datamngrui.exe

Bandoo Media, Inc

The application datamngrui.exe by Bandoo Media, Inc has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘DATAMNGR’. This file is typically installed with the program Windows Searchqu Toolbar by Bandoo Media Inc which is a potentially unwanted software program.
Publisher:
Bandoo Media, Inc  (signed and verified)

MD5:
2ed9c81918815af05d81159955fc3643

SHA-1:
61f840693cae61d77e397b9b7c9b8363c2b7ec73

SHA-256:
b92fd9286c4c483a2662fcf691f38b4297c3e70facfb7e4ca6d73339e870dacb

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/24/2024 11:34:02 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.BandooToolbar (M)
17.1.28.19

File size:
1.6 MB (1,694,608 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\windows searchqu toolbar\datamngr\datamngrui.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
11/3/2010 9:00:00 AM

Valid to:
11/3/2012 8:59:59 AM

Subject:
CN="Bandoo Media, Inc", O="Bandoo Media, Inc", L=Panama City, S=Panama, C=PA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
7AD02DB75E76EA8D8CF4A4D1C2591229

File PE Metadata
Compilation timestamp:
11/10/2011 9:03:44 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0xF8288

Entry point:
E8, 4B, B8, 00, 00, E9, 79, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D, 08, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, A4, 01, 00, 00, 81, F9, 00, 01, 00, 00, 72, 1F, 83, 3D, 08, 19, 55, 00, 00, 74, 16, 57, 56, 83, E7, 0F, 83, E6, 0F, 3B, FE, 5E, 5F, 75, 08, 5E, 5F, 5D, E9, 0E, B9, 00, 00, F7, C7, 03, 00, 00, 00, 75, 15, C1, E9, 02, 83, E2, 03, 83, F9, 08, 72, 2A, F3, A5, FF, 24, 95, 14, 84, 4F, 00, 90, 8B, C7, BA, 03...
 
[+]

Entropy:
6.1637

Code size:
1.1 MB (1,167,872 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
DATAMNGR

Command:
C:\Program Files2\wia6eb~1\datamngr\datamn~1.exe


The file datamngrui.exe has been discovered within the following programs.

Windows Searchqu Toolbar  by Bandoo Media Inc
Windows Searchqu Toolbar is an ad-supported program installed into Internet Explorer, Firefox and Chrome.
www.searchqu.com
88% remove it
 
Powered by Should I Remove It?

Remove datamngrui.exe - Powered by Reason Core Security