Home Malware Programs Adware Baidu Toolbar

Baidu Toolbar

Posted: October 18, 2010

Threat Metric

Ranking: 8,120
Threat Level: 2/10
Infected PCs: 25,051
First Seen: July 24, 2009
Last Seen: March 2, 2025
OS(es) Affected: Windows

Baidu Toolbar uses the name of the huge Chinese search engine Baidu.com but is actually an annoying program similar to a browser hijacker. Baidu Toolbar will attack the targeted browser before delivering constant pop-ups and spam adverts. Baidu promises big things but mostly just spies on you and clogs your computer with spam. Remove it immediately using an updated malware remover.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\Baidu\bar\BDBar_tmp\BaiduBar.dll File name: BaiduBar.dll
Size: 1.6 MB (1604848 bytes)
MD5: 3122e49eb49ba7135b0c6a6a72155519
Detection count: 201
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Baidu\bar\BDBar_tmp
Group: Malware file
Last Updated: August 8, 2017
bdsl2.dll File name: bdsl2.dll
Size: 86.01 KB (86016 bytes)
MD5: 972e70449ff97ada4f9bf2b902e7777a
Detection count: 45
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
C:\Program Files (x86)\Baidu\Toolbar\BaiduBarX_Tmp\BaiduBarX.dll File name: BaiduBarX.dll
Size: 2.89 MB (2898888 bytes)
MD5: 09a713cf696e24ab7f3e53cd012d568b
Detection count: 42
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Program Files (x86)\Baidu\Toolbar\BaiduBarX_Tmp\BaiduBarX.dll
Group: Malware file
Last Updated: August 13, 2021
bdsyslink.dll File name: bdsyslink.dll
Size: 86.01 KB (86016 bytes)
MD5: a9f40beb8050bf7a76b34ab0f3558a1b
Detection count: 39
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{23A2B2B7-21DE-4B88-AFBA-5A918ABBF463}{2923508C-9425-4A61-B9CE-A98239055916}{3A8C9D89-3271-45F4-98C0-56B0F5A16172}{464C8A26-31E9-411C-9583-5B858E631DCC}{4C2BFEC9-F03C-4F74-932E-5723E603B4AC}{5BECD27B-DCF5-4DEF-B066-486A47245C03}{6AFC2761-1253-427C-9A56-385B4609BE1D}{6C773CA2-F142-4B2C-981A-FD3B1BEC1578}{77FEF28E-EB96-44FF-B511-3185DEA48697}{7A33CE9E-4F33-4B4E-B263-6AEEAB6C3DC2}{7C76C055-ED6E-4535-A70F-CD476E727F67}{7EF05EFF-0E62-4040-8D81-73A10D8DE60F}{89FDCC4B-8D91-49B0-81A6-18BCFF582735}{96249369-D3DC-4AE6-8A3B-E7109D46E98D}{A294F8EB-86D9-4C4A-8B3E-909253761C64}{A7F05EE4-0426-454F-8013-C41E3596E9E9}{B580CF65-E151-49C3-B73F-70B13FCA8E86}{D12F94FA-FC9A-41F7-B808-7FBB419DD7A6}{D158174C-004B-4A2E-9410-5442C10C60D2}{E5D5D4A1-17F0-41D7-B1C6-0979F91E6F46}{FE14F22E-BE14-4F08-A80F-F27BC3A67B2D}HKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\baidu\BaiduToolbarSOFTWARE\Baidu\BaiduToolbarSOFTWARE\Baidu\tbserviceSOFTWARE\Classes\AppID\BarBroker.EXESOFTWARE\Classes\BarBroker.BDBrokerSOFTWARE\Classes\BarBroker.BDBroker.1SOFTWARE\Classes\Wow6432Node\AppID\BarBroker.EXESOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7A33CE9E-4F33-4B4E-B263-6AEEAB6C3DC2}SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CC865B26-C31D-4D23-B17B-96548EEF03F6}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{B580CF65-E151-49C3-B73F-70B13FCA8E86}SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77FEF28E-EB96-44FF-B511-3185DEA48697}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{23A2B2B7-21DE-4B88-AFBA-5A918ABBF463}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E5D5D4A1-17F0-41D7-B1C6-0979F91E6F46}Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{77FEF28E-EB96-44FF-B511-3185DEA48697}Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{B580CF65-E151-49C3-B73F-70B13FCA8E86}SOFTWARE\Wow6432Node\Baidu\BaiduToolbarSOFTWARE\Wow6432Node\Baidu\tbserviceSOFTWARE\Wow6432Node\Classes\AppID\BarBroker.EXESOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7A33CE9E-4F33-4B4E-B263-6AEEAB6C3DC2}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{B580CF65-E151-49C3-B73F-70B13FCA8E86}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77FEF28E-EB96-44FF-B511-3185DEA48697}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{23A2B2B7-21DE-4B88-AFBA-5A918ABBF463}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E5D5D4A1-17F0-41D7-B1C6-0979F91E6F46}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}BaiduBarXsobar

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Application Data\Baidu\tbservice%ALLUSERSPROFILE%\Baidu\tbservice%APPDATA%\Baidu\BaiduToolbar%APPDATA%\Baidu\tbservice%PROGRAMFILES%\Baidu\Toolbar%PROGRAMFILES(X86)%\Baidu\Toolbar%USERPROFILE%\AppData\LocalLow\Baidu\Toolbar%appdata%\Baidu\Toolbar

Related Posts

Loading...