Should I block it?

98%
Yes, 98% block recommendation.
Possible reasons:
Multiple malware detections
Performance resource utilization

VersionsAdditional versions

2.10.31.0 2.90%
2.9.8.2 1.45%
2.8.11.9 2.90%
2.7.23.2 1.45%
2.7.14.4 2.90%
1.7.0.72 2.90%
1.5.0.71 24.64%
1.4.3.7 2.90%
1.4.2.2 1.45%
1.4.1.12 20.29%
1.4.0.65 17.39%
1.3.0.184 1.45%
1.2.5.2 4.35%
1.2.3.6 11.59%
1.2.2.4 1.45%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegCloseKey, RegisterEventSourceW, ReportEventW, DeregisterEventSource, SetServiceStatus, ImpersonateLoggedOnUser, RegOpenCurrentUser, RevertToSelf, RegOpenKeyW, RegQueryValueExW, RegDeleteValueW, QueryServiceStatusEx, ControlService, RegisterServiceCtrlHandlerW, OpenServiceW, CloseServiceHandle, OpenSCManagerW, CreateServiceW, ChangeServiceConfig2W, StartServiceW, DeleteService, StartServiceCtrlDispatcherW, RegisterServiceCtrlHandlerExW, RegisterEventSourceA, ReportEventA, OpenThreadToken, AllocateAndInitializeSid, FreeSid, CheckTokenMembership, ChangeServiceConfigW, RegOpenKeyExW, ConvertSidToStringSidW, DuplicateTokenEx, CreateProcessAsUserW, GetTokenInformation, OpenProcessToken
crypt32.dll
CryptQueryObject, CryptMsgGetParam, CertFindCertificateInStore, CertGetNameStringW, CertFreeCertificateContext, CertCloseStore, CryptMsgClose
dbghelp.dll
MiniDumpWriteDump
kernel32.dll
GetCommandLineW, GetCurrentProcessId, GetCurrentProcess, GetLongPathNameW, MoveFileExW, FormatMessageA, InterlockedExchange, InterlockedCompareExchange, HeapSetInformation, GetStartupInfoW, EncodePointer, DecodePointer, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, QueryPerformanceCounter, GetCurrentThreadId, GetSystemTimeAsFileTime, LocalAlloc, GetModuleFileNameW, WaitForSingleObject, Sleep, GetTickCount, CloseHandle, CreateProcessW, GetFileAttributesW, CreateEventW, SetEvent, GetLastError, LocalFree, WaitForMultipleObjects, OpenProcess, WTSGetActiveConsoleSessionId, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, CreateEventA, InitializeCriticalSectionAndSpinCount, InitializeCriticalSection, TryEnterCriticalSection, DuplicateHandle, SetLastError, FlushConsoleInputBuffer, GetVersion, DeviceIoControl, SetEndOfFile, ReadConsoleW, ReadConsoleInputA, ExitThread, SetEnvironmentVariableA, FlushFileBuffers, WriteConsoleW, SetStdHandle, SetEnvironmentVariableW, GetCurrentThread, GetVersionExW, ProcessIdToSessionId, ResetEvent, TerminateThread, LoadLibraryA, GetProcAddress, MultiByteToWideChar, LoadLibraryW, GetVersionExA, GetModuleHandleW, FreeLibrary, GetModuleHandleExW, GetUserDefaultLCID, GetLocaleInfoW, GetSystemInfo, CreateMutexW, WideCharToMultiByte, TlsSetValue, TlsGetValue, TlsAlloc, GetFileAttributesExW, CreateFileW, SetFilePointer, WriteFile, ReleaseMutex, GetFileSize, ReadFile, GetDiskFreeSpaceExW, CreateDirectoryW, GetModuleHandleExA, GetModuleFileNameA, SetConsoleMode, RaiseException, GetProcessHeap, HeapFree, HeapAlloc, LockFileEx, UnlockFileEx, lstrcpynA, lstrcpyA, lstrlenA, FileTimeToLocalFileTime, FileTimeToDosDateTime, CreateFileA, GetFileTime, VirtualQuery, GetModuleHandleA, OutputDebugStringA, GlobalMemoryStatus, GetLocalTime, InterlockedIncrement, InterlockedDecrement, GetStringTypeW, OpenEventA, ReleaseSemaphore, SetWaitableTimer, ResumeThread, TlsFree, CreateWaitableTimerA, SystemTimeToFileTime, IsProcessorFeaturePresent, HeapReAlloc, CreateThread, LoadLibraryExW, GetCPInfo, ExitProcess, AreFileApisANSI, RtlUnwind, CreateSemaphoreW, GetDateFormatW, GetTimeFormatW, CompareStringW, LCMapStringW, IsValidLocale, EnumSystemLocalesW, HeapSize, GetStdHandle, IsValidCodePage, GetACP, GetOEMCP, GetFileType, GetEnvironmentStringsW, FreeEnvironmentStringsW, SetConsoleCtrlHandler, GetTimeZoneInformation, OutputDebugStringW, GetConsoleCP, GetConsoleMode, SetFilePointerEx
msvcp100.dll
DllMain
msvcr100.dll
DllMain
ole32.dll
CoCreateGuid, StringFromGUID2
rpcrt4.dll
RpcObjectInqType, RpcImpersonateClient, I_RpcBindingInqLocalClientPID, RpcServerUseProtseqEpW, NdrServerCall2, RpcBindingSetObject, RpcBindingFromStringBindingW, RpcStringBindingComposeW, RpcEpResolveBinding, RpcBindingFree, RpcStringFreeW, NdrClientCall2, RpcBindingInqObject, RpcObjectSetType, RpcServerUnregisterIfEx, RpcServerRegisterIfEx, RpcRevertToSelfEx, I_RpcBindingInqTransportType
shell32.dll
CommandLineToArgvW, SHGetFolderPathW
shlwapi.dll
PathFileExistsW
user32.dll
GetSystemMetrics, RegisterClassW, SetTimer, KillTimer, PostThreadMessageW, DefWindowProcW, CreateWindowExW, SetWindowLongW, MessageBoxA, GetDesktopWindow, GetProcessWindowStation, GetUserObjectInformationW, DestroyWindow, GetMessageW, PostQuitMessage, DispatchMessageW, GetWindowLongW, RegisterClassExW, TranslateMessage, PostMessageW, UnregisterClassW
userenv.dll
DestroyEnvironmentBlock, CreateEnvironmentBlock
version.dll
GetFileVersionInfoSizeA, VerQueryValueA, GetFileVersionInfoA
wtsapi32.dll
WTSQueryUserToken, WTSEnumerateSessionsW, WTSRegisterSessionNotification, WTSEnumerateProcessesW, WTSFreeMemory, WTSOpenServerW, WTSUnRegisterSessionNotification, WTSCloseServer

cltmngsvc.exe

Search Protect by Conduit Ltd. (Signed)

Remove cltmngsvc.exe
Version:   1.4.1.12
MD5:   09d38aec081f064fd67b8b9c49790020
SHA1:   77448bd92178191ef5a4d6a6a0a7fb1b8b45f3b8
SHA256:   3093eb543d346be006565e895f66f4f651b21eadedfb8e3c3e2a4b81acd42114
Warning 10 antivirus scanners has detected malware.

Overview

cltmngsvc.exe is malware that runs as a service under the name Search Protect by Conduit Service (CltMngSvc) with extensive SYSTEM privileges (full administrator access). It is installed with a couple of know programs including Search Protect by conduit published by Conduit Ltd., Search Protect by conduit from Conduit Ltd. and Search Protect by conduit by Conduit Ltd.. The file is digitally signed by Conduit Ltd. which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:cltmngsvc.exe
Publisher:Conduit
Product name:Search Protect
Description:Search Protect by Conduit
Typical file path:C:\Program Files\searchprotect\bin\cltmngsvc.exe
Original name:SearchProtect (R)
File version:1.4.1.12
Size:91.78 KB (93,984 bytes)
Certificate
Issued to:Conduit Ltd.
Authority (CA):VeriSign
Expiration date:Sunday, April 3, 2016
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 10.0
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
Conduit Ltd.
  82% remove
The Conduit Search Protect software is designed to prevent other competing web browser plugins from changing the homepage and search settings that are created by the Conduit OurToolbar from being changed automatically. It is typically installed with various Community toolbars. During install of a Conduit Toolbar, you by default except the EULA to install the included SearchProtect software (which is required). Upon installation the p...

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'CltMngSvc' (Search Protect by Conduit Service)
  • CltMngSvc

MalwareMalware detections

Based on 40+ industry antivirus scanners, 10 of them detected the following malware.
Antivirus engineEngine versionDetection
Bkav Security 1.3.0.4923 W32.Clod68e.Trojan.7e43
Dr.Web 8.13.8.11 Adware.BGuard.15
eSafe 7.0.17.0 Win32.Trojan
ESET NOD32 7.9338 Win32/Conduit.SearchProtect.A
G Data 14.2.24 Win32.Trojan.Agent.DPJ5P0
Kingsoft 2013.4.9.267 Win32.Troj.Agent.xh.(kcloud)
Malwarebytes 1.75.0.1 PUP.Optional.Conduit.A
NANO AntiVirus 0.28.0.57380 Trojan.Win32.BGuard.cracok
Panda Antivirus 10.0.3.5 Adware/Conduit
VIPRE Antivirus 25818 Conduit (fs)

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00337697%
0.028634%
Kernel CPU:0.00129860%
0.013761%
User CPU:0.00207837%
0.014873%
Kernel CPU time:2,945 ms/min
100,923,805ms/min
CPU cycles:238,405/sec
17,470,203/sec
Context switches:2/sec
284/sec
Memory
Private memory:3.38 MB
21.59 MB
Private (maximum):3.4 MB
Private (minimum):2.41 MB
Non-paged memory:3.38 MB
21.59 MB
Virtual memory:46.82 MB
140.96 MB
Virtual memory (peak):48.2 MB
169.69 MB
Working set:2.91 MB
18.61 MB
Working set (peak):4.49 MB
37.95 MB
Page faults:14,181/min
2,039/min
I/O
I/O read transfer:88 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O other transfer:4 Bytes/sec
448.09 KB/min
I/O other operations:1/sec
1,671/min
Resource allocations
Threads:6
12
Handles:86
600

BehaviorsProcess properties

Integrety level:System
Platform:64-bit
Command line:"C:\Program Files\searchprotect\bin\cltmngsvc.exe"
Owner:SYSTEM
Windows Service
Service name:CltMngSvc
Display name:Search Protect by Conduit Service
Description:“This service loads the Search Protector, which maintains your selected Search settings, and enables auto-updates.”
Type:Win32OwnProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
wow64.dll
Total CPU:0.02000117%
0.272967%
Kernel CPU:0.00812548%
0.107585%
User CPU:0.01187570%
0.165382%
CPU cycles:673,348/sec
5,741,424/sec
Context switches:2/sec
79/sec
Memory:252 KB
1.16 MB
sechost.dll
Total CPU:0.00798026%
Kernel CPU:0.00306354%
User CPU:0.00491673%
CPU cycles:460,911/sec
Context switches:2/sec
Memory:100 KB
CltMngSvc.exe (main module)
Total CPU:0.00094284%
Kernel CPU:0.00047200%
User CPU:0.00047084%
CPU cycles:15,762/sec
Memory:96 KB

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 40.58%
Windows 7 Ultimate 23.19%
Microsoft Windows XP 8.70%
Windows 7 Professional 7.25%
Windows 8 Pro 5.80%
Windows 8 4.35%
Windows Vista Home Premium 4.35%
Windows 7 Starter 2.90%
Windows Vista Ultimate 2.90%

Distribution by countryDistribution by country

United States installs about 53.62% of Search Protect.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Toshiba 25.64%
Hewlett-Packard 21.79%
Dell 20.51%
Acer 17.95%
ASUS 5.13%
Compaq 2.56%
Samsung 2.56%
Lenovo 2.56%
Sahara 1.28%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE