Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

3.5.1307.82 2.17%
3.5.1307.76 2.17%
3.5.1304.29 6.52%
3.5.1302.61 6.52%
3.5.1208.41 2.17%
3.5.1208.36 10.87%
3.5.1208.34 4.35%
3.5.1208.24 10.87%
3.5.1207.40 6.52%
3.5.1205.18 2.17%
3.5.1205.17 6.52%
3.5.1205.15 10.87%
3.5.1205.12 2.17%
3.5.1201.94 15.22%
3.5.1108.73 6.52%
3.5.1108.70 2.17%
3.5.1108.50 2.17%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
CryptGenRandom, OpenProcessToken, DuplicateTokenEx, GetLengthSid, SetTokenInformation, CreateProcessAsUserA, ConvertStringSidToSidW, RegisterServiceCtrlHandlerExW, StartServiceCtrlDispatcherW, SetServiceStatus, RegCloseKey, RegQueryValueExW, RegOpenKeyExW, GetTokenInformation, RegDeleteKeyW, RegQueryInfoKeyW, RegEnumKeyExW, RegSetValueExW, RegSetValueExA, RegOpenKeyA, CryptEncrypt, CryptAcquireContextW, CryptGenKey, CryptReleaseContext, CryptImportKey, CryptExportKey, CryptDestroyKey, RegOpenKeyExA, RegQueryValueExA, OpenSCManagerW, OpenServiceW, CloseServiceHandle, ConvertSidToStringSidA, AllocateAndInitializeSid, EqualSid, FreeSid, SetNamedSecurityInfoW, SetEntriesInAclW, GetEffectiveRightsFromAclW, GetNamedSecurityInfoW
kernel32.dll
GetProcessHeap, HeapFree, IsDebuggerPresent, UnhandledExceptionFilter, lstrcatW, lstrcpyW, lstrlenW, GetFullPathNameW, FindCloseChangeNotification, FindNextChangeNotification, FindFirstChangeNotificationW, FileTimeToLocalFileTime, OpenEventA, GetStartupInfoA, EnterCriticalSection, LeaveCriticalSection, GetLastError, InterlockedIncrement, InterlockedDecrement, Sleep, DeleteCriticalSection, InitializeCriticalSection, WaitForSingleObject, GetTickCount, CreateThread, CloseHandle, ProcessIdToSessionId, TerminateProcess, OpenProcess, GetModuleFileNameA, GetProcessTimes, GetExitCodeProcess, GetCurrentProcessId, GetModuleHandleW, GetCurrentThreadId, InterlockedCompareExchange, SetUnhandledExceptionFilter, QueryPerformanceCounter, GetCurrentProcess, GetProcAddress, GetModuleHandleA, QueryPerformanceFrequency, SetLastError, GetFileAttributesW, InterlockedExchange, OutputDebugStringA, LoadLibraryA, GetCurrentThread, ResumeThread, GetThreadContext, SuspendThread, SleepEx, Process32NextW, Process32FirstW, CreateToolhelp32Snapshot, Module32NextW, Module32FirstW, FreeLibrary, CreateFileA, TlsGetValue, TlsAlloc, GetModuleFileNameW, VirtualQuery, RtlCaptureContext, GetSystemInfo, LocalFree, QueryDosDeviceA, MultiByteToWideChar, GetVersionExW, CreateFileW, WideCharToMultiByte, DeleteFileW, MoveFileW, CopyFileW, CreateDirectoryW, FindClose, RemoveDirectoryW, FindNextFileW, FindFirstFileW, FindNextFileA, FindFirstFileA, CompareFileTime, FlushInstructionCache, VirtualProtect, InterlockedExchangeAdd, GetSystemTime, SetEvent, WaitForMultipleObjects, ResetEvent, SetWaitableTimer, CancelWaitableTimer, CreateEventW, CreateWaitableTimerW, DeviceIoControl, ReadFile, GetSystemDirectoryA, GetWindowsDirectoryA, GetSystemTimeAsFileTime, lstrlenA, GetVolumeInformationA, FileTimeToSystemTime, CreateProcessW, GlobalFree, GlobalAlloc, LoadLibraryExA, GetFileAttributesA, IsWow64Process, GetFileTime
msvcp80.dll
DllMain
msvcr80.dll
DllMain
ole32.dll
CoSetProxyBlanket, CoUninitialize, CoInitializeEx, CoCreateInstance, OleRun
psapi.dll
GetModuleInformation, GetModuleFileNameExA, EnumProcesses
rapportutil.dll
DllMain
shell32.dll
SHGetFolderPathW, SHGetFolderPathA
shlwapi.dll
PathAppendA, SHDeleteKeyW, AssocQueryStringA
trf.dll
iterate_pid_with_logs, env_alloc_default, stacktrace_get_stack_trace, counters_release, counters_acquire, env_is_inited, iterate_pid, env_get, get_application_directory, counters_get, GetCurrentSessionId, stacktrace_get_caller_module, stacktrace_get_stack_trace_unl, proctools_get_process_image_name, iterate_modules, set_application_directory
user32.dll
wsprintfW, MessageBoxA
userenv.dll
CreateEnvironmentBlock, DestroyEnvironmentBlock
version.dll
GetFileVersionInfoSizeW, VerQueryValueW, GetFileVersionInfoW
wininet.dll
InternetSetOptionA, HttpQueryInfoW, InternetGetConnectedState, InternetOpenA, InternetCrackUrlA, InternetCloseHandle, InternetReadFileExA, InternetSetStatusCallbackA, InternetSetOptionW, InternetConnectA, HttpOpenRequestA, HttpQueryInfoA, HttpSendRequestA
wtsapi32.dll
WTSFreeMemory, WTSQuerySessionInformationW, WTSEnumerateSessionsW, WTSQueryUserToken

rapportmgmtservice.exe

Rapport by Trusteer (Signed)

Remove rapportmgmtservice.exe
Version:   3.5.1205.18
MD5:   35468625105f5b10fcf43e5d58659924
SHA1:   f6a5a10d4e31f77db93166e710caca479c9e2c3f
SHA256:   c629574240ec04e190a5ba43ff56a95fd4ee23ad46b8e07752ada19ed285bd31

What is rapportmgmtservice.exe?

Trusteer Rapport is lightweight security software designed to protect confidential data, such as account credentials, from being stolen by malicious software (malware) and via phishing. To achieve this goal, the software first includes anti-phishing measures to protect against misdirection and attempts to prevent malicious screen scraping.

Overview

rapportmgmtservice.exe runs as a service under the name Rapport Management Service (RapportMgmtService) within the local user context. The file is digitally signed by Trusteer which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:rapportmgmtservice.exe
Publisher:Trusteer Ltd.
Product name:Rapport
Description:RapportMgmtService
Typical file path:C:\Program Files\trusteer\rapport\bin\rapportmgmtservice.exe
Original name:RapportMgmtService
File version:3.5.1205.18
Size:953.84 KB (976,728 bytes)
Certificate
Issued to:Trusteer
Authority (CA):VeriSign
Effective date:Friday, February 12, 2010
Expiration date:Thursday, May 1, 2014
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 8.0
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'RapportMgmtService' (Rapport Management Service)
  • RapportMgmtService

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 54.35%
Microsoft Windows XP 13.04%
Windows 7 Professional 8.70%
Windows Vista Home Premium 8.70%
Windows 8 Pro 8.70%
Windows 7 Ultimate 6.52%

Distribution by countryDistribution by country

United States installs about 42.22% of Rapport.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Sony 31.25%
Dell 25.00%
Hewlett-Packard 12.50%
Intel 12.50%
GIGABYTE 6.25%
ASUS 6.25%
Toshiba 6.25%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE