Home Malware Programs Bad Toolbars iPumper Toolbar

iPumper Toolbar

Posted: October 2, 2013

Threat Metric

Ranking: 12,344
Threat Level: 1/10
Infected PCs: 4,075
First Seen: October 2, 2013
Last Seen: September 10, 2023
OS(es) Affected: Windows

iPumper Toolbar Screenshot 1The iPumper Toolbar is a browser add-on that promotes the Conduit.com site's search features by modifying your browser to redirect to that site. Although Conduit.com isn't an immediate danger to your site, its search results aren't always optimally relevant, and malware experts usually suggest that you uninstall the iPumper Toolbar and other Conduit-affiliated toolbars, which are officially classified as Potentially Unwanted Programs and browser hijackers. Since the iPumper Toolbar PUP often is installed along with other programs that are historically difficult to uninstall, anti-malware applications generally should be used for deleting the iPumper Toolbar and making sure that all browser changes associated with the iPumper Toolbar have been reverted.

What iPumper Pumps into Your Browser Besides File Downloads

The iPumper Toolbar usually isn't installed by itself and tends to be installed only with iPumper, a download manager copied from previous products like Fast File Downloader. Besides having a questionable history for fulfilling its functions as a download assistant, iPumper also often is installed without your permission, along with the iPumper Toolbar, whose purpose is to make self-serving changes to your Web browser.

Changes enacted by the iPumper Toolbar are similar to those of other Conduit-affiliated browsers, and usually include:

  • Locking your homepage to Conduit.com.
  • Redirecting your online searches to Conduit.com.

The iPumper Toolbar and its related iPumper download manager may resist any uninstallation attempts by exploiting admin account settings to prevent non-administrator accounts from removing them. PC users who actually have access to their admin accounts tend to find that the iPumper Toolbar and its comrade-in-arms simply will not display in the Control Panel's list of installed programs. The iPumper Toolbar can't be disabled through your normal Web browser's add-on-managing settings.

Cleaning the Pipes of Your Browser of an iPumper Toolbar Clog

Like a standard PUP, the iPumper Toolbar doesn't do anything more harmful than take your browser to places you probably don't want to visit, but SpywareRemove.com malware experts still recommend uninstalling the iPumper Toolbar for the sake of your browser's safety – especially in light of iPumper's own risky traits that make its value as a download manager extremely questionable. To overcome the exploits being used to keep iPumper-brand software on your computer against your will, anti-malware applications generally should be trusted for deleting an iPumper Toolbar and its fellows.

The iPumper Toolbar may be partnered with an exceptionally stubborn program, but the iPumper Toolbar also is far from being a unique snowflake of a toolbar. SpywareRemove.com malware experts have seen a long line of toolbars that redirect their victims to Conduit.com just like the iPumper Toolbar, with some foremost examples including the MakeMeBabies Toolbar, the MySavings Toolbar, the Mini001 Toolbar, the Top 10 Toolbar, the Goofler Toolbar and the Trustworthy Toolbar.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\iPumper\ipumperinst.exe File name: ipumperinst.exe
Size: 4.88 MB (4886472 bytes)
MD5: aa56fd711541352b336811f4b4b6a434
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\iPumper
Group: Malware file
Last Updated: January 28, 2014
%APPDATA%\iPumper\ipumperinst.exe File name: ipumperinst.exe
Size: 4.67 MB (4671944 bytes)
MD5: 0aa6cd40c484a4607862c49fa73eb841
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\iPumper
Group: Malware file
Last Updated: January 28, 2014
%APPDATA%\iPumper\ipumperinst.exe File name: ipumperinst.exe
Size: 4.88 MB (4886472 bytes)
MD5: 888b8d15a1751f0c18cafbe179f05019
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\iPumper
Group: Malware file
Last Updated: January 28, 2014
%APPDATA%\iPumper\ipumperinst.exe File name: ipumperinst.exe
Size: 4.88 MB (4886472 bytes)
MD5: 57665b1364069f3180672c273cc70653
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\iPumper
Group: Malware file
Last Updated: January 28, 2014
%APPDATA%\iPumper\ipumperinst.exe File name: ipumperinst.exe
Size: 4.88 MB (4886472 bytes)
MD5: cf7bb2366e854c7f1321ca3216904cd2
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\iPumper
Group: Malware file
Last Updated: January 28, 2014
C:\!!! DESKTOP XP\DIRECTORIES\Music\iPumper.exe File name: iPumper.exe
Size: 581.86 KB (581864 bytes)
MD5: 4dcb97c728ee20688b75d183acdb4fe4
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: C:\!!! DESKTOP XP\DIRECTORIES\Music\iPumper.exe
Group: Malware file
Last Updated: January 28, 2023
%APPDATA%\iPumper\ipumperinst.exe File name: ipumperinst.exe
Size: 4.67 MB (4671944 bytes)
MD5: 1dc8dddee682f6bbc368ee6e430d15c8
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\iPumper
Group: Malware file
Last Updated: January 28, 2014
%SystemDrive%\Users\<username>\AppData\Roaming\iPumper\ipumperinst.exe File name: ipumperinst.exe
Size: 4.86 MB (4868040 bytes)
MD5: 7e7c7b877a315572ecf3f7c03e62f505
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\AppData\Roaming\iPumper
Group: Malware file
Last Updated: January 28, 2014
%APPDATA%\iPumper\ipumperinst.exe File name: ipumperinst.exe
Size: 5.43 MB (5435848 bytes)
MD5: 605ba89623898589dd6924d35792e78e
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\iPumper
Group: Malware file
Last Updated: January 28, 2014
%APPDATA%\iPumper\ipumperinst.exe File name: ipumperinst.exe
Size: 4.67 MB (4671944 bytes)
MD5: 2a950fa0b996d3be5f0b5db23d9defd5
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\iPumper
Group: Malware file
Last Updated: January 28, 2014
%APPDATA%\iPumper\ipumperinst.exe File name: ipumperinst.exe
Size: 4.88 MB (4886472 bytes)
MD5: ec58c544e7affac11ff9b5e1f4e2c471
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\iPumper
Group: Malware file
Last Updated: January 28, 2014
%APPDATA%\iPumper\ipumperinst.exe File name: ipumperinst.exe
Size: 4.88 MB (4880896 bytes)
MD5: 46525b82d20959a1ebdf46b62ee67706
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\iPumper
Group: Malware file
Last Updated: January 28, 2014
%SystemDrive%\Users\<username>\AppData\Roaming\iPumper\ipumperinst.exe File name: ipumperinst.exe
Size: 4.86 MB (4868040 bytes)
MD5: 9e94722d253d6f8f21ad96a78f7c4320
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\AppData\Roaming\iPumper
Group: Malware file
Last Updated: January 28, 2014
%APPDATA%\iPumper\ipumperinst.exe File name: ipumperinst.exe
Size: 3.08 MB (3086792 bytes)
MD5: 87d01cea6f8ca96f81c38dcee3b966f8
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\iPumper
Group: Malware file
Last Updated: January 28, 2014
%APPDATA%\iPumper\ipumperinst.exe File name: ipumperinst.exe
Size: 3.08 MB (3086792 bytes)
MD5: b31a72dbd4e0bca9610d69f4a055f5cd
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\iPumper
Group: Malware file
Last Updated: January 28, 2014
%APPDATA%\iPumper\ipumperinst.exe File name: ipumperinst.exe
Size: 4.88 MB (4886472 bytes)
MD5: 02116631929ca51a7248a7b1d686490a
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\iPumper
Group: Malware file
Last Updated: January 28, 2014
%APPDATA%\iPumper\ipumperinst.exe File name: ipumperinst.exe
Size: 4.88 MB (4886472 bytes)
MD5: 839cde2a0b7a935a745965c740d39b7b
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\iPumper
Group: Malware file
Last Updated: January 28, 2014
%APPDATA%\iPumper\ipumperinst.exe File name: ipumperinst.exe
Size: 4.86 MB (4869064 bytes)
MD5: 6f091616d7329eaafec4289d598ed0b4
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\iPumper
Group: Malware file
Last Updated: January 28, 2014
%APPDATA%\iPumper\ipumperinst.exe File name: ipumperinst.exe
Size: 4.88 MB (4886472 bytes)
MD5: 6ad18bf960caabe24d85ec7ed197a857
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\iPumper
Group: Malware file
Last Updated: January 28, 2014
%APPDATA%\iPumper\ipumperinst.exe File name: ipumperinst.exe
Size: 4.88 MB (4886472 bytes)
MD5: 7a4498f975370ae34bfdeca2f5c03f51
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\iPumper
Group: Malware file
Last Updated: January 28, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

File name without pathiPumper.lnkPileFile.lnkRegexp file mask%windir%\system32\tasks\escoladeHKEY..\..\..\..{RegistryKeys}Software\Informer Technologies, Inc.\UniKeeperSOFTWARE\Mozilla\Firefox\Extensions\ntfdsaftsfdfdxx@mozilla.orgSOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions\ntfdsaftsfdfdxx@mozilla.orgHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{A0099012-E037-4DEF-A539-2E02F0DC7446}_is1{E2AF26F0-6DCC-410c-A24D-ED093DDE1638}

Additional Information

The following directories were created:
%APPDATA%\Microsoft\Windows\Start Menu\Programs\UniKeeper%APPDATA%\UniKeeper%APPDATA%\iPumper%AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\UniKeeper%PROGRAMFILES%\UniKeeper%PROGRAMFILES%\iPumper%PROGRAMFILES(x86)%\UniKeeper%PROGRAMFILES(x86)%\iPumper%Temp%\CT3282330
Loading...