Should I block it?

98%
Yes, 98% block recommendation.
Possible reasons:
Multiple malware detections
Performance resource utilization

VersionsAdditional versions

2,6,1562,220 16.67%
2,6,1339,144 83.33%

Relationships

Parent processes
Child processes
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
AddAce, ConvertStringSecurityDescriptorToSecurityDescriptorW, RegQueryInfoKeyW, RegEnumKeyExW, StartServiceCtrlDispatcherW, RegisterServiceCtrlHandlerW, GetTokenInformation, DuplicateTokenEx, CreateProcessAsUserW, OpenSCManagerW, OpenServiceW, QueryServiceConfigW, ChangeServiceConfigW, CloseServiceHandle, SetServiceStatus, RegEnumKeyW, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, ConvertStringSecurityDescriptorToSecurityDescriptorA, GetSecurityDescriptorSacl, SetSecurityDescriptorSacl, RegSetValueExW, RegQueryValueExW, RegCloseKey, RegCreateKeyExW, RegOpenKeyExW, RegEnumValueW, CreateServiceW, ChangeServiceConfig2W, StartServiceW, ControlService, RegDeleteValueW, RegDeleteKeyW, DeleteService, RegisterEventSourceA, ReportEventA, DeregisterEventSource, IsValidSid, ConvertSidToStringSidW, GetLengthSid, InitializeAcl, OpenThreadToken, OpenProcessToken, GetSecurityInfo, GetAclInformation, SetSecurityInfo, DeleteAce, GetAce
gdi32.dll
CreateFontIndirectW, GetObjectW, DeleteObject, SelectObject, SetBkMode, SetTextColor, Rectangle, CreatePen, DeleteDC, RoundRect, CreateSolidBrush, CreatePatternBrush, BitBlt, CreateCompatibleBitmap, CreateDIBSection, CreateCompatibleDC
kernel32.dll
DllMain
ole32.dll
CoInitialize, CoUninitialize, CoCreateInstance, StringFromGUID2, CoInitializeEx, CoInitializeSecurity, CoSetProxyBlanket
rpcrt4.dll
UuidFromStringA
shell32.dll
SHGetSpecialFolderPathW, CommandLineToArgvW
shlwapi.dll
SHGetValueW, PathRemoveFileSpecW, PathIsDirectoryW, PathFindFileNameW, StrCmpW, StrCpyW, StrCmpNIW, PathStripPathW, PathRemoveExtensionW, PathFindExtensionW, PathAddExtensionW, PathFileExistsW, PathStripToRootW, PathIsRootW, PathAppendW
user32.dll
GetWindowRect, ShowWindow, ScreenToClient, KillTimer, ChildWindowFromPoint, MoveWindow, SetTimer, PeekMessageW, GetMessageW, TranslateMessage, DispatchMessageW, SystemParametersInfoW, GetClassInfoExW, LoadCursorW, IsWindow, EndDialog, DestroyWindow, RegisterClassExW, CreateWindowExW, GetUserObjectInformationW, GetProcessWindowStation, GetDesktopWindow, MessageBoxA, MessageBoxW, SetFocus, SetWindowPos, MapWindowPoints, GetMonitorInfoW, MonitorFromWindow, GetWindow, UnregisterClassA, LoadStringA, GetActiveWindow, GetTopWindow, TrackMouseEvent, GetCursorPos, LoadImageW, GetDlgItem, SendMessageW, GetSystemMetrics, DrawTextW, GetWindowTextW, GetWindowTextLengthW, DialogBoxParamW, CallWindowProcW, GetWindowLongW, DefWindowProcW, SetWindowLongW, SetWindowTextW, FindWindowW, SetLayeredWindowAttributes, FillRect, ReleaseDC, GetDC, GetSysColor, GetSysColorBrush, GetParent, InvalidateRect, EndPaint, BeginPaint, GetClientRect
userenv.dll
CreateEnvironmentBlock
uxtheme.dll
OpenThemeData, CloseThemeData, DrawThemeBackground, IsThemeBackgroundPartiallyTransparent, DrawThemeParentBackground
version.dll
GetFileVersionInfoSizeW, VerQueryValueW, GetFileVersionInfoW
winhttp.dll
WinHttpReceiveResponse, WinHttpAddRequestHeaders, WinHttpQueryDataAvailable, WinHttpReadData, WinHttpOpen, WinHttpSendRequest, WinHttpOpenRequest, WinHttpQueryHeaders, WinHttpConnect, WinHttpCloseHandle, WinHttpGetProxyForUrl, WinHttpGetIEProxyConfigForCurrentUser, WinHttpSetOption, WinHttpSetStatusCallback
wtsapi32.dll
WTSQueryUserToken

browserdefender.exe

Application Manager by Bit89 Inc. (Signed)

Remove browserdefender.exe
Version:   2,6,1339,144
MD5:   013a330f16b1cecbde5cb6f921689523
SHA1:   9c1f62b0654c2e3193f608ef490de5495708a583
SHA256:   6479863dd0ce70b802697d82d71a0efe620555cafb3fec9990150a6d3526cbfd
Warning 15 antivirus scanners has detected malware.

Overview

browserdefender.exe is malware that runs as a service under the name BrowserDefendert with extensive SYSTEM privileges (full administrator access) as a shared service. This is typically installed with the program BrowserDefender published by Bit89 Inc and is most likely removed by most users once installed (80% removed). The file is digitally signed by Bit89 Inc. which was issued by the GoDaddy.com certificate authority (CA).

DetailsDetails

File name:browserdefender.exe
Publisher:PerformerSoft LLC
Product name:Application Manager
Typical file path:C:\ProgramData\browserdefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\browserdefender.exe
File version:2,6,1339,144
Size:2.7 MB (2,827,728 bytes)
Build date:5/23/2013 2:09 AM
Certificate
Issued to:Bit89 Inc.
Authority (CA):GoDaddy.com
Effective date:Tuesday, September 4, 2012
Expiration date:Friday, September 4, 2015
Digital DNA
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
Bit89 Inc
  80% remove
PerformerSoft/Bit89 BrowserDefender, a variant of the Browser Protector Software is a web browser add-in classified mostly a potentially unwanted application that used to be bundled with PerformerSoft products including PC Performer. BrowserDefender is designed to protect its bundled programs and make sure they remain installed or unchanged by other third party programs. It does this by preventing changes to the registry by other progra...

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' as a shared service by the Service Host (svchost.exe)
  • 'BrowserDefendert'

MalwareMalware detections

Based on 40+ industry antivirus scanners, 15 of them detected the following malware.
Antivirus engineEngine versionDetection
Avira AntiVir 7.11.104.164 APPL/BProtector.Gen
avast! 8.0.1489.320 Win32:BProtect-A [PUP]
AVG 13.0.0.3169 Generic5.AFZM
Dr.Web 8.13.9.29 Adware.BGuard.18
ESET NOD32 7.8846 a variant of Win32/bProtector.A
G Data 13.9.22 Win32.Application.BHO.A
Kaspersky 9.0.0.837 not-a-virus:AdWare.Win32.Bromngr.k
Kingsoft 2013.4.9.267 Win32.Troj.Generic.a.(kcloud)
Malwarebytes 1.75.0.1 PUP.Optional.PerformerSoft.A
McAfee 5.600.1067 Adware-Bprotect.b
McAfee Gateway Anti-Malware v2013-dat Artemis!013A330F16B1
PC Tools 9.0.0.2 Adware.GoonSquad!rem
Sophos 4.93.0 BProtector
Symantec 20131.1.5.61 Adware.GoonSquad
VIPRE Antivirus 21842 Bprotector (fs)

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00856604%
0.028634%
Kernel CPU:0.00357416%
0.013761%
User CPU:0.00499188%
0.014873%
Kernel CPU time:369,391,866 ms/min
100,923,805ms/min
CPU cycles:917,833/sec
17,470,203/sec
Context switches:12/sec
284/sec
Memory
Private memory:3.71 MB
21.59 MB
Private (maximum):7.44 MB
Private (minimum):4.34 MB
Non-paged memory:3.71 MB
21.59 MB
Virtual memory:163.17 MB
140.96 MB
Virtual memory (peak):186.8 MB
169.69 MB
Working set:5.47 MB
18.61 MB
Working set (peak):7.6 MB
37.95 MB
Page faults:55,230,324/min
2,039/min
I/O
I/O read transfer:508 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O write transfer:27 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:176 Bytes/sec
448.09 KB/min
I/O other operations:3/sec
1,671/min
Resource allocations
Threads:10
12
Handles:233
600
GUI GDI count:9
103
GUI GDI peak:20
142
GUI USER count:4
49
GUI USER peak:13
71

BehaviorsProcess properties

Integrety level:Undefined
Platform:32-bit
Command lines:
  • C:\ProgramData\browserdefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\browserdefender.exe
  • "C:\ProgramData\browserdefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\browserdefender.exe" /protect
  • "C:\Documents and Settings\user\Application data\browserdefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\browserdefender.exe" /protect
  • "C:\Documents and Settings\user\Application data\browserdefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\browserdefender.exe"
  • "C:\dokumente und einstellungen\all users\anwendungsdaten\browserdefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\browserdefender.exe"
  • "C:\dokumente und einstellungen\all users\anwendungsdaten\browserdefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\browserdefender.exe" /protect
  • (7 more)
Owner:SYSTEM
Windows Service
Service name:BrowserDefendert
Description:“Your browser protector service”
Type:Win32ShareProcess
Parent processes:

ResourcesThreads

Averages
 
BrowserDefender.exe (main module)
Total CPU:0.25128511%
0.272967%
Kernel CPU:0.21866693%
0.107585%
User CPU:0.03261817%
0.165382%
CPU cycles:6,614,845/sec
5,741,424/sec
Context switches:12/sec
79/sec
Memory:2.78 MB
1.16 MB
browserdefender.dll (Application Manager by PerformerSoft LLC)
Total CPU:0.01078797%
Kernel CPU:0.00570923%
User CPU:0.00507874%
CPU cycles:159,220/sec
Context switches:1/sec
Memory:2.52 MB
ADVAPI32.dll
Total CPU:0.00213762%
Kernel CPU:0.00000000%
User CPU:0.00213762%
Memory:620 KB
wow64.dll
Total CPU:0.00007530%
Kernel CPU:0.00007530%
User CPU:0.00000000%
CPU cycles:38,363/sec
Context switches:2/sec
Memory:276 KB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 35.56%
Microsoft Windows XP 33.33%
Windows 8 8.89%
Windows 8 Pro 6.67%
Windows Vista Home Premium 6.67%
Windows 7 Home Premium 4.44%
Windows Vista Ultimate 2.22%
Windows 7 Professional 2.22%

Distribution by countryDistribution by country

Vietnam installs about 14.29% of Application Manager.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 37.74%
Acer 22.64%
Hewlett-Packard 15.09%
Intel 11.32%
Toshiba 7.55%
American Megatrends 5.66%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE