Should I block it?
Yes, 98% block recommendation.
Possible reasons:
Multiple malware detections
Performance resource utilization
Additional versions
Relationships
umbrella.exe
Iminent Protection by Iminent (Signed)
| Version: | 3.4.5.2 |
| MD5: | 791227582a5070bd78b7e05285d13446 |
| SHA1: | c6179024480270544c0380c0dcfcc10d55bcba64 |
| SHA256: | 0539d3d434e1743bb0b3caea14fbfd5c62a8e38e5ca1fb8dc3bd7cb36ca68002 |
Warning 3 antivirus scanners has detected malware.
Overview
umbrella.exe is malware that runs as a service under the name SProtection with extensive SYSTEM privileges (full administrator access). The file is digitally signed by Iminent which was issued by the GlobalSign nv-sa certificate authority (CA).
Details
| File name: | umbrella.exe |
| Publisher: | Iminent |
| Product name: | Iminent Protection |
| Typical file path: | C:\Program Files\common files\umbrella\umbrella.exe |
| File version: | 3.4.5.2 |
| Size: | 2.54 MB (2,663,976 bytes) |
| Certificate |
| Issued to: | Iminent |
| Authority (CA): | GlobalSign nv-sa |
| Digital DNA |
| File packed: | No |
| .NET CLR: | No |
More details
Behaviors
Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
Malware detections
Based on 40+ industry antivirus scanners, 3 of them detected the following malware.
| Antivirus engine | Engine version | Detection |
| Dr.Web |
8.13.9.26 |
Adware.BGuard.13 |
| Malwarebytes |
1.75.0.1 |
PUP.Optional.Iminent |
| VIPRE Antivirus |
22588 |
Iminent (fs) |
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
| CPU |
| Total CPU: | 0.00018191% | |
| Kernel CPU: | 0.00011902% | |
| User CPU: | 0.00006288% | |
| Kernel CPU time: | 265 ms/min | |
| CPU cycles: | 115,147/sec | |
| Memory |
| Private memory: | 3.67 MB | |
| Private (maximum): | 2.77 MB | |
| Private (minimum): | 248 KB | |
| Non-paged memory: | 3.67 MB | |
| Virtual memory: | 70.25 MB | |
| Virtual memory (peak): | 75.98 MB | |
| Working set: | 340 KB | |
| Working set (peak): | 7.66 MB | |
| Page faults: | 15,106/min | |
| I/O |
| I/O read transfer: | 0 Bytes/sec | |
| I/O read operations: | 1/sec | |
| I/O write transfer: | 0 Bytes/sec | |
| I/O write operations: | 1/sec | |
| I/O other transfer: | 25 Bytes/sec | |
| I/O other operations: | 1/sec | |
| Resource allocations |
| Threads: | 5 | |
| Handles: | 160 | |
Process properties
Threads
Averages
| sechost.dll |
| Total CPU: | 0.00022421% | |
| Kernel CPU: | 0.00012612% | |
| User CPU: | 0.00009809% | |
| CPU cycles: | 84,291/sec | |
| Memory: | 100 KB | |
| umbrella.exe (main module) |
| Total CPU: | 0.00005605% | |
| Kernel CPU: | 0.00005605% | |
| User CPU: | 0.00000000% | |
| CPU cycles: | 1,234/sec | |
| Memory: | 2.58 MB | |
Distribution by Windows OS
| OS version | distribution |
| Windows 7 Home Premium |
40.00% |
|
| Windows 7 Ultimate |
30.00% |
|
| Windows Vista Home Premium |
10.00% |
|
| Windows 8 Pro |
10.00% |
|
| Microsoft Windows XP |
10.00% |
|
Distribution by country
United States installs about 50.00% of Iminent Protection.
Distribution by PC manufacturer
| PC Manufacturer | distribution |
| ASUS |
40.00% |
|
| Toshiba |
20.00% |
|
| Dell |
20.00% |
|
| Acer |
10.00% |
|
| Hewlett-Packard |
10.00% |
|