Should I block it?

40%
40% of PCs block this file from running.
Possible reason:
Performance resource utilization

Relationships

Parent process
Child process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
GetAce, RegEnumValueW, CreateServiceW, ChangeServiceConfig2W, DeleteService, ControlService, ConvertStringSecurityDescriptorToSecurityDescriptorW, RegQueryInfoKeyW, RegEnumKeyExW, StartServiceCtrlDispatcherW, RegisterServiceCtrlHandlerW, GetTokenInformation, DuplicateTokenEx, CreateProcessAsUserW, OpenSCManagerW, OpenServiceW, QueryServiceConfigW, ChangeServiceConfigW, CloseServiceHandle, SetServiceStatus, RegEnumKeyW, RegSetValueExW, RegDeleteKeyW, RegCreateKeyExW, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, ConvertStringSecurityDescriptorToSecurityDescriptorA, GetSecurityDescriptorSacl, SetSecurityDescriptorSacl, RegQueryValueExW, RegCloseKey, RegOpenKeyExW, RegDeleteValueW, SetSecurityInfo, DeleteAce, StartServiceW, GetAclInformation, GetSecurityInfo, OpenProcessToken, OpenThreadToken, AddAce, InitializeAcl, GetLengthSid, ConvertSidToStringSidW, IsValidSid, DeregisterEventSource, ReportEventA, RegisterEventSourceA
crypt32.dll
CertFreeCertificateContext, CertGetNameStringW, CertFindCertificateInStore, CryptMsgClose, CertCloseStore, CryptMsgGetParam, CryptQueryObject
gdi32.dll
CreatePatternBrush, GetObjectW, DeleteObject, CreateDIBSection, CreateCompatibleBitmap, BitBlt, CreateCompatibleDC, CreateFontIndirectW, CreateSolidBrush, RoundRect, DeleteDC, CreatePen, Rectangle, SetTextColor, SetBkMode, SelectObject
kernel32.dll
DllMain
ole32.dll
CoInitializeSecurity, CoInitializeEx, CoCreateInstance, StringFromGUID2, CoInitialize, CoUninitialize, CoSetProxyBlanket
rpcrt4.dll
UuidFromStringA
shell32.dll
CommandLineToArgvW, SHGetSpecialFolderPathW
shlwapi.dll
PathIsDirectoryW, PathFindFileNameW, StrCmpW, StrCpyW, PathFileExistsW, PathAppendW, PathStripToRootW, PathStripPathW, PathRemoveExtensionW, PathFindExtensionW, PathAddExtensionW, PathRemoveFileSpecW, SHGetValueW, PathIsRootW, StrCmpNIW
user32.dll
DrawTextW, SetWindowLongW, GetWindowTextW, GetWindowTextLengthW, GetSystemMetrics, LoadImageW, GetCursorPos, GetTopWindow, TrackMouseEvent, ChildWindowFromPoint, KillTimer, ScreenToClient, DefWindowProcW, GetClassInfoExW, LoadCursorW, IsWindow, FindWindowW, DestroyWindow, RegisterClassExW, CreateWindowExW, GetUserObjectInformationW, GetProcessWindowStation, GetDesktopWindow, MessageBoxA, MessageBoxW, SetFocus, SetWindowPos, MapWindowPoints, GetMonitorInfoW, GetClientRect, GetWindow, UnregisterClassA, LoadStringA, GetWindowLongW, CallWindowProcW, DialogBoxParamW, GetActiveWindow, ShowWindow, GetWindowRect, MoveWindow, SystemParametersInfoW, DispatchMessageW, EndDialog, GetDlgItem, SendMessageW, SetWindowTextW, SetTimer, PeekMessageW, GetMessageW, MonitorFromWindow, SetLayeredWindowAttributes, FillRect, ReleaseDC, GetDC, GetSysColor, GetSysColorBrush, GetParent, InvalidateRect, EndPaint, BeginPaint, TranslateMessage
userenv.dll
CreateEnvironmentBlock
uxtheme.dll
DrawThemeBackground, DrawThemeParentBackground, IsThemeBackgroundPartiallyTransparent, OpenThemeData, CloseThemeData
version.dll
GetFileVersionInfoSizeW, GetFileVersionInfoW, VerQueryValueW
winhttp.dll
WinHttpConnect, WinHttpOpen, WinHttpSetStatusCallback, WinHttpGetIEProxyConfigForCurrentUser, WinHttpCloseHandle, WinHttpGetProxyForUrl, WinHttpSetOption, WinHttpReceiveResponse, WinHttpAddRequestHeaders, WinHttpQueryDataAvailable, WinHttpReadData, WinHttpOpenRequest, WinHttpQueryHeaders, WinHttpSendRequest
wtsapi32.dll
WTSQueryUserToken

bprotect.exe

Application Manager by MediaTechSoft Inc. (Signed)

Remove bprotect.exe
Version:   2,7,1769,27
MD5:   e66e725e10b9cb8a6f5c74d7ca9e98a9
SHA1:   ffd259de1b68d162fe613ee5bd03709fe7815b22

Overview

bprotect.exe runs as a service under the name bProtector (BitGuard) within the local user context as a shared service. This is typically installed with the program BitGuard published by MediaTechSoft Inc. and is most likely removed by most users once installed (74% removed). The file is digitally signed by MediaTechSoft Inc. which was issued by the GoDaddy.com certificate authority (CA).

DetailsDetails

File name:bprotect.exe
Publisher:PerformerSoft LLC
Product name:Application Manager
Typical file path:C:\ProgramData\bprotectorforwindows\2.7.1769.27\{eab34bca-99d8-4192-8f3b-58b53f6d08e7}\bprotect.exe
File version:2,7,1769,27
Size:2.73 MB (2,864,096 bytes)
Build date:10/22/2013 11:10 AM
Certificate
Issued to:MediaTechSoft Inc.
Authority (CA):GoDaddy.com
Effective date:Sunday, August 4, 2013
Expiration date:Tuesday, March 29, 2016
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
MediaTechSoft Inc.
  74% remove
BitGuard also known as BProtector, Application Manager and Browser Protector is an application designed to prevent the removal of software installed by the provider and affiliates (including web browser extensions deployed by PerformerSoft). BitGuard and its variations are registered under the company name MediaTechSoft but actually are associated with PerformerSoft LLC. While the BitGuard service (BitGuard.exe) is signed with a digital...

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' as a shared service by the Service Host (svchost.exe)
  • 'BitGuard'
  • 'bProtector'
Network connections
  • [UDP] listens on port 2622

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.04595785%
    0.028634%
    Kernel CPU:0.02229095%
    0.013761%
    User CPU:0.02366690%
    0.014873%
    Kernel CPU time:2,856,374 ms/min
    100,923,805ms/min
    CPU cycles:14,093,019/sec
    17,470,203/sec
    Context switches:29/sec
    284/sec
    Memory
    Private memory:3.92 MB
    21.59 MB
    Private (maximum):7.3 MB
    Private (minimum):5.28 MB
    Non-paged memory:3.92 MB
    21.59 MB
    Virtual memory:170.59 MB
    140.96 MB
    Virtual memory (peak):194.17 MB
    169.69 MB
    Working set:6.48 MB
    18.61 MB
    Working set (peak):7.55 MB
    37.95 MB
    Page faults:2,183,866/min
    2,039/min
    I/O
    I/O read transfer:60.14 KB/sec
    1.02 MB/min
    I/O read operations:4/sec
    343/min
    I/O write transfer:108.61 KB/sec
    274.99 KB/min
    I/O write operations:2/sec
    227/min
    I/O other transfer:854 Bytes/sec
    448.09 KB/min
    I/O other operations:52/sec
    1,671/min
    Resource allocations
    Threads:12
    12
    Handles:286
    600
    GUI GDI count:9
    103
    GUI GDI peak:10
    142
    GUI USER count:4
    49
    GUI USER peak:5
    71

    BehaviorsProcess properties

    Integrety level:High
    Platform:32-bit
    Command lines:
    • "C:\ProgramData\bitguard\2.7.1769.27\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\bitguard.exe" /protect
    • C:\ProgramData\bitguard\2.7.1769.27\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\bitguard.exe
    • "C:\Documents and Settings\user\Application data\bitguard\2.7.1769.27\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\bitguard.exe" /protect
    • "C:\Documents and Settings\user\Application data\bitguard\2.7.1769.27\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\bitguard.exe"
    • "C:\ProgramData\bprotectorforwindows\2.7.1769.27\{eab34bca-99d8-4192-8f3b-58b53f6d08e7}\bprotect.exe" /protect
    • C:\ProgramData\bprotectorforwindows\2.7.1769.27\{eab34bca-99d8-4192-8f3b-58b53f6d08e7}\bprotect.exe
    Owner:User
    Windows Service
    Service name:BitGuard
    Display name:bProtector
    Type:Win32ShareProcess
    Parent processes:

    ResourcesThreads

    Averages
     
    bProtect.exe (main module)
    Total CPU:0.24602342%
    0.272967%
    Kernel CPU:0.21251426%
    0.107585%
    User CPU:0.03350916%
    0.165382%
    CPU cycles:8,393,939/sec
    5,741,424/sec
    Context switches:9/sec
    79/sec
    Memory:2.81 MB
    1.16 MB
    protector.dll (Application Manager by PerformerSoft LLC)
    Total CPU:0.00776101%
    Kernel CPU:0.00419884%
    User CPU:0.00356217%
    CPU cycles:112,864/sec
    Memory:2.73 MB
    sechost.dll
    Total CPU:0.00121269%
    Kernel CPU:0.00000000%
    User CPU:0.00121269%
    CPU cycles:32,478/sec
    Context switches:1/sec
    Memory:100 KB

    Common loaded modules

    These are modules that are typiclaly loaded within the context of this process.

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows Developer Preview 30.00%
    Microsoft Windows XP 30.00%
    Windows 7 Ultimate 30.00%
    Windows 7 Professional 10.00%

    Distribution by countryDistribution by country

    Vietnam installs about 60.00% of Application Manager.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Lenovo 31.58%
    Intel 31.58%
    ASUS 31.58%
    Acer 5.26%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE