protectwindowsmanager.exe

WindowsProtectManger control

Fuyu LIMITED

The application protectwindowsmanager.exe, “WindowsProtectManger Service” has been detected as a potentially unwanted program by 7 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “WindowsMangerProtect Service”.
Publisher:
Fuyu LIMITED

Product:
WindowsProtectManger control

Description:
WindowsProtectManger Service

Version:
20.0.0.1270

MD5:
eb4cb42caf84f853523799f8d51795f7

SHA-1:
78e20f7af5df9c162281b1149fdda24fd96f311c

SHA-256:
b96f7cdc53e1eb04638fe78b02b5ee4603ec0a249bd9e8d78e2de70a9a486448

Scanner detections:
7 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 10:02:19 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/Adware.Gen
7.11.188.106

Baidu Antivirus
Adware.Win32.ELEX
4.0.3.141126

ESET NOD32
Win32/ELEX.BC (variant)
8.10771

Fortinet FortiGate
Riskware/Elex
11/26/2014

Malwarebytes
PUP.Optional.WindowsProtectManger.A
v2014.11.26.10

Sophos
Generic PUA HI
4.98

Trend Micro House Call
Suspicious_GEN.F47V1123
7.2.330

File size:
473 KB (484,352 bytes)

Product version:
20.0.0.1270

Copyright:
Copyright (C) 2013

Original file name:
WindowsProtectManger.exe

File type:
Executable application (Win32 EXE)

Language:
English (United Kingdom)

Common path:
C:\ProgramData\windowsmangerprotect\protectwindowsmanager.exe

File PE Metadata
Compilation timestamp:
11/21/2014 5:08:40 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:DHZWmdtN4jubhyhdvxsx+qKaq4Qi3x7BkJD/yhUEqO7/Iw7pyUIY7wrpS:DHZWoNFY7xsgbrxi3xdvUnY/IwtEFpS

Entry address:
0x1CA95

Entry point:
E8, 90, DF, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 8B, 55, 14, 8B, 4D, 08, 56, 85, D2, 75, 0D, 85, C9, 75, 0D, 39, 4D, 0C, 75, 21, 33, C0, EB, 2E, 85, C9, 74, 19, 8B, 45, 0C, 85, C0, 74, 12, 85, D2, 75, 04, 88, 11, EB, E9, 8B, 75, 10, 85, F6, 75, 17, C6, 01, 00, E8, AD, 06, 00, 00, 6A, 16, 5E, 89, 30, E8, 8F, 72, 00, 00, 8B, C6, 5E, 5D, C3, 53, 57, 8B, D9, 8B, F8, 83, FA, FF, 75, 11, 2B, DE, 8A, 06, 88, 04, 33, 46, 84, C0, 74, 1D, 4F, 75, F3, EB, 18, 2B, F1, 8A, 04, 1E, 88, 03, 43, 84, C0, 74, 06, 4F, 74...
 
[+]

Code size:
313 KB (320,512 bytes)

Service
Display name:
WindowsMangerProtect Service

Service name:
WindowsMangerProtect

Description:
WindowsMangerProtect service

Type:
Win32OwnProcess

Group:
SchedulerGroup


Remove protectwindowsmanager.exe - Powered by Reason Core Security