Somoto Toolbar

Somoto Toolbar

Known Toolbar

by Somoto Ltd.

What is Somoto Toolbar?

Somoto Toolbar is software application developed by Somoto Ltd.. It is most commonly found on computers running Windows 7 with nearly 74.36% of installations running this operating system. Somoto Toolbar's installer is typically 4.00 MB in size and installs around 18 files. The most common release is 6.9.0.16 with 33.33% of all installations currently using this version.

Somoto Toolbar is most popular in the United States with 84.71% of installations residing in this country.

Somoto Toolbar adds 2 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times. When using a computer that is connected to the internet, Somoto Toolbar is known to create 1 firewall exception to allow inbound and outbound connectivity.

About Somoto Toolbar?

This software installs the OurToolbar, powered by Conduit, into Internet Explorer, Chrome, and Firefox web browsers. The OurToolbar collects and stores information about web browsing activities, which is then sent to OurToolbar in order to suggest services or deliver advertisements via the toolbar. During installation, the Somoto Toolbar may attempt to change the user's home page and search provider, and it offers a search box and various other generic features within the toolbar. Additionally, the toolbar may automatically download and install updates without user notification. It should be noted that this is a PPI (pay per install) toolbar, meaning the publisher receives compensation from Conduit for each install and for each month the toolbar remains installed in a user's web browser, with the payment amount varying based on the country of install.

Multiple virus scanners have detected malware in Somoto Toolbar.

uninstall.exe (MD5: b728fa6a309e5d18141947b95b730e95) has been flagged by 3 scanners:
Scanner Software Result
Panda Antivirus PUP/Conduit.A
VIPRE Antivirus Conduit (fs)
ESET-NOD32 a variant of Win32/Toolbar.Conduit.P
tbSomo.dll (MD5: 1c1d673fb3efc0643271226ea42a25d9) has been flagged by 3 scanners:
Scanner Software Result
ESET-NOD32 a variant of Win32/Toolbar.Conduit.B
Panda Antivirus PUP/Conduit.A
VIPRE Antivirus Conduit (fs)
tbSom0.dll (MD5: cef32b574f8c732bacafd93210642dbb) has been flagged by 4 scanners:
Scanner Software Result
Bkav FE HW32.Stranact.ckae
ESET-NOD32 a variant of Win32/Toolbar.Conduit.B
Panda Antivirus PUP/Conduit.A
VIPRE Antivirus Conduit (fs)
prxtbSomo.dll (MD5: 4c163bd2a5905d18893ee311608e8c54) has been flagged by 6 scanners:
Scanner Software Result
AVware Conduit (fs)
Baidu-International Adware.Win32.Conduit.45
ESET-NOD32 Win32/Toolbar.Conduit.O
Panda Antivirus PUP/Conduit.A
VIPRE Antivirus Conduit (fs)
Bkav FE HW32.Stranact.ckae
prxtbSom0.dll (MD5: c89d9c80fd468c6b51c4aadcc8463c2d) has been flagged by 8 scanners:
Scanner Software Result
AVware Conduit (fs)
Baidu-International PUA.Win32.Conduit.BX
ESET-NOD32 Win32/Toolbar.Conduit.X
Fortinet FortiGate Riskware/Toolbar_Conduit
G Data Win32.Application.Conduit.F
Panda Antivirus PUP/Conduit.A
VIPRE Antivirus Conduit (fs)
Bkav FE HW32.Stranact.ckae

Software Behaviors

Firewall:
  • SomotoToolbarHelper1.exe is added as a firewall exception for 'C:\Program Files\eTvOnline.ro\eTvOnline.roToolbarHelper.exe'.
Scheduled tasks:
  • uninstall.exe is scheduled as a task with the class '{42CD7A24-AF4B-44A0-A119-1C6F9B6E2A90}' (runs on registration).
  • SomotoToolbarHelper.exe is scheduled as a task with the class '{34C01E1F-1D33-4264-8F52-97E13432C5E2}' (runs on registration).

Software Details

URL:
https://somoto.ourtoolbar.com
Support:
https://somoto.ourtoolbar.com/help
Installation path:
C:\Program Files\somoto
Uninstaller:
C:\Program Files\Somoto\uninstall.exe toolbar
Size:
4.00 MB
Language:
English

Somoto Toolbar Executable Details

Primary executable:
SomotoToolbarHelper.exe
Name:
Somoto Toolbar
Path:
C:\Program Files\somoto\SomotoToolbarHelper.exe
MD5:
da11d78d765e4b8fa4cfa5a37e8a94ff
SHA-1:
SHA-256:
Files installed by Somoto Toolbar
File Type Filename MD5
EXE
b728fa6a309e5d18141947b95b730e95
DLL
tbSomo.dll
Malware
1c1d673fb3efc0643271226ea42a25d9
DLL
tbSom0.dll
Malware
cef32b574f8c732bacafd93210642dbb
DLL
4c163bd2a5905d18893ee311608e8c54
DLL
c89d9c80fd468c6b51c4aadcc8463c2d
DLL
76b3946090c94bb38dbbca54ac8ff9f7
DLL
ce49528c9b0b3b3018ee2f70e76b362a
DLL
522f5bdde2bc5c590381df1534147be2
DLL
39111185759adaae97d12113dfa3aba1
EXE
da11d78d765e4b8fa4cfa5a37e8a94ff