shARES Toolbar

shARES Toolbar

Known Toolbar

by Conduit Ltd.

What is shARES Toolbar?

shARES Toolbar is software application developed by Conduit Ltd.. It is most commonly found on computers running Windows 7 with nearly 73.79% of installations running this operating system. shARES Toolbar's installer is typically 10.00 MB in size and installs around 19 files. The most common release is 6.2.2.4 with 23.30% of all installations currently using this version.

shARES Toolbar is most popular in the United States with 28.83% of installations residing in this country.

shARES Toolbar adds 3 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times. When using a computer that is connected to the internet, shARES Toolbar is known to create 2 firewall exceptions to allow inbound and outbound connectivity.

About shARES Toolbar?

This toolbar is commonly included as an optional component during the installation of the free shARES software. Developed by Conduit, it functions as a Community Toolbar accessible on Internet Explorer, Chrome, and Firefox web browsers. The toolbar gathers and retains data related to web browsing activities, which is then transmitted to OurToolbar for the purpose of recommending services or delivering advertisements through the toolbar. Additionally, it may endeavor to modify the browser's home page and search provider settings upon installation, with this action typically being preselected (though optional) and also furnishes a search box and a range of other standard features within the toolbar. Furthermore, it has the capability to automatically download and install updates without user notification. This toolbar is classified as a pay-per-install (PPI) toolbar, wherein the publisher receives payment from Conduit based on the number of installations and the duration for which the toolbar remains installed in the user's web browser. Its inclusion often occurs as part of the installation process for the free shARES program, and its removal may be required even if shARES is uninstalled from the user's PC. If the toolbar has modified the home page and search settings, users will need to manually revert them to their original state.

Multiple virus scanners have detected malware in shARES Toolbar.

uninstall.exe (MD5: b728fa6a309e5d18141947b95b730e95) has been flagged by 2 scanners:
Scanner Software Result
Panda Antivirus PUP/Conduit.A
VIPRE Antivirus Conduit (fs)
tbshAR.dll (MD5: d9a0ce26ada5bd15b1b03a752ddf14a6) has been flagged by 10 scanners:
Scanner Software Result
AVware Conduit (fs)
ESET-NOD32 a variant of Win32/Toolbar.Conduit.B
Panda Antivirus PUP/Conduit.A
VIPRE Antivirus Conduit (fs)
Baidu-International Adware.Win32.Conduit.Y
Bkav FE W32.HfsAdware.C534
Dr.Web Adware.Conduit.299
G Data Win32.Application.Conduit.F
IKARUS anti.virus PUA.ClientConnect
Comodo Security Application.Win32.Conduit.ks
tbshA2.dll (MD5: 8de9d8fda8df6dd2e1b99a1f297faa8a) has been flagged by 4 scanners:
Scanner Software Result
Comodo Security Application.Win32.Conduit.ks
ESET-NOD32 a variant of Win32/Toolbar.Conduit.B
VIPRE Antivirus Conduit (fs)
Panda Antivirus PUP/Conduit.A
tbshA0.dll (MD5: 1a8438854dd15e4389f5bdef502c369d) has been flagged by 10 scanners:
Scanner Software Result
AVware Conduit (fs)
Baidu-International Adware.Win32.Conduit.Y
Bkav FE W32.HfsAdware.C534
Dr.Web Adware.Conduit.299
ESET-NOD32 a variant of Win32/Toolbar.Conduit.B potentially unwanted
Panda Antivirus PUP/Conduit.A
VIPRE Antivirus Conduit (fs)
G Data Win32.Application.Conduit.F
IKARUS anti.virus PUA.ClientConnect
Comodo Security Application.Win32.Conduit.ks
prxtbshA2.dll (MD5: 9117027aea464e41c60b87b9826e8447) has been flagged by 10 scanners:
Scanner Software Result
AVware Conduit (fs)
Baidu-International PUA.Win32.Conduit.BX
ESET-NOD32 a variant of Win32/Toolbar.Conduit.X
G Data Win32.Application.Conduit.F
Panda Antivirus PUP/Conduit.A
VIPRE Antivirus Conduit (fs)
Bkav FE W32.HfsAdware.C534
Dr.Web Adware.Conduit.300
IKARUS anti.virus PUA.ClientConnect
Comodo Security Application.Win32.Conduit.ks

Software Behaviors

Services:
  • UNWISE.EXE runs as a service named 'Browser System Enahncer' (671c50b0).
Firewall:
  • UNWISE.EXE is added as a firewall exception for 'C:\Program Files1\Yahoo!\MESSEN~1\UNWISE.EXE'.
  • shARESToolbarHelper.exe is added as a firewall exception for 'C:\Program Files\eTvOnline.ro\eTvOnline.roToolbarHelper.exe'.
Scheduled tasks:
  • uninstall.exe is scheduled as a task with the class '{42CD7A24-AF4B-44A0-A119-1C6F9B6E2A90}' (runs on registration).
  • UNWISE.EXE is scheduled as a task with the class '{F71A9918-1861-4EFE-AE94-530BDDE46DD4}' (runs on registration).
  • shARESToolbarHelper.exe is scheduled as a task with the class '{B8E8E278-F25D-478A-BAB2-24A5EDB01F6C}' (runs on registration).

Software Details

URL:
https://shares.media-toolbar.com
Support:
https://shares.media-toolbar.com/help
Installation path:
C:\Program Files\shares
Uninstaller:
C:\Program Files\shARES\uninstall.exe
Size:
10.00 MB
Language:
English

shARES Toolbar Executable Details

Primary executable:
tbshAR.dll
Name:
shARES Toolbar
Path:
C:\Program Files\shares\tbshAR.dll
MD5:
d9a0ce26ada5bd15b1b03a752ddf14a6
SHA-1:
SHA-256:
Files installed by shARES Toolbar
File Type Filename MD5
EXE
b728fa6a309e5d18141947b95b730e95
EXE
973567b98cdfc147df4e60471d9df072
EXE
56bc02a4bbc848a5374837fbb379ec78
DLL
tbshAR.dll
Malware
d9a0ce26ada5bd15b1b03a752ddf14a6
DLL
tbshA2.dll
Malware
8de9d8fda8df6dd2e1b99a1f297faa8a
DLL
tbshA0.dll
Malware
1a8438854dd15e4389f5bdef502c369d
DLL
b92293778555ce3dabe7f0a7e98b34c0
DLL
9117027aea464e41c60b87b9826e8447
DLL
4c163bd2a5905d18893ee311608e8c54
DLL
4c163bd2a5905d18893ee311608e8c54