~~~browsermngr-16.0.dll

Application Manager Extension

ForwardTech Inc

This is part of a Performersoft product, a 'PC optimzation' application that provides minimal benifits and may have been bundled by a third party installer. The module ~~~browsermngr-16.0.dll by ForwardTech Inc has been detected as adware by 21 anti-malware scanners. This web browser add-on will claim to protect the web browser but will instead hijack it by modifying the home and search pages.
Publisher:
PerformerSoft LLC  (signed by ForwardTech Inc)

Product:
Application Manager Extension

Version:
2,4,897,175

MD5:
b66492b656e3d696873362456c8916db

SHA-1:
66a1ab62482b2a0a361b7d04bdf407edd6b8c473

SHA-256:
8c33b86732ac11796a133f99e178e35196cadd16ff2970fbfa5720f66bc1dfd3

Scanner detections:
21 / 68

Status:
Adware

Explanation:
This service will prevent resources from modifying the web browser's home and search pages as well as the search provider set by the product, an affiliate search engine partner.

Analysis date:
4/24/2024 5:53:53 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.BHO.Bprotector.1
442

Avira AntiVirus
TR/BProtector.Gen
7.11.129.138

avast!
Win32:BProtect-D [Trj]
2014.9-151120

AVG
AdPlugin
2016.0.2920

Bitdefender
Gen:Variant.Adware.BHO.Bprotector.1
1.0.20.1620

Clam AntiVirus
Win.Adware.BProtector
0.98/18355

Comodo Security
UnclassifiedMalware
17737

Emsisoft Anti-Malware
Gen:Variant.Adware.BHO.Bprotector
8.15.11.20.08

ESET NOD32
Win32/bProtector (variant)
9.9385

F-Secure
Gen:Variant.Adware.BHO.Bprotector.1
11.2015-20-11_6

G Data
Gen:Variant.Adware.BHO.Bprotector
15.11.24

Malwarebytes
PUP.Optional.BProtector
v2015.11.20.08

McAfee
Adware-Bprotect!B66492B656E3
5600.6576

Microsoft Security Essentials
TrojanDropper:Win32/Rotbrow.A
1.165.247.01

MicroWorld eScan
Gen:Variant.Adware.BHO.Bprotector.1
16.0.0.972

Reason Heuristics
PUP.Performersoft.ForwardTech (M)
15.11.20.8

Sophos
BProtector
4.97

Trend Micro House Call
ADW_BROMNGR
7.2.324

Trend Micro
ADW_BROMNGR
10.465.20

Vba32 AntiVirus
AdWare.Bromngr
3.12.24.3

VIPRE Antivirus
Bprotector
26172

File size:
524.5 KB (537,120 bytes)

Product version:
2,4,897,175

Copyright:
Copyright 2012

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\ProgramData\~browser manager\~2.4.897.175\~{61d8b74e-8d89-46ff-afa6-33382c54ac73}\~~~firefoxextension\~~firefoxextension\~~~components\~~~browsermngr-16.0.dll

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
9/11/2012 9:46:30 PM

Valid to:
9/11/2015 9:46:30 PM

Subject:
CN=ForwardTech Inc, O=ForwardTech Inc, L=Beaverton, S=OR, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
07BCB9E09D11D2

File PE Metadata
Compilation timestamp:
11/2/2012 1:59:32 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
12288:X8zYw8z0O2/sjBZiYZOPRt9GS0+w0V9T8HiV2/jew:XQo7ZOZ2r+wQ9T8HByw

Entry address:
0x4266F

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 34, 88, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 83, 3D, 20, 4F, 08, 10, 00, 74, 2D, 55, 8B, EC, 83, EC, 08, 83, E4, F8, DD, 1C, 24, F2, 0F, 2C, 04, 24, C9, C3, 83, 3D, 20, 4F, 08, 10, 00, 74, 11, 83, EC, 04, D9, 3C, 24, 58, 66, 83, E0, 7F, 66, 83, F8, 7F, 74, D3, 55, 8B, EC, 83, EC, 20, 83, E4, F0, D9, C0, D9, 54, 24, 18, DF, 7C, 24, 10, DF, 6C, 24, 10, 8B, 54...
 
[+]

Entropy:
6.5532

Code size:
365.5 KB (374,272 bytes)

Remove ~~~browsermngr-16.0.dll - Powered by Reason Core Security