cltmng.exe

Search Protect

Conduit Ltd.

The file belongs to the Conduit API platform, a utility that bundles and monetizes search toolbars and web browser extensions. The application cltmng.exe, “Search Protect by Conduit” by Conduit has been detected as a potentially unwanted program by 16 anti-malware scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘SearchProtect’. This file is typically installed with the program Search Protect by conduit by Conduit Ltd. which is a potentially unwanted software program.
Publisher:
Conduit  (signed by Conduit Ltd.)

Product:
Search Protect

Description:
Search Protect by Conduit

Version:
1.7.0.72

MD5:
0a89171e6f87ea8848f6fbbee8ad366e

SHA-1:
9ad04a7058ac026d71a9dbbb65d3405a0fe1f966

SHA-256:
802ccacb70b4ef27970e4766672112398e4ff78e37b8d0b6d1b975cb003647d1

Scanner detections:
16 / 68

Status:
Potentially unwanted

Explanation:
Part of the Conduit/ClientConnect toolbar/extension distribution.

Analysis date:
4/25/2024 4:41:27 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.BHO.BProtector.E
1144

avast!
Win32:SearchProtect-C [Adw]
2014.9-131116

Baidu Antivirus
Adware.Win32.BHO
4.0.3.131224

Bitdefender
Adware.BHO.BProtector.E
1.0.20.1685

Bkav FE
W32.Clod703.Trojan
1.3.0.4613

Boost by Reason
Optional.Startup.Conduit.G
188838

Comodo Security
Application.Win32.Conduit.~A
17397

Dr.Web
Adware.BGuard.15
9.0.1.0358

Emsisoft Anti-Malware
Adware.BHO.BProtector
8.13.12.03.01

ESET NOD32
Win32/Conduit.SearchProtect (variant)
7.9142

G Data
Adware.BHO.BProtector
13.12.22

Malwarebytes
PUP.Optional.Conduit.A
v2013.11.16.06

MicroWorld eScan
Adware.BHO.BProtector.E
14.0.0.1011

Panda Antivirus
PUP/Conduit.A
14.02.14.12

Reason Heuristics
PUP.Startup.Conduit.G
14.8.7.22

VIPRE Antivirus
Conduit
24088

File size:
3.3 MB (3,470,624 bytes)

Product version:
1.7.0.72

Copyright:
2012 (c) Conduit. All rights reserved.

Original file name:
SearchProtect (R) P

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\searchprotect\bin\cltmng.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/2/2013 4:00:00 PM

Valid to:
4/3/2016 4:59:59 PM

Subject:
CN=Conduit Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Conduit Ltd., L=Ness Ziona, S=Israel, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3A82654719D8F75B59134F7B66465210

File PE Metadata
Compilation timestamp:
9/22/2013 4:57:27 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
49152:h7AIg9GQWcysClrgTGRhshQnWxoQlTdfEcN6ch/jbJzlI04a5eou5xXAb/5JhGxb:xUCZETdMcsch/jbJz/8Pvy+r

Entry address:
0x18C4DA

Entry point:
E8, 47, 9E, 00, 00, E9, 7F, FE, FF, FF, 6A, 08, 68, 80, 72, 6A, 00, E8, 10, A6, 00, 00, 33, C0, 8B, 75, 08, 85, F6, 0F, 95, C0, 85, C0, 75, 16, E8, 7B, 35, 00, 00, C7, 00, 16, 00, 00, 00, E8, FD, A1, 00, 00, E8, 32, A6, 00, 00, C3, 89, 75, 08, 56, E8, 32, C8, 00, 00, 8B, F8, 56, E8, C3, 58, 00, 00, 59, 59, 83, 65, FC, 00, 56, E8, B8, 00, 00, 00, 59, 83, 66, 0C, CF, 83, FF, FF, 74, 1B, 83, FF, FE, 74, 16, 8B, C7, C1, F8, 05, 8B, CF, 83, E1, 1F, C1, E1, 06, 03, 0C, 85, E0, EF, 6E, 00, EB, 05, B9, C8, 76, 6E...
 
[+]

Entropy:
6.3556

Code size:
2.3 MB (2,446,336 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SearchProtect

Command:
C:\users\{user}\appdata\roaming\searchprotect\bin\cltmng.exe


Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SearchProtectAll

Command:
C:\Program Files\searchprotect\bin\cltmng.exe


The file cltmng.exe has been discovered within the following programs.

Search Protect by conduit  by Conduit Ltd.
The Conduit Search Protect software is designed to prevent other competing web browser plugins from changing the homepage and search settings that are created by the Conduit OurToolbar from being changed automatically. It is typically installed with various Community toolbars.
www.conduit.com/privacy/search-protect-privacy-policy.aspx
82% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-54-225-182-66.compute-1.amazonaws.com  (54.225.182.66:80)

TCP (HTTP SSL):
Connects to a23-12-68-139.deploy.static.akamaitechnologies.com  (23.12.68.139:443)

TCP (HTTP SSL):
Connects to a23-12-64-94.deploy.static.akamaitechnologies.com  (23.12.64.94:443)

TCP (HTTP):
Connects to ec2-23-23-99-139.compute-1.amazonaws.com  (23.23.99.139:80)

TCP (HTTP SSL):
Connects to a23-40-112-229.deploy.static.akamaitechnologies.com  (23.40.112.229:443)

TCP (HTTP SSL):
Connects to a172-227-168-170.deploy.static.akamaitechnologies.com  (172.227.168.170:443)

TCP (HTTP SSL):
Connects to a72-246-38-238.deploy.akamaitechnologies.com  (72.246.38.238:443)

TCP (HTTP SSL):
Connects to a69-192-205-76.deploy.akamaitechnologies.com  (69.192.205.76:443)

TCP (HTTP SSL):
Connects to a23-217-150-79.deploy.static.akamaitechnologies.com  (23.217.150.79:443)

TCP (HTTP SSL):
Connects to a23-217-148-201.deploy.static.akamaitechnologies.com  (23.217.148.201:443)

TCP (HTTP):
Connects to a23-214-155-116.deploy.static.akamaitechnologies.com  (23.214.155.116:80)

Remove cltmng.exe - Powered by Reason Core Security