Should I block it?

98%
Yes, 98% block recommendation.
Possible reasons:
Multiple malware detections
Performance resource utilization

VersionsAdditional versions

2,6,1562,220 16.67%
2,6,1339,144 83.33%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
AddAce, ConvertStringSecurityDescriptorToSecurityDescriptorW, RegQueryInfoKeyW, RegEnumKeyExW, StartServiceCtrlDispatcherW, RegisterServiceCtrlHandlerW, GetTokenInformation, DuplicateTokenEx, CreateProcessAsUserW, OpenSCManagerW, OpenServiceW, QueryServiceConfigW, ChangeServiceConfigW, CloseServiceHandle, SetServiceStatus, RegEnumKeyW, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, ConvertStringSecurityDescriptorToSecurityDescriptorA, GetSecurityDescriptorSacl, SetSecurityDescriptorSacl, RegSetValueExW, RegQueryValueExW, RegCloseKey, RegCreateKeyExW, RegOpenKeyExW, RegEnumValueW, CreateServiceW, ChangeServiceConfig2W, StartServiceW, ControlService, RegDeleteValueW, RegDeleteKeyW, DeleteService, RegisterEventSourceA, ReportEventA, DeregisterEventSource, IsValidSid, ConvertSidToStringSidW, GetLengthSid, InitializeAcl, OpenThreadToken, OpenProcessToken, GetSecurityInfo, GetAclInformation, SetSecurityInfo, DeleteAce, GetAce
gdi32.dll
CreateFontIndirectW, GetObjectW, DeleteObject, SelectObject, SetBkMode, SetTextColor, Rectangle, CreatePen, DeleteDC, RoundRect, CreateSolidBrush, CreatePatternBrush, BitBlt, CreateCompatibleBitmap, CreateDIBSection, CreateCompatibleDC
kernel32.dll
DllMain
ole32.dll
CoInitialize, CoUninitialize, CoCreateInstance, StringFromGUID2, CoInitializeEx, CoInitializeSecurity, CoSetProxyBlanket
rpcrt4.dll
UuidFromStringA
shell32.dll
SHGetSpecialFolderPathW, CommandLineToArgvW
shlwapi.dll
SHGetValueW, PathRemoveFileSpecW, PathIsDirectoryW, PathFindFileNameW, StrCmpW, StrCpyW, StrCmpNIW, PathStripPathW, PathRemoveExtensionW, PathFindExtensionW, PathAddExtensionW, PathFileExistsW, PathStripToRootW, PathIsRootW, PathAppendW
user32.dll
GetWindowRect, ShowWindow, ScreenToClient, KillTimer, ChildWindowFromPoint, MoveWindow, SetTimer, PeekMessageW, GetMessageW, TranslateMessage, DispatchMessageW, SystemParametersInfoW, GetClassInfoExW, LoadCursorW, IsWindow, EndDialog, DestroyWindow, RegisterClassExW, CreateWindowExW, GetUserObjectInformationW, GetProcessWindowStation, GetDesktopWindow, MessageBoxA, MessageBoxW, SetFocus, SetWindowPos, MapWindowPoints, GetMonitorInfoW, MonitorFromWindow, GetWindow, UnregisterClassA, LoadStringA, GetActiveWindow, GetTopWindow, TrackMouseEvent, GetCursorPos, LoadImageW, GetDlgItem, SendMessageW, GetSystemMetrics, DrawTextW, GetWindowTextW, GetWindowTextLengthW, DialogBoxParamW, CallWindowProcW, GetWindowLongW, DefWindowProcW, SetWindowLongW, SetWindowTextW, FindWindowW, SetLayeredWindowAttributes, FillRect, ReleaseDC, GetDC, GetSysColor, GetSysColorBrush, GetParent, InvalidateRect, EndPaint, BeginPaint, GetClientRect
userenv.dll
CreateEnvironmentBlock
uxtheme.dll
OpenThemeData, CloseThemeData, DrawThemeBackground, IsThemeBackgroundPartiallyTransparent, DrawThemeParentBackground
version.dll
GetFileVersionInfoSizeW, VerQueryValueW, GetFileVersionInfoW
winhttp.dll
WinHttpReceiveResponse, WinHttpAddRequestHeaders, WinHttpQueryDataAvailable, WinHttpReadData, WinHttpOpen, WinHttpSendRequest, WinHttpOpenRequest, WinHttpQueryHeaders, WinHttpConnect, WinHttpCloseHandle, WinHttpGetProxyForUrl, WinHttpGetIEProxyConfigForCurrentUser, WinHttpSetOption, WinHttpSetStatusCallback
wtsapi32.dll
WTSQueryUserToken

browserdefender.exe

Application Manager by Bit89 Inc. (Signed)

Remove browserdefender.exe
Version:   2,6,1562,220
MD5:   daf56ec5e652f629d6d2b3930ff199f6
SHA1:   5b1b511c55f5e656c01c34fc3812af210a942d7b
SHA256:   d97aa20513a491338a30ff88d0dc441af1924ba2fd98f1f7652a238c6d9bf33d
Warning 21 antivirus scanners has detected malware.

Overview

browserdefender.exe is malware that runs as a service under the name BrowserDefendert within the local user context as a shared service. This is typically installed with the program BrowserDefender published by Bit89 Inc and is most likely removed by most users once installed (80% removed). The file is digitally signed by Bit89 Inc. which was issued by the GoDaddy.com certificate authority (CA).

DetailsDetails

File name:browserdefender.exe
Publisher:PerformerSoft LLC
Product name:Application Manager
Typical file path:C:\ProgramData\browserdefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\browserdefender.exe
File version:2,6,1562,220
Size:2.71 MB (2,838,480 bytes)
Build date:8/13/2013 11:41 PM
Certificate
Issued to:Bit89 Inc.
Authority (CA):GoDaddy.com
Effective date:Tuesday, September 4, 2012
Expiration date:Friday, September 4, 2015
Digital DNA
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
Bit89 Inc
  80% remove
PerformerSoft/Bit89 BrowserDefender, a variant of the Browser Protector Software is a web browser add-in classified mostly a potentially unwanted application that used to be bundled with PerformerSoft products including PC Performer. BrowserDefender is designed to protect its bundled programs and make sure they remain installed or unchanged by other third party programs. It does this by preventing changes to the registry by other progra...

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' as a shared service by the Service Host (svchost.exe)
  • 'BrowserDefendert'
Network connections
  • [UDP] listens on port 3236

  • MalwareMalware detections

    Based on 40+ industry antivirus scanners, 21 of them detected the following malware.
    Antivirus engineEngine versionDetection
    AhnLab V3 Internet Security 2013.10.09 Downloader/Win32.MultiDl
    Avira AntiVir 7.11.106.104 APPL/Bprotect.E
    Antiy Labs AVL 2.0.3.7 Trojan/Win32.MultiDL
    avast! 8.0.1489.320 Win32:Adware-BAC [PUP]
    AVG 13.0.0.3169 Bprotect.B
    Comodo Internet Security 17075 Application.Win32.Bprotect.~L
    Dr.Web 8.13.10.10 Adware.BGuard.27
    ESET NOD32 7.8893 a variant of Win32/bProtector.A
    Fortinet 5.1.147.0 Riskware/BProtectBHO
    F-Secure 11.0.19100.45 Application:W32/BProtector.A
    G Data 13.10.22 Win32.Application.BHO.A
    K7 AntiVirus 9.173.9818 Riskware
    K7GW 12.7.0.14 Riskware
    Kaspersky 9.0.0.837 Trojan-Downloader.Win32.MultiDL.k
    Kingsoft 2013.4.9.267 Win32.Troj.Generic.a.(kcloud)
    Malwarebytes 1.75.0.1 PUP.Optional.BrowserProtect.A
    McAfee 5.600.1067 Adware-Bprotect.b
    McAfee Gateway Anti-Malware v2013-dat Artemis!DAF56EC5E652
    Sophos 4.93.0 BProtector
    Vba32 AntiVirus 3.12.24.3 TrojanDownloader.MultiDL
    VIPRE Antivirus 22222 Bprotector (fs)

    ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.00046716%
    0.028634%
    Kernel CPU:0.00023477%
    0.013761%
    User CPU:0.00023239%
    0.014873%
    Kernel CPU time:11,351 ms/min
    100,923,805ms/min
    Memory
    Private memory:5.04 MB
    21.59 MB
    Private (maximum):8.63 MB
    Private (minimum):2.65 MB
    Non-paged memory:5.04 MB
    21.59 MB
    Virtual memory:162.87 MB
    140.96 MB
    Virtual memory (peak):192.06 MB
    169.69 MB
    Working set:2.34 MB
    18.61 MB
    Working set (peak):8.68 MB
    37.95 MB
    Page faults:25,811,971/min
    2,039/min
    I/O
    I/O read transfer:460 Bytes/sec
    1.02 MB/min
    I/O read operations:1/sec
    343/min
    I/O write transfer:11 Bytes/sec
    274.99 KB/min
    I/O write operations:1/sec
    227/min
    I/O other transfer:205 Bytes/sec
    448.09 KB/min
    I/O other operations:6/sec
    1,671/min
    Resource allocations
    Threads:12
    12
    Handles:330
    600
    GUI GDI count:12
    103
    GUI USER count:4
    49

    BehaviorsProcess properties

    Integrety level:Undefined
    Platform:32-bit
    Command lines:
    • "C:\Documents and Settings\user\Application data\browserdefender\2.6.1562.220\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\browserdefender.exe" /protect
    • "C:\Documents and Settings\user\Application data\browserdefender\2.6.1562.220\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\browserdefender.exe"
    Owner:User
    Windows Service
    Service name:BrowserDefendert
    Description:“Your browser protector service”
    Type:Win32ShareProcess
    Parent processes:

    ResourcesThreads

    Averages
     
    BrowserDefender.exe (main module)
    Total CPU:0.00589063%
    0.272967%
    Kernel CPU:0.00509117%
    0.107585%
    User CPU:0.00079946%
    0.165382%
    Memory:2.79 MB
    1.16 MB
    WINHTTP.dll
    Total CPU:0.00000697%
    Kernel CPU:0.00000000%
    User CPU:0.00000697%
    Memory:356 KB

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows 7 Ultimate 35.56%
    Microsoft Windows XP 33.33%
    Windows 8 8.89%
    Windows 8 Pro 6.67%
    Windows Vista Home Premium 6.67%
    Windows 7 Home Premium 4.44%
    Windows Vista Ultimate 2.22%
    Windows 7 Professional 2.22%

    Distribution by countryDistribution by country

    Vietnam installs about 14.29% of Application Manager.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Dell 37.74%
    Acer 22.64%
    Hewlett-Packard 15.09%
    Intel 11.32%
    Toshiba 7.55%
    American Megatrends 5.66%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE