ToolbarFR

ToolbarFR

Known Toolbar

by ReSoft Ltd.

What is ToolbarFR?

ToolbarFR is software application developed by ReSoft Ltd.. It is most commonly found on computers running Windows 7 with nearly 55.09% of installations running this operating system. ToolbarFR's installer is typically 19.00 MB in size and installs around 109 files.

ToolbarFR is most popular in France with 90.18% of installations residing in this country.

ToolbarFR adds 5 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times. When using a computer that is connected to the internet, ToolbarFR is known to create 4 firewall exceptions to allow inbound and outbound connectivity.

About ToolbarFR?

This software is a web browser toolbar designed for use with Orange. Please note that this software may display advertisements as part of its functionality.

Multiple virus scanners have detected malware in ToolbarFR.

browserhelper.exe (MD5: 697943b11eb0974c32acc82f585d8abb) has been flagged by 5 scanners:
Scanner Software Result
ESET-NOD32 a variant of MSIL/Toolbar.Linkury.A
TrendMicro-HouseCall TROJ_GEN.F47V1225
VIPRE Antivirus Adware.Linkury (fs)
Dr.Web Adware.Linkury.1
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
smartbar.exe (MD5: 593eb3b509c6e91690f5ebf5bac9f03a) has been flagged by 5 scanners:
Scanner Software Result
Dr.Web Adware.Linkury.1
ESET-NOD32 a variant of Win32/Toolbar.Linkury.A
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
TrendMicro-HouseCall TROJ_GEN.F47V1021
VIPRE Antivirus Adware.Linkury (fs)

Software Behaviors

Firewall:
  • facebookvideocalling.exe is added as a firewall exception for 'C:\Documents and Settings\user\Application Data\Facebook\Video\Skype\FacebookVideoCalling.exe'.
  • mynetview.exe is added as a firewall exception for 'C:\Program Files\Western Digital\My Net View\MyNetView.exe'.
  • maconfservice.exe is added as a firewall exception for 'C:\Program Files\ma-config.com\maconfservice.exe'.
  • hpwucli.exe is added as a firewall exception for 'C:\Program Files\HP\HP Software Update\HPWUCli.exe'.
Scheduled tasks:
  • javacpl.exe is scheduled as a task with the class '{4A96D4E3-15D0-4D39-A551-3EC96D94D3B5}' (runs on registration).
  • issch.exe is scheduled as a task named 'InstallShield software-updateservice' (runs weekly on Mondays at 10:00).
  • hpwuschd2.exe is scheduled as a task named 'hp digital imaging - hp all-in-one series MAGIX PCCT' (runs weekly on Wednesdays at 12:00 AM).
  • mynetview.exe is scheduled as a task with the class '{96622AC3-F62B-4C5A-8BBE-D2CF58A167E6}' (runs on registration).
  • ssbkgdupdate.exe is scheduled as a task named 'SSBkgdUpdate' (runs weekly on Mondays at 10:00).

Startup Entries

Startup tasks:
  • ssbkgdupdate.exe is automatically launched at startup through a scheduled task named 1.
Registry entries:
  • snapdo.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'Browser Infrastructure Helper' and executes as C:\Documents and Settings\user\Application Data\Smartbar\Application\SnapDo.exe startup.
  • smartbar.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'Browser Infrastructure Helper' and executes as C:\users\user\appdata\Local\Smartbar\Application\Smartbar.exe startup.

Software Details

URL:
https://www.snap.do
Support:
Installation path:
C:\users\user\appdata\Local\smartbar
Uninstaller:
MsiExec.exe /X{A047FE02-C91C-41CB-898C-4ED21B86025A}
Size:
19.00 MB
Language:
French

ToolbarFR Executable Details

Primary executable:
browserhelper.exe
Name:
ToolbarFR
Path:
C:\users\user\appdata\Local\smartbar\browserhelper.exe
MD5:
697943b11eb0974c32acc82f585d8abb
SHA-1:
SHA-256:
Files installed by ToolbarFR
File Type Filename MD5
DLL
07e55a8b8ce1317bc8edf868fcc8d8a8
DLL
8d54e09b0b7a6e745a7c0882d614aa7f
EXE
859c8daea5636a89023b27d5f026c798
DLL
4fd20600ad27a7cb96786ef7b9dc7868
DLL
82a15b04102b461b5141d8a199b08d42
DLL
787a890a08f63e19b104545de4a91dfe
DLL
ef65eda82e82ccf4067ed097d47daf0c
DLL
19ee800a9ff35e9b018e888838237f19
DLL
c40ebac4346522a0f69af12b00e2dd6f
DLL
81c08d2acf5975c6e5e17d9a0efc3fe6