IncrediMail_MediaBar_2 Toolbar

IncrediMail_MediaBar_2 Toolbar

Known Toolbar

by Client Connect LTD

What is IncrediMail_MediaBar_2 Toolbar?

IncrediMail_MediaBar_2 Toolbar is software application developed by Client Connect LTD. It is most commonly found on computers running Windows Vista with nearly 50.00% of installations running this operating system.

IncrediMail_MediaBar_2 Toolbar is most popular in the United States with 71.43% of installations residing in this country.

IncrediMail_MediaBar_2 Toolbar adds 2 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times. When using a computer that is connected to the internet, IncrediMail_MediaBar_2 Toolbar is known to create 1 firewall exception to allow inbound and outbound connectivity.

About IncrediMail_MediaBar_2 Toolbar?

The IncrediMail MediaBar, powered by the Trovi platform, is a browser toolbar designed to customize the web browser's home page, search provider, and new tab pages by setting them to trovi.com or a partner website. This toolbar includes the following features: - Modification of the default home page and new tabs, as well as protection of search settings through the installation of Search Protect software - Change of the default search engine in the Internet Browser, including the browser's built-in search box - Permission for cookies to be installed in the browser - Granting Trovi access to information contained on the user's social network account - Addition of alternative error page functionality, such as "Page Not Found" Please note that any changes made by the IncrediMail MediaBar toolbar can be customized by the user to suit their preferences.

Multiple virus scanners have detected malware in IncrediMail_MediaBar_2 Toolbar.

uninstall.exe (MD5: b728fa6a309e5d18141947b95b730e95) has been flagged by 2 scanners:
Scanner Software Result
Panda Antivirus PUP/Conduit.A
VIPRE Antivirus Conduit (fs)
tbIncr.dll (MD5: 895c4812245e244b2f81c71bad0c4e55) has been flagged by 19 scanners:
Scanner Software Result
Bkav FE HW32.Stranfom
ESET-NOD32 a variant of Win32/Toolbar.Conduit.B
Panda Antivirus Adware/Conduit
VIPRE Antivirus Conduit (fs)
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/Win32.Agent.azm
AVware Conduit (fs)
Baidu-International Adware.Win32.Conduit.M
Cyren W32/Conduit.TTAU-0102
F-Prot W32/Conduit.A
G Data Win32.Application.Conduit.F
K7 AntiVirus Trojan ( 004b219d1 )
K7GW Trojan ( 004b219d1 )
Kaspersky not-a-virus:WebToolbar.Win32.Agent.azm
Dr.Web Adware.Conduit.299
Fortinet FortiGate Riskware/Toolbar_Conduit
Comodo Security Application.Win32.Conduit.~A
Malwarebytes PUP.Optional.Conduit
TrendMicro-HouseCall TROJ_GEN.F47V1113
IKARUS anti.virus PUA.ClientConnect
tbInc2.dll (MD5: 975993043e355206a1fba5a702044f0c) has been flagged by 10 scanners:
Scanner Software Result
Comodo Security Application.Win32.Conduit.~A
ESET-NOD32 a variant of Win32/Toolbar.Conduit.B
Malwarebytes PUP.Optional.Conduit
Panda Antivirus Adware/Conduit
TrendMicro-HouseCall TROJ_GEN.F47V1113
VIPRE Antivirus Conduit (fs)
Bkav FE W32.HfsAdware.C534
Dr.Web Adware.Conduit.300
G Data Win32.Adware.Conduit.B
IKARUS anti.virus PUA.ClientConnect
prxtbIncr.dll (MD5: d0133250565180c9dc8ee0aecccbfd53) has been flagged by 19 scanners:
Scanner Software Result
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/Win32.Agent.azm
AVware Conduit (fs)
Baidu-International Adware.Win32.Conduit.M
Cyren W32/Conduit.TTAU-0102
ESET-NOD32 Win32/Toolbar.Conduit.N potentially unwanted
F-Prot W32/Conduit.A
G Data Win32.Application.Conduit.F
K7 AntiVirus Trojan ( 004b219d1 )
K7GW Trojan ( 004b219d1 )
Kaspersky not-a-virus:WebToolbar.Win32.Agent.azm
Panda Antivirus PUP/Conduit.A
VIPRE Antivirus Conduit (fs)
Bkav FE W32.HfsAdware.C534
Dr.Web Adware.Conduit.299
Fortinet FortiGate Riskware/Toolbar_Conduit
Comodo Security Application.Win32.Conduit.~A
Malwarebytes PUP.Optional.Conduit
TrendMicro-HouseCall TROJ_GEN.F47V1113
IKARUS anti.virus PUA.ClientConnect
prxtbInc2.dll (MD5: 5b13aa512d57acf528700f1083fc3e4d) has been flagged by 6 scanners:
Scanner Software Result
Bkav FE HW32.Laneul.oicu
Dr.Web Adware.Conduit.16
TrendMicro-HouseCall TROJ_GEN.F47V0926
VIPRE Antivirus Conduit (fs)
ESET-NOD32 a variant of Win32/Toolbar.Conduit.P
Panda Antivirus PUP/Conduit.A

Software Behaviors

Services:
  • UNWISE.EXE runs as a service named 'Browser System Enahncer' (671c50b0).
Firewall:
  • UNWISE.EXE is added as a firewall exception for 'C:\Program Files1\Yahoo!\MESSEN~1\UNWISE.EXE'.
Scheduled tasks:
  • UNWISE.EXE is scheduled as a task with the class '{F71A9918-1861-4EFE-AE94-530BDDE46DD4}' (runs on registration).
  • IncrediMail_MediaBar_2ToolbarHelper.exe is scheduled as a task with the class '{B8E8E278-F25D-478A-BAB2-24A5EDB01F6C}' (runs on registration).

Software Details

URL:
https://incredimailmediabar2.ourtoolbar.com
Support:
https://incredimailmediabar2.ourtoolbar.com/help
Installation path:
C:\Program Files\IncrediMail_MediaBar_2
Uninstaller:
C:\Program Files2\INCRED~2\UNWISE.EXE /U C:\Program Files2\INCRED~2\INSTALL.LOG
Size:
0.00 B
Language:
English

IncrediMail_MediaBar_2 Toolbar Executable Details

Name:
IncrediMail_MediaBar_2 Toolbar
Path:
C:\Program Files\IncrediMail_MediaBar_2\IncrediMail_MediaBar_2ToolbarHelper.exe
MD5:
a320df2b47cfcaf98d06eb59cd72084c
SHA-1:
SHA-256:
Files installed by IncrediMail_MediaBar_2 Toolbar
File Type Filename MD5
DLL
e055e5e9888a21a1f8e40c7235ce6fbe
DLL
65394bd2969dd5002fef2eaa6096fd99
DLL
b69c4f58f49e614f75758d22e4ebc6bf
DLL
bb9a3d5b48a59dfea97b22a4db5ecb4b
EXE
a320df2b47cfcaf98d06eb59cd72084c
DLL
8e75f45d45bf0f694831e16069d922a2
DLL
tbInc0.dll
Malware
1a8438854dd15e4389f5bdef502c369d
DLL
3f2f3a8e549c3df03c160433215d5768
DLL
70d21b81ea8d1811ed3509e6d859eb5f
DLL
72287069d443718b08590770ee23d76a