows 10

  • Click on the Start menu and choose Settings
  • Then click on System and choose Apps & Features in the left column
  • Find Toolbar888 under in the list and click Uninstall button near it.
  • Confirm by clicking Uninstall button in opened window if necessary.

Windows 8/8.1

  • Right click on the bottom left corner of the screen (while on your desktop)
  • In the menu choose Control Panel
  • Click Uninstall a program under Programs and Features.
  • Locate programs that can be connected with Toolbar888 or other related suspicious program.
  • Click Uninstall button.
  • Wait until uninstall process is complete.

Windows 7/Vista

  • Click Start and choose Control Panel.
  • Choose Programs and Features and Uninstall a program.
  • In the list of installed programs find entries related to Toolbar888
  • Click Uninstall button.

Windows XP

  • Click Start
  • In the menu choose Control Panel
  • Choose Add / Remove Programs.
  • Find Toolbar888 related entries.
  • Click Remove button.

Remove Toolbar888 related extensions from your browsers

Toolbar888 in some cases can be accompanied with browsers extension. We recommend you to use free option Toolbar Remover under Tools in Spyhunter Remediation Tool to remove unwanted browser extensions related to Toolbar888. We recommend you to perform scan your PC with Removal Tool or Spyhunter Remediation Tool. To remove extenions from your browsers manually do the following:

Internet Explorer

  • While in Internet Explorer click cogwheel icon in the top right corner
  • In the menu choose the Manage Add-ons
  • Select Toolbar and Extension tab.
  • Choose add-on possibly related to Toolbar888 or other related adware BHO.
  • Click Disable button.

Warning: This option will only disable unwanted plugin. For effective Toolbar888 removal use WiperSoft Antispyware Malware Remediation Tool.

Google Chrome

  • Start Google Chrome.
  • In the address bar type chrome://extensions/
  • In the list of add-ons find related to Toolbar888 and click recycle bin icon.
  • Confirm Toolbar888 removal.

Mozilla Firefox

  • Open Firefox
  • In the address bar type about:addons
  • Click Extensions tab.
  • In the list of extension locate ones related to Toolbar888.
  • Click Remove button near it.

Reset browsers search and homepage settings

Toolbar888 can affect your browsers which results in browser redirection or search hijack. We recommend you to use free option Reset Browsers under Tools in Spyhunter Remediation Tool to reset all the browsers at once. Mention that you need to remove all files and kill all processes belonging to Toolbar888 before doing this. To reset your browsers manually and restore your homepage perform the following steps:

Internet Explorer

  • If you use Windows XP, click Start, and then click Run. Type the following in the Open box without quotes, and press Enter: "inetcpl.cpl"
  • If you use Windows 7 or Windows Vista, click Start. Type the following in the Search box without quotes, and press Enter: "inetcpl.cpl"
  • Click the Advanced tab
  • In Reset Internet Explorer settings, click Reset. Click Reset in opened window again.
  • Select Delete personal settings checkbox to remove browsing history, search providers, homepage
  • After Internet Explorer finishes resetting, click Close in the Reset Internet Explorer Settings dialog box

Warning: In case this option will not work use free option Reset Browsers under Tools in Spyhunter Remediation Tool.

Google Chrome

  • Go to the installation folder of Google Chrome: C:\Users\"your username"\AppData\Local\Google\Chrome\Application\User Data.
  • In the User Data folder, look for a file named as Default and rename it to DefaultBackup.
  • Launch Google Chrome and a new clean Default file will be created.

Warning: This option might not work if in Google Chrome you use online synchronization between PCs. In this case use free option Reset Browsers under Tools in Spyhunter Remediation Tool.

Mozilla Firefox

  • Open Firefox

  • Go to Help > Troubleshooting Information in menu.
  • Click the Reset Firefox button.
  • After Firefox is done, it will show a window and create folder on the desktop. Click Finish.

Warning: This option will also clean all your account passwords for all websites. If you don't want it use free option Reset Browsers under Tools in Spyhunter Remediation Tool.


Here are the descriptions of problems connected with Toolbar888 and matcash.exe we received earlier:

Problem Summary: error loading winnhz32.rom ; the specified module could be found & error loading c:\users\conns\AppData\Temp\efCrQjGY.dll the specified module could not be found

I have two error that are showing up whenever I start or restart my laptop. those two errors are:
error loading winnhz32.rom
the specified module could be found
&
error loading c:\users\conns\AppData\Temp\efCrQjGY.dll
the specified module could not be found

I tried to restore my computer in the past good settings but no solution. please if you know how to solve that problem, help me solve it.
sincerely Simon

Problem was successfully solved. Ticket was closed.

Problem Summary: trojaner ??

every time when i start up my computer he sows me that an file dont be found it called (winqca32.rom). My intenet its very slow now , but i dont know why !! csn you help me ?

Problem was successfully solved. Ticket was closed.

Problem Summary: winqca32.rom error

every time i start or re-start my computer i get a winqca32.rom error im not sure what it is and i have did virus scans, and registry scans and spyware scans and i can not get it to go away....please help

Problem was successfully solved. Ticket was closed.

Home | Partners | Shop | Support | Terms of use | Contact Us | Privacy Policy | Sitemap

Copyright © 2021 Security Stronghold. All Rights Reserved. All content on this website is protected and belongs to Security Stronghold LLC.