Should I block it?

60%
60% of PCs block this file from running.
Possible reason:
Performance resource utilization

VersionsAdditional versions

3.26.5.0 10.00%
3.21.2.1 10.00%
3.14.1.3 10.00%
3.4.5.2 10.00%
3.1.0.3 50.00%
3.0.0.7 10.00%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
CryptDestroyHash, CryptHashData, CryptSetHashParam, CryptCreateHash, CryptAcquireContextW, RegOpenKeyA, RegSetValueExA, RegFlushKey, RegRestoreKeyW, RegSaveKeyW, LookupPrivilegeValueW, AdjustTokenPrivileges, RegEnumValueW, RegQueryValueW, RegEnumKeyW, RegDeleteKeyW, RegDeleteValueW, RegCreateKeyExW, RegSetValueExW, RegisterServiceCtrlHandlerW, DeleteService, CreateServiceW, ControlService, OpenSCManagerW, OpenServiceW, StartServiceW, CloseServiceHandle, CreateProcessAsUserW, RegQueryValueExW, SetServiceStatus, StartServiceCtrlDispatcherW, OpenProcessToken, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, LookupAccountSidW, GetTokenInformation, CryptDecrypt, CryptAcquireContextA, CryptReleaseContext, CryptImportKey, CryptEncrypt, CryptDestroyKey, RegOpenKeyExW, RegCloseKey, RegQueryInfoKeyW, RegEnumKeyExW, ConvertSidToStringSidW, CryptGetHashParam
comctl32.dll
ImageList_GetIconSize
comdlg32.dll
GetFileTitleW
gdi32.dll
SetWindowExtEx, ScaleWindowExtEx, ExtSelectClipRgn, DeleteDC, SelectPalette, GetObjectType, CreateHatchBrush, GetRgnBox, GetBkColor, GetTextColor, GetTextExtentPoint32W, CreateDIBSection, CreateRoundRectRgn, CreatePolygonRgn, CombineRgn, PatBlt, CreateEllipticRgn, Polyline, Ellipse, Polygon, SetRectRgn, GetMapMode, DPtoLP, OffsetWindowOrgEx, GetNearestPaletteIndex, RealizePalette, GetSystemPaletteEntries, OffsetRgn, SetDIBColorTable, StretchBlt, SetPixel, Rectangle, EnumFontFamiliesExW, LPtoDP, GetWindowOrgEx, GetViewportOrgEx, PtInRegion, FillRgn, FrameRgn, GetBoundsRect, ScaleViewportExtEx, SetPaletteEntries, GetTextFaceW, SetPixelV, CreatePalette, SetWindowOrgEx, GetPixel, GetWindowExtEx, GetViewportExtEx, CreateRectRgn, SelectClipRgn, SetLayout, GetLayout, SetTextAlign, MoveToEx, LineTo, IntersectClipRect, ExcludeClipRect, GetClipBox, SetMapMode, SetROP2, SetPolyFillMode, SetBkMode, RestoreDC, SaveDC, DeleteObject, GetTextCharsetInfo, EnumFontFamiliesW, GetTextMetricsW, BitBlt, CreateCompatibleDC, CreateRectRgnIndirect, CreateCompatibleBitmap, CreateFontIndirectW, SetViewportExtEx, OffsetViewportOrgEx, SetViewportOrgEx, SelectObject, Escape, ExtTextOutW, TextOutW, RectVisible, ExtFloodFill, PtVisible, CreateDIBitmap, CreatePatternBrush, CreateSolidBrush, CreatePen, GetStockObject, GetDeviceCaps, CopyMetaFileW, CreateDCW, CreateBitmap, SetTextColor, SetBkColor, GetObjectW, GetPaletteEntries
gdiplus.dll
GdipFree, GdipDeleteGraphics, GdipDisposeImage, GdipCreateBitmapFromHBITMAP, GdiplusStartup, GdiplusShutdown, GdipCreateFromHDC, GdipSetInterpolationMode, GdipDrawImageRectI, GdipCloneImage, GdipGetImageWidth, GdipGetImageHeight, GdipGetImagePixelFormat, GdipGetImagePaletteSize, GdipGetImagePalette, GdipCreateBitmapFromStream, GdipCreateBitmapFromScan0, GdipBitmapLockBits, GdipBitmapUnlockBits, GdipGetImageGraphicsContext, GdipDrawImageI, GdipAlloc
imm32.dll
ImmReleaseContext, ImmGetContext, ImmGetOpenStatus
kernel32.dll
DllMain
msimg32.dll
TransparentBlt, AlphaBlend
ole32.dll
OleInitialize, CoFreeUnusedLibraries, OleUninitialize, CoInitializeEx, CLSIDFromProgID, CreateILockBytesOnHGlobal, StgCreateDocfileOnILockBytes, StgOpenStorageOnILockBytes, CoGetClassObject, CLSIDFromString, CoCreateInstance, CoCreateGuid, CoTaskMemAlloc, ReleaseStgMedium, OleGetClipboard, RegisterDragDrop, CoLockObjectExternal, OleCreateMenuDescriptor, OleDestroyMenuDescriptor, OleTranslateAccelerator, IsAccelerator, OleLockRunning, CreateStreamOnHGlobal, OleIsCurrentClipboard, OleFlushClipboard, CoRevokeClassObject, CoRegisterMessageFilter, CoDisconnectObject, RevokeDragDrop, OleDuplicateData, DoDragDrop, CoTaskMemFree, CoInitialize, CoUninitialize
oleacc.dll
AccessibleObjectFromWindow, CreateStdAccessibleObject, LresultFromObject
oledlg.dll
OleUIBusyW
psapi.dll
GetProcessMemoryInfo
shell32.dll
SHGetFolderPathW, DragQueryFileW, SHAppBarMessage, DragFinish, SHGetFileInfoW, SHBrowseForFolderW, SHGetPathFromIDListW, SHGetMalloc, SHGetSpecialFolderLocation, SHGetDesktopFolder, ShellExecuteW, SHGetSpecialFolderPathW
shlwapi.dll
SHQueryValueExW, PathAppendW, UrlUnescapeW, PathRemoveFileSpecW, PathIsUNCW, PathStripToRootW, PathFindFileNameW, PathFindExtensionW, PathFileExistsW
urlmon.dll
URLDownloadToFileW
user32.dll
DllMain
userenv.dll
CreateEnvironmentBlock
version.dll
GetFileVersionInfoSizeW, GetFileVersionInfoW, VerQueryValueW
winhttp.dll
WinHttpQueryDataAvailable, WinHttpAddRequestHeaders, WinHttpOpen, WinHttpConnect, WinHttpCloseHandle, WinHttpOpenRequest, WinHttpSendRequest, WinHttpReceiveResponse, WinHttpReadData
wininet.dll
InternetCrackUrlW, DeleteUrlCacheEntryW, InternetCanonicalizeUrlW
winmm.dll
PlaySoundW
winspool.drv
OpenPrinterW, ClosePrinter, DocumentPropertiesW
wtsapi32.dll
WTSFreeMemory, WTSQuerySessionInformationW, WTSEnumerateSessionsW, WTSQueryUserToken

umbrella.exe

Iminent Protection by Iminent (Signed)

Remove umbrella.exe
Version:   3.21.2.1
MD5:   ceea05e64c2230bb2b6924132f766272
SHA1:   66182499cc1b9c59cae42d7f7a3928e534031d86
SHA256:   6fe5be05b1d1142148ba2d1fad1c6f5c1817425ab9b00a42962845083f4d356b

Overview

umbrella.exe runs as a service under the name SProtection within the local user context. The file is digitally signed by Iminent which was issued by the GlobalSign nv-sa certificate authority (CA). Note, some antivirus scanners have flagged this file, however it is not necessarily considered malware (see below for details).

DetailsDetails

File name:umbrella.exe
Publisher:Iminent
Product name:Iminent Protection
Typical file path:C:\Program Files\common files\umbrella\umbrella.exe
File version:3.21.2.1
Size:2.71 MB (2,839,592 bytes)
Certificate
Issued to:Iminent
Authority (CA):GlobalSign nv-sa
Digital DNA
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'SProtection'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00013497%
0.028634%
Kernel CPU:0.00009845%
0.013761%
User CPU:0.00003652%
0.014873%
Kernel CPU time:1,248,008 ms/min
100,923,805ms/min
Memory
Private memory:3.13 MB
21.59 MB
Private (maximum):8.5 MB
Private (minimum):8.16 MB
Non-paged memory:3.13 MB
21.59 MB
Virtual memory:83.02 MB
140.96 MB
Virtual memory (peak):86.77 MB
169.69 MB
Working set:8.44 MB
18.61 MB
Working set (peak):8.5 MB
37.95 MB
Resource allocations
Threads:5
12
Handles:149
600

BehaviorsProcess properties

Integrety level:System
Platform:64-bit
Command line:"C:\Program Files\common files\umbrella\umbrella.exe"
Owner:User
Windows Service
Service name:SProtection
Type:Win32OwnProcess, InteractiveProcess
Parent process:services.exe (Services and Controller app by Microsoft)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 40.00%
Windows 7 Ultimate 30.00%
Windows Vista Home Premium 10.00%
Windows 8 Pro 10.00%
Microsoft Windows XP 10.00%

Distribution by countryDistribution by country

United States installs about 50.00% of Iminent Protection.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
ASUS 40.00%
Toshiba 20.00%
Dell 20.00%
Acer 10.00%
Hewlett-Packard 10.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE