NCH_EN Toolbar

NCH_EN Toolbar

Known Toolbar

by NCH Software

What is NCH_EN Toolbar?

NCH_EN Toolbar is software application developed by NCH Software. It is most commonly found on computers running Windows 7 with nearly 67.92% of installations running this operating system. NCH_EN Toolbar's installer is typically 4.00 MB in size and installs around 22 files. The most common release is 6.15.0.27 with 25.47% of all installations currently using this version.

NCH_EN Toolbar is most popular in the United States with 40.98% of installations residing in this country.

NCH_EN Toolbar adds 2 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times. When using a computer that is connected to the internet, NCH_EN Toolbar is known to create 1 firewall exception to allow inbound and outbound connectivity.

About NCH_EN Toolbar?

The NCH English (EN) Toolbar is a Community Toolbar provided by Conduit for integration with popular web browsers, such as Google Chrome, Firefox, and Internet Explorer. This ad-supported program is designed to display targeted advertisements within the toolbar, as well as modify the browser's home page and search settings to capture web search traffic and collect usage information and statistics. The toolbar is commonly bundled with third-party developer programs to monetize free and some paid software. During installation, users may be given the option to modify the home and search pages, although this is often enabled by default and overlooked. If the software is removed from the user's PC, the settings will need to be manually reverted back. According to the End User License Agreement (EULA), the company may automatically download and install remote updates, as well as collect and store details about the user's web browsing activities locally on the PC. This information is used to interact with the toolbar application to suggest additional services or provide more targeted advertising. The EULA states, "By Using a Conduit Software you may enable Conduit to access, use and collect a variety of information, both personal and non-personal, regarding your Internet Browser, your browsing habits, and information about your computer."

Multiple virus scanners have detected malware in NCH_EN Toolbar.

uninstall.exe (MD5: b728fa6a309e5d18141947b95b730e95) has been flagged by 2 scanners:
Scanner Software Result
Panda Antivirus PUP/Conduit.A
VIPRE Antivirus Conduit (fs)
tbNCH0.dll (MD5: 975993043e355206a1fba5a702044f0c) has been flagged by 10 scanners:
Scanner Software Result
Comodo Security Application.Win32.Conduit.~A
ESET-NOD32 a variant of Win32/Toolbar.Conduit.B
Malwarebytes PUP.Optional.Conduit
Panda Antivirus Adware/Conduit
TrendMicro-HouseCall TROJ_GEN.F47V1113
VIPRE Antivirus Conduit (fs)
Bkav FE W32.HfsAdware.C534
Dr.Web Adware.Conduit.300
G Data Win32.Adware.Conduit.B
IKARUS anti.virus PUA.ClientConnect
tbNCH_.dll (MD5: 3549ca5e8809ff9be5f7216d4fbb7443) has been flagged by 19 scanners:
Scanner Software Result
Bkav FE HW32.Stranact
VIPRE Antivirus Conduit (fs)
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/Win32.Agent.azm
AVware Conduit (fs)
Baidu-International Adware.Win32.Conduit.M
Cyren W32/Conduit.TTAU-0102
ESET-NOD32 Win32/Toolbar.Conduit.N potentially unwanted
F-Prot W32/Conduit.A
G Data Win32.Application.Conduit.F
K7 AntiVirus Trojan ( 004b219d1 )
K7GW Trojan ( 004b219d1 )
Kaspersky not-a-virus:WebToolbar.Win32.Agent.azm
Panda Antivirus PUP/Conduit.A
Fortinet FortiGate Riskware/Toolbar_Conduit
Comodo Security Application.Win32.Conduit.~A
Malwarebytes PUP.Optional.Conduit
TrendMicro-HouseCall TROJ_GEN.F47V1113
Dr.Web Adware.Conduit.300
IKARUS anti.virus PUA.ClientConnect
prxtbNCH0.dll (MD5: c89d9c80fd468c6b51c4aadcc8463c2d) has been flagged by 13 scanners:
Scanner Software Result
AVware Conduit (fs)
Baidu-International PUA.Win32.Conduit.BX
ESET-NOD32 Win32/Toolbar.Conduit.X
Fortinet FortiGate Riskware/Toolbar_Conduit
G Data Win32.Application.Conduit.F
Panda Antivirus PUP/Conduit.A
VIPRE Antivirus Conduit (fs)
Comodo Security Application.Win32.Conduit.~A
Malwarebytes PUP.Optional.Conduit
TrendMicro-HouseCall TROJ_GEN.F47V1113
Bkav FE W32.HfsAdware.C534
Dr.Web Adware.Conduit.300
IKARUS anti.virus PUA.ClientConnect
prxtbNCH_.dll (MD5: d0133250565180c9dc8ee0aecccbfd53) has been flagged by 19 scanners:
Scanner Software Result
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/Win32.Agent.azm
AVware Conduit (fs)
Baidu-International Adware.Win32.Conduit.M
Cyren W32/Conduit.TTAU-0102
ESET-NOD32 Win32/Toolbar.Conduit.N potentially unwanted
F-Prot W32/Conduit.A
G Data Win32.Application.Conduit.F
K7 AntiVirus Trojan ( 004b219d1 )
K7GW Trojan ( 004b219d1 )
Kaspersky not-a-virus:WebToolbar.Win32.Agent.azm
Panda Antivirus PUP/Conduit.A
VIPRE Antivirus Conduit (fs)
Fortinet FortiGate Riskware/Toolbar_Conduit
Comodo Security Application.Win32.Conduit.~A
Malwarebytes PUP.Optional.Conduit
TrendMicro-HouseCall TROJ_GEN.F47V1113
Bkav FE W32.HfsAdware.C534
Dr.Web Adware.Conduit.300
IKARUS anti.virus PUA.ClientConnect

Software Behaviors

Firewall:
  • NCH_ENToolbarHelper.exe is added as a firewall exception for 'C:\Program Files\eTvOnline.ro\eTvOnline.roToolbarHelper.exe'.
Scheduled tasks:
  • uninstall.exe is scheduled as a task with the class '{42CD7A24-AF4B-44A0-A119-1C6F9B6E2A90}' (runs on registration).
  • NCH_ENToolbarHelper.exe is scheduled as a task with the class '{34C01E1F-1D33-4264-8F52-97E13432C5E2}' (runs on registration).

Software Details

URL:
https://nchentoolbar.ourtoolbar.com
Support:
https://nchentoolbar.ourtoolbar.com/help
Installation path:
C:\Program Files\nch_en
Uninstaller:
C:\Program Files\NCH_EN\uninstall.exe toolbar
Size:
4.00 MB
Language:
English

NCH_EN Toolbar Executable Details

Primary executable:
tbNCH_.dll
Name:
NCH_EN Toolbar
Path:
C:\Program Files\nch_en\tbNCH_.dll
MD5:
3549ca5e8809ff9be5f7216d4fbb7443
SHA-1:
–
SHA-256:
–
Files installed by NCH_EN Toolbar
File Type Filename MD5
DLL
ce49528c9b0b3b3018ee2f70e76b362a
DLL
76b3946090c94bb38dbbca54ac8ff9f7
DLL
f7057821b040a7d169711ce27c55012a
DLL
9a302f14b18a9fb9b351ad7048cc15b5
DLL
bbccf6b24155d931fd339c6c4210710c
DLL
8f7928532b88f3c8ae75d7af16d13bdd
EXE
da11d78d765e4b8fa4cfa5a37e8a94ff
DLL
5e6f6c1d35ade76cb898becc9c5d9e44
DLL
db10401ed351b75b7021ce6e03374e59
EXE
8c25acfaa9f7e6152b44e53a7facd5a6