Should I block it?

98%
Yes, 98% block recommendation.
Possible reasons:
Multiple malware detections
Performance resource utilization

VersionsAdditional versions

2,6,1249,132 50.00%
2,4,897,176 25.00%
2,3,813,156 25.00%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
CloseServiceHandle, RegisterEventSourceA, StartServiceW, ChangeServiceConfig2W, CreateServiceW, RegEnumValueW, ConvertStringSecurityDescriptorToSecurityDescriptorW, RegQueryInfoKeyW, RegEnumKeyExW, StartServiceCtrlDispatcherW, RegisterServiceCtrlHandlerW, GetTokenInformation, DuplicateTokenEx, CreateProcessAsUserW, SetServiceStatus, RegEnumKeyW, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, ConvertStringSecurityDescriptorToSecurityDescriptorA, GetSecurityDescriptorSacl, SetSecurityDescriptorSacl, RegSetValueExW, RegQueryValueExW, RegCloseKey, RegCreateKeyExW, RegOpenKeyExW, DeregisterEventSource, IsValidSid, ConvertSidToStringSidW, GetLengthSid, InitializeAcl, ReportEventA, AddAce, OpenThreadToken, OpenProcessToken, GetSecurityInfo, GetAclInformation, GetAce, DeleteAce, SetSecurityInfo, RegDeleteKeyW, RegDeleteValueW, DeleteService, ControlService, OpenServiceW, OpenSCManagerW, QueryServiceConfigW, ChangeServiceConfigW
gdi32.dll
CreateDIBSection, CreateFontIndirectW, GetObjectW, DeleteObject, SelectObject, SetBkMode, SetTextColor, Rectangle, CreatePen, RoundRect, CreateSolidBrush, CreatePatternBrush, CreateCompatibleDC, BitBlt, CreateCompatibleBitmap, DeleteDC
kernel32.dll
DllMain
ole32.dll
StringFromGUID2, CoInitializeEx, CoInitializeSecurity, CoInitialize, CoUninitialize, CoCreateInstance, CoSetProxyBlanket
rpcrt4.dll
UuidFromStringA
shell32.dll
SHFileOperationW, CommandLineToArgvW, SHGetSpecialFolderPathW
shlwapi.dll
PathFileExistsW, PathAddExtensionW, PathAppendW, PathFindExtensionW, PathRemoveExtensionW, PathStripPathW, StrCpyW, PathFindFileNameW, PathIsDirectoryW, PathRemoveFileSpecW, StrCmpW, SHGetValueW, StrCmpNIW, PathIsRootW, PathRenameExtensionW, PathStripToRootW, PathRemoveFileSpecA
user32.dll
GetParent, InvalidateRect, EndPaint, BeginPaint, GetClientRect, GetWindowTextLengthW, MessageBoxA, GetClassInfoExW, LoadCursorW, IsWindow, FindWindowW, DestroyWindow, GetSysColorBrush, CreateWindowExW, GetUserObjectInformationW, GetProcessWindowStation, GetDesktopWindow, MessageBoxW, SetFocus, SetWindowPos, MapWindowPoints, GetMonitorInfoW, MonitorFromWindow, GetWindow, UnregisterClassA, GetWindowTextW, DrawTextW, GetSystemMetrics, LoadImageW, DialogBoxParamW, GetSysColor, GetWindowRect, GetDC, GetCursorPos, TrackMouseEvent, GetTopWindow, ChildWindowFromPoint, ReleaseDC, FillRect, SetLayeredWindowAttributes, GetActiveWindow, LoadStringA, KillTimer, ShowWindow, ScreenToClient, MoveWindow, EndDialog, GetDlgItem, SendMessageW, SetWindowTextW, SetTimer, PeekMessageW, GetMessageW, TranslateMessage, DispatchMessageW, SystemParametersInfoW, CallWindowProcW, GetWindowLongW, SetWindowLongW, DefWindowProcW, SetWindowsHookExW, UnhookWindowsHookEx, RegisterClassExW
userenv.dll
CreateEnvironmentBlock
uxtheme.dll
DrawThemeParentBackground, DrawThemeBackground, OpenThemeData, CloseThemeData, IsThemeBackgroundPartiallyTransparent
version.dll
GetFileVersionInfoSizeW, GetFileVersionInfoW, VerQueryValueW
winhttp.dll
WinHttpReadData, WinHttpQueryDataAvailable, WinHttpAddRequestHeaders, WinHttpOpen, WinHttpConnect, WinHttpSetStatusCallback, WinHttpSetOption, WinHttpGetIEProxyConfigForCurrentUser, WinHttpCloseHandle, WinHttpSendRequest, WinHttpOpenRequest, WinHttpQueryHeaders, WinHttpReceiveResponse, WinHttpGetProxyForUrl
wtsapi32.dll
WTSQueryUserToken

etypemngr.exe

Application Manager by Bit89 Inc. (Signed)

Remove etypemngr.exe
Version:   2,4,897,176
MD5:   432348fc02e4293c42c66fe123f0641e
SHA1:   665db8920e662ca4358e86ced8180a2ea10b2e24
SHA256:   a28ab6af0cbc73ed4512fc5caf90701221c4d7c981363afa574a2c49c51d59fd
Warning 14 antivirus scanners has detected malware.

What is etypemngr.exe?

The PerformerSoft Browser Manager (Application Manager) program classified mostly as exhibiting adware like actions, is bundled with PerformerSoft products including PC Performer. Browser Manager is designed to protect its bundled programs and make sure they remain installed or unchanged by other thrid party programs. The Browser Manager program was developed by Bit89 (Bit89.com) a know adware maker.

About etypemngr.exe (from Bit89 Inc.)

eType is your online multi-language dictionary with translations and word substitutes to virtually any language in the world. eType is your writing guide that auto-completes your words as you type the

DetailsDetails

File name:etypemngr.exe
Publisher:PerformerSoft LLC
Product name:Application Manager
Typical file path:C:\ProgramData\etype manager\2.3.813.156\{52de144c-c70b-4e0a-9b16-29a2e18c255e}\etypemngr.exe
File version:2,4,897,176
Size:2.29 MB (2,400,792 bytes)
Certificate
Issued to:Bit89 Inc.
Authority (CA):GoDaddy.com
Effective date:Tuesday, September 4, 2012
Expiration date:Friday, September 4, 2015
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' as a shared service by the Service Host (svchost.exe)
  • Browser Manager
  • 'eType Manager'

MalwareMalware detections

Based on 40+ industry antivirus scanners, 14 of them detected the following malware.
Antivirus engineEngine versionDetection
Avira AntiVir 7.11.61.114 Adware/Agent.2400792
AVG 2014.0.3629 Generic5.SCR
ESET NOD32 7.8018 a variant of Win32/bProtector.A
Fortinet 5.0.43.0 Adware/Bromngr
K7 AntiVirus 9.160.8224 Adware
Kaspersky 9.0.0.837 not-a-virus:AdWare.Win32.Bromngr.b
McAfee 5.400.1158 Artemis!432348FC02E4
McAfee Gateway Anti-Malware v2012.1-dat Artemis!432348FC02E4
nProtect 2013-02-16.01 Trojan-Clicker/W32.Agent.2400792
Panda Antivirus 10.0.3.5 Trj/OCJ.C
Trend Micro 9.740.0.1012 TROJ_SPNR.0BLJ12
Trend Micro HouseCall 9.700.0.1001 TROJ_SPNR.0BLJ12
Vba32 AntiVirus 3.12.20.2 AdWare.Bromngr.b
VIPRE Antivirus 15594 Bprotector (fs)

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00652756%
0.028634%
Kernel CPU:0.00351709%
0.013761%
User CPU:0.00301047%
0.014873%
Kernel CPU time:13,179 ms/min
100,923,805ms/min
Memory
Private memory:2.77 MB
21.59 MB
Private (maximum):524 KB
Private (minimum):464 KB
Non-paged memory:2.77 MB
21.59 MB
Virtual memory:162.1 MB
140.96 MB
Virtual memory (peak):186.19 MB
169.69 MB
Working set:530 KB
18.61 MB
Working set (peak):8.59 MB
37.95 MB
Resource allocations
Threads:11
12
Handles:246
600
GUI GDI count:28
103
GUI GDI peak:36
142
GUI USER count:14
49
GUI USER peak:24
71

BehaviorsProcess properties

Integrety level:High
Platform:32-bit
Command lines:
  • "C:\ProgramData\etype manager\2.4.897.176\{16cdff19-861d-48e3-a751-d99a27784753}\etypemngr.exe" /protect
  • "C:\ProgramData\etype manager\2.4.897.176\{16cdff19-861d-48e3-a751-d99a27784753}\etypemngr.exe"
Owner:User
Windows Service
Service name:eType Manager
Display name:Browser Manager
Type:Win32ShareProcess
Parent processes:

ResourcesThreads

Averages
 
etypemngr.exe (main module)
Total CPU:0.16131135%
0.272967%
Kernel CPU:0.14861252%
0.107585%
User CPU:0.01269883%
0.165382%
CPU cycles:5,000,826/sec
5,741,424/sec
Memory:2.35 MB
1.16 MB
etypemngr.dll (Application Manager by PerformerSoft LLC)
Total CPU:0.00034322%
Kernel CPU:0.00034322%
User CPU:0.00000000%
CPU cycles:3,146/sec
Memory:2.13 MB
sechost.dll
Total CPU:0.00022999%
Kernel CPU:0.00000000%
User CPU:0.00022999%
CPU cycles:25,527/sec
Memory:100 KB

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate N 50.00%
Windows Vista Home Premium 25.00%
Windows 7 Ultimate 25.00%

Distribution by countryDistribution by country

United States installs about 50.00% of Application Manager.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 66.67%
Hewlett-Packard 33.33%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE