Winload Toolbar

Winload Toolbar

Known Toolbar

by Conduit Ltd.

What is Winload Toolbar?

Winload Toolbar is software application developed by Conduit Ltd.. It is most commonly found on computers running Windows 7 with nearly 72.20% of installations running this operating system. Winload Toolbar's installer is typically 4.00 MB in size and installs around 24 files. The most common release is 6.9.0.16 with 28.48% of all installations currently using this version.

Winload Toolbar is most popular in Germany with 81.21% of installations residing in this country.

Winload Toolbar adds 2 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times. When using a computer that is connected to the internet, Winload Toolbar is known to create 1 firewall exception to allow inbound and outbound connectivity.

About Winload Toolbar?

The Winload Toolbar, developed by Conduit, is a browser extension compatible with Internet Explorer, Chrome, and Firefox. It gathers and retains browsing data, forwarding it to OurToolbar for the purpose of offering personalized services and displaying ads through the toolbar. The installation process may prompt the user to modify their home page and search provider settings, with these options pre-selected by default. Once installed, the toolbar furnishes a search box and a range of standard features. Additionally, it has the capability to automatically download and install updates without user notification. Classified as a PPI (pay per install) toolbar, Conduit compensates the publisher for each installation and for every month the toolbar remains installed on a user's web browser, offering various payment rates depending on the country of installation.

Multiple virus scanners have detected malware in Winload Toolbar.

uninstall.exe (MD5: b728fa6a309e5d18141947b95b730e95) has been flagged by 3 scanners:
Scanner Software Result
Panda Antivirus PUP/Conduit.A
VIPRE Antivirus Conduit (fs)
ESET-NOD32 a variant of Win32/Toolbar.Conduit.P
tbWinl.dll (MD5: 1a8438854dd15e4389f5bdef502c369d) has been flagged by 13 scanners:
Scanner Software Result
AVware Conduit (fs)
Baidu-International Adware.Win32.Conduit.Y
Bkav FE W32.HfsAdware
Dr.Web Adware.Conduit.299
ESET-NOD32 a variant of Win32/Toolbar.Conduit.B potentially unwanted
Panda Antivirus PUP/Conduit.A
VIPRE Antivirus Conduit (fs)
Fortinet FortiGate Riskware/Toolbar_Conduit
G Data Win32.Application.Conduit.F
Comodo Security Application.Win32.Conduit.~A
Malwarebytes PUP.Optional.Conduit
TrendMicro-HouseCall TROJ_GEN.F47V1113
IKARUS anti.virus PUA.ClientConnect
tbWin2.dll (MD5: 975993043e355206a1fba5a702044f0c) has been flagged by 11 scanners:
Scanner Software Result
Comodo Security Application.Win32.Conduit.~A
ESET-NOD32 a variant of Win32/Toolbar.Conduit.B
Malwarebytes PUP.Optional.Conduit
Panda Antivirus Adware/Conduit
TrendMicro-HouseCall TROJ_GEN.F47V1113
VIPRE Antivirus Conduit (fs)
Bkav FE W32.HfsAdware.C534
Dr.Web Adware.Conduit.300
G Data Win32.Adware.Conduit.B
IKARUS anti.virus PUA.ClientConnect
AVware Conduit (fs)
tbWin0.dll (MD5: 90a1b31ba3d3c1fd73b6021c1d8c1c8f) has been flagged by 4 scanners:
Scanner Software Result
Comodo Security Application.Win32.Conduit.r
ESET-NOD32 a variant of Win32/Toolbar.Conduit.B
Panda Antivirus Adware/Conduit
VIPRE Antivirus Conduit (fs)
prxtbWin2.dll (MD5: 9117027aea464e41c60b87b9826e8447) has been flagged by 12 scanners:
Scanner Software Result
AVware Conduit (fs)
Baidu-International PUA.Win32.Conduit.BX
ESET-NOD32 a variant of Win32/Toolbar.Conduit.X
G Data Win32.Application.Conduit.F
Panda Antivirus PUP/Conduit.A
VIPRE Antivirus Conduit (fs)
Comodo Security Application.Win32.Conduit.~A
Malwarebytes PUP.Optional.Conduit
TrendMicro-HouseCall TROJ_GEN.F47V1113
Bkav FE W32.HfsAdware.C534
Dr.Web Adware.Conduit.300
IKARUS anti.virus PUA.ClientConnect

Software Behaviors

Firewall:
  • WinloadToolbarHelper1.exe is added as a firewall exception for 'C:\Program Files\eTvOnline.ro\eTvOnline.roToolbarHelper.exe'.
Scheduled tasks:
  • uninstall.exe is scheduled as a task with the class '{42CD7A24-AF4B-44A0-A119-1C6F9B6E2A90}' (runs on registration).
  • WinloadToolbarHelper.exe is scheduled as a task with the class '{B8E8E278-F25D-478A-BAB2-24A5EDB01F6C}' (runs on registration).

Software Details

URL:
https://winload.ourtoolbar.com
Support:
https://winload.ourtoolbar.com/help
Installation path:
C:\Program Files\winload
Uninstaller:
C:\Program Files\Winload\uninstall.exe toolbar
Size:
4.00 MB
Language:
English

Winload Toolbar Executable Details

Primary executable:
tbWinl.dll
Name:
Winload Toolbar
Path:
C:\Program Files\winload\tbWinl.dll
MD5:
1a8438854dd15e4389f5bdef502c369d
SHA-1:
SHA-256:
Files installed by Winload Toolbar
File Type Filename MD5
EXE
b728fa6a309e5d18141947b95b730e95
EXE
5cf949316c40314d66b45f0bf00aa6f6
DLL
da75109279d84c9942749df6d1e0ff7b
EXE
789060d700b364358cfb645c6e6f02e9
DLL
tbWinl.dll
Malware
1a8438854dd15e4389f5bdef502c369d
DLL
tbWin2.dll
Malware
975993043e355206a1fba5a702044f0c
DLL
tbWin0.dll
Malware
90a1b31ba3d3c1fd73b6021c1d8c1c8f
DLL
4c163bd2a5905d18893ee311608e8c54
DLL
9117027aea464e41c60b87b9826e8447
DLL
5c6b58516ebb518e1e91f1fb65eab04b