Should I block it?

60%
60% of PCs block this file from running.
Possible reason:
Performance resource utilization

VersionsAdditional versions

0.4.0.146 66.67%
0.2.2.113 13.33%
0.2.2.104 20.00%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
OpenProcessToken, GetTokenInformation, CryptDecrypt, CryptDestroyKey, CryptEncrypt, CryptImportKey, CryptReleaseContext, CryptAcquireContextW, GetUserNameW, RegCloseKey, RegQueryValueExW, RegNotifyChangeKeyValue, RegOpenKeyExW, RegDeleteKeyW, RegQueryInfoKeyW, RegCreateKeyExW, RegDeleteValueW, RegSetValueExW, RegEnumValueW, RegEnumKeyExW
comctl32.dll
InitCommonControlsEx
gdi32.dll
GetTextAlign, TextOutW, CreatePen, LineTo, MoveToEx, GetStockObject, SetWindowOrgEx, DeleteObject, CreateFontW, ExtTextOutW, SelectObject, SetTextAlign, SetTextColor, SetBkMode, GetTextExtentPoint32W
gdiplus.dll
GdipAlloc, GdipDisposeImage, GdipCreateFromHDC, GdipDeleteGraphics, GdipDrawImageRectRectI, GdipCloneImage, GdipCreateBitmapFromStream, GdiplusStartup, GdipGetImageHeight, GdipGetImageWidth, GdiplusShutdown, GdipFree
kernel32.dll
DllMain
msimg32.dll
GradientFill
ole32.dll
CoResumeClassObjects, CoSuspendClassObjects, StringFromGUID2, CoTaskMemAlloc, CoTaskMemRealloc, CoUninitialize, CoInitialize, OleRun, CoCreateInstance, CLSIDFromString, CoTaskMemFree, CoCreateGuid, CoRegisterClassObject, CoRevokeClassObject, CreateStreamOnHGlobal, StringFromCLSID
shell32.dll
ShellExecuteW, SHGetSpecialFolderPathW, SHFileOperationW, SHCreateDirectoryExW, CommandLineToArgvW
shlwapi.dll
UrlEscapeW
user32.dll
DispatchMessageW, TranslateMessage, PostThreadMessageW, PeekMessageW, IsWindow, DestroyWindow, GetActiveWindow, DialogBoxParamW, GetDlgItem, DefWindowProcW, CharNextW, CharLowerW, UnregisterClassA, GetMessageW, ShowWindow, MoveWindow, GetDesktopWindow, MonitorFromPoint, GetMonitorInfoW, ReleaseDC, SetFocus, MessageBeep, SetDlgItemTextW, GetWindowTextLengthW, EndDialog, EndPaint, BeginPaint, EnableWindow, DrawTextW, ScreenToClient, GetWindowTextW, SetWindowPos, GetDC, OffsetRect, ReleaseCapture, SetCapture, GetCapture, GetParent, PtInRect, GetWindowRect, ClientToScreen, InvalidateRect, GetClientRect, SetWindowTextW, CreateWindowExW, LoadCursorW, GetClassInfoExW, RegisterClassExW, KillTimer, SetTimer, CallWindowProcW, GetWindowLongW, SendMessageW, SetWindowLongW
version.dll
GetFileVersionInfoW, VerQueryValueW, GetFileVersionInfoSizeW

praetorian.exe

Yandex by OOO Yandex (Signed)

Remove praetorian.exe
Version:   0.2.2.104
MD5:   059ffb75d74173521f4e3bec425d8e7f
SHA1:   bf331d7db2f9e36b64094721764bc83d145ec50d
SHA256:   920e2db822d3809989ab4776c06cd2aca15fa3781b7393a81c056bbfa07c0ed9

What is praetorian.exe?

praetorian.exe is the software updater program which runs in the background of Windows and automatically starts up when your PC boots. It checks for software udpates and automatically downloads and installs them if found.

Overview

praetorian.exe executes as a process with the local user's privileges. It is set to be run when the PC boots and the user logs into Windows (added to the Run registry key for the current user). This is typically installed with the program Internet Explorer için Yandex.Bar 6.7 published by Yandex and is most likely removed by most users once installed (64% removed). The file is digitally signed by OOO Yandex which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:praetorian.exe
Publisher:Yandex LLC
Product name:Yandex
Typical file path:C:\users\user\appdata\local\yandex\updater\praetorian.exe
File version:0.2.2.104
Size:1.46 MB (1,534,976 bytes)
Certificate
Issued to:OOO Yandex
Authority (CA):VeriSign
Expiration date:Thursday, May 2, 2013
Digital DNA
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
Yandex
  64% remove
Yandex.Bar for IE is a web browser extension that changes the browsers search and home pages as well as delivers. In order to provide search advertising revenue, the software is designed not only to modify the search provider but to protect it so that it remains the default browser search engine. It is typically installed via a bundled offer within a third-party software distribution. What the toolbar does: - Change of the default s...

BehaviorsBehaviors

Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'Praetorian' → C:\users\user\appdata\Local\Yandex\Updater\praetorian.exe

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 40.00%
Microsoft Windows XP 20.00%
Windows 7 Home Basic 13.33%
Windows 7 Home Premium 13.33%
Windows 8 Single Language 6.67%
Windows 7 Starter 6.67%

Distribution by countryDistribution by country

UA installs about 40.00% of Yandex.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
ASUS 28.57%
Lenovo 19.05%
Dell 19.05%
Sony 9.52%
Hewlett-Packard 9.52%
Acer 4.76%
GIGABYTE 4.76%
Samsung 4.76%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE