Threat Database Potentially Unwanted Programs Search Protect By Client Connect Ltd

Search Protect By Client Connect Ltd

By GoldSparrow in Potentially Unwanted Programs

Threat Scorecard

Ranking: 1,192
Threat Level: 50 % (Medium)
Infected Computers: 164,250
First Seen: July 7, 2014
Last Seen: April 25, 2024
OS(es) Affected: Windows

Search Protect By Client Connect Ltd is another variation of the Search Protect program, which is a potentially unwanted program that was once by Conduit. Search Protect may cause various issues on a computer where it may display advertisements or cause redirects to unwanted pages. The Search Protect ads or redirects may be an automatic process once it is loaded on your system. Various components or add-ons could cause your web browser to load alternate home pages or cause various ads to appear that also redirect you to unwanted pages. Removing the Search Protect program from your system may require using an antispyware application.

Aliases

13 security vendors flagged this file as malicious.

Anti-Virus Software Detection
GData Win64.Application.SearchProtect.AB@gen
McAfee-GW-Edition Artemis
McAfee Artemis!A2C9DD9C88B8
AVG Generic.ABF
Fortinet Riskware/ClientConnect
DrWeb Adware.Conduit.298
AVG SearchProtect.1DD
Fortinet Riskware/Searchprotect
AhnLab-V3 PUP/Win32.SearchProtect
Sophos Conduit Search Protect
Kaspersky not-a-virus:RiskTool.Win32.SearchProtect.a
K7AntiVirus Trojan ( 0049ef011 )
CAT-QuickHeal RiskTool.SearchProtect.r6 (Not a Virus)

SpyHunter Detects & Remove Search Protect By Client Connect Ltd

File System Details

Search Protect By Client Connect Ltd may create the following file(s):
# File Name MD5 Detections
1. bvyvavay.exe 3fecacabe8cd7a900ea2423d6765f040 7
2. VC32LO~1.DLL 5b7fca43cb166c8520aa436c84b78845 2
3. cltmng.exe 941663f8a1a09853bd7bb17116187e9f 2
4. cltmngui.exe 05d73dd302f1202841aaa88cfa7db648 2
5. VC32LO~1.DLL 106fc33504ded471797f3650a3059885 1
6. CltMngSvc.exe 88556832027cdeb45394b5883df00a16 1
7. VC64Loader.dll c1d32b1462f6c92c507b157ea00caaba 1
8. VC32LO~1.DLL eeeb6458a904dbddb2e30d3190476c29 1
9. CltMngSvc.exe 7b3a081c41d97c366fb78b7042c08994 1
10. SPPD.sys bf47089977bba0a0fe4aa9b7bfcf310d 1
11. cltmngui.exe 52a4d97313e888b35cbaa8b6c01183d8 1
12. cltmng.exe 1f8f074bd28e69db6b0d36733f0d41ea 1
13. SPPD.sys bc93b6c15237718a06bb325c49071abf 1
14. CltMngSvc.exe 23a89e668465ee970182c5812deb5c74 1
15. VC64LO~1.DLL 07da861511af296a7f64c3afa2da1a2f 1
16. CltMngSvc.exe 50ce1e27440dc18eb5252955a74e62ec 1
17. VC32LO~1.DLL 91ac133097d92c10f3632172ae14c2d6 1
18. VC32LO~1.DLL 0b7c31a875f05a4664911b1e5d4335bb 1
19. SPPD.sys 68d7304239069573a46d384cd71f5ec3 1
20. VC32LO~1.DLL b1bbd3ddc3c7556e053d00019c83eb44 1
21. VC64LO~1.DLL cea1f3c1147a4564be99bc406c2ac71a 1
22. VC32Loader.dll 98d147ccd483cb71926dfaad168c48f8 1
23. VC64LO~1.DLL 11d05707c3f825000e5b27a5c4e209d2 1
24. VC32LO~1.DLL 7bccece3b36ef34e5ab24a8a7114cbad 1
25. VC32Loader.dll 20a8b186142a0f70e3e89e04cf3c34ea 1
26. VC64LO~1.DLL c598cc2ada03e90b588957e9a2ff7715 1
27. VC32LO~1.DLL 8c81ca4fe5deb7bdad504896864d5b49 1
More files

Registry Details

Search Protect By Client Connect Ltd may create the following registry entry or registry entries:
CLSID
{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
File name without path
OrbiterInstaller[1].exe
Regexp file mask
%PROGRAMFILES%\SearchProtect\Main\bin\CltMngSvc.exe
%PROGRAMFILES%\SearchProtect\SearchProtect\bin\SPVC32Loader.dll
%PROGRAMFILES(x86)%\SearchProtect\Main\bin\CltMngSvc.exe
%PROGRAMFILES(x86)%\SearchProtect\SearchProtect\bin\SPVC32Loader.dll
%PROGRAMFILES(x86)%\SearchProtect\SearchProtect\bin\SPVC64Loader.dll
%PROGRAMFILES(x86)%\SearchProtect\SearchProtect\bin\VC64Loader.dll
%WINDIR%\AppPatch\AppPatch64\VCLdr64.dll
%WINDIR%\AppPatch\Custom\Custom64\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb
%WINDIR%\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
%WINDIR%\AppPatch\nbin\VC32Loader.dll
%WINDIR%\system32\SearchProtectService.exe
%WinDir%\System32\Tasks\avaavaevy[RANDOM CHARACTERS]
%WinDir%\System32\Tasks\avaavxvyex
%WinDir%\System32\Tasks\avabvbavad
%WinDir%\System32\Tasks\avabvbxvh
%WinDir%\System32\Tasks\avabvbyvyb
%WinDir%\System32\Tasks\avabvbyvyc
%WinDir%\System32\Tasks\avabvdxvy
%WinDir%\System32\Tasks\avabvexvac
%WINDIR%\System32\Tasks\avabvyxvdy
%WINDIR%\System32\Tasks\avaxvavya
%WinDir%\System32\Tasks\avaxvbxvgx
%windir%\System32\Tasks\avayvaxvaa
%WinDir%\System32\Tasks\bvxvaxxvyd
%WinDir%\System32\Tasks\bvxvbvef
%WinDir%\System32\Tasks\bvxvbxvd
%WinDir%\System32\Tasks\bvxvbxxvaa
%WinDir%\System32\Tasks\bvxvbyxvaa
%WinDir%\System32\Tasks\bvxvcxxvaf
%WinDir%\System32\Tasks\bvxvcyxvyy
%WinDir%\System32\Tasks\bvxvdxvx
%WinDir%\System32\Tasks\bvxvexvbg
%WinDir%\System32\Tasks\bvxvgxvyy
%WinDir%\System32\Tasks\bvxvyxvgy
%WinDir%\System32\Tasks\bvxvyxxvcy
%WinDir%\System32\Tasks\bvyvavay
%WinDir%\System32\Tasks\bvyvbvhx
%WinDir%\System32\Tasks\bvyvbvyb
%WinDir%\System32\Tasks\bvyvbvyf
%WINDIR%\SysWOW64\SearchProtectService.exe
%WinDir%\Tasks\avaavxvyex[RANDOM CHARACTERS]
%WinDir%\Tasks\avabvbxvh[RANDOM CHARACTERS]
%WinDir%\Tasks\avaxvbxvgx[RANDOM CHARACTERS]
%WinDir%\Tasks\bvxvcxxvaf.job
%WinDir%\Tasks\bvxvdxvx[RANDOM CHARACTERS]
Software\Conduit_Search_Protect
Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Software\Microsoft\Internet Explorer\SearchScopes\{015DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SearchProtect
SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\chrome.exe\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\chrome.exe\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb
SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\explorer.xxx\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\explorer.zza\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb
SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\firefox.exe\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\iexplore.exe\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\iexplore.exe\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb
SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\Layers\VC32Ldr
SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\software_removal_tool.exe\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\software_reporter_tool.exe\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\InstalledSDB\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\InstalledSDB\{cf2797aa-b7ec-e311-8ed9-005056c00008}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avaavxvyex
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avabvbavad
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avabvbxvh
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avabvbyvyb
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avabvbyvyc
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avabvdxvy
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avabvexvac
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avabvyxvdy
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avaxvbxvgx
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvavc
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvaxxvyd
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvbvef
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvbxvd
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvbxxvaa
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvbyxvaa
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvcxxvaf
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvcyxvyy
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvdxvx
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvexvbg
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvgxvyy
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvyxvec
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvyxvgy
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvyxxvcy
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvyvavay
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvyvbvhx
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvyvbvyb
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvyvbvyf
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\ORBTR
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sonocontrol
Software\Microsoft\Windows\CurrentVersion\Run\SearchProtect
SOFTWARE\ORBTR
Software\SearchProtect
Software\SearchProtectIN4T
Software\SearchProtectINT
Software\SearchProtectINT2
Software\SearchProtectWS
SOFTWARE\SPPDCOM
SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost\ORBTR
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\sonocontrol
SOFTWARE\Wow6432Node\ORBTR
SOFTWARE\Wow6432Node\SearchProtect
SOFTWARE\Wow6432Node\SPPDCOM
SYSTEM\ControlSet001\Enum\Root\LEGACY_SPPD
SYSTEM\ControlSet001\services\CltMngSvc
SYSTEM\ControlSet001\services\Orbiter
SYSTEM\ControlSet001\services\SPPD
SYSTEM\ControlSet001\services\SPS
SYSTEM\ControlSet002\Enum\Root\LEGACY_SPPD
SYSTEM\ControlSet002\services\CltMngSvc
SYSTEM\ControlSet002\services\Orbiter
SYSTEM\ControlSet002\services\SPPD
SYSTEM\ControlSet002\services\SPS
SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SPPD
SYSTEM\CurrentControlSet\services\CltMngSvc
SYSTEM\CurrentControlSet\services\Orbiter
SYSTEM\CurrentControlSet\services\SPPD
SYSTEM\CurrentControlSet\services\SPS
SearchProtect
Setup Support for SearchProtect
{2AEF02C3-5159-4C81-A688-8D954F0DEE56}_NewSearch

Directories

Search Protect By Client Connect Ltd may create the following directory or directories:

%AppData%\SearchProtect
%LOCALAPPDATA%\GuardboxEngine
%LOCALAPPDATA%\NextSearch
%LOCALAPPDATA%\avaavaevy
%LOCALAPPDATA%\avaavxvyex
%LOCALAPPDATA%\avabvbavad
%LOCALAPPDATA%\avabvbxvh
%LOCALAPPDATA%\avabvbyvyb
%LOCALAPPDATA%\avabvbyvyc
%LOCALAPPDATA%\avabvcxvyx
%LOCALAPPDATA%\avabvdxvy
%LOCALAPPDATA%\avabvexvac
%LOCALAPPDATA%\avabvyxvdy
%LOCALAPPDATA%\avaxvbxvgx
%LOCALAPPDATA%\avayvaxxvae
%LOCALAPPDATA%\avayvxvaxc
%LOCALAPPDATA%\bvxvavc
%LOCALAPPDATA%\bvxvaxxvyd
%LOCALAPPDATA%\bvxvbvbh
%LOCALAPPDATA%\bvxvbvef
%LOCALAPPDATA%\bvxvbxvd
%LOCALAPPDATA%\bvxvbxxvaa
%LOCALAPPDATA%\bvxvbyxvaa
%LOCALAPPDATA%\bvxvcxxvaf
%LOCALAPPDATA%\bvxvcyxvyy
%LOCALAPPDATA%\bvxvdxvx
%LOCALAPPDATA%\bvxvexvbg
%LOCALAPPDATA%\bvxvgxvyy
%LOCALAPPDATA%\bvxvhxvh
%LOCALAPPDATA%\bvxvyxvec
%LOCALAPPDATA%\bvxvyxvgy
%LOCALAPPDATA%\bvxvyxxvcy
%LOCALAPPDATA%\bvyvavay
%LOCALAPPDATA%\bvyvbvhx
%LOCALAPPDATA%\bvyvbvyb
%LOCALAPPDATA%\bvyvbvyf
%LOCALAPPDATA%\bvyvcvbb
%LOCALAPPDATA%\bvyvdvag
%LOCALAPPDATA%\bvyvdvyh
%LocalAppData%\SearchProtect
%PROGRAMFILES%\GuardboxEngine
%PROGRAMFILES%\NextSearch
%PROGRAMFILES%\ORBTR
%PROGRAMFILES%\Search-Protect
%PROGRAMFILES%\SearchProtect
%PROGRAMFILES%\Setup Support for SearchProtect
%PROGRAMFILES(x86)%\GuardboxEngine
%PROGRAMFILES(x86)%\NextSearch
%PROGRAMFILES(x86)%\ORBTR
%PROGRAMFILES(x86)%\Search-Protect
%PROGRAMFILES(x86)%\SearchProtect
%PROGRAMFILES(x86)%\Setup Support for SearchProtect
%PROGRAMFILES(x86)%\sp-downloader
%USERPROFILE%\Configuración local\Datos de programa\SearchProtect
%USERPROFILE%\Configurações Locais\Dados de aplicativos\SearchProtect
%USERPROFILE%\Impostazioni locali\Dati applicazioni\SearchProtect
%USERPROFILE%\Local Settings\Application Data\avabvbxvh
%USERPROFILE%\Lokale Einstellungen\Anwendungsdaten\SearchProtect
%USERPROFILE%\Ustawienia lokalne\Dane aplikacji\SearchProtect
%UserProfile%\Local Settings\Application Data\GuardboxEngine
%UserProfile%\Local Settings\Application Data\SearchProtect
%UserProfile%\Local Settings\Application Data\avaavaevy
%UserProfile%\Local Settings\Application Data\avaavxvyex
%UserProfile%\Local Settings\Application Data\avabvbavad
%UserProfile%\Local Settings\Application Data\avabvexvac
%UserProfile%\Local Settings\Application Data\avaxvbxvgx
%UserProfile%\Local Settings\Application Data\avayvaxxvae
%UserProfile%\Local Settings\Application Data\avayvxvaxc
%UserProfile%\Local Settings\Application Data\bvxvbvef
%UserProfile%\Local Settings\Application Data\bvxvdxvx
%UserProfile%\Local Settings\Application Data\bvxvexvbg
%UserProfile%\Local Settings\Application Data\bvxvgxvyy
%UserProfile%\Local Settings\Application Data\bvxvhxvh
%UserProfile%\Local Settings\Application Data\bvxvyxvec
%UserProfile%\Local Settings\Application Data\bvxvyxxvcy
%WINDIR%\SysWOW64\config\systemprofile\AppData\Local\SearchProtect
%WINDIR%\System32\config\systemprofile\AppData\Local\SearchProtect
%WinDir%\SysWOW64\SearchProtect
%WinDir%\System32\SearchProtect

Trending

Most Viewed

Loading...