Roxaq Apps is a Potentially Unwanted Application (PUA) that acts as a dropper for the Legion Loader malware. This malicious program infiltrates systems through deceptive means, such as rogue webpages and bundled software installations. Once inside a system, Roxaq Apps installs additional malware, leading to severe security threats, including ransomware, trojans, cryptocurrency miners, and spyware.
During our investigation, we discovered that Roxaq Apps was installed along with a fake “Save to Google Drive”browser extension, which functioned as spyware, collecting browsing data, extracting email contents, and turning browsers into HTTP proxies for malicious activities.
How Roxaq Apps Infects Your System
Like many potentially unwanted programs, Roxaq Apps is spread using deceptive tactics, including:
- Bundled software installers – The application gets installed alongside other free software.
- Deceptive pop-up ads – Clicking on misleading ads on rogue websites can trigger an installation.
- Fake browser extensions – Roxaq Apps was distributed with a fraudulent “Save to Google Drive” extension, which altered browser settings and gathered user data.
Once installed, Roxaq Apps starts its malicious activities in the background, dropping Legion Loader and other malware into the infected system.
Threat Summary Table
Threat Name | Roxaq Apps |
---|---|
Threat Type | PUP (Potentially Unwanted Program), PUA (Potentially Unwanted Application), Dropper |
Payload | Legion Loader |
Encrypted File Extension | N/A (Not a ransomware) |
Ransom Note File Name | N/A (Not a ransomware) |
Detection Names | N/A (VirusTotal) |
Symptoms | Unexpected program installations, intrusive ads, rogue redirects, slow browsing speed |
Distribution Methods | Bundled software installers, deceptive pop-up ads, fake browser extensions |
Related Domains | feedshareeasyfile[.]com |
Damage | System infections, monetary loss, privacy issues, slow performance |
Danger Level | High |

Remove Roxaq Apps
With SpyHunter
Why Roxaq Apps is Dangerous
Acts as a Dropper for Legion Loader
Roxaq Apps’ primary function is to install Legion Loader, a sophisticated malware capable of deploying multiple threats, including:
- Information-stealing trojans – These steal passwords, financial data, and sensitive information.
- Ransomware – Encrypts user files and demands a ransom for decryption.
- Cryptocurrency miners – Uses system resources to mine cryptocurrency, slowing down performance.
- Malicious browser extensions – Turns browsers into proxy networks for cybercriminals.
Steals Personal Data
Roxaq Apps installs browser extensions that can:
- Monitor browsing activity and extract personal information.
- Read and alter clipboard content, which can capture sensitive data.
- Display intrusive pop-up ads that may lead to further infections.
Slows Down Your System
Since Roxaq Apps facilitates the installation of multiple types of malware, affected systems often experience:
- Lagging and freezing due to high resource consumption.
- Unwanted browser redirects leading to malicious or phishing websites.
- Increased internet usage as data is transmitted to remote servers.
How to Remove Potentially Unwanted Programs (PUPs) – Full Guide
Potentially Unwanted Programs (PUPs) are intrusive applications that often install without clear user consent, usually bundled with free software. These programs can cause browser hijacking, unwanted ads, slow performance, and security risks. Follow the instructions below to remove PUPs from your Windows or Mac system, as well as from popular browsers.

Remove Roxaq Apps
With SpyHunter
Manual PUP Removal Guide (Windows & Mac)
Step 1: Uninstall Suspicious Programs
For Windows Users
- Open Control Panel:
- Press Win + R, type
appwiz.cpl
, and hit Enter.
- Press Win + R, type
- Find and Remove Suspicious Applications:
- Look for unfamiliar or suspicious applications.
- Right-click the unwanted program and select Uninstall.
- Follow the On-Screen Prompts:
- If a dialog box appears asking for confirmation, click Yes.
For Mac Users
- Open Finder → Click Applications.
- Locate Unwanted Apps:
- Look for recently installed suspicious programs.
- Move to Trash:
- Drag the program to Trash or right-click and select Move to Trash.
- Empty the Trash:
- Right-click the Trash icon and select Empty Trash.
Step 2: Remove PUP-Related Browser Extensions
PUPs often install malicious browser extensions that cause unwanted redirects and intrusive ads.
Google Chrome
- Open Chrome → Click on the three-dot menu (top-right).
- Navigate to Extensions:
- Click More Tools → Extensions.
- Remove Suspicious Extensions:
- Locate unknown extensions and click Remove.
Mozilla Firefox
- Open Firefox → Click on the menu button (≡) → Select Add-ons and themes.
- Go to the Extensions tab.
- Find and Remove suspicious extensions.
Microsoft Edge
- Open Edge → Click on the three-dot menu.
- Select Extensions → Click Manage Extensions.
- Locate and Remove unwanted extensions.
Safari (Mac)
- Open Safari → Click Safari in the menu bar → Select Preferences.
- Navigate to the Extensions tab.
- Find and Uninstall unknown extensions.
Step 3: Reset Browser Settings (Optional)
If the PUP modified browser settings, reset them.
Google Chrome
- Open Chrome → Click three-dot menu → Settings.
- Scroll down and click Reset settings → Restore settings to their original defaults.
- Confirm by clicking Reset settings.
Mozilla Firefox
- Open Firefox → Click Menu → Help → More Troubleshooting Information.
- Click Refresh Firefox → Confirm.
Microsoft Edge
- Open Edge → Go to Settings → Click Reset settings.
- Choose Restore settings to their default values → Confirm.
Safari (Mac)
- Open Safari → Click Safari in the menu bar → Clear History.
- Select All History → Click Clear History.
Step 4: Check for Remaining PUP Files
Windows
- Press Win + R, type
%temp%
, and hit Enter. - Delete all files in the Temp folder.
- Repeat the process with
%appdata%
,%localappdata%
, andC:\ProgramData
.
Mac
- Open Finder → Click Go → Go to Folder.
- Enter:javascriptCopyEdit
~/Library/Application Support/
- Locate and delete suspicious folders.
Automatic PUP Removal Using SpyHunter

Remove Roxaq Apps
With SpyHunter
For a faster and more secure method, use SpyHunter, a trusted anti-malware tool. Follow these steps to remove PUPs automatically.
Step 1: Download and Install SpyHunter
- Go to the official SpyHunter download page:
- Click the Download button and follow the on-screen installation steps.
Step 2: Perform a Full System Scan
- Open SpyHunter after installation.
- Click Start Scan Now to begin scanning your system.
- Wait for the scan to complete and review the detected threats.
Step 3: Remove Detected PUPs
- Click Fix Threats to remove all detected PUPs.
- Restart your computer to complete the process.
For detailed SpyHunter download and installation instructions, refer to: SpyHunter Installation Guide
Final Recommendations
- Avoid Free Software Bundles: Always opt-out of unwanted applications when installing free software.
- Use a Reputable Anti-Malware Tool: SpyHunter helps prevent and remove PUP infections.
- Stay Vigilant: Regularly check installed programs and browser extensions.
By following this guide, you can effectively remove and prevent Potentially Unwanted Programs (PUPs) from infecting your device. If you need a quick solution, download and use SpyHunter for automated removal.
Download SpyHunter for PUP Removal: SpyHunter Official Download
Final Thoughts
Roxaq Apps is a highly dangerous Potentially Unwanted Application (PUA) that serves as a dropper for Legion Loader malware. Once installed, it can lead to multiple system infections, privacy violations, financial loss, and performance degradation.
To safeguard your device, follow the detailed removal steps provided and adopt best practices to prevent future infections. If you are still having trouble, consider contacting remote technical support.

Remove Roxaq Apps
With SpyHunter