cltmng.exe

Search Protect

Conduit Ltd.

The file belongs to the Conduit API platform, a utility that bundles and monetizes search toolbars and web browser extensions. The application cltmng.exe, “Search Protect by Conduit” by Conduit has been detected as a potentially unwanted program by 16 anti-malware scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘SearchProtect’. This file is typically installed with the program Search Protect by conduit by Conduit Ltd. which is a potentially unwanted software program.
Publisher:
Conduit  (signed by Conduit Ltd.)

Product:
Search Protect

Description:
Search Protect by Conduit

Version:
1.5.0.71

MD5:
e7bfaec48b638814f9da09ff1f4b723a

SHA-1:
fd93ccaeba15517ce2171a1637bc837d393ade8e

SHA-256:
42178c44cbb9c0a4f00261ec1802ba79ceaf9277d366b7bd272dea4ad6732757

Scanner detections:
16 / 68

Status:
Potentially unwanted

Explanation:
Part of the Conduit/ClientConnect toolbar/extension distribution.

Analysis date:
11/5/2024 10:04:31 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.BHO.BProtector.E
1088

avast!
Win32:SearchProtect-C [Adw]
2014.9-140211

Baidu Antivirus
Adware.Win32.BHO
4.0.3.131125

Bitdefender
Adware.BHO.BProtector.E
1.0.20.210

Bkav FE
W32.Clod703.Trojan
1.3.0.4613

Boost by Reason
Optional.Startup.Conduit.G
188838

Comodo Security
Application.Win32.Conduit.~A
17397

Dr.Web
Adware.BGuard.15
9.0.1.0206

Emsisoft Anti-Malware
Adware.BHO.BProtector
8.14.02.11.10

ESET NOD32
Win32/Conduit.SearchProtect (variant)
7.9142

G Data
Adware.BHO.BProtector
14.2.22

Malwarebytes
PUP.Optional.Conduit.A
v2013.11.25.12

MicroWorld eScan
Adware.BHO.BProtector.E
15.0.0.126

Panda Antivirus
PUP/Conduit.A
14.02.11.10

Reason Heuristics
PUP.Startup.Conduit.G
14.8.7.22

VIPRE Antivirus
Conduit
24088

File size:
2.7 MB (2,852,640 bytes)

Product version:
1.5.0.71

Copyright:
2012 (c) Conduit. All rights reserved.

Original file name:
SearchProtect (R) P

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\searchprotect\bin\cltmng.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/2/2013 4:00:00 PM

Valid to:
4/3/2016 4:59:59 PM

Subject:
CN=Conduit Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Conduit Ltd., L=Ness Ziona, S=Israel, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3A82654719D8F75B59134F7B66465210

File PE Metadata
Compilation timestamp:
5/7/2013 11:16:09 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:K15MbZ9SR+d8e8u8+FxeB3V/1MhI50zJFur9S4JjbZvTnM/ID09nVUb53Uqd:VbZ9SR+aeZvFxo3V9MOQ6d

Entry address:
0x146FF0

Entry point:
E8, 15, 04, 00, 00, E9, 6B, FD, FF, FF, FF, 25, 34, B6, 5E, 00, FF, 25, 30, B6, 5E, 00, FF, 25, 2C, B6, 5E, 00, FF, 25, 28, B6, 5E, 00, FF, 25, 24, B6, 5E, 00, FF, 25, 1C, B6, 5E, 00, FF, 25, 14, B6, 5E, 00, FF, 25, 10, B6, 5E, 00, FF, 25, 08, B6, 5E, 00, FF, 25, FC, B5, 5E, 00, FF, 25, F8, B5, 5E, 00, FF, 25, F4, B5, 5E, 00, FF, 25, E8, B5, 5E, 00, FF, 25, E4, B5, 5E, 00, FF, 25, D4, B5, 5E, 00, FF, 25, 74, B5, 5E, 00, 6A, 10, 68, E8, F8, 62, 00, E8, 5A, 05, 00, 00, 33, C0, 89, 45, E0, 89, 45, FC, 89, 45...
 
[+]

Entropy:
6.5236

Code size:
1.9 MB (2,004,992 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SearchProtect

Command:
C:\users\{user}\appdata\roaming\searchprotect\bin\cltmng.exe


Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SearchProtectAll

Command:
C:\Program Files\searchprotect\bin\cltmng.exe


The file cltmng.exe has been discovered within the following programs.

Search Protect by conduit  by Conduit Ltd.
The Conduit Search Protect software is designed to prevent other competing web browser plugins from changing the homepage and search settings that are created by the Conduit OurToolbar from being changed automatically. It is typically installed with various Community toolbars.
www.conduit.com/privacy/search-protect-privacy-policy.aspx
82% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-23-23-99-139.compute-1.amazonaws.com  (23.23.99.139:80)

TCP (HTTP):
Connects to ec2-54-225-182-66.compute-1.amazonaws.com  (54.225.182.66:80)

TCP (HTTP SSL):
Connects to a23-46-131-152.deploy.static.akamaitechnologies.com  (23.46.131.152:443)

TCP (HTTP SSL):
Connects to a23-34-48-11.deploy.static.akamaitechnologies.com  (23.34.48.11:443)

TCP (HTTP SSL):
Connects to a104-82-60-175.deploy.static.akamaitechnologies.com  (104.82.60.175:443)

TCP (HTTP SSL):
Connects to a184-27-113-197.deploy.static.akamaitechnologies.com  (184.27.113.197:443)

TCP (HTTP SSL):
Connects to a184-26-173-48.deploy.static.akamaitechnologies.com  (184.26.173.48:443)

TCP (HTTP SSL):
Connects to a184-29-184-72.deploy.static.akamaitechnologies.com  (184.29.184.72:443)

TCP (HTTP SSL):
Connects to a184-27-177-128.deploy.static.akamaitechnologies.com  (184.27.177.128:443)

TCP (HTTP):

TCP (HTTP SSL):
Connects to a23-74-71-61.deploy.static.akamaitechnologies.com  (23.74.71.61:443)

TCP (HTTP SSL):
Connects to a104-97-75-49.deploy.static.akamaitechnologies.com  (104.97.75.49:443)

TCP (HTTP SSL):
Connects to a104-97-136-212.deploy.static.akamaitechnologies.com  (104.97.136.212:443)

TCP (HTTP SSL):
Connects to a23-57-48-71.deploy.static.akamaitechnologies.com  (23.57.48.71:443)

TCP (HTTP):

TCP (HTTP SSL):
Connects to a23-74-67-152.deploy.static.akamaitechnologies.com  (23.74.67.152:443)

TCP (HTTP):

TCP (HTTP SSL):
Connects to a23-13-225-91.deploy.static.akamaitechnologies.com  (23.13.225.91:443)

TCP (HTTP SSL):
Connects to a104-81-135-228.deploy.static.akamaitechnologies.com  (104.81.135.228:443)

TCP (HTTP SSL):
Connects to a104-74-141-241.deploy.static.akamaitechnologies.com  (104.74.141.241:443)

Remove cltmng.exe - Powered by Reason Core Security