shARES Toolbar

shARES Toolbar

Known Toolbar

by Conduit Ltd.

What is shARES Toolbar?

shARES Toolbar is software application developed by Conduit Ltd.. It is most commonly found on computers running Windows 7 with nearly 73.79% of installations running this operating system. shARES Toolbar's installer is typically 10.00 MB in size and installs around 19 files. The most common release is 6.2.2.4 with 23.30% of all installations currently using this version.

shARES Toolbar is most popular in the United States with 28.83% of installations residing in this country.

shARES Toolbar adds 3 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times. When using a computer that is connected to the internet, shARES Toolbar is known to create 2 firewall exceptions to allow inbound and outbound connectivity.

About shARES Toolbar?

This toolbar is commonly included as an optional component during the installation of the free shARES software. Developed by Conduit, it functions as a Community Toolbar accessible on Internet Explorer, Chrome, and Firefox web browsers. The toolbar gathers and retains data related to web browsing activities, which is then transmitted to OurToolbar for the purpose of recommending services or delivering advertisements through the toolbar. Additionally, it may endeavor to modify the browser's home page and search provider settings upon installation, with this action typically being preselected (though optional) and also furnishes a search box and a range of other standard features within the toolbar. Furthermore, it has the capability to automatically download and install updates without user notification. This toolbar is classified as a pay-per-install (PPI) toolbar, wherein the publisher receives payment from Conduit based on the number of installations and the duration for which the toolbar remains installed in the user's web browser. Its inclusion often occurs as part of the installation process for the free shARES program, and its removal may be required even if shARES is uninstalled from the user's PC. If the toolbar has modified the home page and search settings, users will need to manually revert them to their original state.

Multiple virus scanners have detected malware in shARES Toolbar.

uninstall.exe (MD5: b728fa6a309e5d18141947b95b730e95) has been flagged by 2 scanners:
Scanner Software Result
Panda Antivirus PUP/Conduit.A
VIPRE Antivirus Conduit (fs)
tbshAR.dll (MD5: d9a0ce26ada5bd15b1b03a752ddf14a6) has been flagged by 10 scanners:
Scanner Software Result
AVware Conduit (fs)
ESET-NOD32 a variant of Win32/Toolbar.Conduit.B
Panda Antivirus PUP/Conduit.A
VIPRE Antivirus Conduit (fs)
Baidu-International Adware.Win32.Conduit.Y
Bkav FE W32.HfsAdware.C534
Dr.Web Adware.Conduit.299
G Data Win32.Application.Conduit.F
IKARUS anti.virus PUA.ClientConnect
Comodo Security Application.Win32.Conduit.ks
tbshA2.dll (MD5: 8de9d8fda8df6dd2e1b99a1f297faa8a) has been flagged by 4 scanners:
Scanner Software Result
Comodo Security Application.Win32.Conduit.ks
ESET-NOD32 a variant of Win32/Toolbar.Conduit.B
VIPRE Antivirus Conduit (fs)
Panda Antivirus PUP/Conduit.A
tbshA0.dll (MD5: 1a8438854dd15e4389f5bdef502c369d) has been flagged by 10 scanners:
Scanner Software Result
AVware Conduit (fs)
Baidu-International Adware.Win32.Conduit.Y
Bkav FE W32.HfsAdware.C534
Dr.Web Adware.Conduit.299
ESET-NOD32 a variant of Win32/Toolbar.Conduit.B potentially unwanted
Panda Antivirus PUP/Conduit.A
VIPRE Antivirus Conduit (fs)
G Data Win32.Application.Conduit.F
IKARUS anti.virus PUA.ClientConnect
Comodo Security Application.Win32.Conduit.ks
prxtbshA2.dll (MD5: 9117027aea464e41c60b87b9826e8447) has been flagged by 10 scanners:
Scanner Software Result
AVware Conduit (fs)
Baidu-International PUA.Win32.Conduit.BX
ESET-NOD32 a variant of Win32/Toolbar.Conduit.X
G Data Win32.Application.Conduit.F
Panda Antivirus PUP/Conduit.A
VIPRE Antivirus Conduit (fs)
Bkav FE W32.HfsAdware.C534
Dr.Web Adware.Conduit.300
IKARUS anti.virus PUA.ClientConnect
Comodo Security Application.Win32.Conduit.ks

Software Behaviors

Services:
  • UNWISE.EXE runs as a service named 'Browser System Enahncer' (671c50b0).
Firewall:
  • UNWISE.EXE is added as a firewall exception for 'C:\Program Files1\Yahoo!\MESSEN~1\UNWISE.EXE'.
  • shARESToolbarHelper.exe is added as a firewall exception for 'C:\Program Files\eTvOnline.ro\eTvOnline.roToolbarHelper.exe'.
Scheduled tasks:
  • uninstall.exe is scheduled as a task with the class '{42CD7A24-AF4B-44A0-A119-1C6F9B6E2A90}' (runs on registration).
  • UNWISE.EXE is scheduled as a task with the class '{F71A9918-1861-4EFE-AE94-530BDDE46DD4}' (runs on registration).
  • shARESToolbarHelper.exe is scheduled as a task with the class '{B8E8E278-F25D-478A-BAB2-24A5EDB01F6C}' (runs on registration).

Software Details

URL:
https://shares.media-toolbar.com
Support:
https://shares.media-toolbar.com/help
Installation path:
C:\Program Files\shares
Uninstaller:
C:\Program Files\shARES\uninstall.exe
Size:
10.00 MB
Language:
English

shARES Toolbar Executable Details

Primary executable:
tbshAR.dll
Name:
shARES Toolbar
Path:
C:\Program Files\shares\tbshAR.dll
MD5:
d9a0ce26ada5bd15b1b03a752ddf14a6
SHA-1:
SHA-256:
Files installed by shARES Toolbar
File Type Filename MD5
DLL
76b3946090c94bb38dbbca54ac8ff9f7
DLL
76b3946090c94bb38dbbca54ac8ff9f7
DLL
9a302f14b18a9fb9b351ad7048cc15b5
DLL
522f5bdde2bc5c590381df1534147be2
DLL
8f7928532b88f3c8ae75d7af16d13bdd
DLL
39111185759adaae97d12113dfa3aba1
EXE
f3011af04d7bf1afe16cec5eb7d9a586
EXE
a320df2b47cfcaf98d06eb59cd72084c
DLL
tbshA1.dll
Malware
0210a8ccafcb04413748b6cc8744b452