Should I block it?

90%
90% of PCs block this file from running.
Possible reason:
Multiple malware detections

VersionsAdditional versions

5bb21 12.50%
069aa 12.50%
b29d2 25.00%
f5578 25.00%
9b528 12.50%
8e179 12.50%
(Note, AnchorFree Inc publishes each variation of this file with the same version, but the hashes are unique.)

Relationships

Parent process
Child process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegEnumKeyExA, RegOpenKeyExA, RegCloseKey, RegCreateKeyExW, RegQueryValueExW, RegDeleteValueW, RegOpenKeyExW, GetUserNameW, RegSetValueExW
iphlpapi.dll
GetAdaptersInfo
kernel32.dll
GetLastError, ProcessIdToSessionId, GetCurrentProcessId, SetConsoleCtrlHandler, Sleep, WaitForSingleObject, TerminateThread, GetExitCodeProcess, OpenProcess, DeleteFileW, GetTempPathW, CloseHandle, CreateProcessW, GetStartupInfoW, GetModuleFileNameW, LockResource, SizeofResource, LoadResource, FindResourceW, CreateMutexW, CompareStringW, GetTimeZoneInformation, GetCurrentDirectoryW, PeekNamedPipe, GetFileInformationByHandle, GetFullPathNameW, FindFirstFileExW, GetDriveTypeW, FileTimeToLocalFileTime, FileTimeToSystemTime, FindClose, FindResourceExW, SetEnvironmentVariableA, WideCharToMultiByte, SetEndOfFile, WriteConsoleW, FlushFileBuffers, SetStdHandle, GetFileSize, SetFilePointer, GetModuleHandleW, WriteFile, ReadFile, CreateFileW, MultiByteToWideChar, GetProcAddress, GetVolumeInformationW, SetLastError, CreateThread, GetCurrentThreadId, CreateEventW, PostQueuedCompletionStatus, SetEvent, CreateIoCompletionPort, GetQueuedCompletionStatus, InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, WaitForMultipleObjects, CreateToolhelp32Snapshot, Process32FirstW, Process32NextW, SetWaitableTimer, GetTickCount, CreateWaitableTimerW, ResetEvent, ReleaseMutex, RaiseException, InitializeCriticalSectionAndSpinCount, HeapDestroy, HeapAlloc, HeapFree, HeapReAlloc, HeapSize, GetProcessHeap, GetSystemTimeAsFileTime, EncodePointer, DecodePointer, CreateFileA, GetCommandLineW, HeapSetInformation, ExitThread, ResumeThread, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, IsProcessorFeaturePresent, HeapCreate, GetCPInfo, InterlockedIncrement, InterlockedDecrement, GetACP, GetOEMCP, IsValidCodePage, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, LCMapStringW, LoadLibraryW, GetStdHandle, FreeEnvironmentStringsW, GetEnvironmentStringsW, SetHandleCount, GetFileType, QueryPerformanceCounter, RtlUnwind, GetStringTypeW, GetConsoleCP, GetConsoleMode, ExitProcess
ole32.dll
CoCreateInstance
psapi.dll
GetProcessMemoryInfo, GetModuleFileNameExW
shell32.dll
SHGetFolderPathW
shlwapi.dll
PathFileExistsW
user32.dll
SetForegroundWindow, GetWindowTextLengthW, GetWindowThreadProcessId, GetClassNameW, SetWindowPos, FindWindowExW, GetWindowRect, IsWindowVisible, GetForegroundWindow, PostMessageA, IsWindow, CopyRect, EnumChildWindows, GetWindowTextW
wininet.dll
InternetCrackUrlA
ws2_32.dll
WSAWaitForMultipleEvents, WSARecv, WSAAccept, WSAEnumNetworkEvents, WSACloseEvent, WSAEventSelect, WSACreateEvent, WSASend

fbwmgr.exe

By AnchorFree Inc (Signed)

Remove fbwmgr.exe
MD5:   069aa8b3b869790d8b2cd51ba5fa207c
SHA1:   58e59e049574d20662ef65b330c266f37b348d2d
SHA256:   fa7f9481e9fd95d3f80d80fd3ce5aebcfbc079e40f15fdd921dc853f958970ec
Warning 5 antivirus scanners has detected malware.

About fbwmgr.exe (from AnchorFree Inc)

Hotspot Shield creates a virtual private network (VPN) between your laptop or iPhone and our Internet gateway. This impenetrable tunnel prevents snoopers, hackers, ISP‘s, from viewing your web browsin

Overview

fbwmgr.exe is malware that executes as a process with the local user's privileges typically within the context of its parent openvpntray.exe (by AnchorFree Inc). This is typically installed with the program Hotspot Shield 3.09 published by AnchorFree Inc and is most likely removed by most users once installed (58% removed). The file is digitally signed by AnchorFree Inc which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:fbwmgr.exe
Typical file path:C:\Program Files\hotspot shield\bin\fbwmgr.exe
Size:281.86 KB (288,624 bytes)
Certificate
Issued to:AnchorFree Inc
Authority (CA):VeriSign
Effective date:Monday, March 28, 2011
Expiration date:Monday, April 14, 2014
Digital DNA
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
AnchorFree Inc
  58% remove
If you are using the free Service, AnchorFree may deliver third-party Advertisements within the content of any web page accessed. Advertisements may be injected into the top of the page, inserted directly into the page content, or even displayed to overlay the page. A “hotspot” is a Wi-Fi connection access point. Usually this type of connection is public; therefore, it is completely insecure. Hotspot Shield allows you to create a VPN, ...

MalwareMalware detections

Based on 40+ industry antivirus scanners, 5 of them detected the following malware.
Antivirus engineEngine versionDetection
Emsisoft Anti-Malware 3.0.0.569 Gen:Variant.Graftor.48415 (B)
The Hacker None Trojan/Agent.havx
Trend Micro HouseCall 9.700.0.1001 TROJ_GEN.F47V1019
Vba32 AntiVirus 3.12.18.3 Trojan.Agent.ahis
ViRobot 2011.4.7.4223 Trojan.Win32.A.Agent.288624

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.01296244%
0.028634%
Kernel CPU:0.00972183%
0.013761%
User CPU:0.00324061%
0.014873%
Kernel CPU time:441 ms/min
100,923,805ms/min
Context switches:240/sec
284/sec
Memory
Private memory:1.74 MB
21.59 MB
Private (maximum):1.3 MB
Private (minimum):1.18 MB
Non-paged memory:1.74 MB
21.59 MB
Virtual memory:59.11 MB
140.96 MB
Virtual memory (peak):63.22 MB
169.69 MB
Working set:1.29 MB
18.61 MB
Working set (peak):4.9 MB
37.95 MB
Resource allocations
Threads:7
12
Handles:137
600
GUI GDI count:4
103
GUI GDI peak:4
142
GUI USER count:3
49
GUI USER peak:3
71

BehaviorsProcess properties

Integrety level:Medium
Platform:32-bit
Command line:-sp 896
Owner:User
Parent process:openvpntray.exe (by AnchorFree Inc)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 62.50%
Windows 7 Ultimate N 25.00%
Windows 7 Professional 12.50%

Distribution by countryDistribution by country

United States installs about 50.00% of fbwmgr.exe.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Acer 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE