cltmngui.exe

Search Protect

ClientConnect LTD

The file belongs to the ClientConnect (Conduit/Perion) platform, a utility that bundles and monetizes search toolbars and browser add-ons. The application cltmngui.exe by ClientConnect has been detected as adware by 16 anti-malware scanners.
Publisher:
Client Connect LTD  (signed by ClientConnect LTD)

Product:
Search Protect

Version:
2.13.3.38

MD5:
e08bdcb2af67b0117fb34cf030f1e0ab

SHA-1:
0f00eb8310c851aad8ae9c7c17ef5f0d81617d3a

SHA-256:
c7e2762651f4dd99326baa1499761d1e1fcd48f6adb8ca9096590e6cab8e1ae5

Scanner detections:
16 / 68

Status:
Adware

Explanation:
Part of the Conduit/ClientConnect toolbar/extension distribution.

Analysis date:
4/19/2024 10:23:02 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Trash.Gen
7.11.30.172

AVG
SearchProtect
2015.0.3460

Baidu Antivirus
Adware.Win32.Conduit
4.0.3.14529

Dr.Web
Trojan.Damaged.1
9.0.1.0213

ESET NOD32
Win32/Conduit.SearchProtect (variant)
8.9848

G Data
Win32.Application.SearchProtect.AA@gen
14.5.24

IKARUS anti.virus
PUA.SearchProtect
t3scan.1.6.1.0

Malwarebytes
PUP.Optional.SearchProtect.A
v2014.08.01.12

McAfee
Artemis!DDB6010BF5EF
5600.7052

Panda Antivirus
Trj/Genetic.gen
14.05.29.09

Reason Heuristics
PUP.ClientConnect.I
14.8.1.0

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
10449

VIPRE Antivirus
Conduit
29612

File size:
2.9 MB (3,080,000 bytes)

Product version:
2.13.3.38

Copyright:
© 2014 ClientConnect Ltd.

Original file name:
SearchProtect (R)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\searchprotect\ui\bin\cltmngui.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/3/2014 1:00:00 AM

Valid to:
2/5/2016 12:59:59 AM

Subject:
CN=ClientConnect LTD, OU=Digital ID Class 3 - Microsoft Software Validation v2, OU=Search Protect, O=ClientConnect LTD, L=Ness Ziona, S=Israel, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
173D1F00E27A9D60265B3AB0B87F2ED8

File PE Metadata
Compilation timestamp:
5/23/2014 9:19:04 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
49152:ftm14J9A6q2u626pB75LkTnseGfu5n/LxTbms0NVcBWzDWEm:ft9A+uCT75Iz/K0XF/

Entry address:
0x102273

Entry point:
E8, DB, 9E, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 8D, 45, 14, 50, 6A, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 87, A2, 00, 00, 83, C4, 14, 5D, C3, 55, 8B, EC, 51, 51, 8D, 45, F8, 50, FF, 15, 00, D1, 5B, 00, 8B, 4D, F8, 8B, 45, FC, 6A, 00, 81, C1, 00, 80, C1, 2A, 68, 80, 96, 98, 00, 15, 21, 4E, 62, FE, 50, 51, E8, 39, 47, 00, 00, 83, FA, 07, 7C, 0E, 7F, 07, 3D, FF, 6F, 40, 93, 76, 05, 83, C8, FF, 8B, D0, 8B, 4D, 08, 85, C9, 74, 05, 89, 01, 89, 51, 04, C9, C3, 55, 8B, EC, 56, E8, 36, AF, 00, 00, 8B, F0...
 
[+]

Code size:
1.7 MB (1,815,552 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to a23-209-176-11.deploy.static.akamaitechnologies.com  (23.209.176.11:443)

TCP (HTTP SSL):
Connects to a184-86-116-18.deploy.static.akamaitechnologies.com  (184.86.116.18:443)

TCP (HTTP SSL):
Connects to a184-25-160-11.deploy.static.akamaitechnologies.com  (184.25.160.11:443)

TCP (HTTP SSL):
Connects to a23-35-119-61.deploy.static.akamaitechnologies.com  (23.35.119.61:443)

TCP (HTTP):
Connects to ec2-107-21-212-85.compute-1.amazonaws.com  (107.21.212.85:80)

TCP (HTTP SSL):
Connects to a92-122-104-191.deploy.akamaitechnologies.com  (92.122.104.191:443)

TCP (HTTP SSL):
Connects to a23-63-135-61.deploy.static.akamaitechnologies.com  (23.63.135.61:443)

TCP (HTTP SSL):
Connects to a23-218-42-243.deploy.static.akamaitechnologies.com  (23.218.42.243:443)

TCP (HTTP SSL):
Connects to a23-218-136-32.deploy.static.akamaitechnologies.com  (23.218.136.32:443)

TCP (HTTP SSL):
Connects to a23-215-35-109.deploy.static.akamaitechnologies.com  (23.215.35.109:443)

TCP (HTTP):
Connects to ec2-54-83-197-43.compute-1.amazonaws.com  (54.83.197.43:80)

TCP (HTTP):
Connects to ec2-184-72-217-85.compute-1.amazonaws.com  (184.72.217.85:80)

TCP (HTTP SSL):
Connects to a95-101-64-11.deploy.akamaitechnologies.com  (95.101.64.11:443)

TCP (HTTP SSL):
Connects to a95-101-156-11.deploy.akamaitechnologies.com  (95.101.156.11:443)

TCP (HTTP SSL):
Connects to a95-101-100-11.deploy.akamaitechnologies.com  (95.101.100.11:443)

TCP (HTTP SSL):
Connects to a23-79-60-32.deploy.static.akamaitechnologies.com  (23.79.60.32:443)

TCP (HTTP SSL):
Connects to a23-77-151-61.deploy.static.akamaitechnologies.com  (23.77.151.61:443)

TCP (HTTP SSL):
Connects to a23-76-183-63.deploy.static.akamaitechnologies.com  (23.76.183.63:443)

TCP (HTTP SSL):
Connects to a23-74-87-61.deploy.static.akamaitechnologies.com  (23.74.87.61:443)

TCP (HTTP SSL):
Connects to a23-74-164-11.deploy.static.akamaitechnologies.com  (23.74.164.11:443)

Remove cltmngui.exe - Powered by Reason Core Security