Baidu Toolbar

Baidu Toolbar Description

Baidu Toolbar is able to track a user's internet activity and send the gathered data to a remote third-party. When inside a machine, Baidu Toolbar will display annoying advertisements and redirect the browser to potentially harmful websites. It has not been established whether or not Baidu Toolbar is officially associated with the BaiDu search engine. If not intentionally installed onto your machine, remove Baidu Toolbar from your system sooner rather than later.

Technical Information

File System Details

Baidu Toolbar creates the following file(s):
# File Name Size MD5 Detection Count
1 %PROGRAMFILES%\Baidu\Toolbar\BaiduBarX.dll 2,898,888 09a713cf696e24ab7f3e53cd012d568b 13
2 bdsyslink.dll 86,016 a9f40beb8050bf7a76b34ab0f3558a1b 0
3 bdsl2.dll 86,016 972e70449ff97ada4f9bf2b902e7777a 0
4 BaiduBar.dll 1,192,027 29146247deb8796cdcb43993e21df63e 0
More files

Registry Details

Baidu Toolbar creates the following registry entry or registry entries:
Directory
%ALLUSERSPROFILE%\Application Data\Baidu\tbservice
%ALLUSERSPROFILE%\Baidu\tbservice
%APPDATA%\Baidu\BaiduToolbar
%APPDATA%\Baidu\tbservice
%appdata%\Baidu\Toolbar
%PROGRAMFILES%\Baidu\Toolbar
%PROGRAMFILES(X86)%\Baidu\Toolbar
%USERPROFILE%\AppData\LocalLow\Baidu\Toolbar
Registry key
Software\AppDataLow\Software\baidu\BaiduToolbar
SOFTWARE\Baidu\BaiduToolbar
SOFTWARE\Baidu\tbservice
SOFTWARE\Classes\AppID\BarBroker.EXE
SOFTWARE\Classes\BarBroker.BDBroker
SOFTWARE\Classes\BarBroker.BDBroker.1
SOFTWARE\Classes\Wow6432Node\AppID\BarBroker.EXE
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7A33CE9E-4F33-4B4E-B263-6AEEAB6C3DC2}
SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CC865B26-C31D-4D23-B17B-96548EEF03F6}
SOFTWARE\Microsoft\Internet Explorer\Toolbar\{B580CF65-E151-49C3-B73F-70B13FCA8E86}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77FEF28E-EB96-44FF-B511-3185DEA48697}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{23A2B2B7-21DE-4B88-AFBA-5A918ABBF463}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E5D5D4A1-17F0-41D7-B1C6-0979F91E6F46}
Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{77FEF28E-EB96-44FF-B511-3185DEA48697}
Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{B580CF65-E151-49C3-B73F-70B13FCA8E86}
SOFTWARE\Wow6432Node\Baidu\BaiduToolbar
SOFTWARE\Wow6432Node\Baidu\tbservice
SOFTWARE\Wow6432Node\Classes\AppID\BarBroker.EXE
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7A33CE9E-4F33-4B4E-B263-6AEEAB6C3DC2}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{B580CF65-E151-49C3-B73F-70B13FCA8E86}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77FEF28E-EB96-44FF-B511-3185DEA48697}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{23A2B2B7-21DE-4B88-AFBA-5A918ABBF463}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E5D5D4A1-17F0-41D7-B1C6-0979F91E6F46}
Uninstaller
BaiduBarX
sobar
CLSID
{23A2B2B7-21DE-4B88-AFBA-5A918ABBF463}
{2923508C-9425-4A61-B9CE-A98239055916}
{3A8C9D89-3271-45F4-98C0-56B0F5A16172}
{464C8A26-31E9-411C-9583-5B858E631DCC}
{4C2BFEC9-F03C-4F74-932E-5723E603B4AC}
{5BECD27B-DCF5-4DEF-B066-486A47245C03}
{6AFC2761-1253-427C-9A56-385B4609BE1D}
{6C773CA2-F142-4B2C-981A-FD3B1BEC1578}
{77FEF28E-EB96-44FF-B511-3185DEA48697}
{7A33CE9E-4F33-4B4E-B263-6AEEAB6C3DC2}
{7C76C055-ED6E-4535-A70F-CD476E727F67}
{7EF05EFF-0E62-4040-8D81-73A10D8DE60F}
{89FDCC4B-8D91-49B0-81A6-18BCFF582735}
{96249369-D3DC-4AE6-8A3B-E7109D46E98D}
{A294F8EB-86D9-4C4A-8B3E-909253761C64}
{A7F05EE4-0426-454F-8013-C41E3596E9E9}
{B580CF65-E151-49C3-B73F-70B13FCA8E86}
{D12F94FA-FC9A-41F7-B808-7FBB419DD7A6}
{D158174C-004B-4A2E-9410-5442C10C60D2}
{E5D5D4A1-17F0-41D7-B1C6-0979F91E6F46}
{FE14F22E-BE14-4F08-A80F-F27BC3A67B2D}

Related Posts

Site Disclaimer

Enigmasoftware.com is not associated, affiliated, sponsored or owned by the malware creators or distributors mentioned on this article. This article should NOT be mistaken or confused in being associated in any way with the promotion or endorsement of malware. Our intent is to provide information that will educate computer users on how to detect, and ultimately remove, malware from their computer with the help of SpyHunter and/or manual removal instructions provided on this article.

This article is provided "as is" and to be used for educational information purposes only. By following any instructions on this article, you agree to be bound by the disclaimer. We make no guarantees that this article will help you completely remove the malware threats on your computer. Spyware changes regularly; therefore, it is difficult to fully clean an infected machine through manual means.

One Comment

Leave a Reply

Please DO NOT use this comment system for support or billing questions. For SpyHunter technical support requests, please contact our technical support team directly by opening a customer support ticket via your SpyHunter. For billing issues, please refer to our "Billing Questions or Problems?" page. For general inquiries (complaints, legal, press, marketing, copyright), visit our "Inquiries and Feedback" page.


HTML is not allowed.