Should I block it?

60%
60% of PCs block this file from running.
Possible reason:
Performance resource utilization

VersionsAdditional versions

0.4.0.146 66.67%
0.2.2.113 13.33%
0.2.2.104 20.00%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
OpenProcessToken, GetTokenInformation, CryptDecrypt, CryptDestroyKey, CryptEncrypt, CryptImportKey, CryptReleaseContext, CryptAcquireContextW, GetUserNameW, RegCloseKey, RegQueryValueExW, RegNotifyChangeKeyValue, RegOpenKeyExW, RegDeleteKeyW, RegQueryInfoKeyW, RegCreateKeyExW, RegDeleteValueW, RegSetValueExW, RegEnumValueW, RegEnumKeyExW
comctl32.dll
InitCommonControlsEx
gdi32.dll
GetTextAlign, TextOutW, CreatePen, LineTo, MoveToEx, GetStockObject, SetWindowOrgEx, DeleteObject, CreateFontW, ExtTextOutW, SelectObject, SetTextAlign, SetTextColor, SetBkMode, GetTextExtentPoint32W
gdiplus.dll
GdipAlloc, GdipDisposeImage, GdipCreateFromHDC, GdipDeleteGraphics, GdipDrawImageRectRectI, GdipCloneImage, GdipCreateBitmapFromStream, GdiplusStartup, GdipGetImageHeight, GdipGetImageWidth, GdiplusShutdown, GdipFree
kernel32.dll
DllMain
msimg32.dll
GradientFill
ole32.dll
CoResumeClassObjects, CoSuspendClassObjects, StringFromGUID2, CoTaskMemAlloc, CoTaskMemRealloc, CoUninitialize, CoInitialize, OleRun, CoCreateInstance, CLSIDFromString, CoTaskMemFree, CoCreateGuid, CoRegisterClassObject, CoRevokeClassObject, CreateStreamOnHGlobal, StringFromCLSID
shell32.dll
ShellExecuteW, SHGetSpecialFolderPathW, SHFileOperationW, SHCreateDirectoryExW, CommandLineToArgvW
shlwapi.dll
UrlEscapeW
user32.dll
DispatchMessageW, TranslateMessage, PostThreadMessageW, PeekMessageW, IsWindow, DestroyWindow, GetActiveWindow, DialogBoxParamW, GetDlgItem, DefWindowProcW, CharNextW, CharLowerW, UnregisterClassA, GetMessageW, ShowWindow, MoveWindow, GetDesktopWindow, MonitorFromPoint, GetMonitorInfoW, ReleaseDC, SetFocus, MessageBeep, SetDlgItemTextW, GetWindowTextLengthW, EndDialog, EndPaint, BeginPaint, EnableWindow, DrawTextW, ScreenToClient, GetWindowTextW, SetWindowPos, GetDC, OffsetRect, ReleaseCapture, SetCapture, GetCapture, GetParent, PtInRect, GetWindowRect, ClientToScreen, InvalidateRect, GetClientRect, SetWindowTextW, CreateWindowExW, LoadCursorW, GetClassInfoExW, RegisterClassExW, KillTimer, SetTimer, CallWindowProcW, GetWindowLongW, SendMessageW, SetWindowLongW
version.dll
GetFileVersionInfoW, VerQueryValueW, GetFileVersionInfoSizeW

praetorian.exe

Yandex by OOO Yandex (Signed)

Remove praetorian.exe
Version:   0.4.0.146
MD5:   f082c76cf8a1c41db23ec397b4b5b03b
SHA1:   59c508165b1cee0b453c34ab57f163aee1927fa4
SHA256:   d9f3cfcfe9651c67d7dfbb005e0914bb0b16f245a249a905cedcb87446977e02

What is praetorian.exe?

praetorian.exe is the software updater program which runs in the background of Windows and automatically starts up when your PC boots. It checks for software udpates and automatically downloads and installs them if found.

Overview

praetorian.exe executes as a process with the local user's privileges usually within the context of Windows Explorer. It is set to be run when the PC boots and the user logs into Windows (added to the Run registry key for the current user). The file is digitally signed by OOO Yandex which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:praetorian.exe
Publisher:Yandex LLC
Product name:Yandex
Typical file path:C:\users\user\appdata\local\yandex\updater\praetorian.exe
File version:0.4.0.146
Size:1.54 MB (1,618,304 bytes)
Certificate
Issued to:OOO Yandex
Authority (CA):VeriSign
Expiration date:Thursday, May 2, 2013
Digital DNA
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'Praetorian' → C:\users\user\appdata\Local\Yandex\Updater\praetorian.exe

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00778483%
0.028634%
Kernel CPU:0.00279696%
0.013761%
User CPU:0.00498787%
0.014873%
Kernel CPU time:153,192,982 ms/min
100,923,805ms/min
Memory
Private memory:4.25 MB
21.59 MB
Private (maximum):9.89 MB
Private (minimum):6.05 MB
Non-paged memory:4.25 MB
21.59 MB
Virtual memory:79.81 MB
140.96 MB
Virtual memory (peak):86.99 MB
169.69 MB
Working set:6.12 MB
18.61 MB
Working set (peak):10.62 MB
37.95 MB
Resource allocations
Threads:7
12
Handles:135
600
GUI GDI count:18
103
GUI GDI peak:31
142
GUI USER count:14
49
GUI USER peak:26
71

BehaviorsProcess properties

Integrety level:Medium
Platform:32-bit
Command line:"C:\users\user\appdata\local\yandex\updater\praetorian.exe"
Owner:User
Parent process:explorer.exe (Windows Explorer by Microsoft Corporation)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 40.00%
Microsoft Windows XP 20.00%
Windows 7 Home Basic 13.33%
Windows 7 Home Premium 13.33%
Windows 8 Single Language 6.67%
Windows 7 Starter 6.67%

Distribution by countryDistribution by country

UA installs about 40.00% of Yandex.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
ASUS 28.57%
Lenovo 19.05%
Dell 19.05%
Sony 9.52%
Hewlett-Packard 9.52%
Acer 4.76%
GIGABYTE 4.76%
Samsung 4.76%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE