PHPNukeDU Toolbar

PHPNukeDU Toolbar

Known Toolbar

by Conduit Ltd.

What is PHPNukeDU Toolbar?

PHPNukeDU Toolbar is software application developed by Conduit Ltd.. It is most commonly found on computers running Windows 7 with nearly 57.50% of installations running this operating system. PHPNukeDU Toolbar's installer is typically 12.00 MB in size and installs around 22 files. The most common release is 6.1.0.7 with 32.50% of all installations currently using this version.

PHPNukeDU Toolbar is most popular in Netherlands with 44.44% of installations residing in this country.

PHPNukeDU Toolbar adds 3 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times. When using a computer that is connected to the internet, PHPNukeDU Toolbar is known to create 2 firewall exceptions to allow inbound and outbound connectivity.

About PHPNukeDU Toolbar?

PHPNukeDU Toolbar is a web browser plugin developed by Conduit for use with Internet Explorer, Chrome, and Firefox. This plugin is designed to gather information about a user's web browsing habits and transmit this data to Conduit for targeted advertising purposes. Additionally, the toolbar has the capability to modify the user's home page and search provider upon installation, with this feature being enabled by default but optional for the user. Along with a search box, the toolbar also offers various social features for user engagement. In the event that the home page and search settings are altered by PHPNukeDU Toolbar, users will need to manually restore these settings if they choose to uninstall the toolbar. As stated in the License Agreement, "The Application may also collect and store information about your web browsing locally on your device. This locally saved information may interact with the Application and send us information about your web browsing so we can suggest services or provide you ads that may be more relevant to you. Only generalized inferences are passed from the Application to our servers."

Multiple virus scanners have detected malware in PHPNukeDU Toolbar.

uninstall.exe (MD5: b728fa6a309e5d18141947b95b730e95) has been flagged by 2 scanners:
Scanner Software Result
Panda Antivirus PUP/Conduit.A
VIPRE Antivirus Conduit (fs)
tbPHPN.dll (MD5: 895c4812245e244b2f81c71bad0c4e55) has been flagged by 13 scanners:
Scanner Software Result
Bkav FE HW32.Stranfom
ESET-NOD32 a variant of Win32/Toolbar.Conduit.B
Panda Antivirus Adware/Conduit
VIPRE Antivirus Conduit (fs)
AVware Conduit (fs)
Baidu-International Adware.Win32.Conduit.Y
Dr.Web Adware.Conduit.299
Fortinet FortiGate Riskware/Toolbar_Conduit
G Data Win32.Application.Conduit.F
Comodo Security Application.Win32.Conduit.~A
Malwarebytes PUP.Optional.Conduit
TrendMicro-HouseCall TROJ_GEN.F47V1113
IKARUS anti.virus PUA.ClientConnect
tbPHP2.dll (MD5: 1a8438854dd15e4389f5bdef502c369d) has been flagged by 13 scanners:
Scanner Software Result
AVware Conduit (fs)
Baidu-International Adware.Win32.Conduit.Y
Bkav FE W32.HfsAdware.C534
Dr.Web Adware.Conduit.299
ESET-NOD32 a variant of Win32/Toolbar.Conduit.B potentially unwanted
Panda Antivirus PUP/Conduit.A
VIPRE Antivirus Conduit (fs)
Fortinet FortiGate Riskware/Toolbar_Conduit
G Data Win32.Application.Conduit.F
Comodo Security Application.Win32.Conduit.~A
Malwarebytes PUP.Optional.Conduit
TrendMicro-HouseCall TROJ_GEN.F47V1113
IKARUS anti.virus PUA.ClientConnect
prxtbPHP2.dll (MD5: 9117027aea464e41c60b87b9826e8447) has been flagged by 12 scanners:
Scanner Software Result
AVware Conduit (fs)
Baidu-International PUA.Win32.Conduit.BX
ESET-NOD32 a variant of Win32/Toolbar.Conduit.X
G Data Win32.Application.Conduit.F
Panda Antivirus PUP/Conduit.A
VIPRE Antivirus Conduit (fs)
Comodo Security Application.Win32.Conduit.~A
Malwarebytes PUP.Optional.Conduit
TrendMicro-HouseCall TROJ_GEN.F47V1113
Bkav FE W32.HfsAdware.C534
Dr.Web Adware.Conduit.300
IKARUS anti.virus PUA.ClientConnect
prxtbPHP0.dll (MD5: c89d9c80fd468c6b51c4aadcc8463c2d) has been flagged by 13 scanners:
Scanner Software Result
AVware Conduit (fs)
Baidu-International PUA.Win32.Conduit.BX
ESET-NOD32 Win32/Toolbar.Conduit.X
Fortinet FortiGate Riskware/Toolbar_Conduit
G Data Win32.Application.Conduit.F
Panda Antivirus PUP/Conduit.A
VIPRE Antivirus Conduit (fs)
Comodo Security Application.Win32.Conduit.~A
Malwarebytes PUP.Optional.Conduit
TrendMicro-HouseCall TROJ_GEN.F47V1113
Bkav FE W32.HfsAdware.C534
Dr.Web Adware.Conduit.300
IKARUS anti.virus PUA.ClientConnect

Software Behaviors

Services:
  • UNWISE.EXE runs as a service named 'Browser System Enahncer' (671c50b0).
Firewall:
  • UNWISE.EXE is added as a firewall exception for 'C:\Program Files1\Yahoo!\MESSEN~1\UNWISE.EXE'.
  • PHPNukeDUToolbarHelper.exe is added as a firewall exception for 'C:\Program Files\eTvOnline.ro\eTvOnline.roToolbarHelper.exe'.
Scheduled tasks:
  • uninstall.exe is scheduled as a task with the class '{42CD7A24-AF4B-44A0-A119-1C6F9B6E2A90}' (runs on registration).
  • UNWISE.EXE is scheduled as a task with the class '{F71A9918-1861-4EFE-AE94-530BDDE46DD4}' (runs on registration).
  • PHPNukeDUToolbarHelper.exe is scheduled as a task with the class '{B8E8E278-F25D-478A-BAB2-24A5EDB01F6C}' (runs on registration).

Software Details

URL:
https://phpnukedu.ourtoolbar.com
Support:
https://phpnukedu.ourtoolbar.com/help
Installation path:
C:\Program Files\phpnukedu
Uninstaller:
C:\Program Files\PHPNukeDU\uninstall.exe
Size:
12.00 MB
Language:
English

PHPNukeDU Toolbar Executable Details

Primary executable:
tbPHPN.dll
Name:
PHPNukeDU Toolbar
Path:
C:\Program Files\phpnukedu\tbPHPN.dll
MD5:
895c4812245e244b2f81c71bad0c4e55
SHA-1:
–
SHA-256:
–
Files installed by PHPNukeDU Toolbar
File Type Filename MD5
EXE
b728fa6a309e5d18141947b95b730e95
EXE
973567b98cdfc147df4e60471d9df072
EXE
ccc71ae981da397f7eb35f235672240c
DLL
3b12bd8c009b7715e6409261f5d650ef
EXE
75d5c0dca0257a70b72f2a9d127d4c56
DLL
0ee6ef49f86c92063c0f9f1b99193e1a
DLL
tbPHPN.dll
Malware
895c4812245e244b2f81c71bad0c4e55
DLL
tbPHP2.dll
Malware
1a8438854dd15e4389f5bdef502c369d
DLL
b92293778555ce3dabe7f0a7e98b34c0
DLL
9117027aea464e41c60b87b9826e8447