tbedrs.dll

Conduit Toolbar Automatic Update

Conduit Ltd.

The file is part of the Conduit Toolbar platform, a web browser monetization engine that is typiclaly distributed with third party programs through a bundled installation, this particular version is part of the Conduit Toolbar Automatic Update bundle. The module tbedrs.dll by Conduit has been detected as a potentially unwanted program by 10 anti-malware scanners. Additionally, the file is typically installed by a number of programs including uTorrentBar Toolbar by Conduit Ltd. and BS_Player Toolbar by Conduit Ltd., both potentially unwanted software.
Publisher:
Conduit Ltd.  (signed and verified)

Product:
Conduit Toolbar Automatic Update

Version:
6.13.3.501

MD5:
c4ba40238919cc14a4591e1f59434fd7

SHA-1:
70e94c3740c0a11d19cb4d5d71d4b92f4c742571

SHA-256:
b96c81f9d3c4491bafaa67b58287e8bf1e71e2f38a981ec59570f74eb0049f5a

Scanner detections:
10 / 68

Status:
Potentially unwanted

Explanation:
This component is distributed and installed with the Conduit Toolbar platform.

Analysis date:
11/23/2024 7:49:54 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
HW32.Laneul
1.3.0.4246

Boost by Reason
Optional.Conduit.G
188838

Clam AntiVirus
Win.Trojan.Agent-723879
0.98/21411

Dr.Web
Adware.Conduit.6
9.0.1.0321

ESET NOD32
Win32/Toolbar.Conduit.Y potentially unwanted application
8.7.0.302.0

NANO AntiVirus
Trojan.Win32.Conduit.crfrgr
0.28.0.57029

Panda Antivirus
PUP/Conduit.A
14.08.07.10

Reason Heuristics
SearchPlugin.ConduitSearchBar.ToolbarAutomaticUpdate.G
14.8.7.22

Trend Micro House Call
TROJ_GEN.F47V0909
7.2.321

VIPRE Antivirus
Conduit
23442

File size:
2.3 MB (2,389,280 bytes)

Product version:
6.13.3.501

Copyright:
Conduit © 2013 All Rights Reserved

Original file name:
Conduit Toolbar Automatic Update

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\tbedrs.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/2/2013 7:00:00 PM

Valid to:
4/3/2016 7:59:59 PM

Subject:
CN=Conduit Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Conduit Ltd., L=Ness Ziona, S=Israel, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3A82654719D8F75B59134F7B66465210

File PE Metadata
Compilation timestamp:
5/20/2013 5:22:27 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
49152:mcIVkBwJGX+RYb4nf82ByG8IHmHyiDED0jp9LftLaqhl:mcOkBwJGXoYb4nffEx8mHRDgup9bFll

Entry address:
0xA840

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 35, 68, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, E8, 6E, 02, 10, E8, 41, 5B, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, F8, A8, 02, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, F8, F0, 01, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Entropy:
7.9246

Developed / compiled with:
Microsoft Visual C++

Code size:
113 KB (115,712 bytes)

The file tbedrs.dll has been discovered within the following programs.

Brothersoft Toolbar  by Brothersoft
Brothersoft Toolbar is a 'Community Toolbar' from Conduit, which integrates with major web browsers including Google Chrome, Firefox and Internet Explorer.
Brothersoft.OurToolbar.com
66% remove it
BS Player Toolbar  by AB Team, d.o.o.
Installs a Conduit powered OurToolbar in Internet Explorer, Chrome and Firefox web browsers. The software collects and stores information about your web browsing and sends this information to OurToolbar so they can suggest services or provide ads via the toolbar.
BSPlayer.OurToolbar.com
63% remove it
BS_Player Toolbar  by Conduit Ltd.
This is a Conduit/Perion (ClientConnect) powered toolbar that provides limited web browser functionality but will modify the user's search and home pages as well as bundle various ad-supported components.
www.ourtoolbar.com
69% remove it
Freecorder Toolbar  by Freecorder
Freecorder Toolbar installs various third part ad supported applications during installation including SweetPacks which changes the web browser's home page and search provider as well as the DealCabby Toolbar.
Freecorder.Media-Toolbar.com
69% remove it
FreeSoundRecorder Toolbar  by Conduit Ltd.
FreeSoundRecorder Toolbar is MyRadio Toolbar by Conduit that runs in IE, Chrome and Firefox Web browsers. The toolbar collects and stores information about your web browsing and sends this information to OurToolbar so they can suggest services or provide ads via the toolbar.
FreeSoundRecorder.MyRadioToolbar.com
68% remove it
HotSpot International Toolbar is a Conduit Community toolbar for various web browsers. The toolbar collects information about a user's web browsing habits and sends this information to Conduit so they can suggest services or provide advertising.
HotSpotInternational.OurToolbar.com
88% remove it
IObitCom Toolbar  by IObit
IObitCom Toolbar is an ad-supported (users may see additional banner and in-text link advertisements) cross web browser plugin for Internet Explorer (BHO) and Firefox/Chrome (plugin) and distributed through various monetization platforms during installation.
66% remove it
MyAshampoo Toolbar  by Ashampoo GmbH & Co. KG
Publisher's description - “Ashampoo is one of the leading Internet-based companies worldwide in the field of software development, sales and web portal sites.”
MyAshampoo.OurToolbar.com
72% remove it
myBabylon_English Toolbar  by Babylon Ltd
Installs a Conduit toolbar in your Web browser that collects and stores information about your web browsing and sends this information to Conduit so they can suggest services or provide ads via the toolbar.
71% remove it
NCH EN Toolbar  by NCH Software
NCH Toolbar is a generic web browser toolbar that installs a search feature and various buttons for social integration and links to web sites such as facebook and various search providers.
NCHEN.OurToolbar.com
67% remove it
 
Latest 20 of 15 programs
Powered by Should I Remove It?

The file tbedrs.dll has been seen being distributed by the following 2 URLs.

Remove tbedrs.dll - Powered by Reason Core Security