browserprotect.exe
Application Manager by Bit89 Inc. (Signed)
Version: | 2,6,1095,52 |
MD5: | 639838b4bd0ed95f308650b910e3ec82 |
SHA1: | 872918bb02b724ff42cf3239649bbe399f06bb7a |
SHA256: | 04e0ede2520aeb6aacb70870992263eb34d70bb54c3a5aa5fdced308d654932d |
Warning 13 antivirus scanners has detected malware.
What is browserprotect.exe?
The PerformerSoft Browser Manager (Application Manager) program classified mostly as exhibiting adware like actions, is bundled with PerformerSoft products including PC Performer. Browser Manager is designed to protect its bundled programs and make sure they remain installed or unchanged by other thrid party programs. The Browser Manager program was developed by Bit89 (Bit89.com) a know adware maker.
Overview
browserprotect.exe is malware that runs as a service under the name BrowserDefendert (FindAmo Manager) within the local user context as a shared service. This is typically installed with the program BrowserProtect published by Bit89 Inc and is most likely removed by most users once installed (88% removed). The file is digitally signed by Bit89 Inc. which was issued by the GoDaddy.com certificate authority (CA).
Details
File name: | browserprotect.exe |
Publisher: | PerformerSoft LLC |
Product name: | Application Manager |
Typical file path: | C:\ProgramData\browserprotect\2.5.986.67\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\browserprotect.exe |
File version: | 2,6,1095,52 |
Size: | 2.43 MB (2,550,224 bytes) |
Certificate |
Issued to: | Bit89 Inc. |
Authority (CA): | GoDaddy.com |
Effective date: | Tuesday, September 4, 2012 |
Expiration date: | Friday, September 4, 2015 |
Digital DNA |
PE subsystem: | Windows GUI |
File packed: | No |
.NET CLR: | No |
More details
Programs
The following program will install this file
PerformerSoft BrowserProtect is a third party web browser add-in classified mostly as a potentially unwanted software application that used to be bundled with PerformerSoft products including PC Performer. The maker of this program is a known adware/malware distributor, so caution should be taken. The PerformerSoft BrowserProtect (Browser Manager) program classified mostly as exhibiting adware like actions, is bundled with PerformerSoft...
Behaviors
Services
Runs under 'SYSTEM\CurrentControlSet\Services' as a shared service by the Service Host (svchost.exe)
- BrowserDefendert
- 'FindAmo Manager'
- 'BrowserProtect'
Malware detections
Based on 40+ industry antivirus scanners, 13 of them detected the following malware.
Antivirus engine | Engine version | Detection |
AhnLab V3 Internet Security |
2013.07.04.01 |
Win-Trojan/Rbot.2550224 |
Antiy Labs AVL |
2.0.3.7 |
Trojan/Win32.Buzus |
Dr.Web |
8.13.6.16 |
Adware.BGuard.21 |
ESET NOD32 |
7.8524 |
a variant of Win32/bProtector.A |
K7 AntiVirus |
9.170.8954 |
Backdoor |
K7GW |
12.7.0.12 |
Backdoor |
PC Tools |
9.0.0.2 |
Adware.GoonSquad!rem |
Sophos |
4.90.0 |
BProtector |
Symantec |
20131.1.0.101 |
Adware.GoonSquad |
The Hacker |
None |
Adware/BrowserManager |
Vba32 AntiVirus |
3.12.22.2 |
Backdoor.Rbot |
VIPRE Antivirus |
19278 |
Bprotector (fs) |
ViRobot |
2011.4.7.4223 |
Backdoor.Win32.A.Rbot.2550224.A |
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
CPU |
Total CPU: | 0.01468189% | |
Kernel CPU: | 0.00878712% | |
User CPU: | 0.00589477% | |
Kernel CPU time: | 483,498,402 ms/min | |
CPU cycles: | 2,965,476/sec | |
Context switches: | 24/sec | |
Memory |
Private memory: | 3.34 MB | |
Private (maximum): | 6.96 MB | |
Private (minimum): | 3.29 MB | |
Non-paged memory: | 3.34 MB | |
Virtual memory: | 164.25 MB | |
Virtual memory (peak): | 195.1 MB | |
Working set: | 4.4 MB | |
Working set (peak): | 7.11 MB | |
Page faults: | 78,701,160/min | |
I/O |
I/O read transfer: | 159 Bytes/sec | |
I/O read operations: | 2/sec | |
I/O write transfer: | 8 Bytes/sec | |
I/O write operations: | 2/sec | |
I/O other transfer: | 232 Bytes/sec | |
I/O other operations: | 24/sec | |
Resource allocations |
Threads: | 12 | |
Handles: | 238 | |
GUI GDI count: | 9 | |
GUI GDI peak: | 11 | |
GUI USER count: | 7 | |
GUI USER peak: | 10 | |
Process properties
Integrety level: | High |
Platform: | 32-bit |
Command lines: |
- "C:\ProgramData\browserprotect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\browserprotect.exe" /protect
- C:\ProgramData\browserprotect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\browserprotect.exe
- "C:\Documents and Settings\user\Application data\browserprotect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\browserprotect.exe"
- "C:\Documents and Settings\user\Application data\browserprotect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\browserprotect.exe" /protect
|
Owner: | User |
Windows Service |
Service name: | FindAmo Manager |
Display name: | BrowserDefendert |
Description: | “Your browser protector service” |
Type: | Win32ShareProcess |
Parent processes: |
|
Threads
Averages
BrowserProtect.exe (main module) |
Total CPU: | 0.44752665% | |
Kernel CPU: | 0.41837713% | |
User CPU: | 0.02914952% | |
CPU cycles: | 10,768,973/sec | |
Context switches: | 10/sec | |
Memory: | 2.51 MB | |
BrowserProtect.dll (Application Manager by PerformerSoft LLC) |
Total CPU: | 0.00346783% | |
Kernel CPU: | 0.00147031% | |
User CPU: | 0.00199752% | |
CPU cycles: | 15,452/sec | |
Memory: | 2.23 MB | |
sechost.dll |
Total CPU: | 0.00055431% | |
Kernel CPU: | 0.00027316% | |
User CPU: | 0.00028115% | |
CPU cycles: | 37,567/sec | |
Context switches: | 1/sec | |
Memory: | 100 KB | |
ntdll.dll |
Total CPU: | 0.00045334% | |
Kernel CPU: | 0.00045334% | |
User CPU: | 0.00000000% | |
CPU cycles: | 2,293/sec | |
Memory: | 1.23 MB | |
Common loaded modules
These are modules that are typiclaly loaded within the context of this process.
Distribution by Windows OS
OS version | distribution |
Windows 7 Home Premium |
27.27% |
|
Windows 7 Ultimate |
14.29% |
|
Microsoft Windows XP |
14.29% |
|
Windows 8 Pro |
11.69% |
|
Windows Vista Home Premium |
10.39% |
|
Windows 8 |
7.79% |
|
Windows 7 Professional |
5.19% |
|
Windows 7 Starter |
3.90% |
|
Windows 8 Pro with Media Center |
3.90% |
|
Windows 8 Single Language |
1.30% |
|
Distribution by country
United States installs about 28.57% of Application Manager.
Distribution by PC manufacturer
PC Manufacturer | distribution |
Hewlett-Packard |
26.67% |
|
Acer |
25.00% |
|
Sony |
13.33% |
|
Toshiba |
13.33% |
|
Dell |
10.00% |
|
GIGABYTE |
5.00% |
|
Intel |
3.33% |
|
ASUS |
3.33% |
|