chromemodule.dll

Search Protect

Conduit Ltd.

The file belongs to the Conduit API platform, a utility that bundles and monetizes search toolbars and web browser extensions. The module chromemodule.dll, “Search Protect by Conduit” by Conduit has been detected as a potentially unwanted program by 17 anti-malware scanners. This file is typically installed with the program Search Protect by conduit by Conduit Ltd. which is a potentially unwanted software program. While running, it connects to the Internet address usage.toolbar.conduit-services.com on port 80 using the HTTP protocol.
Publisher:
Conduit  (signed by Conduit Ltd.)

Product:
Search Protect

Description:
Search Protect by Conduit

Version:
1.5.0.71

MD5:
427bd933e1e35f75b39ea0e97420672e

SHA-1:
3e528bf4bf06f3491d6d62cb756facd726252e87

SHA-256:
f697b60788c8d020e4b2db20a5b471dd7049f1fbaf26f4b6cfc7956037a03a0e

Scanner detections:
17 / 68

Status:
Potentially unwanted

Explanation:
Part of the Conduit/ClientConnect toolbar/extension distribution.

Analysis date:
4/26/2024 8:28:56 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SearchProtect-C [Adw]
2014.9-140211

Baidu Antivirus
Hacktool.Win32.Keygen
4.0.3.131125

Bkav FE
W32.Clod017.Trojan
1.3.0.4613

Boost by Reason
Adware.SearchProtect.Conduit.M
2013.7.25.17

Dr.Web
Adware.BGuard.15
9.0.1.0206

ESET NOD32
Win32/Conduit.SearchProtect (variant)
7.9125

Fortinet FortiGate
Riskware/Toolbar
7/25/2013

G Data
Win32.Application.SearchProtect
13.12.24

K7 AntiVirus
Trojan
13.174.10656

Kaspersky
not-a-virus:WebToolbar.Win32.Toolbar
14.0.0.4325

Malwarebytes
PUP.Optional.Conduit.A
v2013.11.25.12

NANO AntiVirus
Trojan.Win32.BGuard.cfelez
0.28.0.57029

Panda Antivirus
PUP/Conduit.A
14.02.11.10

Quick Heal
Trojan.Agent.gen
11.13.12.00

Reason Heuristics
PUP.SearchProtect.Conduit.M
14.8.7.22

Trend Micro House Call
TROJ_GEN.F47V1019
7.2.42

VIPRE Antivirus
Conduit
26304

File size:
817.3 KB (836,896 bytes)

Product version:
1.5.0.71

Copyright:
2012 (c) Conduit. All rights reserved.

Original file name:
SearchProtect (R) P

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\searchprotect\bin\chromemodule.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/2/2013 4:00:00 PM

Valid to:
4/3/2016 4:59:59 PM

Subject:
CN=Conduit Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Conduit Ltd., L=Ness Ziona, S=Israel, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3A82654719D8F75B59134F7B66465210

File PE Metadata
Compilation timestamp:
5/7/2013 11:16:33 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:fT2NyDITftCeL4Gb7EWV21mqET1fZ/JTag4/:fNT8VEWV+iT1fxlag4/

Entry address:
0x6ECC0

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 4A, 03, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, CC, FE, FF, FF, 59, 5D, C2, 0C, 00, 6A, 14, 68, 38, 15, 09, 10, E8, 61, 07, 00, 00, FF, 35, CC, DA, 0A, 10, 8B, 35, 48, 50, 08, 10, FF, D6, 89, 45, E4, 83, F8, FF, 75, 0C, FF, 75, 08, FF, 15, 38, 52, 08, 10, 59, EB, 64, 6A, 08, E8, C2, 07, 00, 00, 59, 83, 65, FC, 00, FF, 35, CC, DA, 0A, 10, FF, D6, 89, 45, E4, FF, 35, C8, DA, 0A, 10, FF, D6, 89, 45, E0, 8D, 45, E0, 50, 8D, 45, E4, 50, FF, 75, 08, 8B, 35...
 
[+]

Entropy:
6.3211

Code size:
525.5 KB (538,112 bytes)

The file chromemodule.dll has been discovered within the following programs.

Search Protect by conduit  by Conduit Ltd.
The Conduit Search Protect software is designed to prevent other competing web browser plugins from changing the homepage and search settings that are created by the Conduit OurToolbar from being changed automatically. It is typically installed with various Community toolbars.
www.conduit.com/privacy/search-protect-privacy-policy.aspx
82% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to usage.toolbar.conduit-services.com  (66.77.197.165:80)

Remove chromemodule.dll - Powered by Reason Core Security