cltmng.exe

Search Protect

ClientConnect LTD

The file belongs to the ClientConnect (Conduit/Perion) platform, a utility that bundles and monetizes search toolbars and browser add-ons. The application cltmng.exe by ClientConnect has been detected as adware by 10 anti-malware scanners. This file is typically installed with the program Search Protect by Conduit Ltd. which is a potentially unwanted software program.
Publisher:
Client Connect LTD  (signed by ClientConnect LTD)

Product:
Search Protect

Version:
2.13.2.14

MD5:
54ec350c3e4d900e123c571a3060bcb8

SHA-1:
4929eb5864840e7f5a0aca7fa5723d703f4b5e73

SHA-256:
4eadf1143059a402b6bfefd4f3d3dd577afad76b0a4b7165ead2d60c5c5b3617

Scanner detections:
10 / 68

Status:
Adware

Explanation:
Part of the Conduit/ClientConnect toolbar/extension distribution.

Analysis date:
4/19/2024 9:12:21 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
SearchProtect
2015.0.3396

Baidu Antivirus
Adware.Win32.Conduit
4.0.3.1481

Dr.Web
Trojan.Damaged.1
9.0.1.0213

ESET NOD32
Win32/Conduit.SearchProtect (variant)
8.9805

G Data
Win32.Application.SearchProtect.AA@gen
14.8.24

Malwarebytes
PUP.Optional.SearchProtect.A
v2014.08.01.12

Panda Antivirus
Trj/Genetic.gen
14.05.17.12

Reason Heuristics
PUP.ClientConnect.G
14.8.1.0

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
10449

VIPRE Antivirus
Conduit
29242

File size:
4.5 MB (4,761,920 bytes)

Product version:
2.13.2.14

Copyright:
© 2014 ClientConnect Ltd.

Original file name:
SearchProtect (R)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\searchprotect\searchprotect\bin\cltmng.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/2/2014 7:00:00 PM

Valid to:
2/4/2016 6:59:59 PM

Subject:
CN=ClientConnect LTD, OU=Digital ID Class 3 - Microsoft Software Validation v2, OU=Search Protect, O=ClientConnect LTD, L=Ness Ziona, S=Israel, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
173D1F00E27A9D60265B3AB0B87F2ED8

File PE Metadata
Compilation timestamp:
5/14/2014 3:50:51 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
98304:Ib+QOR2Au5iHfH1+BaPljxsK7wj7zLDixy4BiVAy:o+QORJ/H1+BQFsK7UWC3

Entry address:
0x21717C

Entry point:
E8, DB, D5, 00, 00, E9, 7F, FE, FF, FF, 6A, 0C, 68, 18, EF, 77, 00, E8, 8E, A2, 00, 00, 83, 65, E4, 00, 8B, 5D, 0C, 8B, C3, 8B, 7D, 10, 0F, AF, C7, 8B, 75, 08, 03, F0, 89, 75, 08, 83, 65, FC, 00, 4F, 89, 7D, 10, 78, 0C, 2B, F3, 89, 75, 08, 8B, CE, FF, 55, 14, EB, EE, 33, C0, 40, 89, 45, E4, C7, 45, FC, FE, FF, FF, FF, E8, 14, 00, 00, 00, E8, 8F, A2, 00, 00, C2, 10, 00, 8B, 7D, 10, 8B, 5D, 0C, 8B, 75, 08, 8B, 45, E4, 85, C0, 75, 0B, FF, 75, 14, 57, 53, 56, E8, 01, 00, 00, 00, C3, 6A, 14, 68, 38, EF, 77, 00...
 
[+]

Entropy:
6.4498

Code size:
3 MB (3,150,336 bytes)

The file cltmng.exe has been discovered within the following programs.

Search Protect  by Conduit Ltd.
From the Terms of Service: "Search Protect is a separate piece of software installed on your hard-drive in connection with your installation of a Toolbar. It is designed to protect your Search settings from takeover by third parties.
84% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-184-72-217-85.compute-1.amazonaws.com  (184.72.217.85:80)

TCP (HTTP):
Connects to ec2-54-235-66-89.compute-1.amazonaws.com  (54.235.66.89:80)

TCP (HTTP SSL):
Connects to a23-209-176-11.deploy.static.akamaitechnologies.com  (23.209.176.11:443)

TCP (HTTP):
Connects to ec2-54-243-118-76.compute-1.amazonaws.com  (54.243.118.76:80)

TCP (HTTP):
Connects to ec2-23-23-100-240.compute-1.amazonaws.com  (23.23.100.240:80)

TCP (HTTP):
Connects to ec2-54-83-197-43.compute-1.amazonaws.com  (54.83.197.43:80)

TCP (HTTP):
Connects to ec2-50-16-210-106.compute-1.amazonaws.com  (50.16.210.106:80)

TCP (HTTP):
Connects to ec2-54-235-252-228.compute-1.amazonaws.com  (54.235.252.228:80)

TCP (HTTP):
Connects to ec2-50-16-220-76.compute-1.amazonaws.com  (50.16.220.76:80)

TCP (HTTP):
Connects to ec2-50-16-209-186.compute-1.amazonaws.com  (50.16.209.186:80)

TCP (HTTP):
Connects to ec2-107-21-212-85.compute-1.amazonaws.com  (107.21.212.85:80)

TCP (HTTP SSL):
Connects to a95-100-164-11.deploy.akamaitechnologies.com  (95.100.164.11:443)

TCP (HTTP SSL):
Connects to a23-58-215-63.deploy.static.akamaitechnologies.com  (23.58.215.63:443)

TCP (HTTP SSL):
Connects to a23-51-135-61.deploy.static.akamaitechnologies.com  (23.51.135.61:443)

TCP (HTTP SSL):
Connects to a23-214-186-116.deploy.static.akamaitechnologies.com  (23.214.186.116:443)

TCP (HTTP):
Connects to m321-mp1-cvx1b.lan.ntl.com  (62.252.169.65:80)

TCP (HTTP):
Connects to ec2-54-83-40-196.compute-1.amazonaws.com  (54.83.40.196:80)

TCP (HTTP):
Connects to ec2-107-20-252-96.compute-1.amazonaws.com  (107.20.252.96:80)

TCP (HTTP SSL):
Connects to a96-6-12-11.deploy.akamaitechnologies.com  (96.6.12.11:443)

TCP (HTTP SSL):
Connects to a95-101-64-11.deploy.akamaitechnologies.com  (95.101.64.11:443)

Remove cltmng.exe - Powered by Reason Core Security