Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

5bb21 12.50%
069aa 12.50%
b29d2 25.00%
f5578 25.00%
9b528 12.50%
8e179 12.50%
(Note, AnchorFree Inc publishes each variation of this file with the same version, but the hashes are unique.)

Relationships

Parent process
Child process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegEnumKeyExA, RegOpenKeyExA, RegCloseKey, RegCreateKeyExW, RegQueryValueExW, RegDeleteValueW, RegOpenKeyExW, GetUserNameW, RegSetValueExW
iphlpapi.dll
GetAdaptersInfo
kernel32.dll
GetLastError, ProcessIdToSessionId, GetCurrentProcessId, SetConsoleCtrlHandler, Sleep, WaitForSingleObject, TerminateThread, GetExitCodeProcess, OpenProcess, DeleteFileW, GetTempPathW, CloseHandle, CreateProcessW, GetStartupInfoW, GetModuleFileNameW, LockResource, SizeofResource, LoadResource, FindResourceW, CreateMutexW, CompareStringW, GetTimeZoneInformation, GetCurrentDirectoryW, PeekNamedPipe, GetFileInformationByHandle, GetFullPathNameW, FindFirstFileExW, GetDriveTypeW, FileTimeToLocalFileTime, FileTimeToSystemTime, FindClose, FindResourceExW, SetEnvironmentVariableA, WideCharToMultiByte, SetEndOfFile, WriteConsoleW, FlushFileBuffers, SetStdHandle, GetFileSize, SetFilePointer, GetModuleHandleW, WriteFile, ReadFile, CreateFileW, MultiByteToWideChar, GetProcAddress, GetVolumeInformationW, SetLastError, CreateThread, GetCurrentThreadId, CreateEventW, PostQueuedCompletionStatus, SetEvent, CreateIoCompletionPort, GetQueuedCompletionStatus, InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, WaitForMultipleObjects, CreateToolhelp32Snapshot, Process32FirstW, Process32NextW, SetWaitableTimer, GetTickCount, CreateWaitableTimerW, ResetEvent, ReleaseMutex, RaiseException, InitializeCriticalSectionAndSpinCount, HeapDestroy, HeapAlloc, HeapFree, HeapReAlloc, HeapSize, GetProcessHeap, GetSystemTimeAsFileTime, EncodePointer, DecodePointer, CreateFileA, GetCommandLineW, HeapSetInformation, ExitThread, ResumeThread, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, IsProcessorFeaturePresent, HeapCreate, GetCPInfo, InterlockedIncrement, InterlockedDecrement, GetACP, GetOEMCP, IsValidCodePage, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, LCMapStringW, LoadLibraryW, GetStdHandle, FreeEnvironmentStringsW, GetEnvironmentStringsW, SetHandleCount, GetFileType, QueryPerformanceCounter, RtlUnwind, GetStringTypeW, GetConsoleCP, GetConsoleMode, ExitProcess
ole32.dll
CoCreateInstance
psapi.dll
GetProcessMemoryInfo, GetModuleFileNameExW
shell32.dll
SHGetFolderPathW
shlwapi.dll
PathFileExistsW
user32.dll
SetForegroundWindow, GetWindowTextLengthW, GetWindowThreadProcessId, GetClassNameW, SetWindowPos, FindWindowExW, GetWindowRect, IsWindowVisible, GetForegroundWindow, PostMessageA, IsWindow, CopyRect, EnumChildWindows, GetWindowTextW
wininet.dll
InternetCrackUrlA
ws2_32.dll
WSAWaitForMultipleEvents, WSARecv, WSAAccept, WSAEnumNetworkEvents, WSACloseEvent, WSAEventSelect, WSACreateEvent, WSASend

fbwmgr.exe

By AnchorFree Inc (Signed)

Remove fbwmgr.exe
MD5:   f55787f7db2fa26be49735bbb7a5c757
SHA1:   39dcec80b4159cea51a933c5c5833bced490e729
SHA256:   897966959ddab400b6fe1d858cc5dcd5f91e8774c02d2f25170876ad4be16cd4

About fbwmgr.exe (from AnchorFree Inc)

Hotspot Shield creates a virtual private network (VPN) between your laptop or iPhone and our Internet gateway. This impenetrable tunnel prevents snoopers, hackers, ISP‘s, from viewing your web browsin

Overview

fbwmgr.exe executes as a process with the local user's privileges typically within the context of its parent openvpntray.exe (by AnchorFree Inc). The file is digitally signed by AnchorFree Inc which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:fbwmgr.exe
Typical file path:C:\Program Files\hotspot shield\bin\fbwmgr.exe
Size:281.36 KB (288,112 bytes)
Certificate
Issued to:AnchorFree Inc
Authority (CA):VeriSign
Effective date:Monday, March 28, 2011
Expiration date:Monday, April 14, 2014
Digital DNA
File packed:No
.NET CLR:No
More details

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.01272662%
0.028634%
Kernel CPU:0.01017076%
0.013761%
User CPU:0.00255586%
0.014873%
Kernel CPU time:3,986 ms/min
100,923,805ms/min
Memory
Private memory:2.03 MB
21.59 MB
Private (maximum):3.06 MB
Private (minimum):2.57 MB
Non-paged memory:2.03 MB
21.59 MB
Virtual memory:58.69 MB
140.96 MB
Virtual memory (peak):62.75 MB
169.69 MB
Working set:2.59 MB
18.61 MB
Working set (peak):4.59 MB
37.95 MB
Resource allocations
Threads:8
12
Handles:126
600
GUI GDI count:4
103
GUI GDI peak:4
142
GUI USER count:2
49
GUI USER peak:2
71

BehaviorsProcess properties

Integrety level:Medium
Platform:32-bit
Command line:-sp 896
Owner:User
Parent process:openvpntray.exe (by AnchorFree Inc)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 62.50%
Windows 7 Ultimate N 25.00%
Windows 7 Professional 12.50%

Distribution by countryDistribution by country

United States installs about 50.00% of fbwmgr.exe.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Acer 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE