IncrediMail_MediaBar_2 Toolbar

IncrediMail_MediaBar_2 Toolbar

Known Toolbar

by Client Connect LTD

What is IncrediMail_MediaBar_2 Toolbar?

IncrediMail_MediaBar_2 Toolbar is software application developed by Client Connect LTD. It is most commonly found on computers running Windows Vista with nearly 50.00% of installations running this operating system.

IncrediMail_MediaBar_2 Toolbar is most popular in the United States with 71.43% of installations residing in this country.

IncrediMail_MediaBar_2 Toolbar adds 2 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times. When using a computer that is connected to the internet, IncrediMail_MediaBar_2 Toolbar is known to create 1 firewall exception to allow inbound and outbound connectivity.

About IncrediMail_MediaBar_2 Toolbar?

The IncrediMail MediaBar, powered by the Trovi platform, is a browser toolbar designed to customize the web browser's home page, search provider, and new tab pages by setting them to trovi.com or a partner website. This toolbar includes the following features: - Modification of the default home page and new tabs, as well as protection of search settings through the installation of Search Protect software - Change of the default search engine in the Internet Browser, including the browser's built-in search box - Permission for cookies to be installed in the browser - Granting Trovi access to information contained on the user's social network account - Addition of alternative error page functionality, such as "Page Not Found" Please note that any changes made by the IncrediMail MediaBar toolbar can be customized by the user to suit their preferences.

Multiple virus scanners have detected malware in IncrediMail_MediaBar_2 Toolbar.

uninstall.exe (MD5: b728fa6a309e5d18141947b95b730e95) has been flagged by 2 scanners:
Scanner Software Result
Panda Antivirus PUP/Conduit.A
VIPRE Antivirus Conduit (fs)
tbIncr.dll (MD5: 895c4812245e244b2f81c71bad0c4e55) has been flagged by 19 scanners:
Scanner Software Result
Bkav FE HW32.Stranfom
ESET-NOD32 a variant of Win32/Toolbar.Conduit.B
Panda Antivirus Adware/Conduit
VIPRE Antivirus Conduit (fs)
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/Win32.Agent.azm
AVware Conduit (fs)
Baidu-International Adware.Win32.Conduit.M
Cyren W32/Conduit.TTAU-0102
F-Prot W32/Conduit.A
G Data Win32.Application.Conduit.F
K7 AntiVirus Trojan ( 004b219d1 )
K7GW Trojan ( 004b219d1 )
Kaspersky not-a-virus:WebToolbar.Win32.Agent.azm
Dr.Web Adware.Conduit.299
Fortinet FortiGate Riskware/Toolbar_Conduit
Comodo Security Application.Win32.Conduit.~A
Malwarebytes PUP.Optional.Conduit
TrendMicro-HouseCall TROJ_GEN.F47V1113
IKARUS anti.virus PUA.ClientConnect
tbInc2.dll (MD5: 975993043e355206a1fba5a702044f0c) has been flagged by 10 scanners:
Scanner Software Result
Comodo Security Application.Win32.Conduit.~A
ESET-NOD32 a variant of Win32/Toolbar.Conduit.B
Malwarebytes PUP.Optional.Conduit
Panda Antivirus Adware/Conduit
TrendMicro-HouseCall TROJ_GEN.F47V1113
VIPRE Antivirus Conduit (fs)
Bkav FE W32.HfsAdware.C534
Dr.Web Adware.Conduit.300
G Data Win32.Adware.Conduit.B
IKARUS anti.virus PUA.ClientConnect
prxtbIncr.dll (MD5: d0133250565180c9dc8ee0aecccbfd53) has been flagged by 19 scanners:
Scanner Software Result
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/Win32.Agent.azm
AVware Conduit (fs)
Baidu-International Adware.Win32.Conduit.M
Cyren W32/Conduit.TTAU-0102
ESET-NOD32 Win32/Toolbar.Conduit.N potentially unwanted
F-Prot W32/Conduit.A
G Data Win32.Application.Conduit.F
K7 AntiVirus Trojan ( 004b219d1 )
K7GW Trojan ( 004b219d1 )
Kaspersky not-a-virus:WebToolbar.Win32.Agent.azm
Panda Antivirus PUP/Conduit.A
VIPRE Antivirus Conduit (fs)
Bkav FE W32.HfsAdware.C534
Dr.Web Adware.Conduit.299
Fortinet FortiGate Riskware/Toolbar_Conduit
Comodo Security Application.Win32.Conduit.~A
Malwarebytes PUP.Optional.Conduit
TrendMicro-HouseCall TROJ_GEN.F47V1113
IKARUS anti.virus PUA.ClientConnect
prxtbInc2.dll (MD5: 5b13aa512d57acf528700f1083fc3e4d) has been flagged by 6 scanners:
Scanner Software Result
Bkav FE HW32.Laneul.oicu
Dr.Web Adware.Conduit.16
TrendMicro-HouseCall TROJ_GEN.F47V0926
VIPRE Antivirus Conduit (fs)
ESET-NOD32 a variant of Win32/Toolbar.Conduit.P
Panda Antivirus PUP/Conduit.A

Software Behaviors

Services:
  • UNWISE.EXE runs as a service named 'Browser System Enahncer' (671c50b0).
Firewall:
  • UNWISE.EXE is added as a firewall exception for 'C:\Program Files1\Yahoo!\MESSEN~1\UNWISE.EXE'.
Scheduled tasks:
  • UNWISE.EXE is scheduled as a task with the class '{F71A9918-1861-4EFE-AE94-530BDDE46DD4}' (runs on registration).
  • IncrediMail_MediaBar_2ToolbarHelper.exe is scheduled as a task with the class '{B8E8E278-F25D-478A-BAB2-24A5EDB01F6C}' (runs on registration).

Software Details

URL:
https://incredimailmediabar2.ourtoolbar.com
Support:
https://incredimailmediabar2.ourtoolbar.com/help
Installation path:
C:\Program Files\IncrediMail_MediaBar_2
Uninstaller:
C:\Program Files2\INCRED~2\UNWISE.EXE /U C:\Program Files2\INCRED~2\INSTALL.LOG
Size:
0.00 B
Language:
English

IncrediMail_MediaBar_2 Toolbar Executable Details

Name:
IncrediMail_MediaBar_2 Toolbar
Path:
C:\Program Files\IncrediMail_MediaBar_2\IncrediMail_MediaBar_2ToolbarHelper.exe
MD5:
a320df2b47cfcaf98d06eb59cd72084c
SHA-1:
SHA-256:
Files installed by IncrediMail_MediaBar_2 Toolbar
File Type Filename MD5
EXE
0dca1fefae4bc710fb21190f90066d22
DLL
553bd5fffdf21022dfed7337ff003f24
DLL
265d65a0757d53542ddc02aadb02dcdc
EXE
6b860015eb3278fad09f659ee27f57ef
DLL
697ba60622e6ca0f46737ac582fed619
DLL
a827f80c188192d748f02f81e9e050cb
DLL
9cd3d1529b1e69c7a9a73fe3791f781a
DLL
ee2af5b8bf7a25137c383318bf4c6a09
DLL
2d7c558150dbf10cd7169716333f8775