cltmngui.exe

Search Protect

ClientConnect LTD

The file belongs to the ClientConnect (Conduit/Perion) platform, a utility that bundles and monetizes search toolbars and browser add-ons. The application cltmngui.exe by ClientConnect has been detected as adware by 17 anti-malware scanners.
Publisher:
Client Connect LTD  (signed by ClientConnect LTD)

Product:
Search Protect

Version:
2.17.26.7

MD5:
d2931d2cdf0fbe2efd8dbbc4422f9c5f

SHA-1:
b470497f7ea96f4b7447c32ebb0052d56a8f8daf

SHA-256:
4a409c538a1ce445020f07ca56ac1a49dbf0669be697d8009714e0d208b5f8cd

Scanner detections:
17 / 68

Status:
Adware

Explanation:
Part of the Conduit/ClientConnect toolbar/extension distribution.

Analysis date:
4/16/2024 6:48:51 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.SearchProtect
2014.10.06

Avira AntiVirus
TR/Trash.Gen
7.11.30.172

avast!
Win32:Conduit-B [PUP]
2014.9-141007

AVG
ClientConnect
2015.0.3328

Baidu Antivirus
Adware.Win32.Conduit
4.0.3.14107

Dr.Web
Trojan.Damaged.1
9.0.1.0280

ESET NOD32
Win32/ClientConnect (variant)
8.10515

G Data
Win32.Application.SearchProtect.AA@gen
14.10.24

IKARUS anti.virus
PUA.SearchProtect
t3scan.1.6.1.0

Kaspersky
not-a-virus:WebToolbar.NSIS.Agent
14.0.0.3136

Malwarebytes
PUP.Optional.SearchProtect.A
v2014.10.07.05

McAfee
Artemis!DDB6010BF5EF
5600.6984

Panda Antivirus
Trj/Genetic.gen
14.10.07.05

Reason Heuristics
PUP.ClientConnect.I
14.10.7.17

Sophos
Conduit Search Protect
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
10314

VIPRE Antivirus
Conduit
33544

File size:
3.1 MB (3,242,456 bytes)

Product version:
2.17.26.7

Copyright:
© 2014 ClientConnect Ltd.

Original file name:
SearchProtect (R)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\searchprotect\ui\bin\cltmngui.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
6/19/2014 2:00:00 AM

Valid to:
6/20/2016 1:59:59 AM

Subject:
CN=ClientConnect LTD, OU=Search Protect 2, O=ClientConnect LTD, L=Ness Ziona, S=Israel, C=IL

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
552491364DFD4261C3C5D20F5503F94C

File PE Metadata
Compilation timestamp:
10/2/2014 8:16:01 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
98304:jeDwgH5HAU/fEsc+Nx7gYDWbHEcjoDTDD9DDDe0DDDDwCNSB:iH5AUlc+NZXDWIcUDTDD9DDDe0DDDDw9

Entry address:
0x1AAF13

Entry point:
E8, 10, AC, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 8D, 45, 14, 50, 6A, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, C4, AF, 00, 00, 83, C4, 14, 5D, C3, 55, 8B, EC, 51, 51, 8D, 45, F8, 50, FF, 15, 04, 01, 5F, 00, 8B, 4D, F8, 8B, 45, FC, 81, C1, 00, 80, C1, 2A, 6A, 00, 68, 80, 96, 98, 00, 15, 21, 4E, 62, FE, 50, 51, E8, 99, 45, 00, 00, 83, FA, 07, 7C, 0E, 7F, 07, 3D, FF, 6F, 40, 93, 76, 05, 83, C8, FF, 8B, D0, 8B, 4D, 08, 85, C9, 74, 05, 89, 01, 89, 51, 04, 8B, E5, 5D, C3, 55, 8B, EC, 56, E8, 42, BC, 00, 00...
 
[+]

Code size:
1.9 MB (2,027,008 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to a125-56.179-133.deploy.akamaitechnologies.com  (125.56.179.133:443)

TCP (HTTP):
Connects to ec2-54-243-151-8.compute-1.amazonaws.com  (54.243.151.8:80)

TCP (HTTP SSL):
Connects to a23-7-183-61.deploy.static.akamaitechnologies.com  (23.7.183.61:443)

TCP (HTTP SSL):
Connects to a23-58-184-191.deploy.static.akamaitechnologies.com  (23.58.184.191:443)

TCP (HTTP SSL):
Connects to a23-57-97-67.deploy.static.akamaitechnologies.com  (23.57.97.67:443)

TCP (HTTP SSL):
Connects to a23-46-55-61.deploy.static.akamaitechnologies.com  (23.46.55.61:443)

TCP (HTTP SSL):
Connects to a23-45-52-241.deploy.static.akamaitechnologies.com  (23.45.52.241:443)

TCP (HTTP SSL):
Connects to a23-44-176-238.deploy.static.akamaitechnologies.com  (23.44.176.238:443)

TCP (HTTP SSL):
Connects to a23-33-165-72.deploy.static.akamaitechnologies.com  (23.33.165.72:443)

TCP (HTTP SSL):
Connects to a23-3-224-190.deploy.static.akamaitechnologies.com  (23.3.224.190:443)

TCP (HTTP SSL):
Connects to a23-209-68-11.deploy.static.akamaitechnologies.com  (23.209.68.11:443)

TCP (HTTP SSL):
Connects to a23-208-216-11.deploy.static.akamaitechnologies.com  (23.208.216.11:443)

TCP (HTTP SSL):
Connects to a23-205-23-61.deploy.static.akamaitechnologies.com  (23.205.23.61:443)

TCP (HTTP SSL):
Connects to a23-203-240-11.deploy.static.akamaitechnologies.com  (23.203.240.11:443)

TCP (HTTP SSL):
Connects to a23-195-208-31.deploy.static.akamaitechnologies.com  (23.195.208.31:443)

TCP (HTTP SSL):
Connects to a23-192-32-11.deploy.static.akamaitechnologies.com  (23.192.32.11:443)

TCP (HTTP SSL):
Connects to a172-230-217-248.deploy.static.akamaitechnologies.com  (172.230.217.248:443)

TCP (HTTP SSL):
Connects to a172-228-54-164.deploy.static.akamaitechnologies.com  (172.228.54.164:443)

TCP (HTTP SSL):
Connects to a104-66-87-36.deploy.static.akamaitechnologies.com  (104.66.87.36:443)

Remove cltmngui.exe - Powered by Reason Core Security